Line data Source code
1 : #ifndef HEADER_fd_src_ballet_rsa_fd_rsa_h 2 : #define HEADER_fd_src_ballet_rsa_fd_rsa_h 3 : 4 : /* fd_rsa.h provides RSA signature verification (RFC 8017) for 5 : RSASSA-PKCS1-v1_5 and RSASSA-PSS with SHA-{256,384,512}. 6 : Accepts moduli of 2048 to 4096 bits and public exponents of at most 7 : 64 bits. */ 8 : 9 : #include "../fd_ballet_base.h" 10 : 11 2409 : #define FD_RSA_SUCCESS (1) 12 2970 : #define FD_RSA_FAILURE (0) 13 : 14 : /* Accepted modulus size range, in bits */ 15 : 16 : #define FD_RSA_MOD_BITS_MIN (2048UL) 17 : #define FD_RSA_MOD_BITS_MAX (4096UL) 18 : 19 : /* FD_RSA_MOD_SZ_MAX is the max modulus (and thus signature) size in 20 : bytes. FD_RSA_LIMB_CNT_MAX is the corresponding limb count. */ 21 : 22 : #define FD_RSA_MOD_SZ_MAX (FD_RSA_MOD_BITS_MAX/8UL) 23 : #define FD_RSA_LIMB_CNT_MAX (FD_RSA_MOD_SZ_MAX/8UL) 24 : 25 : /* Hash functions used with RSA signatures */ 26 : 27 32979 : #define FD_RSA_HASH_SHA256 (0) 28 2454 : #define FD_RSA_HASH_SHA384 (1) 29 1836 : #define FD_RSA_HASH_SHA512 (2) 30 : 31 : /* fd_rsa_pubkey_t is a parsed RSA public key. Limbs are little endian 32 : 64-bit words. */ 33 : 34 : struct fd_rsa_pubkey { 35 : ulong n[ FD_RSA_LIMB_CNT_MAX ]; 36 : ulong e; 37 : ulong limb_cnt; /* limbs in n */ 38 : ulong n_sz; /* modulus size in bytes, ceil(mod_bits/8) */ 39 : ulong mod_bits; /* modulus size in bits */ 40 : }; 41 : 42 : typedef struct fd_rsa_pubkey fd_rsa_pubkey_t; 43 : 44 : FD_PROTOTYPES_BEGIN 45 : 46 : /* fd_rsa_pubkey_init loads a public key from big endian modulus 47 : [n,n+n_sz) and public exponent [e,e+e_sz). Leading zero bytes are 48 : permitted. Returns key on success and NULL if the key is rejected: 49 : modulus even or outside [FD_RSA_MOD_BITS_MIN,FD_RSA_MOD_BITS_MAX] 50 : bits, or exponent even, smaller than 3, or larger than 64 bits. */ 51 : 52 : fd_rsa_pubkey_t * 53 : fd_rsa_pubkey_init( fd_rsa_pubkey_t * key, 54 : uchar const * n, 55 : ulong n_sz, 56 : uchar const * e, 57 : ulong e_sz ); 58 : 59 : /* fd_rsa_verify_pkcs1_v15 verifies an RSASSA-PKCS1-v1_5 signature 60 : (RFC 8017 Section 8.2.2) over msg. hash is FD_RSA_HASH_{...}. 61 : sig_sz must equal key->n_sz. Returns FD_RSA_SUCCESS if the 62 : signature is valid and FD_RSA_FAILURE otherwise. */ 63 : 64 : int 65 : fd_rsa_verify_pkcs1_v15( fd_rsa_pubkey_t const * key, 66 : uchar const * sig, 67 : ulong sig_sz, 68 : uchar const * msg, 69 : ulong msg_sz, 70 : int hash ); 71 : 72 : /* fd_rsa_verify_pss verifies an RSASSA-PSS signature (RFC 8017 Section 73 : 8.1.2) over msg with MGF1 over the same hash and a salt length equal 74 : to the hash length, as TLS 1.3 requires (RFC 8446 Section 4.2.3). 75 : Returns FD_RSA_SUCCESS if the signature is valid and FD_RSA_FAILURE 76 : otherwise. */ 77 : 78 : int 79 : fd_rsa_verify_pss( fd_rsa_pubkey_t const * key, 80 : uchar const * sig, 81 : ulong sig_sz, 82 : uchar const * msg, 83 : ulong msg_sz, 84 : int hash ); 85 : 86 : FD_PROTOTYPES_END 87 : 88 : #endif /* HEADER_fd_src_ballet_rsa_fd_rsa_h */