blob: 952d487c9e3c416a09e2ad51d505219578e7320c [file] [log] [blame]
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +01001/*
2 * Example ECDHE with Curve25519 program
3 *
Bence Szépkúti1e148272020-08-07 13:07:28 +02004 * Copyright The Mbed TLS Contributors
Dave Rodgman16799db2023-11-02 19:47:20 +00005 * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +01006 */
7
Felix Conway998760a2025-03-24 11:37:33 +00008#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
9
Bence Szépkútic662b362021-05-27 11:25:03 +020010#include "mbedtls/build_info.h"
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010011
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010012#include "mbedtls/platform.h"
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010013
Thomas Daubney88fed8e2022-04-12 09:03:22 +010014#if !defined(MBEDTLS_ECDH_C) || \
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010015 !defined(MBEDTLS_ECP_DP_CURVE25519_ENABLED) || \
16 !defined(MBEDTLS_ENTROPY_C) || !defined(MBEDTLS_CTR_DRBG_C)
Gilles Peskine449bd832023-01-11 14:50:10 +010017int main(void)
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010018{
Gilles Peskine449bd832023-01-11 14:50:10 +010019 mbedtls_printf("MBEDTLS_ECDH_C and/or "
20 "MBEDTLS_ECP_DP_CURVE25519_ENABLED and/or "
21 "MBEDTLS_ENTROPY_C and/or MBEDTLS_CTR_DRBG_C "
22 "not defined\n");
23 mbedtls_exit(0);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010024}
25#else
26
27#include "mbedtls/entropy.h"
28#include "mbedtls/ctr_drbg.h"
29#include "mbedtls/ecdh.h"
30
Thomas Daubney88fed8e2022-04-12 09:03:22 +010031#include <string.h>
32
Simon Butcher63cb97e2018-12-06 17:43:31 +000033
Gilles Peskine449bd832023-01-11 14:50:10 +010034int main(int argc, char *argv[])
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010035{
Andres Amaya Garciaf47c9c12018-04-29 22:16:23 +010036 int ret = 1;
37 int exit_code = MBEDTLS_EXIT_FAILURE;
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010038 mbedtls_ecdh_context ctx_cli, ctx_srv;
39 mbedtls_entropy_context entropy;
40 mbedtls_ctr_drbg_context ctr_drbg;
Thomas Daubney88fed8e2022-04-12 09:03:22 +010041 unsigned char cli_to_srv[36], srv_to_cli[33];
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010042 const char pers[] = "ecdh";
Thomas Daubney88fed8e2022-04-12 09:03:22 +010043
Thomas Daubney70c00882022-05-20 18:43:09 +010044 size_t srv_olen;
45 size_t cli_olen;
Thomas Daubney306a8902022-05-18 14:22:08 +010046 unsigned char secret_cli[32] = { 0 };
47 unsigned char secret_srv[32] = { 0 };
Thomas Daubney88fed8e2022-04-12 09:03:22 +010048 const unsigned char *p_cli_to_srv = cli_to_srv;
49
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010050 ((void) argc);
51 ((void) argv);
52
Gilles Peskine449bd832023-01-11 14:50:10 +010053 mbedtls_ecdh_init(&ctx_cli);
54 mbedtls_ecdh_init(&ctx_srv);
55 mbedtls_ctr_drbg_init(&ctr_drbg);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010056
57 /*
58 * Initialize random number generation
59 */
Gilles Peskine449bd832023-01-11 14:50:10 +010060 mbedtls_printf(" . Seed the random number generator...");
61 fflush(stdout);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010062
Gilles Peskine449bd832023-01-11 14:50:10 +010063 mbedtls_entropy_init(&entropy);
64 if ((ret = mbedtls_ctr_drbg_seed(&ctr_drbg, mbedtls_entropy_func,
65 &entropy,
66 (const unsigned char *) pers,
Dave Rodgman6dd757a2023-02-02 12:40:50 +000067 sizeof(pers))) != 0) {
Gilles Peskine449bd832023-01-11 14:50:10 +010068 mbedtls_printf(" failed\n ! mbedtls_ctr_drbg_seed returned %d\n",
69 ret);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010070 goto exit;
71 }
72
Gilles Peskine449bd832023-01-11 14:50:10 +010073 mbedtls_printf(" ok\n");
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010074
75 /*
HowJMayccbd6222020-07-29 16:59:19 +080076 * Client: initialize context and generate keypair
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010077 */
Gilles Peskine449bd832023-01-11 14:50:10 +010078 mbedtls_printf(" . Set up client context, generate EC key pair...");
79 fflush(stdout);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010080
Gilles Peskine449bd832023-01-11 14:50:10 +010081 ret = mbedtls_ecdh_setup(&ctx_cli, MBEDTLS_ECP_DP_CURVE25519);
82 if (ret != 0) {
83 mbedtls_printf(" failed\n ! mbedtls_ecdh_setup returned %d\n", ret);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010084 goto exit;
85 }
86
Gilles Peskine449bd832023-01-11 14:50:10 +010087 ret = mbedtls_ecdh_make_params(&ctx_cli, &cli_olen, cli_to_srv,
88 sizeof(cli_to_srv),
89 mbedtls_ctr_drbg_random, &ctr_drbg);
90 if (ret != 0) {
91 mbedtls_printf(" failed\n ! mbedtls_ecdh_make_params returned %d\n",
92 ret);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010093 goto exit;
94 }
95
Gilles Peskine449bd832023-01-11 14:50:10 +010096 mbedtls_printf(" ok\n");
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +010097
98 /*
99 * Server: initialize context and generate keypair
100 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100101 mbedtls_printf(" . Server: read params, generate public key...");
102 fflush(stdout);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100103
Gilles Peskine449bd832023-01-11 14:50:10 +0100104 ret = mbedtls_ecdh_read_params(&ctx_srv, &p_cli_to_srv,
105 p_cli_to_srv + sizeof(cli_to_srv));
106 if (ret != 0) {
107 mbedtls_printf(" failed\n ! mbedtls_ecdh_read_params returned %d\n",
108 ret);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100109 goto exit;
110 }
111
Gilles Peskine449bd832023-01-11 14:50:10 +0100112 ret = mbedtls_ecdh_make_public(&ctx_srv, &srv_olen, srv_to_cli,
113 sizeof(srv_to_cli),
114 mbedtls_ctr_drbg_random, &ctr_drbg);
115 if (ret != 0) {
116 mbedtls_printf(" failed\n ! mbedtls_ecdh_make_public returned %d\n",
117 ret);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100118 goto exit;
119 }
120
Gilles Peskine449bd832023-01-11 14:50:10 +0100121 mbedtls_printf(" ok\n");
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100122
123 /*
Thomas Daubney88fed8e2022-04-12 09:03:22 +0100124 * Client: read public key
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100125 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100126 mbedtls_printf(" . Client: read public key...");
127 fflush(stdout);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100128
Gilles Peskine449bd832023-01-11 14:50:10 +0100129 ret = mbedtls_ecdh_read_public(&ctx_cli, srv_to_cli,
130 sizeof(srv_to_cli));
131 if (ret != 0) {
132 mbedtls_printf(" failed\n ! mbedtls_ecdh_read_public returned %d\n",
133 ret);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100134 goto exit;
135 }
136
Gilles Peskine449bd832023-01-11 14:50:10 +0100137 mbedtls_printf(" ok\n");
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100138
139 /*
Thomas Daubney88fed8e2022-04-12 09:03:22 +0100140 * Calculate secrets
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100141 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100142 mbedtls_printf(" . Calculate secrets...");
143 fflush(stdout);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100144
Gilles Peskine449bd832023-01-11 14:50:10 +0100145 ret = mbedtls_ecdh_calc_secret(&ctx_cli, &cli_olen, secret_cli,
146 sizeof(secret_cli),
147 mbedtls_ctr_drbg_random, &ctr_drbg);
148 if (ret != 0) {
149 mbedtls_printf(" failed\n ! mbedtls_ecdh_calc_secret returned %d\n",
150 ret);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100151 goto exit;
152 }
153
Gilles Peskine449bd832023-01-11 14:50:10 +0100154 ret = mbedtls_ecdh_calc_secret(&ctx_srv, &srv_olen, secret_srv,
155 sizeof(secret_srv),
156 mbedtls_ctr_drbg_random, &ctr_drbg);
157 if (ret != 0) {
158 mbedtls_printf(" failed\n ! mbedtls_ecdh_calc_secret returned %d\n",
159 ret);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100160 goto exit;
161 }
162
Gilles Peskine449bd832023-01-11 14:50:10 +0100163 mbedtls_printf(" ok\n");
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100164
165 /*
Ron Eldor2a47be52017-06-20 15:23:23 +0300166 * Verification: are the computed secrets equal?
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100167 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100168 mbedtls_printf(" . Check if both calculated secrets are equal...");
169 fflush(stdout);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100170
Gilles Peskine449bd832023-01-11 14:50:10 +0100171 ret = memcmp(secret_srv, secret_cli, srv_olen);
172 if (ret != 0 || (cli_olen != srv_olen)) {
173 mbedtls_printf(" failed\n ! Shared secrets not equal.\n");
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100174 goto exit;
175 }
176
Gilles Peskine449bd832023-01-11 14:50:10 +0100177 mbedtls_printf(" ok\n");
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100178
Andres Amaya Garciaf47c9c12018-04-29 22:16:23 +0100179 exit_code = MBEDTLS_EXIT_SUCCESS;
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100180
181exit:
182
Gilles Peskine449bd832023-01-11 14:50:10 +0100183 mbedtls_ecdh_free(&ctx_srv);
184 mbedtls_ecdh_free(&ctx_cli);
185 mbedtls_ctr_drbg_free(&ctr_drbg);
186 mbedtls_entropy_free(&entropy);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100187
Gilles Peskine449bd832023-01-11 14:50:10 +0100188 mbedtls_exit(exit_code);
Manuel Pégourié-Gonnard3eb8c342015-10-09 12:11:14 +0100189}
190#endif /* MBEDTLS_ECDH_C && MBEDTLS_ECP_DP_CURVE25519_ENABLED &&
191 MBEDTLS_ENTROPY_C && MBEDTLS_CTR_DRBG_C */