2020-05-22 16:18:41 +03:00
|
|
|
/*
|
2023-12-19 19:29:08 -05:00
|
|
|
* Copyright (c) 2013-2023, The PurpleI2P Project
|
2020-05-22 16:18:41 +03:00
|
|
|
*
|
|
|
|
* This file is part of Purple i2pd project and licensed under BSD3
|
|
|
|
*
|
|
|
|
* See full license text in LICENSE file at top of project tree
|
|
|
|
*/
|
|
|
|
|
2015-04-09 10:03:21 -04:00
|
|
|
#include <memory>
|
2015-04-08 15:31:13 -04:00
|
|
|
#include "Log.h"
|
2015-04-08 13:21:49 -04:00
|
|
|
#include "Signature.h"
|
|
|
|
|
|
|
|
namespace i2p
|
|
|
|
{
|
|
|
|
namespace crypto
|
|
|
|
{
|
2020-03-01 13:25:50 +03:00
|
|
|
#if OPENSSL_EDDSA
|
2023-12-19 19:29:08 -05:00
|
|
|
EDDSA25519Verifier::EDDSA25519Verifier ():
|
|
|
|
m_Pkey (nullptr)
|
2018-09-03 17:39:49 -04:00
|
|
|
{
|
|
|
|
}
|
|
|
|
|
|
|
|
EDDSA25519Verifier::~EDDSA25519Verifier ()
|
|
|
|
{
|
2023-12-19 19:29:08 -05:00
|
|
|
EVP_PKEY_free (m_Pkey);
|
2018-09-03 17:39:49 -04:00
|
|
|
}
|
|
|
|
|
2019-01-01 17:00:37 -05:00
|
|
|
void EDDSA25519Verifier::SetPublicKey (const uint8_t * signingKey)
|
|
|
|
{
|
2023-12-19 19:29:08 -05:00
|
|
|
if (m_Pkey) EVP_PKEY_free (m_Pkey);
|
|
|
|
m_Pkey = EVP_PKEY_new_raw_public_key (EVP_PKEY_ED25519, NULL, signingKey, 32);
|
2020-03-01 13:25:50 +03:00
|
|
|
}
|
|
|
|
|
2018-09-03 17:39:49 -04:00
|
|
|
bool EDDSA25519Verifier::Verify (const uint8_t * buf, size_t len, const uint8_t * signature) const
|
|
|
|
{
|
2023-12-30 15:55:53 -05:00
|
|
|
if (m_Pkey)
|
|
|
|
{
|
|
|
|
EVP_MD_CTX * ctx = EVP_MD_CTX_create ();
|
|
|
|
EVP_DigestVerifyInit (ctx, NULL, NULL, NULL, m_Pkey);
|
|
|
|
auto ret = EVP_DigestVerify (ctx, signature, 64, buf, len);
|
|
|
|
EVP_MD_CTX_destroy (ctx);
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
else
|
|
|
|
LogPrint (eLogError, "EdDSA verification key is not set");
|
|
|
|
return false;
|
2018-09-03 17:39:49 -04:00
|
|
|
}
|
2020-03-01 13:25:50 +03:00
|
|
|
|
|
|
|
#else
|
2019-01-01 17:00:37 -05:00
|
|
|
EDDSA25519Verifier::EDDSA25519Verifier ()
|
2015-04-09 10:03:21 -04:00
|
|
|
{
|
|
|
|
}
|
|
|
|
|
2018-09-03 17:39:49 -04:00
|
|
|
EDDSA25519Verifier::~EDDSA25519Verifier ()
|
|
|
|
{
|
2020-03-01 13:25:50 +03:00
|
|
|
}
|
2019-01-01 17:00:37 -05:00
|
|
|
|
|
|
|
void EDDSA25519Verifier::SetPublicKey (const uint8_t * signingKey)
|
|
|
|
{
|
|
|
|
memcpy (m_PublicKeyEncoded, signingKey, EDDSA25519_PUBLIC_KEY_LENGTH);
|
|
|
|
BN_CTX * ctx = BN_CTX_new ();
|
|
|
|
m_PublicKey = GetEd25519 ()->DecodePublicKey (m_PublicKeyEncoded, ctx);
|
|
|
|
BN_CTX_free (ctx);
|
2020-03-01 13:25:50 +03:00
|
|
|
}
|
|
|
|
|
2015-04-08 16:28:52 -04:00
|
|
|
bool EDDSA25519Verifier::Verify (const uint8_t * buf, size_t len, const uint8_t * signature) const
|
2015-04-08 16:18:16 -04:00
|
|
|
{
|
2015-11-03 09:15:49 -05:00
|
|
|
uint8_t digest[64];
|
2015-11-26 10:25:51 -05:00
|
|
|
SHA512_CTX ctx;
|
|
|
|
SHA512_Init (&ctx);
|
|
|
|
SHA512_Update (&ctx, signature, EDDSA25519_SIGNATURE_LENGTH/2); // R
|
|
|
|
SHA512_Update (&ctx, m_PublicKeyEncoded, EDDSA25519_PUBLIC_KEY_LENGTH); // public key
|
2018-01-06 11:48:51 +08:00
|
|
|
SHA512_Update (&ctx, buf, len); // data
|
2015-11-26 10:25:51 -05:00
|
|
|
SHA512_Final (digest, &ctx);
|
2018-01-06 11:48:51 +08:00
|
|
|
|
2015-11-26 10:25:51 -05:00
|
|
|
return GetEd25519 ()->Verify (m_PublicKey, digest, signature);
|
2015-04-09 10:03:21 -04:00
|
|
|
}
|
2018-09-03 17:39:49 -04:00
|
|
|
#endif
|
2015-04-09 10:03:21 -04:00
|
|
|
|
2018-09-14 21:23:16 -04:00
|
|
|
EDDSA25519SignerCompat::EDDSA25519SignerCompat (const uint8_t * signingPrivateKey, const uint8_t * signingPublicKey)
|
2018-01-06 11:48:51 +08:00
|
|
|
{
|
2015-11-03 09:15:49 -05:00
|
|
|
// expand key
|
2018-06-05 12:53:13 -04:00
|
|
|
Ed25519::ExpandPrivateKey (signingPrivateKey, m_ExpandedPrivateKey);
|
2015-11-03 09:15:49 -05:00
|
|
|
// generate and encode public key
|
2018-01-06 11:48:51 +08:00
|
|
|
BN_CTX * ctx = BN_CTX_new ();
|
2015-11-23 09:26:32 -05:00
|
|
|
auto publicKey = GetEd25519 ()->GeneratePublicKey (m_ExpandedPrivateKey, ctx);
|
2018-01-06 11:48:51 +08:00
|
|
|
GetEd25519 ()->EncodePublicKey (publicKey, m_PublicKeyEncoded, ctx);
|
|
|
|
|
2017-01-07 21:20:09 -05:00
|
|
|
if (signingPublicKey && memcmp (m_PublicKeyEncoded, signingPublicKey, EDDSA25519_PUBLIC_KEY_LENGTH))
|
|
|
|
{
|
|
|
|
// keys don't match, it means older key with 0x1F
|
|
|
|
LogPrint (eLogWarning, "Older EdDSA key detected");
|
2018-01-06 11:48:51 +08:00
|
|
|
m_ExpandedPrivateKey[EDDSA25519_PRIVATE_KEY_LENGTH - 1] &= 0xDF; // drop third bit
|
2017-01-07 21:20:09 -05:00
|
|
|
publicKey = GetEd25519 ()->GeneratePublicKey (m_ExpandedPrivateKey, ctx);
|
2018-01-06 11:48:51 +08:00
|
|
|
GetEd25519 ()->EncodePublicKey (publicKey, m_PublicKeyEncoded, ctx);
|
2017-01-07 21:20:09 -05:00
|
|
|
}
|
2015-11-23 09:26:32 -05:00
|
|
|
BN_CTX_free (ctx);
|
2018-01-06 11:48:51 +08:00
|
|
|
}
|
|
|
|
|
2018-09-14 21:23:16 -04:00
|
|
|
EDDSA25519SignerCompat::~EDDSA25519SignerCompat ()
|
2018-09-03 17:39:49 -04:00
|
|
|
{
|
2020-03-01 13:25:50 +03:00
|
|
|
}
|
|
|
|
|
2018-09-14 21:23:16 -04:00
|
|
|
void EDDSA25519SignerCompat::Sign (const uint8_t * buf, int len, uint8_t * signature) const
|
2015-04-09 10:03:21 -04:00
|
|
|
{
|
2015-11-26 10:25:51 -05:00
|
|
|
GetEd25519 ()->Sign (m_ExpandedPrivateKey, m_PublicKeyEncoded, buf, len, signature);
|
2018-01-06 11:48:51 +08:00
|
|
|
}
|
2020-03-01 13:25:50 +03:00
|
|
|
|
|
|
|
#if OPENSSL_EDDSA
|
2018-09-14 21:23:16 -04:00
|
|
|
EDDSA25519Signer::EDDSA25519Signer (const uint8_t * signingPrivateKey, const uint8_t * signingPublicKey):
|
2023-12-30 15:55:53 -05:00
|
|
|
m_Pkey (nullptr), m_Fallback (nullptr)
|
2020-03-01 13:25:50 +03:00
|
|
|
{
|
2023-12-19 19:29:08 -05:00
|
|
|
m_Pkey = EVP_PKEY_new_raw_private_key (EVP_PKEY_ED25519, NULL, signingPrivateKey, 32);
|
2020-03-01 13:25:50 +03:00
|
|
|
uint8_t publicKey[EDDSA25519_PUBLIC_KEY_LENGTH];
|
2018-09-14 21:23:16 -04:00
|
|
|
size_t len = EDDSA25519_PUBLIC_KEY_LENGTH;
|
2023-12-19 19:29:08 -05:00
|
|
|
EVP_PKEY_get_raw_public_key (m_Pkey, publicKey, &len);
|
2019-02-22 13:17:43 -05:00
|
|
|
if (signingPublicKey && memcmp (publicKey, signingPublicKey, EDDSA25519_PUBLIC_KEY_LENGTH))
|
2018-09-14 21:23:16 -04:00
|
|
|
{
|
|
|
|
LogPrint (eLogWarning, "EdDSA public key mismatch. Fallback");
|
|
|
|
m_Fallback = new EDDSA25519SignerCompat (signingPrivateKey, signingPublicKey);
|
2023-12-30 15:55:53 -05:00
|
|
|
EVP_PKEY_free (m_Pkey);
|
|
|
|
m_Pkey = nullptr;
|
2018-09-14 21:23:16 -04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
EDDSA25519Signer::~EDDSA25519Signer ()
|
|
|
|
{
|
|
|
|
if (m_Fallback) delete m_Fallback;
|
2023-12-30 15:55:53 -05:00
|
|
|
if (m_Pkey) EVP_PKEY_free (m_Pkey);
|
2018-09-14 21:23:16 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
void EDDSA25519Signer::Sign (const uint8_t * buf, int len, uint8_t * signature) const
|
|
|
|
{
|
2023-12-30 15:55:53 -05:00
|
|
|
if (m_Fallback)
|
|
|
|
return m_Fallback->Sign (buf, len, signature);
|
|
|
|
else if (m_Pkey)
|
2020-03-01 13:25:50 +03:00
|
|
|
{
|
2023-12-30 15:55:53 -05:00
|
|
|
|
|
|
|
EVP_MD_CTX * ctx = EVP_MD_CTX_create ();
|
2020-03-01 13:25:50 +03:00
|
|
|
size_t l = 64;
|
2022-05-20 19:56:05 +03:00
|
|
|
uint8_t sig[64]; // temporary buffer for signature. openssl issue #7232
|
2023-12-30 15:55:53 -05:00
|
|
|
EVP_DigestSignInit (ctx, NULL, NULL, NULL, m_Pkey);
|
|
|
|
if (!EVP_DigestSign (ctx, sig, &l, buf, len))
|
2023-12-19 19:29:08 -05:00
|
|
|
LogPrint (eLogError, "EdDSA signing failed");
|
2018-09-16 18:08:59 -04:00
|
|
|
memcpy (signature, sig, 64);
|
2023-12-30 15:55:53 -05:00
|
|
|
EVP_MD_CTX_destroy (ctx);
|
2020-03-01 13:25:50 +03:00
|
|
|
}
|
2023-12-30 15:55:53 -05:00
|
|
|
else
|
|
|
|
LogPrint (eLogError, "EdDSA signing key is not set");
|
2020-03-01 13:25:50 +03:00
|
|
|
}
|
|
|
|
#endif
|
2015-04-08 13:21:49 -04:00
|
|
|
}
|
|
|
|
}
|