gost_keywrap.h revision 296341
1/**********************************************************************
2 *                         gost_keywrap.h                             *
3 *             Copyright (c) 2005-2006 Cryptocom LTD                  *
4 *       This file is distributed under the same license as OpenSSL   *
5 *                                                                    *
6 * Implementation of CryptoPro key wrap algorithm, as defined in      *
7 * RFC 4357 p 6.3 and 6.4                                             *
8 * Doesn't need OpenSSL                                               *
9 **********************************************************************/
10#ifndef GOST_KEYWRAP_H
11# define GOST_KEYWRAP_H
12# include <string.h>
13# include "gost89.h"
14/*-
15 * Diversifies key using random UserKey Material
16 * Implements RFC 4357 p 6.5 key diversification algorithm
17 *
18 * inputKey - 32byte key to be diversified
19 * ukm - 8byte user key material
20 * outputKey - 32byte buffer to store diversified key
21 *
22 */
23void keyDiversifyCryptoPro(gost_ctx * ctx,
24                           const unsigned char *inputKey,
25                           const unsigned char *ukm,
26                           unsigned char *outputKey);
27/*-
28 * Wraps key using RFC 4357 6.3
29 * ctx - gost encryption context, initialized with some S-boxes
30 * keyExchangeKey (KEK) 32-byte (256-bit) shared key
31 * ukm - 8 byte (64 bit) user key material,
32 * sessionKey - 32-byte (256-bit) key to be wrapped
33 * wrappedKey - 44-byte buffer to store wrapped key
34 */
35
36int keyWrapCryptoPro(gost_ctx * ctx,
37                     const unsigned char *keyExchangeKey,
38                     const unsigned char *ukm,
39                     const unsigned char *sessionKey,
40                     unsigned char *wrappedKey);
41/*-
42 * Unwraps key using RFC 4357 6.4
43 * ctx - gost encryption context, initialized with some S-boxes
44 * keyExchangeKey 32-byte shared key
45 * wrappedKey  44 byte key to be unwrapped (concatenation of 8-byte UKM,
46 * 32 byte  encrypted key and 4 byte MAC
47 *
48 * sessionKEy - 32byte buffer to store sessionKey in
49 * Returns 1 if key is decrypted successfully, and 0 if MAC doesn't match
50 */
51
52int keyUnwrapCryptoPro(gost_ctx * ctx,
53                       const unsigned char *keyExchangeKey,
54                       const unsigned char *wrappedKey,
55                       unsigned char *sessionKey);
56#endif
57