mbed-os5 only for TYBLE16

Dependents:   TYBLE16_simple_data_logger TYBLE16_MP3_Air

Committer:
kenjiArai
Date:
Tue Dec 31 06:02:27 2019 +0000
Revision:
1:9db0e321a9f4
Parent:
0:5b88d5760320
updated based on mbed-os5.15.0

Who changed what in which revision?

UserRevisionLine numberNew contents of line
kenjiArai 0:5b88d5760320 1 /*
kenjiArai 0:5b88d5760320 2 * ccm_alt.c
kenjiArai 0:5b88d5760320 3 *
kenjiArai 0:5b88d5760320 4 * Copyright (C) 2018, Arm Limited, All Rights Reserved
kenjiArai 0:5b88d5760320 5 * SPDX-License-Identifier: Apache-2.0
kenjiArai 0:5b88d5760320 6 *
kenjiArai 0:5b88d5760320 7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
kenjiArai 0:5b88d5760320 8 * not use this file except in compliance with the License.
kenjiArai 0:5b88d5760320 9 * You may obtain a copy of the License at
kenjiArai 0:5b88d5760320 10 *
kenjiArai 0:5b88d5760320 11 * http://www.apache.org/licenses/LICENSE-2.0
kenjiArai 0:5b88d5760320 12 *
kenjiArai 0:5b88d5760320 13 * Unless required by applicable law or agreed to in writing, software
kenjiArai 0:5b88d5760320 14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
kenjiArai 0:5b88d5760320 15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
kenjiArai 0:5b88d5760320 16 * See the License for the specific language governing permissions and
kenjiArai 0:5b88d5760320 17 * limitations under the License.
kenjiArai 0:5b88d5760320 18 *
kenjiArai 0:5b88d5760320 19 */
kenjiArai 0:5b88d5760320 20
kenjiArai 0:5b88d5760320 21 #include "mbedtls/ccm.h"
kenjiArai 0:5b88d5760320 22 #if defined(MBEDTLS_CCM_ALT)
kenjiArai 0:5b88d5760320 23 #include <string.h>
kenjiArai 0:5b88d5760320 24 #include "mbedtls/platform.h"
kenjiArai 0:5b88d5760320 25 #include "mbedtls/platform_util.h"
kenjiArai 0:5b88d5760320 26 #include "mbedtls/aes.h"
kenjiArai 0:5b88d5760320 27 #include "crys_aesccm_error.h"
kenjiArai 0:5b88d5760320 28
kenjiArai 0:5b88d5760320 29 void mbedtls_ccm_init( mbedtls_ccm_context *ctx )
kenjiArai 0:5b88d5760320 30 {
kenjiArai 0:5b88d5760320 31 memset( ctx, 0, sizeof( mbedtls_ccm_context ) );
kenjiArai 0:5b88d5760320 32 }
kenjiArai 0:5b88d5760320 33
kenjiArai 0:5b88d5760320 34 void mbedtls_ccm_free( mbedtls_ccm_context *ctx )
kenjiArai 0:5b88d5760320 35 {
kenjiArai 0:5b88d5760320 36 mbedtls_platform_zeroize( ctx, sizeof( mbedtls_ccm_context ) );
kenjiArai 0:5b88d5760320 37 }
kenjiArai 0:5b88d5760320 38
kenjiArai 0:5b88d5760320 39 int mbedtls_ccm_setkey( mbedtls_ccm_context *ctx,
kenjiArai 0:5b88d5760320 40 mbedtls_cipher_id_t cipher,
kenjiArai 0:5b88d5760320 41 const unsigned char *key,
kenjiArai 0:5b88d5760320 42 unsigned int keybits )
kenjiArai 0:5b88d5760320 43 {
kenjiArai 0:5b88d5760320 44 if( ctx == NULL )
kenjiArai 0:5b88d5760320 45 return( MBEDTLS_ERR_CCM_BAD_INPUT );
kenjiArai 0:5b88d5760320 46
kenjiArai 0:5b88d5760320 47 if( cipher != MBEDTLS_CIPHER_ID_AES )
kenjiArai 0:5b88d5760320 48 {
kenjiArai 0:5b88d5760320 49 return( MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED );
kenjiArai 0:5b88d5760320 50 }
kenjiArai 0:5b88d5760320 51
kenjiArai 0:5b88d5760320 52 switch( keybits )
kenjiArai 0:5b88d5760320 53 {
kenjiArai 0:5b88d5760320 54 case 128:
kenjiArai 0:5b88d5760320 55 {
kenjiArai 0:5b88d5760320 56 memcpy( ctx->cipher_key , key, keybits / 8 );
kenjiArai 0:5b88d5760320 57 ctx->key_size = CRYS_AES_Key128BitSize;
kenjiArai 0:5b88d5760320 58 }
kenjiArai 0:5b88d5760320 59 break;
kenjiArai 0:5b88d5760320 60 case 192:
kenjiArai 0:5b88d5760320 61 case 256:
kenjiArai 0:5b88d5760320 62 return( MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED );
kenjiArai 0:5b88d5760320 63 default:
kenjiArai 0:5b88d5760320 64 return( MBEDTLS_ERR_CCM_BAD_INPUT );
kenjiArai 0:5b88d5760320 65 }
kenjiArai 0:5b88d5760320 66
kenjiArai 0:5b88d5760320 67
kenjiArai 0:5b88d5760320 68 return( 0 );
kenjiArai 0:5b88d5760320 69
kenjiArai 0:5b88d5760320 70 }
kenjiArai 0:5b88d5760320 71
kenjiArai 0:5b88d5760320 72 /*
kenjiArai 0:5b88d5760320 73 * Authenticated encryption or decryption
kenjiArai 0:5b88d5760320 74 */
kenjiArai 0:5b88d5760320 75
kenjiArai 0:5b88d5760320 76 int mbedtls_ccm_encrypt_and_tag( mbedtls_ccm_context *ctx, size_t length,
kenjiArai 0:5b88d5760320 77 const unsigned char *iv, size_t iv_len,
kenjiArai 0:5b88d5760320 78 const unsigned char *add, size_t add_len,
kenjiArai 0:5b88d5760320 79 const unsigned char *input,
kenjiArai 0:5b88d5760320 80 unsigned char *output,
kenjiArai 0:5b88d5760320 81 unsigned char *tag, size_t tag_len )
kenjiArai 0:5b88d5760320 82
kenjiArai 0:5b88d5760320 83 {
kenjiArai 0:5b88d5760320 84 CRYSError_t crys_ret = CRYS_OK;
kenjiArai 0:5b88d5760320 85 CRYS_AESCCM_Mac_Res_t cc_mac_res = { 0 };
kenjiArai 0:5b88d5760320 86 int ret = 0;
kenjiArai 0:5b88d5760320 87 /*
kenjiArai 0:5b88d5760320 88 * Check length requirements: SP800-38C A.1
kenjiArai 0:5b88d5760320 89 * Additional requirement: a < 2^16 - 2^8 to simplify the code.
kenjiArai 0:5b88d5760320 90 * 'length' checked later (when writing it to the first block)
kenjiArai 0:5b88d5760320 91 */
kenjiArai 0:5b88d5760320 92 if( tag_len < 4 || tag_len > 16 || tag_len % 2 != 0 )
kenjiArai 0:5b88d5760320 93 return( MBEDTLS_ERR_CCM_BAD_INPUT );
kenjiArai 0:5b88d5760320 94
kenjiArai 0:5b88d5760320 95 if( tag_len > sizeof( cc_mac_res ) )
kenjiArai 0:5b88d5760320 96 return( MBEDTLS_ERR_CCM_BAD_INPUT );
kenjiArai 0:5b88d5760320 97
kenjiArai 0:5b88d5760320 98 /* Also implies q is within bounds */
kenjiArai 0:5b88d5760320 99 if( iv_len < 7 || iv_len > 13 )
kenjiArai 0:5b88d5760320 100 return( MBEDTLS_ERR_CCM_BAD_INPUT );
kenjiArai 0:5b88d5760320 101
kenjiArai 0:5b88d5760320 102 #if SIZE_MAX > UINT_MAX
kenjiArai 0:5b88d5760320 103 if( length > 0xFFFFFFFF || add_len > 0xFFFFFFFF )
kenjiArai 0:5b88d5760320 104 return( MBEDTLS_ERR_CCM_BAD_INPUT );
kenjiArai 0:5b88d5760320 105 #endif
kenjiArai 0:5b88d5760320 106
kenjiArai 0:5b88d5760320 107 crys_ret = CRYS_AESCCM( SASI_AES_ENCRYPT, ctx->cipher_key, ctx->key_size,
kenjiArai 0:5b88d5760320 108 (uint8_t*)iv, iv_len, (uint8_t*)add, add_len,
kenjiArai 0:5b88d5760320 109 (uint8_t*)input, length, output, tag_len,
kenjiArai 0:5b88d5760320 110 cc_mac_res );
kenjiArai 0:5b88d5760320 111 if( crys_ret == CRYS_AESCCM_ILLEGAL_PARAMETER_SIZE_ERROR )
kenjiArai 0:5b88d5760320 112 {
kenjiArai 0:5b88d5760320 113 ret = MBEDTLS_ERR_CCM_BAD_INPUT;
kenjiArai 0:5b88d5760320 114 goto exit;
kenjiArai 0:5b88d5760320 115 }
kenjiArai 0:5b88d5760320 116 else if( crys_ret != CRYS_OK )
kenjiArai 0:5b88d5760320 117 {
kenjiArai 0:5b88d5760320 118 ret = MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED;
kenjiArai 0:5b88d5760320 119 goto exit;
kenjiArai 0:5b88d5760320 120 }
kenjiArai 0:5b88d5760320 121
kenjiArai 0:5b88d5760320 122 memcpy( tag, cc_mac_res, tag_len );
kenjiArai 0:5b88d5760320 123
kenjiArai 0:5b88d5760320 124 exit:
kenjiArai 0:5b88d5760320 125 return( ret );
kenjiArai 0:5b88d5760320 126
kenjiArai 0:5b88d5760320 127 }
kenjiArai 0:5b88d5760320 128
kenjiArai 0:5b88d5760320 129 /*
kenjiArai 0:5b88d5760320 130 * Authenticated decryption
kenjiArai 0:5b88d5760320 131 */
kenjiArai 0:5b88d5760320 132 int mbedtls_ccm_auth_decrypt( mbedtls_ccm_context *ctx, size_t length,
kenjiArai 0:5b88d5760320 133 const unsigned char *iv, size_t iv_len,
kenjiArai 0:5b88d5760320 134 const unsigned char *add, size_t add_len,
kenjiArai 0:5b88d5760320 135 const unsigned char *input, unsigned char *output,
kenjiArai 0:5b88d5760320 136 const unsigned char *tag, size_t tag_len )
kenjiArai 0:5b88d5760320 137
kenjiArai 0:5b88d5760320 138 {
kenjiArai 0:5b88d5760320 139 CRYSError_t crys_ret = CRYS_OK;
kenjiArai 0:5b88d5760320 140 int ret = 0;
kenjiArai 0:5b88d5760320 141 /*
kenjiArai 0:5b88d5760320 142 * Check length requirements: SP800-38C A.1
kenjiArai 0:5b88d5760320 143 * Additional requirement: a < 2^16 - 2^8 to simplify the code.
kenjiArai 0:5b88d5760320 144 * 'length' checked later (when writing it to the first block)
kenjiArai 0:5b88d5760320 145 */
kenjiArai 0:5b88d5760320 146 if( tag_len < 4 || tag_len > 16 || tag_len % 2 != 0 )
kenjiArai 0:5b88d5760320 147 return( MBEDTLS_ERR_CCM_BAD_INPUT );
kenjiArai 0:5b88d5760320 148
kenjiArai 0:5b88d5760320 149 /* Also implies q is within bounds */
kenjiArai 0:5b88d5760320 150 if( iv_len < 7 || iv_len > 13 )
kenjiArai 0:5b88d5760320 151 return( MBEDTLS_ERR_CCM_BAD_INPUT );
kenjiArai 0:5b88d5760320 152
kenjiArai 0:5b88d5760320 153 #if SIZE_MAX > UINT_MAX
kenjiArai 0:5b88d5760320 154 if( length > 0xFFFFFFFF || add_len > 0xFFFFFFFF )
kenjiArai 0:5b88d5760320 155 return( MBEDTLS_ERR_CCM_BAD_INPUT );
kenjiArai 0:5b88d5760320 156 #endif
kenjiArai 0:5b88d5760320 157
kenjiArai 0:5b88d5760320 158 crys_ret = CRYS_AESCCM( SASI_AES_DECRYPT, ctx->cipher_key, ctx->key_size,
kenjiArai 0:5b88d5760320 159 (uint8_t*)iv, iv_len, (uint8_t*)add, add_len,
kenjiArai 0:5b88d5760320 160 (uint8_t*)input, length, output, tag_len,
kenjiArai 0:5b88d5760320 161 (uint8_t*)tag );
kenjiArai 0:5b88d5760320 162 if( crys_ret == CRYS_AESCCM_ILLEGAL_PARAMETER_SIZE_ERROR )
kenjiArai 0:5b88d5760320 163 {
kenjiArai 0:5b88d5760320 164 /*
kenjiArai 0:5b88d5760320 165 * When CRYS_AESCCM_ILLEGAL_PARAMETER_SIZE_ERROR is returned,
kenjiArai 0:5b88d5760320 166 * no operation has occured, and no need to zeroize output.
kenjiArai 0:5b88d5760320 167 * In addition, it could be that the message length is too big,
kenjiArai 0:5b88d5760320 168 * returning this error code, and we don't want to overflow
kenjiArai 0:5b88d5760320 169 * the output buffer.
kenjiArai 0:5b88d5760320 170 */
kenjiArai 0:5b88d5760320 171 return( MBEDTLS_ERR_CCM_BAD_INPUT );
kenjiArai 0:5b88d5760320 172 }
kenjiArai 0:5b88d5760320 173 else if( crys_ret == CRYS_FATAL_ERROR )
kenjiArai 0:5b88d5760320 174 {
kenjiArai 0:5b88d5760320 175 /*
kenjiArai 0:5b88d5760320 176 * Unfortunately, Crys AESCCM returns CRYS_FATAL_ERROR when
kenjiArai 0:5b88d5760320 177 * MAC isn't as expected.
kenjiArai 0:5b88d5760320 178 */
kenjiArai 0:5b88d5760320 179 ret = MBEDTLS_ERR_CCM_AUTH_FAILED;
kenjiArai 0:5b88d5760320 180 goto exit;
kenjiArai 0:5b88d5760320 181 }
kenjiArai 0:5b88d5760320 182 else if( crys_ret != CRYS_OK )
kenjiArai 0:5b88d5760320 183 {
kenjiArai 0:5b88d5760320 184 ret = MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED;
kenjiArai 0:5b88d5760320 185 goto exit;
kenjiArai 0:5b88d5760320 186 }
kenjiArai 0:5b88d5760320 187
kenjiArai 0:5b88d5760320 188 exit:
kenjiArai 0:5b88d5760320 189 if( ret != 0 )
kenjiArai 0:5b88d5760320 190 mbedtls_platform_zeroize( output, length );
kenjiArai 0:5b88d5760320 191 return( ret );
kenjiArai 0:5b88d5760320 192
kenjiArai 0:5b88d5760320 193 }
kenjiArai 0:5b88d5760320 194
kenjiArai 0:5b88d5760320 195 int mbedtls_ccm_star_encrypt_and_tag( mbedtls_ccm_context *ctx, size_t length,
kenjiArai 0:5b88d5760320 196 const unsigned char *iv, size_t iv_len,
kenjiArai 0:5b88d5760320 197 const unsigned char *add, size_t add_len,
kenjiArai 0:5b88d5760320 198 const unsigned char *input,
kenjiArai 0:5b88d5760320 199 unsigned char *output,
kenjiArai 0:5b88d5760320 200 unsigned char *tag, size_t tag_len )
kenjiArai 0:5b88d5760320 201 {
kenjiArai 0:5b88d5760320 202 return( MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED );
kenjiArai 0:5b88d5760320 203 }
kenjiArai 0:5b88d5760320 204
kenjiArai 0:5b88d5760320 205 int mbedtls_ccm_star_auth_decrypt( mbedtls_ccm_context *ctx, size_t length,
kenjiArai 0:5b88d5760320 206 const unsigned char *iv, size_t iv_len,
kenjiArai 0:5b88d5760320 207 const unsigned char *add, size_t add_len,
kenjiArai 0:5b88d5760320 208 const unsigned char *input,
kenjiArai 0:5b88d5760320 209 unsigned char *output,
kenjiArai 0:5b88d5760320 210 const unsigned char *tag, size_t tag_len )
kenjiArai 0:5b88d5760320 211 {
kenjiArai 0:5b88d5760320 212 return( MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED );
kenjiArai 0:5b88d5760320 213 }
kenjiArai 0:5b88d5760320 214
kenjiArai 0:5b88d5760320 215 #endif