avb_crypto.h 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174
  1. /*
  2. * Copyright (C) 2016 The Android Open Source Project
  3. *
  4. * Permission is hereby granted, free of charge, to any person
  5. * obtaining a copy of this software and associated documentation
  6. * files (the "Software"), to deal in the Software without
  7. * restriction, including without limitation the rights to use, copy,
  8. * modify, merge, publish, distribute, sublicense, and/or sell copies
  9. * of the Software, and to permit persons to whom the Software is
  10. * furnished to do so, subject to the following conditions:
  11. *
  12. * The above copyright notice and this permission notice shall be
  13. * included in all copies or substantial portions of the Software.
  14. *
  15. * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
  16. * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
  17. * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
  18. * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
  19. * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
  20. * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
  21. * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
  22. * SOFTWARE.
  23. */
  24. #if !defined(AVB_INSIDE_LIBAVB_H) && !defined(AVB_COMPILATION)
  25. #error "Never include this file directly, include libavb.h instead."
  26. #endif
  27. #ifndef AVB_CRYPTO_H_
  28. #define AVB_CRYPTO_H_
  29. #include "avb_sysdeps.h"
  30. #ifdef __cplusplus
  31. extern "C" {
  32. #endif
  33. /* Size of a RSA-2048 signature. */
  34. #define AVB_RSA2048_NUM_BYTES 256
  35. /* Size of a RSA-4096 signature. */
  36. #define AVB_RSA4096_NUM_BYTES 512
  37. /* Size of a RSA-8192 signature. */
  38. #define AVB_RSA8192_NUM_BYTES 1024
  39. /* Size in bytes of a SHA-1 digest. */
  40. #define AVB_SHA1_DIGEST_SIZE 20
  41. /* Size in bytes of a SHA-256 digest. */
  42. #define AVB_SHA256_DIGEST_SIZE 32
  43. /* Size in bytes of a SHA-512 digest. */
  44. #define AVB_SHA512_DIGEST_SIZE 64
  45. /* Possible digest types supported by libavb routines. */
  46. typedef enum {
  47. AVB_DIGEST_TYPE_SHA256,
  48. AVB_DIGEST_TYPE_SHA512,
  49. } AvbDigestType;
  50. /* Algorithms that can be used in the vbmeta image for
  51. * verification. An algorithm consists of a hash type and a signature
  52. * type.
  53. *
  54. * The data used to calculate the hash is the three blocks mentioned
  55. * in the documentation for |AvbVBMetaImageHeader| except for the data
  56. * in the "Authentication data" block.
  57. *
  58. * For signatures with RSA keys, PKCS v1.5 padding is used. The public
  59. * key data is stored in the auxiliary data block, see
  60. * |AvbRSAPublicKeyHeader| for the serialization format.
  61. *
  62. * Each algorithm type is described below:
  63. *
  64. * AVB_ALGORITHM_TYPE_NONE: There is no hash, no signature of the
  65. * data, and no public key. The data cannot be verified. The fields
  66. * |hash_size|, |signature_size|, and |public_key_size| must be zero.
  67. *
  68. * AVB_ALGORITHM_TYPE_SHA256_RSA2048: The hash function used is
  69. * SHA-256, resulting in 32 bytes of hash digest data. This hash is
  70. * signed with a 2048-bit RSA key. The field |hash_size| must be 32,
  71. * |signature_size| must be 256, and the public key data must have
  72. * |key_num_bits| set to 2048.
  73. *
  74. * AVB_ALGORITHM_TYPE_SHA256_RSA4096: Like above, but only with
  75. * a 4096-bit RSA key and |signature_size| set to 512.
  76. *
  77. * AVB_ALGORITHM_TYPE_SHA256_RSA8192: Like above, but only with
  78. * a 8192-bit RSA key and |signature_size| set to 1024.
  79. *
  80. * AVB_ALGORITHM_TYPE_SHA512_RSA2048: The hash function used is
  81. * SHA-512, resulting in 64 bytes of hash digest data. This hash is
  82. * signed with a 2048-bit RSA key. The field |hash_size| must be 64,
  83. * |signature_size| must be 256, and the public key data must have
  84. * |key_num_bits| set to 2048.
  85. *
  86. * AVB_ALGORITHM_TYPE_SHA512_RSA4096: Like above, but only with
  87. * a 4096-bit RSA key and |signature_size| set to 512.
  88. *
  89. * AVB_ALGORITHM_TYPE_SHA512_RSA8192: Like above, but only with
  90. * a 8192-bit RSA key and |signature_size| set to 1024.
  91. */
  92. typedef enum {
  93. AVB_ALGORITHM_TYPE_NONE,
  94. AVB_ALGORITHM_TYPE_SHA256_RSA2048,
  95. AVB_ALGORITHM_TYPE_SHA256_RSA4096,
  96. AVB_ALGORITHM_TYPE_SHA256_RSA8192,
  97. AVB_ALGORITHM_TYPE_SHA512_RSA2048,
  98. AVB_ALGORITHM_TYPE_SHA512_RSA4096,
  99. AVB_ALGORITHM_TYPE_SHA512_RSA8192,
  100. _AVB_ALGORITHM_NUM_TYPES
  101. } AvbAlgorithmType;
  102. /* Holds algorithm-specific data. The |padding| is needed by avb_rsa_verify. */
  103. typedef struct {
  104. const uint8_t* padding;
  105. size_t padding_len;
  106. size_t hash_len;
  107. } AvbAlgorithmData;
  108. /* Provides algorithm-specific data for a given |algorithm|. Returns NULL if
  109. * |algorithm| is invalid.
  110. */
  111. const AvbAlgorithmData* avb_get_algorithm_data(AvbAlgorithmType algorithm)
  112. AVB_ATTR_WARN_UNUSED_RESULT;
  113. /* The header for a serialized RSA public key.
  114. *
  115. * The size of the key is given by |key_num_bits|, for example 2048
  116. * for a RSA-2048 key. By definition, a RSA public key is the pair (n,
  117. * e) where |n| is the modulus (which can be represented in
  118. * |key_num_bits| bits) and |e| is the public exponent. The exponent
  119. * is not stored since it's assumed to always be 65537.
  120. *
  121. * To optimize verification, the key block includes two precomputed
  122. * values, |n0inv| (fits in 32 bits) and |rr| and can always be
  123. * represented in |key_num_bits|.
  124. * The value |n0inv| is the value -1/n[0] (mod 2^32). The value |rr|
  125. * is (2^key_num_bits)^2 (mod n).
  126. *
  127. * Following this header is |key_num_bits| bits of |n|, then
  128. * |key_num_bits| bits of |rr|. Both values are stored with most
  129. * significant bit first. Each serialized number takes up
  130. * |key_num_bits|/8 bytes.
  131. *
  132. * All fields in this struct are stored in network byte order when
  133. * serialized. To generate a copy with fields swapped to native byte
  134. * order, use the function avb_rsa_public_key_header_validate_and_byteswap().
  135. *
  136. * The avb_rsa_verify() function expects a key in this serialized
  137. * format.
  138. *
  139. * The 'avbtool extract_public_key' command can be used to generate a
  140. * serialized RSA public key.
  141. */
  142. typedef struct AvbRSAPublicKeyHeader {
  143. uint32_t key_num_bits;
  144. uint32_t n0inv;
  145. } AVB_ATTR_PACKED AvbRSAPublicKeyHeader;
  146. /* Copies |src| to |dest| and validates, byte-swapping fields in the
  147. * process if needed. Returns true if valid, false if invalid.
  148. */
  149. bool avb_rsa_public_key_header_validate_and_byteswap(
  150. const AvbRSAPublicKeyHeader* src,
  151. AvbRSAPublicKeyHeader* dest) AVB_ATTR_WARN_UNUSED_RESULT;
  152. #ifdef __cplusplus
  153. }
  154. #endif
  155. #endif /* AVB_CRYPTO_H_ */