| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 1 | /** | 
|  | 2 | * PSA API key derivation demonstration | 
|  | 3 | * | 
|  | 4 | * This program calculates a key ladder: a chain of secret material, each | 
|  | 5 | * derived from the previous one in a deterministic way based on a label. | 
|  | 6 | * Two keys are identical if and only if they are derived from the same key | 
|  | 7 | * using the same label. | 
|  | 8 | * | 
|  | 9 | * The initial key is called the master key. The master key is normally | 
|  | 10 | * randomly generated, but it could itself be derived from another key. | 
|  | 11 | * | 
|  | 12 | * This program derives a series of keys called intermediate keys. | 
|  | 13 | * The first intermediate key is derived from the master key using the | 
|  | 14 | * first label passed on the command line. Each subsequent intermediate | 
|  | 15 | * key is derived from the previous one using the next label passed | 
|  | 16 | * on the command line. | 
|  | 17 | * | 
|  | 18 | * This program has four modes of operation: | 
|  | 19 | * | 
|  | 20 | * - "generate": generate a random master key. | 
|  | 21 | * - "wrap": derive a wrapping key from the last intermediate key, | 
|  | 22 | *           and use that key to encrypt-and-authenticate some data. | 
|  | 23 | * - "unwrap": derive a wrapping key from the last intermediate key, | 
|  | 24 | *             and use that key to decrypt-and-authenticate some | 
|  | 25 | *             ciphertext created by wrap mode. | 
|  | 26 | * - "save": save the last intermediate key so that it can be reused as | 
|  | 27 | *           the master key in another run of the program. | 
|  | 28 | * | 
|  | 29 | * See the usage() output for the command line usage. See the file | 
|  | 30 | * `key_ladder_demo.sh` for an example run. | 
|  | 31 | */ | 
|  | 32 |  | 
| Bence Szépkúti | 8697465 | 2020-06-15 11:59:37 +0200 | [diff] [blame] | 33 | /* | 
| Bence Szépkúti | 1e14827 | 2020-08-07 13:07:28 +0200 | [diff] [blame] | 34 | *  Copyright The Mbed TLS Contributors | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 35 | *  SPDX-License-Identifier: Apache-2.0 | 
|  | 36 | * | 
|  | 37 | *  Licensed under the Apache License, Version 2.0 (the "License"); you may | 
|  | 38 | *  not use this file except in compliance with the License. | 
|  | 39 | *  You may obtain a copy of the License at | 
|  | 40 | * | 
|  | 41 | *  http://www.apache.org/licenses/LICENSE-2.0 | 
|  | 42 | * | 
|  | 43 | *  Unless required by applicable law or agreed to in writing, software | 
|  | 44 | *  distributed under the License is distributed on an "AS IS" BASIS, WITHOUT | 
|  | 45 | *  WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | 
|  | 46 | *  See the License for the specific language governing permissions and | 
|  | 47 | *  limitations under the License. | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 48 | */ | 
|  | 49 |  | 
|  | 50 | /* First include Mbed TLS headers to get the Mbed TLS configuration and | 
|  | 51 | * platform definitions that we'll use in this program. Also include | 
|  | 52 | * standard C headers for functions we'll use here. */ | 
|  | 53 | #if !defined(MBEDTLS_CONFIG_FILE) | 
|  | 54 | #include "mbedtls/config.h" | 
|  | 55 | #else | 
|  | 56 | #include MBEDTLS_CONFIG_FILE | 
|  | 57 | #endif | 
|  | 58 |  | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 59 | #include <stdlib.h> | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 60 | #include <stdio.h> | 
|  | 61 | #include <string.h> | 
|  | 62 |  | 
|  | 63 | #include "mbedtls/platform_util.h" // for mbedtls_platform_zeroize | 
|  | 64 |  | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 65 | #include <psa/crypto.h> | 
|  | 66 |  | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 67 | /* If the build options we need are not enabled, compile a placeholder. */ | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 68 | #if !defined(MBEDTLS_SHA256_C) || !defined(MBEDTLS_MD_C) ||      \ | 
|  | 69 | !defined(MBEDTLS_AES_C) || !defined(MBEDTLS_CCM_C) ||        \ | 
|  | 70 | !defined(MBEDTLS_PSA_CRYPTO_C) || !defined(MBEDTLS_FS_IO) || \ | 
|  | 71 | defined(MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER) | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 72 | int main( void ) | 
|  | 73 | { | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 74 | printf( "MBEDTLS_SHA256_C and/or MBEDTLS_MD_C and/or " | 
|  | 75 | "MBEDTLS_AES_C and/or MBEDTLS_CCM_C and/or " | 
|  | 76 | "MBEDTLS_PSA_CRYPTO_C and/or MBEDTLS_FS_IO " | 
|  | 77 | "not defined and/or MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER " | 
|  | 78 | "defined.\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 79 | return( 0 ); | 
|  | 80 | } | 
|  | 81 | #else | 
|  | 82 |  | 
|  | 83 | /* The real program starts here. */ | 
|  | 84 |  | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 85 | /* Run a system function and bail out if it fails. */ | 
|  | 86 | #define SYS_CHECK( expr )                                       \ | 
|  | 87 | do                                                          \ | 
|  | 88 | {                                                           \ | 
|  | 89 | if( ! ( expr ) )                                        \ | 
|  | 90 | {                                                       \ | 
|  | 91 | perror( #expr );                                    \ | 
|  | 92 | status = DEMO_ERROR;                                \ | 
|  | 93 | goto exit;                                          \ | 
|  | 94 | }                                                       \ | 
|  | 95 | }                                                           \ | 
|  | 96 | while( 0 ) | 
|  | 97 |  | 
|  | 98 | /* Run a PSA function and bail out if it fails. */ | 
|  | 99 | #define PSA_CHECK( expr )                                       \ | 
|  | 100 | do                                                          \ | 
|  | 101 | {                                                           \ | 
|  | 102 | status = ( expr );                                      \ | 
|  | 103 | if( status != PSA_SUCCESS )                             \ | 
|  | 104 | {                                                       \ | 
| Kenneth Soerensen | 518d435 | 2020-04-01 17:22:45 +0200 | [diff] [blame] | 105 | printf( "Error %d at line %d: %s\n",                \ | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 106 | (int) status,                               \ | 
|  | 107 | __LINE__,                                   \ | 
|  | 108 | #expr );                                    \ | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 109 | goto exit;                                          \ | 
|  | 110 | }                                                       \ | 
|  | 111 | }                                                           \ | 
|  | 112 | while( 0 ) | 
|  | 113 |  | 
|  | 114 | /* To report operational errors in this program, use an error code that is | 
|  | 115 | * different from every PSA error code. */ | 
|  | 116 | #define DEMO_ERROR 120 | 
|  | 117 |  | 
|  | 118 | /* The maximum supported key ladder depth. */ | 
|  | 119 | #define MAX_LADDER_DEPTH 10 | 
|  | 120 |  | 
|  | 121 | /* Salt to use when deriving an intermediate key. */ | 
|  | 122 | #define DERIVE_KEY_SALT ( (uint8_t *) "key_ladder_demo.derive" ) | 
|  | 123 | #define DERIVE_KEY_SALT_LENGTH ( strlen( (const char*) DERIVE_KEY_SALT ) ) | 
|  | 124 |  | 
|  | 125 | /* Salt to use when deriving a wrapping key. */ | 
|  | 126 | #define WRAPPING_KEY_SALT ( (uint8_t *) "key_ladder_demo.wrap" ) | 
|  | 127 | #define WRAPPING_KEY_SALT_LENGTH ( strlen( (const char*) WRAPPING_KEY_SALT ) ) | 
|  | 128 |  | 
|  | 129 | /* Size of the key derivation keys (applies both to the master key and | 
|  | 130 | * to intermediate keys). */ | 
|  | 131 | #define KEY_SIZE_BYTES 40 | 
|  | 132 |  | 
|  | 133 | /* Algorithm for key derivation. */ | 
|  | 134 | #define KDF_ALG PSA_ALG_HKDF( PSA_ALG_SHA_256 ) | 
|  | 135 |  | 
|  | 136 | /* Type and size of the key used to wrap data. */ | 
|  | 137 | #define WRAPPING_KEY_TYPE PSA_KEY_TYPE_AES | 
|  | 138 | #define WRAPPING_KEY_BITS 128 | 
|  | 139 |  | 
|  | 140 | /* Cipher mode used to wrap data. */ | 
|  | 141 | #define WRAPPING_ALG PSA_ALG_CCM | 
|  | 142 |  | 
|  | 143 | /* Nonce size used to wrap data. */ | 
|  | 144 | #define WRAPPING_IV_SIZE 13 | 
|  | 145 |  | 
|  | 146 | /* Header used in files containing wrapped data. We'll save this header | 
|  | 147 | * directly without worrying about data representation issues such as | 
|  | 148 | * integer sizes and endianness, because the data is meant to be read | 
|  | 149 | * back by the same program on the same machine. */ | 
|  | 150 | #define WRAPPED_DATA_MAGIC "key_ladder_demo" // including trailing null byte | 
|  | 151 | #define WRAPPED_DATA_MAGIC_LENGTH ( sizeof( WRAPPED_DATA_MAGIC ) ) | 
|  | 152 | typedef struct | 
|  | 153 | { | 
|  | 154 | char magic[WRAPPED_DATA_MAGIC_LENGTH]; | 
|  | 155 | size_t ad_size; /* Size of the additional data, which is this header. */ | 
|  | 156 | size_t payload_size; /* Size of the encrypted data. */ | 
|  | 157 | /* Store the IV inside the additional data. It's convenient. */ | 
|  | 158 | uint8_t iv[WRAPPING_IV_SIZE]; | 
|  | 159 | } wrapped_data_header_t; | 
|  | 160 |  | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 161 | /* The modes that this program can operate in (see usage). */ | 
|  | 162 | enum program_mode | 
|  | 163 | { | 
|  | 164 | MODE_GENERATE, | 
|  | 165 | MODE_SAVE, | 
|  | 166 | MODE_UNWRAP, | 
|  | 167 | MODE_WRAP | 
|  | 168 | }; | 
|  | 169 |  | 
|  | 170 | /* Save a key to a file. In the real world, you may want to export a derived | 
|  | 171 | * key sometimes, to share it with another party. */ | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 172 | static psa_status_t save_key( psa_key_id_t key, | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 173 | const char *output_file_name ) | 
|  | 174 | { | 
|  | 175 | psa_status_t status = PSA_SUCCESS; | 
|  | 176 | uint8_t key_data[KEY_SIZE_BYTES]; | 
|  | 177 | size_t key_size; | 
|  | 178 | FILE *key_file = NULL; | 
|  | 179 |  | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 180 | PSA_CHECK( psa_export_key( key, | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 181 | key_data, sizeof( key_data ), | 
|  | 182 | &key_size ) ); | 
|  | 183 | SYS_CHECK( ( key_file = fopen( output_file_name, "wb" ) ) != NULL ); | 
|  | 184 | SYS_CHECK( fwrite( key_data, 1, key_size, key_file ) == key_size ); | 
|  | 185 | SYS_CHECK( fclose( key_file ) == 0 ); | 
|  | 186 | key_file = NULL; | 
|  | 187 |  | 
|  | 188 | exit: | 
|  | 189 | if( key_file != NULL) | 
|  | 190 | fclose( key_file ); | 
|  | 191 | return( status ); | 
|  | 192 | } | 
|  | 193 |  | 
|  | 194 | /* Generate a master key for use in this demo. | 
|  | 195 | * | 
|  | 196 | * Normally a master key would be non-exportable. For the purpose of this | 
|  | 197 | * demo, we want to save it to a file, to avoid relying on the keystore | 
|  | 198 | * capability of the PSA crypto library. */ | 
|  | 199 | static psa_status_t generate( const char *key_file_name ) | 
|  | 200 | { | 
|  | 201 | psa_status_t status = PSA_SUCCESS; | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 202 | psa_key_id_t key = 0; | 
| Gilles Peskine | dfea0a25 | 2019-04-18 13:39:40 +0200 | [diff] [blame] | 203 | psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 204 |  | 
| Gilles Peskine | dfea0a25 | 2019-04-18 13:39:40 +0200 | [diff] [blame] | 205 | psa_set_key_usage_flags( &attributes, | 
|  | 206 | PSA_KEY_USAGE_DERIVE | PSA_KEY_USAGE_EXPORT ); | 
|  | 207 | psa_set_key_algorithm( &attributes, KDF_ALG ); | 
|  | 208 | psa_set_key_type( &attributes, PSA_KEY_TYPE_DERIVE ); | 
| Gilles Peskine | 3a4f1f8 | 2019-04-26 13:49:28 +0200 | [diff] [blame] | 209 | psa_set_key_bits( &attributes, PSA_BYTES_TO_BITS( KEY_SIZE_BYTES ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 210 |  | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 211 | PSA_CHECK( psa_generate_key( &attributes, &key ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 212 |  | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 213 | PSA_CHECK( save_key( key, key_file_name ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 214 |  | 
|  | 215 | exit: | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 216 | (void) psa_destroy_key( key ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 217 | return( status ); | 
|  | 218 | } | 
|  | 219 |  | 
|  | 220 | /* Load the master key from a file. | 
|  | 221 | * | 
|  | 222 | * In the real world, this master key would be stored in an internal memory | 
|  | 223 | * and the storage would be managed by the keystore capability of the PSA | 
|  | 224 | * crypto library. */ | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 225 | static psa_status_t import_key_from_file( psa_key_usage_t usage, | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 226 | psa_algorithm_t alg, | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 227 | const char *key_file_name, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 228 | psa_key_id_t *master_key ) | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 229 | { | 
|  | 230 | psa_status_t status = PSA_SUCCESS; | 
| Gilles Peskine | dfea0a25 | 2019-04-18 13:39:40 +0200 | [diff] [blame] | 231 | psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 232 | uint8_t key_data[KEY_SIZE_BYTES]; | 
|  | 233 | size_t key_size; | 
|  | 234 | FILE *key_file = NULL; | 
|  | 235 | unsigned char extra_byte; | 
|  | 236 |  | 
|  | 237 | SYS_CHECK( ( key_file = fopen( key_file_name, "rb" ) ) != NULL ); | 
|  | 238 | SYS_CHECK( ( key_size = fread( key_data, 1, sizeof( key_data ), | 
|  | 239 | key_file ) ) != 0 ); | 
|  | 240 | if( fread( &extra_byte, 1, 1, key_file ) != 0 ) | 
|  | 241 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 242 | printf( "Key file too large (max: %u).\n", | 
|  | 243 | (unsigned) sizeof( key_data ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 244 | status = DEMO_ERROR; | 
|  | 245 | goto exit; | 
|  | 246 | } | 
|  | 247 | SYS_CHECK( fclose( key_file ) == 0 ); | 
|  | 248 | key_file = NULL; | 
|  | 249 |  | 
| Gilles Peskine | dfea0a25 | 2019-04-18 13:39:40 +0200 | [diff] [blame] | 250 | psa_set_key_usage_flags( &attributes, usage ); | 
|  | 251 | psa_set_key_algorithm( &attributes, alg ); | 
|  | 252 | psa_set_key_type( &attributes, PSA_KEY_TYPE_DERIVE ); | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 253 | PSA_CHECK( psa_import_key( &attributes, key_data, key_size, master_key ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 254 | exit: | 
|  | 255 | if( key_file != NULL ) | 
|  | 256 | fclose( key_file ); | 
|  | 257 | mbedtls_platform_zeroize( key_data, sizeof( key_data ) ); | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 258 | if( status != PSA_SUCCESS ) | 
|  | 259 | { | 
| Gilles Peskine | 5163a92 | 2019-05-27 14:52:34 +0200 | [diff] [blame] | 260 | /* If the key creation hasn't happened yet or has failed, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 261 | * *master_key is null. psa_destroy_key( 0 ) is | 
|  | 262 | * guaranteed to do nothing and return PSA_SUCCESS. */ | 
|  | 263 | (void) psa_destroy_key( *master_key ); | 
|  | 264 | *master_key = 0; | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 265 | } | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 266 | return( status ); | 
|  | 267 | } | 
|  | 268 |  | 
|  | 269 | /* Derive the intermediate keys, using the list of labels provided on | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 270 | * the command line. On input, *key is the master key identifier. | 
|  | 271 | * This function destroys the master key. On successful output, *key | 
|  | 272 | * is the identifier of the final derived key. | 
|  | 273 | */ | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 274 | static psa_status_t derive_key_ladder( const char *ladder[], | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 275 | size_t ladder_depth, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 276 | psa_key_id_t *key ) | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 277 | { | 
|  | 278 | psa_status_t status = PSA_SUCCESS; | 
| Gilles Peskine | dfea0a25 | 2019-04-18 13:39:40 +0200 | [diff] [blame] | 279 | psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 280 | psa_key_derivation_operation_t operation = PSA_KEY_DERIVATION_OPERATION_INIT; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 281 | size_t i; | 
| Gilles Peskine | dfea0a25 | 2019-04-18 13:39:40 +0200 | [diff] [blame] | 282 |  | 
|  | 283 | psa_set_key_usage_flags( &attributes, | 
|  | 284 | PSA_KEY_USAGE_DERIVE | PSA_KEY_USAGE_EXPORT ); | 
|  | 285 | psa_set_key_algorithm( &attributes, KDF_ALG ); | 
|  | 286 | psa_set_key_type( &attributes, PSA_KEY_TYPE_DERIVE ); | 
| Gilles Peskine | 3a4f1f8 | 2019-04-26 13:49:28 +0200 | [diff] [blame] | 287 | psa_set_key_bits( &attributes, PSA_BYTES_TO_BITS( KEY_SIZE_BYTES ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 288 |  | 
|  | 289 | /* For each label in turn, ... */ | 
|  | 290 | for( i = 0; i < ladder_depth; i++ ) | 
|  | 291 | { | 
|  | 292 | /* Start deriving material from the master key (if i=0) or from | 
|  | 293 | * the current intermediate key (if i>0). */ | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 294 | PSA_CHECK( psa_key_derivation_setup( &operation, KDF_ALG ) ); | 
|  | 295 | PSA_CHECK( psa_key_derivation_input_bytes( | 
|  | 296 | &operation, PSA_KEY_DERIVATION_INPUT_SALT, | 
|  | 297 | DERIVE_KEY_SALT, DERIVE_KEY_SALT_LENGTH ) ); | 
|  | 298 | PSA_CHECK( psa_key_derivation_input_key( | 
|  | 299 | &operation, PSA_KEY_DERIVATION_INPUT_SECRET, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 300 | *key ) ); | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 301 | PSA_CHECK( psa_key_derivation_input_bytes( | 
|  | 302 | &operation, PSA_KEY_DERIVATION_INPUT_INFO, | 
|  | 303 | (uint8_t*) ladder[i], strlen( ladder[i] ) ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 304 | /* When the parent key is not the master key, destroy it, | 
|  | 305 | * since it is no longer needed. */ | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 306 | PSA_CHECK( psa_destroy_key( *key ) ); | 
|  | 307 | *key = 0; | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 308 | /* Derive the next intermediate key from the parent key. */ | 
|  | 309 | PSA_CHECK( psa_key_derivation_output_key( &attributes, &operation, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 310 | key ) ); | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 311 | PSA_CHECK( psa_key_derivation_abort( &operation ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 312 | } | 
|  | 313 |  | 
|  | 314 | exit: | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 315 | psa_key_derivation_abort( &operation ); | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 316 | if( status != PSA_SUCCESS ) | 
|  | 317 | { | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 318 | psa_destroy_key( *key ); | 
|  | 319 | *key = 0; | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 320 | } | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 321 | return( status ); | 
|  | 322 | } | 
|  | 323 |  | 
|  | 324 | /* Derive a wrapping key from the last intermediate key. */ | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 325 | static psa_status_t derive_wrapping_key( psa_key_usage_t usage, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 326 | psa_key_id_t derived_key, | 
|  | 327 | psa_key_id_t *wrapping_key ) | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 328 | { | 
|  | 329 | psa_status_t status = PSA_SUCCESS; | 
| Gilles Peskine | dfea0a25 | 2019-04-18 13:39:40 +0200 | [diff] [blame] | 330 | psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 331 | psa_key_derivation_operation_t operation = PSA_KEY_DERIVATION_OPERATION_INIT; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 332 |  | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 333 | *wrapping_key = 0; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 334 |  | 
| Gilles Peskine | 2a38e24 | 2019-05-29 14:33:00 +0200 | [diff] [blame] | 335 | /* Set up a key derivation operation from the key derived from | 
|  | 336 | * the master key. */ | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 337 | PSA_CHECK( psa_key_derivation_setup( &operation, KDF_ALG ) ); | 
|  | 338 | PSA_CHECK( psa_key_derivation_input_bytes( | 
|  | 339 | &operation, PSA_KEY_DERIVATION_INPUT_SALT, | 
|  | 340 | WRAPPING_KEY_SALT, WRAPPING_KEY_SALT_LENGTH ) ); | 
|  | 341 | PSA_CHECK( psa_key_derivation_input_key( | 
|  | 342 | &operation, PSA_KEY_DERIVATION_INPUT_SECRET, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 343 | derived_key ) ); | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 344 | PSA_CHECK( psa_key_derivation_input_bytes( | 
|  | 345 | &operation, PSA_KEY_DERIVATION_INPUT_INFO, | 
|  | 346 | NULL, 0 ) ); | 
| Gilles Peskine | 2a38e24 | 2019-05-29 14:33:00 +0200 | [diff] [blame] | 347 |  | 
|  | 348 | /* Create the wrapping key. */ | 
|  | 349 | psa_set_key_usage_flags( &attributes, usage ); | 
|  | 350 | psa_set_key_algorithm( &attributes, WRAPPING_ALG ); | 
|  | 351 | psa_set_key_type( &attributes, PSA_KEY_TYPE_AES ); | 
|  | 352 | psa_set_key_bits( &attributes, WRAPPING_KEY_BITS ); | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 353 | PSA_CHECK( psa_key_derivation_output_key( &attributes, &operation, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 354 | wrapping_key ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 355 |  | 
|  | 356 | exit: | 
| Gilles Peskine | 4e2cc53 | 2019-05-29 14:30:27 +0200 | [diff] [blame] | 357 | psa_key_derivation_abort( &operation ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 358 | return( status ); | 
|  | 359 | } | 
|  | 360 |  | 
|  | 361 | static psa_status_t wrap_data( const char *input_file_name, | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 362 | const char *output_file_name, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 363 | psa_key_id_t wrapping_key ) | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 364 | { | 
|  | 365 | psa_status_t status; | 
|  | 366 | FILE *input_file = NULL; | 
|  | 367 | FILE *output_file = NULL; | 
| Bence Szépkúti | ec174e2 | 2021-03-19 18:46:15 +0100 | [diff] [blame] | 368 | psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; | 
|  | 369 | psa_key_type_t key_type; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 370 | long input_position; | 
|  | 371 | size_t input_size; | 
| Gilles Peskine | 5e09bc7 | 2018-12-21 12:06:15 +0100 | [diff] [blame] | 372 | size_t buffer_size = 0; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 373 | unsigned char *buffer = NULL; | 
|  | 374 | size_t ciphertext_size; | 
|  | 375 | wrapped_data_header_t header; | 
|  | 376 |  | 
|  | 377 | /* Find the size of the data to wrap. */ | 
|  | 378 | SYS_CHECK( ( input_file = fopen( input_file_name, "rb" ) ) != NULL ); | 
|  | 379 | SYS_CHECK( fseek( input_file, 0, SEEK_END ) == 0 ); | 
|  | 380 | SYS_CHECK( ( input_position = ftell( input_file ) ) != -1 ); | 
|  | 381 | #if LONG_MAX > SIZE_MAX | 
|  | 382 | if( input_position > SIZE_MAX ) | 
|  | 383 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 384 | printf( "Input file too large.\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 385 | status = DEMO_ERROR; | 
|  | 386 | goto exit; | 
|  | 387 | } | 
|  | 388 | #endif | 
|  | 389 | input_size = input_position; | 
| Bence Szépkúti | ec174e2 | 2021-03-19 18:46:15 +0100 | [diff] [blame] | 390 | PSA_CHECK( psa_get_key_attributes( wrapping_key, &attributes ) ); | 
|  | 391 | key_type = psa_get_key_type( &attributes ); | 
|  | 392 | buffer_size = | 
|  | 393 | PSA_AEAD_ENCRYPT_OUTPUT_SIZE( key_type, WRAPPING_ALG, input_size ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 394 | /* Check for integer overflow. */ | 
|  | 395 | if( buffer_size < input_size ) | 
|  | 396 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 397 | printf( "Input file too large.\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 398 | status = DEMO_ERROR; | 
|  | 399 | goto exit; | 
|  | 400 | } | 
|  | 401 |  | 
|  | 402 | /* Load the data to wrap. */ | 
|  | 403 | SYS_CHECK( fseek( input_file, 0, SEEK_SET ) == 0 ); | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 404 | SYS_CHECK( ( buffer = calloc( 1, buffer_size ) ) != NULL ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 405 | SYS_CHECK( fread( buffer, 1, input_size, input_file ) == input_size ); | 
|  | 406 | SYS_CHECK( fclose( input_file ) == 0 ); | 
|  | 407 | input_file = NULL; | 
|  | 408 |  | 
|  | 409 | /* Construct a header. */ | 
|  | 410 | memcpy( &header.magic, WRAPPED_DATA_MAGIC, WRAPPED_DATA_MAGIC_LENGTH ); | 
|  | 411 | header.ad_size = sizeof( header ); | 
|  | 412 | header.payload_size = input_size; | 
|  | 413 |  | 
|  | 414 | /* Wrap the data. */ | 
|  | 415 | PSA_CHECK( psa_generate_random( header.iv, WRAPPING_IV_SIZE ) ); | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 416 | PSA_CHECK( psa_aead_encrypt( wrapping_key, WRAPPING_ALG, | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 417 | header.iv, WRAPPING_IV_SIZE, | 
|  | 418 | (uint8_t *) &header, sizeof( header ), | 
|  | 419 | buffer, input_size, | 
|  | 420 | buffer, buffer_size, | 
|  | 421 | &ciphertext_size ) ); | 
|  | 422 |  | 
|  | 423 | /* Write the output. */ | 
|  | 424 | SYS_CHECK( ( output_file = fopen( output_file_name, "wb" ) ) != NULL ); | 
|  | 425 | SYS_CHECK( fwrite( &header, 1, sizeof( header ), | 
|  | 426 | output_file ) == sizeof( header ) ); | 
|  | 427 | SYS_CHECK( fwrite( buffer, 1, ciphertext_size, | 
|  | 428 | output_file ) == ciphertext_size ); | 
|  | 429 | SYS_CHECK( fclose( output_file ) == 0 ); | 
|  | 430 | output_file = NULL; | 
|  | 431 |  | 
|  | 432 | exit: | 
|  | 433 | if( input_file != NULL ) | 
|  | 434 | fclose( input_file ); | 
|  | 435 | if( output_file != NULL ) | 
|  | 436 | fclose( output_file ); | 
|  | 437 | if( buffer != NULL ) | 
|  | 438 | mbedtls_platform_zeroize( buffer, buffer_size ); | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 439 | free( buffer ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 440 | return( status ); | 
|  | 441 | } | 
|  | 442 |  | 
|  | 443 | static psa_status_t unwrap_data( const char *input_file_name, | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 444 | const char *output_file_name, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 445 | psa_key_id_t wrapping_key ) | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 446 | { | 
|  | 447 | psa_status_t status; | 
|  | 448 | FILE *input_file = NULL; | 
|  | 449 | FILE *output_file = NULL; | 
| Bence Szépkúti | ec174e2 | 2021-03-19 18:46:15 +0100 | [diff] [blame] | 450 | psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; | 
|  | 451 | psa_key_type_t key_type; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 452 | unsigned char *buffer = NULL; | 
| Gilles Peskine | 5e09bc7 | 2018-12-21 12:06:15 +0100 | [diff] [blame] | 453 | size_t ciphertext_size = 0; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 454 | size_t plaintext_size; | 
|  | 455 | wrapped_data_header_t header; | 
|  | 456 | unsigned char extra_byte; | 
|  | 457 |  | 
|  | 458 | /* Load and validate the header. */ | 
|  | 459 | SYS_CHECK( ( input_file = fopen( input_file_name, "rb" ) ) != NULL ); | 
|  | 460 | SYS_CHECK( fread( &header, 1, sizeof( header ), | 
|  | 461 | input_file ) == sizeof( header ) ); | 
|  | 462 | if( memcmp( &header.magic, WRAPPED_DATA_MAGIC, | 
|  | 463 | WRAPPED_DATA_MAGIC_LENGTH ) != 0 ) | 
|  | 464 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 465 | printf( "The input does not start with a valid magic header.\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 466 | status = DEMO_ERROR; | 
|  | 467 | goto exit; | 
|  | 468 | } | 
|  | 469 | if( header.ad_size != sizeof( header ) ) | 
|  | 470 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 471 | printf( "The header size is not correct.\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 472 | status = DEMO_ERROR; | 
|  | 473 | goto exit; | 
|  | 474 | } | 
| Bence Szépkúti | ec174e2 | 2021-03-19 18:46:15 +0100 | [diff] [blame] | 475 | PSA_CHECK( psa_get_key_attributes( wrapping_key, &attributes) ); | 
|  | 476 | key_type = psa_get_key_type( &attributes); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 477 | ciphertext_size = | 
| Bence Szépkúti | ec174e2 | 2021-03-19 18:46:15 +0100 | [diff] [blame] | 478 | PSA_AEAD_ENCRYPT_OUTPUT_SIZE( key_type, WRAPPING_ALG, header.payload_size ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 479 | /* Check for integer overflow. */ | 
|  | 480 | if( ciphertext_size < header.payload_size ) | 
|  | 481 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 482 | printf( "Input file too large.\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 483 | status = DEMO_ERROR; | 
|  | 484 | goto exit; | 
|  | 485 | } | 
|  | 486 |  | 
|  | 487 | /* Load the payload data. */ | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 488 | SYS_CHECK( ( buffer = calloc( 1, ciphertext_size ) ) != NULL ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 489 | SYS_CHECK( fread( buffer, 1, ciphertext_size, | 
|  | 490 | input_file ) == ciphertext_size ); | 
|  | 491 | if( fread( &extra_byte, 1, 1, input_file ) != 0 ) | 
|  | 492 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 493 | printf( "Extra garbage after ciphertext\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 494 | status = DEMO_ERROR; | 
|  | 495 | goto exit; | 
|  | 496 | } | 
|  | 497 | SYS_CHECK( fclose( input_file ) == 0 ); | 
|  | 498 | input_file = NULL; | 
|  | 499 |  | 
|  | 500 | /* Unwrap the data. */ | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 501 | PSA_CHECK( psa_aead_decrypt( wrapping_key, WRAPPING_ALG, | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 502 | header.iv, WRAPPING_IV_SIZE, | 
|  | 503 | (uint8_t *) &header, sizeof( header ), | 
|  | 504 | buffer, ciphertext_size, | 
|  | 505 | buffer, ciphertext_size, | 
|  | 506 | &plaintext_size ) ); | 
|  | 507 | if( plaintext_size != header.payload_size ) | 
|  | 508 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 509 | printf( "Incorrect payload size in the header.\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 510 | status = DEMO_ERROR; | 
|  | 511 | goto exit; | 
|  | 512 | } | 
|  | 513 |  | 
|  | 514 | /* Write the output. */ | 
|  | 515 | SYS_CHECK( ( output_file = fopen( output_file_name, "wb" ) ) != NULL ); | 
|  | 516 | SYS_CHECK( fwrite( buffer, 1, plaintext_size, | 
|  | 517 | output_file ) == plaintext_size ); | 
|  | 518 | SYS_CHECK( fclose( output_file ) == 0 ); | 
|  | 519 | output_file = NULL; | 
|  | 520 |  | 
|  | 521 | exit: | 
|  | 522 | if( input_file != NULL ) | 
|  | 523 | fclose( input_file ); | 
|  | 524 | if( output_file != NULL ) | 
|  | 525 | fclose( output_file ); | 
|  | 526 | if( buffer != NULL ) | 
|  | 527 | mbedtls_platform_zeroize( buffer, ciphertext_size ); | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 528 | free( buffer ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 529 | return( status ); | 
|  | 530 | } | 
|  | 531 |  | 
|  | 532 | static psa_status_t run( enum program_mode mode, | 
|  | 533 | const char *key_file_name, | 
|  | 534 | const char *ladder[], size_t ladder_depth, | 
|  | 535 | const char *input_file_name, | 
|  | 536 | const char *output_file_name ) | 
|  | 537 | { | 
|  | 538 | psa_status_t status = PSA_SUCCESS; | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 539 | psa_key_id_t derivation_key = 0; | 
|  | 540 | psa_key_id_t wrapping_key = 0; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 541 |  | 
|  | 542 | /* Initialize the PSA crypto library. */ | 
|  | 543 | PSA_CHECK( psa_crypto_init( ) ); | 
|  | 544 |  | 
|  | 545 | /* Generate mode is unlike the others. Generate the master key and exit. */ | 
|  | 546 | if( mode == MODE_GENERATE ) | 
|  | 547 | return( generate( key_file_name ) ); | 
|  | 548 |  | 
|  | 549 | /* Read the master key. */ | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 550 | PSA_CHECK( import_key_from_file( PSA_KEY_USAGE_DERIVE | PSA_KEY_USAGE_EXPORT, | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 551 | KDF_ALG, | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 552 | key_file_name, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 553 | &derivation_key ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 554 |  | 
|  | 555 | /* Calculate the derived key for this session. */ | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 556 | PSA_CHECK( derive_key_ladder( ladder, ladder_depth, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 557 | &derivation_key ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 558 |  | 
|  | 559 | switch( mode ) | 
|  | 560 | { | 
|  | 561 | case MODE_SAVE: | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 562 | PSA_CHECK( save_key( derivation_key, output_file_name ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 563 | break; | 
|  | 564 | case MODE_UNWRAP: | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 565 | PSA_CHECK( derive_wrapping_key( PSA_KEY_USAGE_DECRYPT, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 566 | derivation_key, | 
|  | 567 | &wrapping_key ) ); | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 568 | PSA_CHECK( unwrap_data( input_file_name, output_file_name, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 569 | wrapping_key ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 570 | break; | 
|  | 571 | case MODE_WRAP: | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 572 | PSA_CHECK( derive_wrapping_key( PSA_KEY_USAGE_ENCRYPT, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 573 | derivation_key, | 
|  | 574 | &wrapping_key ) ); | 
| Gilles Peskine | b0edfb5 | 2018-12-03 16:24:51 +0100 | [diff] [blame] | 575 | PSA_CHECK( wrap_data( input_file_name, output_file_name, | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 576 | wrapping_key ) ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 577 | break; | 
|  | 578 | default: | 
|  | 579 | /* Unreachable but some compilers don't realize it. */ | 
|  | 580 | break; | 
|  | 581 | } | 
|  | 582 |  | 
|  | 583 | exit: | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 584 | /* Destroy any remaining key. Deinitializing the crypto library would do | 
|  | 585 | * this anyway since they are volatile keys, but explicitly destroying | 
| Ronald Cron | 77c89f5 | 2020-11-10 17:45:56 +0100 | [diff] [blame] | 586 | * keys makes the code easier to reuse. */ | 
| Ronald Cron | adc2ff2 | 2020-09-16 16:49:27 +0200 | [diff] [blame] | 587 | (void) psa_destroy_key( derivation_key ); | 
|  | 588 | (void) psa_destroy_key( wrapping_key ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 589 | /* Deinitialize the PSA crypto library. */ | 
|  | 590 | mbedtls_psa_crypto_free( ); | 
|  | 591 | return( status ); | 
|  | 592 | } | 
|  | 593 |  | 
|  | 594 | static void usage( void ) | 
|  | 595 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 596 | printf( "Usage: key_ladder_demo MODE [OPTION=VALUE]...\n" ); | 
|  | 597 | printf( "Demonstrate the usage of a key derivation ladder.\n" ); | 
|  | 598 | printf( "\n" ); | 
|  | 599 | printf( "Modes:\n" ); | 
|  | 600 | printf( "  generate  Generate the master key\n" ); | 
|  | 601 | printf( "  save      Save the derived key\n" ); | 
|  | 602 | printf( "  unwrap    Unwrap (decrypt) input with the derived key\n" ); | 
|  | 603 | printf( "  wrap      Wrap (encrypt) input with the derived key\n" ); | 
|  | 604 | printf( "\n" ); | 
|  | 605 | printf( "Options:\n" ); | 
|  | 606 | printf( "  input=FILENAME    Input file (required for wrap/unwrap)\n" ); | 
|  | 607 | printf( "  master=FILENAME   File containing the master key (default: master.key)\n" ); | 
|  | 608 | printf( "  output=FILENAME   Output file (required for save/wrap/unwrap)\n" ); | 
|  | 609 | printf( "  label=TEXT        Label for the key derivation.\n" ); | 
|  | 610 | printf( "                    This may be repeated multiple times.\n" ); | 
|  | 611 | printf( "                    To get the same key, you must use the same master key\n" ); | 
|  | 612 | printf( "                    and the same sequence of labels.\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 613 | } | 
|  | 614 |  | 
|  | 615 | int main( int argc, char *argv[] ) | 
|  | 616 | { | 
| Gilles Peskine | 738f017 | 2019-01-02 17:25:16 +0100 | [diff] [blame] | 617 | const char *key_file_name = "master.key"; | 
|  | 618 | const char *input_file_name = NULL; | 
|  | 619 | const char *output_file_name = NULL; | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 620 | const char *ladder[MAX_LADDER_DEPTH]; | 
|  | 621 | size_t ladder_depth = 0; | 
|  | 622 | int i; | 
|  | 623 | enum program_mode mode; | 
|  | 624 | psa_status_t status; | 
|  | 625 |  | 
|  | 626 | if( argc <= 1 || | 
|  | 627 | strcmp( argv[1], "help" ) == 0 || | 
|  | 628 | strcmp( argv[1], "-help" ) == 0 || | 
|  | 629 | strcmp( argv[1], "--help" ) == 0 ) | 
|  | 630 | { | 
|  | 631 | usage( ); | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 632 | return( EXIT_SUCCESS ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 633 | } | 
|  | 634 |  | 
|  | 635 | for( i = 2; i < argc; i++ ) | 
|  | 636 | { | 
|  | 637 | char *q = strchr( argv[i], '=' ); | 
|  | 638 | if( q == NULL ) | 
|  | 639 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 640 | printf( "Missing argument to option %s\n", argv[i] ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 641 | goto usage_failure; | 
|  | 642 | } | 
|  | 643 | *q = 0; | 
|  | 644 | ++q; | 
|  | 645 | if( strcmp( argv[i], "input" ) == 0 ) | 
|  | 646 | input_file_name = q; | 
|  | 647 | else if( strcmp( argv[i], "label" ) == 0 ) | 
|  | 648 | { | 
|  | 649 | if( ladder_depth == MAX_LADDER_DEPTH ) | 
|  | 650 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 651 | printf( "Maximum ladder depth %u exceeded.\n", | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 652 | (unsigned) MAX_LADDER_DEPTH ); | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 653 | return( EXIT_FAILURE ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 654 | } | 
|  | 655 | ladder[ladder_depth] = q; | 
|  | 656 | ++ladder_depth; | 
|  | 657 | } | 
|  | 658 | else if( strcmp( argv[i], "master" ) == 0 ) | 
|  | 659 | key_file_name = q; | 
|  | 660 | else if( strcmp( argv[i], "output" ) == 0 ) | 
|  | 661 | output_file_name = q; | 
|  | 662 | else | 
|  | 663 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 664 | printf( "Unknown option: %s\n", argv[i] ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 665 | goto usage_failure; | 
|  | 666 | } | 
|  | 667 | } | 
|  | 668 |  | 
|  | 669 | if( strcmp( argv[1], "generate" ) == 0 ) | 
|  | 670 | mode = MODE_GENERATE; | 
|  | 671 | else if( strcmp( argv[1], "save" ) == 0 ) | 
|  | 672 | mode = MODE_SAVE; | 
|  | 673 | else if( strcmp( argv[1], "unwrap" ) == 0 ) | 
|  | 674 | mode = MODE_UNWRAP; | 
|  | 675 | else if( strcmp( argv[1], "wrap" ) == 0 ) | 
|  | 676 | mode = MODE_WRAP; | 
|  | 677 | else | 
|  | 678 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 679 | printf( "Unknown action: %s\n", argv[1] ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 680 | goto usage_failure; | 
|  | 681 | } | 
|  | 682 |  | 
|  | 683 | if( input_file_name == NULL && | 
|  | 684 | ( mode == MODE_WRAP || mode == MODE_UNWRAP ) ) | 
|  | 685 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 686 | printf( "Required argument missing: input\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 687 | return( DEMO_ERROR ); | 
|  | 688 | } | 
|  | 689 | if( output_file_name == NULL && | 
|  | 690 | ( mode == MODE_SAVE || mode == MODE_WRAP || mode == MODE_UNWRAP ) ) | 
|  | 691 | { | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 692 | printf( "Required argument missing: output\n" ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 693 | return( DEMO_ERROR ); | 
|  | 694 | } | 
|  | 695 |  | 
|  | 696 | status = run( mode, key_file_name, | 
|  | 697 | ladder, ladder_depth, | 
|  | 698 | input_file_name, output_file_name ); | 
|  | 699 | return( status == PSA_SUCCESS ? | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 700 | EXIT_SUCCESS : | 
|  | 701 | EXIT_FAILURE ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 702 |  | 
|  | 703 | usage_failure: | 
|  | 704 | usage( ); | 
| Jaeden Amero | fa30c33 | 2018-12-21 18:42:18 +0000 | [diff] [blame] | 705 | return( EXIT_FAILURE ); | 
| Gilles Peskine | f0fa436 | 2018-07-16 17:08:43 +0200 | [diff] [blame] | 706 | } | 
|  | 707 | #endif /* MBEDTLS_SHA256_C && MBEDTLS_MD_C && MBEDTLS_AES_C && MBEDTLS_CCM_C && MBEDTLS_PSA_CRYPTO_C && MBEDTLS_FS_IO */ |