Allow importing Montgomery public keys in PSA Crypto
PSA Crypto was checking the byte length of a to-be-imported public ECP key
against the expected length for Weierstrass keys, forgetting that
Curve25519/Curve448 exists.
Signed-off-by: Steven Cooreman <steven.cooreman@silabs.com>
diff --git a/library/psa_crypto.c b/library/psa_crypto.c
index 6e9d259..056e677 100644
--- a/library/psa_crypto.c
+++ b/library/psa_crypto.c
@@ -732,19 +732,34 @@
mbedtls_ecp_group_id grp_id = MBEDTLS_ECP_DP_NONE;
psa_status_t status;
mbedtls_ecp_keypair *ecp = NULL;
- size_t curve_size = size;
+ size_t curve_size;
if( PSA_KEY_TYPE_IS_PUBLIC_KEY( type ) )
{
- /* A public key is represented as:
- * - The byte 0x04;
- * - `x_P` as a `ceiling(m/8)`-byte string, big-endian;
- * - `y_P` as a `ceiling(m/8)`-byte string, big-endian.
- * So its data length is 2m+1 where n is the key size in bits.
- */
- if( ( size & 1 ) == 0 )
- return( PSA_ERROR_INVALID_ARGUMENT );
- curve_size = size / 2;
+ if( PSA_KEY_TYPE_ECC_GET_FAMILY( type ) == PSA_ECC_FAMILY_MONTGOMERY )
+ {
+ /* A Montgomery public key is represented as its raw
+ * compressed public point.
+ */
+ curve_size = size;
+ }
+ else
+ {
+ /* A Weierstrass public key is represented as:
+ * - The byte 0x04;
+ * - `x_P` as a `ceiling(m/8)`-byte string, big-endian;
+ * - `y_P` as a `ceiling(m/8)`-byte string, big-endian.
+ * So its data length is 2m+1 where n is the key size in bits.
+ */
+ if( ( size & 1 ) == 0 )
+ return( PSA_ERROR_INVALID_ARGUMENT );
+ curve_size = size / 2;
+ }
+ }
+ else
+ {
+ /* Private keys are represented as the raw private value */
+ curve_size = size;
}
/* Allocate and initialize a key representation. */