10#include <botan/hash.h>
12#include <botan/internal/ffi_util.h>
13#include <botan/internal/ffi_pkey.h>
14#include <botan/internal/ffi_rng.h>
15#include <botan/internal/ffi_mp.h>
17#if defined(BOTAN_HAS_ECC_PUBLIC_KEY_CRYPTO)
18 #include <botan/ecc_key.h>
21#if defined(BOTAN_HAS_DL_PUBLIC_KEY_FAMILY)
22 #include <botan/dl_algo.h>
25#if defined(BOTAN_HAS_RSA)
26 #include <botan/rsa.h>
29#if defined(BOTAN_HAS_ELGAMAL)
30 #include <botan/elgamal.h>
33#if defined(BOTAN_HAS_DSA)
34 #include <botan/dsa.h>
37#if defined(BOTAN_HAS_ECDSA)
38 #include <botan/ecdsa.h>
41#if defined(BOTAN_HAS_SM2)
42 #include <botan/sm2.h>
45#if defined(BOTAN_HAS_ECDH)
46 #include <botan/ecdh.h>
49#if defined(BOTAN_HAS_CURVE_25519)
50 #include <botan/curve25519.h>
53#if defined(BOTAN_HAS_ED25519)
54 #include <botan/ed25519.h>
57#if defined(BOTAN_HAS_MCELIECE)
58 #include <botan/mceliece.h>
61#if defined(BOTAN_HAS_MCEIES)
62 #include <botan/mceies.h>
65#if defined(BOTAN_HAS_DIFFIE_HELLMAN)
72#if defined(BOTAN_HAS_ECC_PUBLIC_KEY_CRYPTO)
76template<
class ECPrivateKey_t>
77int privkey_load_ec(std::unique_ptr<ECPrivateKey_t>& key,
79 const char* curve_name)
81 if(curve_name ==
nullptr)
86 key.reset(
new ECPrivateKey_t(null_rng, grp, scalar));
90template<
class ECPublicKey_t>
91int pubkey_load_ec(std::unique_ptr<ECPublicKey_t>& key,
94 const char* curve_name)
96 if(curve_name ==
nullptr)
101 key.reset(
new ECPublicKey_t(grp, uncompressed_point));
108 const std::string& field)
112#if defined(BOTAN_HAS_RSA)
117 else if(field ==
"e")
124#if defined(BOTAN_HAS_DL_PUBLIC_KEY_FAMILY)
129 return dl->group_p();
130 else if(field ==
"q")
131 return dl->group_q();
132 else if(field ==
"g")
133 return dl->group_g();
134 else if(field ==
"y")
141#if defined(BOTAN_HAS_ECC_PUBLIC_KEY_CRYPTO)
144 if(field ==
"public_x")
145 return ecc->public_point().get_affine_x();
146 else if(field ==
"public_y")
147 return ecc->public_point().get_affine_y();
148 else if(field ==
"base_x")
149 return ecc->domain().get_g_x();
150 else if(field ==
"base_y")
151 return ecc->domain().get_g_y();
152 else if(field ==
"p")
153 return ecc->domain().get_p();
154 else if(field ==
"a")
155 return ecc->domain().get_a();
156 else if(field ==
"b")
157 return ecc->domain().get_b();
158 else if(field ==
"cofactor")
159 return ecc->domain().get_cofactor();
160 else if(field ==
"order")
161 return ecc->domain().get_order();
173 const std::string& field)
177#if defined(BOTAN_HAS_RSA)
183 else if(field ==
"q")
185 else if(field ==
"d")
187 else if(field ==
"c")
189 else if(field ==
"d1")
190 return rsa->get_d1();
191 else if(field ==
"d2")
192 return rsa->get_d2();
194 return pubkey_get_field(key, field);
198#if defined(BOTAN_HAS_DL_PUBLIC_KEY_FAMILY)
205 return pubkey_get_field(key, field);
209#if defined(BOTAN_HAS_ECC_PUBLIC_KEY_CRYPTO)
213 return ecc->private_value();
215 return pubkey_get_field(key, field);
219 return pubkey_get_field(key, field);
230 const char* field_name_cstr)
232 if(field_name_cstr ==
nullptr)
235 const std::string field_name(field_name_cstr);
238 safe_get(output) = pubkey_get_field(k, field_name);
244 const char* field_name_cstr)
246 if(field_name_cstr ==
nullptr)
249 const std::string field_name(field_name_cstr);
252 safe_get(output) = privkey_get_field(k, field_name);
260 if(n_bits < 1024 || n_bits > 16*1024)
263 std::string n_str = std::to_string(n_bits);
271#if defined(BOTAN_HAS_RSA)
287 const uint8_t bits[],
290#if defined(BOTAN_HAS_RSA)
308#if defined(BOTAN_HAS_RSA)
356 uint8_t out[],
size_t* out_len,
359#if defined(BOTAN_HAS_RSA)
385#if defined(BOTAN_HAS_DSA)
387 if ((rng_obj ==
nullptr) || (key ==
nullptr))
390 if ((pbits % 64) || (qbits % 8) ||
391 (pbits < 1024) || (pbits > 3072) ||
392 (qbits < 160) || (qbits > 256)) {
411#if defined(BOTAN_HAS_DSA)
429#if defined(BOTAN_HAS_DSA)
478 const char* curve_name)
480#if defined(BOTAN_HAS_ECDSA)
482 std::unique_ptr<Botan::ECDSA_PublicKey> p_key;
484 int rc = pubkey_load_ec(p_key,
safe_get(public_x),
safe_get(public_y), curve_name);
486 *key =
new botan_pubkey_struct(p_key.release());
498 const char* curve_name)
500#if defined(BOTAN_HAS_ECDSA)
502 std::unique_ptr<Botan::ECDSA_PrivateKey> p_key;
503 int rc = privkey_load_ec(p_key,
safe_get(scalar), curve_name);
505 *key =
new botan_privkey_struct(p_key.release());
520#if defined(BOTAN_HAS_ELGAMAL)
522 if ((rng_obj ==
nullptr) || (key ==
nullptr))
525 if ((pbits < 1024) || (qbits<160)) {
548#if defined(BOTAN_HAS_ELGAMAL)
564#if defined(BOTAN_HAS_ELGAMAL)
588#if defined(BOTAN_HAS_DIFFIE_HELLMAN)
605#if defined(BOTAN_HAS_DIFFIE_HELLMAN)
622 if(param_str ==
nullptr)
625 const std::string params(param_str);
627 if(params ==
"curve25519")
636 const char* curve_name)
638#if defined(BOTAN_HAS_ECDH)
640 std::unique_ptr<Botan::ECDH_PublicKey> p_key;
641 int rc = pubkey_load_ec(p_key,
safe_get(public_x),
safe_get(public_y), curve_name);
644 *key =
new botan_pubkey_struct(p_key.release());
655 const char* curve_name)
657#if defined(BOTAN_HAS_ECDH)
659 std::unique_ptr<Botan::ECDH_PrivateKey> p_key;
660 int rc = privkey_load_ec(p_key,
safe_get(scalar), curve_name);
662 *key =
new botan_privkey_struct(p_key.release());
679 if(out ==
nullptr || out_len ==
nullptr)
681 if(ident ==
nullptr ||
hash_algo ==
nullptr || key ==
nullptr)
684#if defined(BOTAN_HAS_SM2)
689 if(ec_key ==
nullptr)
695 const std::string ident_str(ident);
696 std::unique_ptr<Botan::HashFunction>
hash =
699 const std::vector<uint8_t> za =
712 const char* curve_name)
714#if defined(BOTAN_HAS_SM2)
716 std::unique_ptr<Botan::SM2_PublicKey> p_key;
717 if(!pubkey_load_ec(p_key,
safe_get(public_x),
safe_get(public_y), curve_name))
719 *key =
new botan_pubkey_struct(p_key.release());
732 const char* curve_name)
734#if defined(BOTAN_HAS_SM2)
736 std::unique_ptr<Botan::SM2_PrivateKey> p_key;
737 int rc = privkey_load_ec(p_key,
safe_get(scalar), curve_name);
740 *key =
new botan_privkey_struct(p_key.release());
752 const char* curve_name)
759 const char* curve_name)
767 const uint8_t privkey[32])
769#if defined(BOTAN_HAS_ED25519)
783 const uint8_t pubkey[32])
785#if defined(BOTAN_HAS_ED25519)
788 const std::vector<uint8_t> pubkey_vec(pubkey, pubkey + 32);
801#if defined(BOTAN_HAS_ED25519)
806 if(ed_key.size() != 64)
825#if defined(BOTAN_HAS_ED25519)
829 const std::vector<uint8_t>& ed_key = ed->get_public_key();
830 if(ed_key.size() != 32)
849 const uint8_t privkey[32])
851#if defined(BOTAN_HAS_X25519)
865 const uint8_t pubkey[32])
867#if defined(BOTAN_HAS_X25519)
870 const std::vector<uint8_t> pubkey_vec(pubkey, pubkey + 32);
883#if defined(BOTAN_HAS_X25519)
888 if(x25519_key.size() != 32)
907#if defined(BOTAN_HAS_X25519)
911 const std::vector<uint8_t>& x25519_key = x25519->public_value();
912 if(x25519_key.size() != 32)
930 const std::string mce_params = std::to_string(n) +
"," + std::to_string(t);
936 const uint8_t ct[],
size_t ct_len,
937 const uint8_t ad[],
size_t ad_len,
938 uint8_t out[],
size_t* out_len)
943#if defined(BOTAN_HAS_MCELIECE) && defined(BOTAN_HAS_MCEIES)
959 const uint8_t pt[],
size_t pt_len,
960 const uint8_t ad[],
size_t ad_len,
961 uint8_t out[],
size_t* out_len)
967#if defined(BOTAN_HAS_MCELIECE) && defined(BOTAN_HAS_MCEIES)
#define BOTAN_UNUSED(...)
const EC_Group & domain() const
const PointGFp & public_point() const
static std::unique_ptr< HashFunction > create_or_throw(const std::string &algo_spec, const std::string &provider="")
virtual std::string algo_name() const =0
struct botan_pubkey_struct * botan_pubkey_t
struct botan_privkey_struct * botan_privkey_t
int botan_privkey_create(botan_privkey_t *key, const char *algo_name, const char *algo_params, botan_rng_t rng)
#define BOTAN_PRIVKEY_EXPORT_FLAG_PEM
struct botan_mp_struct * botan_mp_t
struct botan_rng_struct * botan_rng_t
#define BOTAN_PRIVKEY_EXPORT_FLAG_DER
@ BOTAN_FFI_ERROR_NOT_IMPLEMENTED
@ BOTAN_FFI_ERROR_UNKNOWN_ERROR
@ BOTAN_FFI_ERROR_BAD_FLAG
@ BOTAN_FFI_ERROR_NULL_POINTER
@ BOTAN_FFI_ERROR_INSUFFICIENT_BUFFER_SPACE
@ BOTAN_FFI_ERROR_BAD_PARAMETER
int botan_privkey_create_elgamal(botan_privkey_t *key, botan_rng_t rng_obj, size_t pbits, size_t qbits)
int botan_pubkey_rsa_get_n(botan_mp_t n, botan_pubkey_t key)
int botan_pubkey_get_field(botan_mp_t output, botan_pubkey_t key, const char *field_name_cstr)
int botan_privkey_load_ecdh(botan_privkey_t *key, const botan_mp_t scalar, const char *curve_name)
int botan_pubkey_load_dh(botan_pubkey_t *key, botan_mp_t p, botan_mp_t g, botan_mp_t y)
int botan_pubkey_ed25519_get_pubkey(botan_pubkey_t key, uint8_t output[32])
int botan_privkey_rsa_get_privkey(botan_privkey_t rsa_key, uint8_t out[], size_t *out_len, uint32_t flags)
int botan_privkey_load_rsa_pkcs1(botan_privkey_t *key, const uint8_t bits[], size_t len)
int botan_pubkey_load_sm2(botan_pubkey_t *key, const botan_mp_t public_x, const botan_mp_t public_y, const char *curve_name)
int botan_pubkey_sm2_compute_za(uint8_t out[], size_t *out_len, const char *ident, const char *hash_algo, const botan_pubkey_t key)
int botan_privkey_load_x25519(botan_privkey_t *key, const uint8_t privkey[32])
int botan_pubkey_dsa_get_p(botan_mp_t p, botan_pubkey_t key)
int botan_privkey_rsa_get_q(botan_mp_t q, botan_privkey_t key)
int botan_privkey_ed25519_get_privkey(botan_privkey_t key, uint8_t output[64])
int botan_privkey_load_sm2_enc(botan_privkey_t *key, const botan_mp_t scalar, const char *curve_name)
int botan_privkey_get_field(botan_mp_t output, botan_privkey_t key, const char *field_name_cstr)
int botan_privkey_load_rsa(botan_privkey_t *key, botan_mp_t rsa_p, botan_mp_t rsa_q, botan_mp_t rsa_e)
int botan_pubkey_dsa_get_y(botan_mp_t y, botan_pubkey_t key)
int botan_privkey_load_dh(botan_privkey_t *key, botan_mp_t p, botan_mp_t g, botan_mp_t x)
int botan_privkey_load_sm2(botan_privkey_t *key, const botan_mp_t scalar, const char *curve_name)
int botan_pubkey_load_ed25519(botan_pubkey_t *key, const uint8_t pubkey[32])
int botan_privkey_load_ecdsa(botan_privkey_t *key, const botan_mp_t scalar, const char *curve_name)
int botan_mceies_encrypt(botan_pubkey_t mce_key_obj, botan_rng_t rng_obj, const char *aead, const uint8_t pt[], size_t pt_len, const uint8_t ad[], size_t ad_len, uint8_t out[], size_t *out_len)
int botan_pubkey_x25519_get_pubkey(botan_pubkey_t key, uint8_t output[32])
int botan_pubkey_load_elgamal(botan_pubkey_t *key, botan_mp_t p, botan_mp_t g, botan_mp_t y)
int botan_privkey_create_dsa(botan_privkey_t *key, botan_rng_t rng_obj, size_t pbits, size_t qbits)
int botan_privkey_rsa_get_p(botan_mp_t p, botan_privkey_t key)
int botan_privkey_create_mceliece(botan_privkey_t *key_obj, botan_rng_t rng_obj, size_t n, size_t t)
int botan_privkey_create_ecdh(botan_privkey_t *key_obj, botan_rng_t rng_obj, const char *param_str)
int botan_privkey_rsa_get_d(botan_mp_t d, botan_privkey_t key)
int botan_pubkey_load_sm2_enc(botan_pubkey_t *key, const botan_mp_t public_x, const botan_mp_t public_y, const char *curve_name)
int botan_mceies_decrypt(botan_privkey_t mce_key_obj, const char *aead, const uint8_t ct[], size_t ct_len, const uint8_t ad[], size_t ad_len, uint8_t out[], size_t *out_len)
int botan_pubkey_load_x25519(botan_pubkey_t *key, const uint8_t pubkey[32])
int botan_privkey_load_elgamal(botan_privkey_t *key, botan_mp_t p, botan_mp_t g, botan_mp_t x)
int botan_privkey_create_rsa(botan_privkey_t *key_obj, botan_rng_t rng_obj, size_t n_bits)
int botan_pubkey_load_dsa(botan_pubkey_t *key, botan_mp_t p, botan_mp_t q, botan_mp_t g, botan_mp_t y)
int botan_privkey_create_dh(botan_privkey_t *key_obj, botan_rng_t rng_obj, const char *param_str)
int botan_privkey_load_dsa(botan_privkey_t *key, botan_mp_t p, botan_mp_t q, botan_mp_t g, botan_mp_t x)
int botan_privkey_rsa_get_n(botan_mp_t n, botan_privkey_t key)
int botan_pubkey_rsa_get_e(botan_mp_t e, botan_pubkey_t key)
int botan_pubkey_dsa_get_g(botan_mp_t g, botan_pubkey_t key)
int botan_pubkey_dsa_get_q(botan_mp_t q, botan_pubkey_t key)
int botan_pubkey_load_ecdsa(botan_pubkey_t *key, const botan_mp_t public_x, const botan_mp_t public_y, const char *curve_name)
int botan_pubkey_load_ecdh(botan_pubkey_t *key, const botan_mp_t public_x, const botan_mp_t public_y, const char *curve_name)
int botan_privkey_load_ed25519(botan_privkey_t *key, const uint8_t privkey[32])
int botan_privkey_rsa_get_e(botan_mp_t e, botan_privkey_t key)
int botan_privkey_x25519_get_privkey(botan_privkey_t key, uint8_t output[32])
int botan_privkey_dsa_get_x(botan_mp_t x, botan_privkey_t key)
int botan_pubkey_load_rsa(botan_pubkey_t *key, botan_mp_t n, botan_mp_t e)
int botan_privkey_create_ecdsa(botan_privkey_t *key_obj, botan_rng_t rng_obj, const char *param_str)
#define BOTAN_FFI_DO(T, obj, param, block)
std::string encode(const uint8_t der[], size_t length, const std::string &label, size_t width)
int ffi_guard_thunk(const char *func_name, std::function< int()> thunk)
T & safe_get(botan_struct< T, M > *p)
int write_str_output(uint8_t out[], size_t *out_len, const std::string &str)
int write_vec_output(uint8_t out[], size_t *out_len, const std::vector< uint8_t, Alloc > &buf)
void copy_mem(T *out, const T *in, size_t n)
std::vector< uint8_t > sm2_compute_za(HashFunction &hash, const std::string &user_id, const EC_Group &domain, const PointGFp &pubkey)
std::vector< T, secure_allocator< T > > secure_vector
AlgorithmIdentifier hash_algo