sphincs.c 32 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053
  1. /* sphincs.c
  2. *
  3. * Copyright (C) 2006-2023 wolfSSL Inc.
  4. *
  5. * This file is part of wolfSSL.
  6. *
  7. * wolfSSL is free software; you can redistribute it and/or modify
  8. * it under the terms of the GNU General Public License as published by
  9. * the Free Software Foundation; either version 2 of the License, or
  10. * (at your option) any later version.
  11. *
  12. * wolfSSL is distributed in the hope that it will be useful,
  13. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  14. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  15. * GNU General Public License for more details.
  16. *
  17. * You should have received a copy of the GNU General Public License
  18. * along with this program; if not, write to the Free Software
  19. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA
  20. */
  21. /* Based on dilithium.c and Reworked for Sphincs by Anthony Hu. */
  22. #ifdef HAVE_CONFIG_H
  23. #include <config.h>
  24. #endif
  25. /* in case user set HAVE_PQC there */
  26. #include <wolfssl/wolfcrypt/settings.h>
  27. #include <wolfssl/wolfcrypt/asn.h>
  28. #if defined(HAVE_PQC) && defined(HAVE_SPHINCS)
  29. #ifdef HAVE_LIBOQS
  30. #include <oqs/oqs.h>
  31. #endif
  32. #include <wolfssl/wolfcrypt/sphincs.h>
  33. #include <wolfssl/wolfcrypt/error-crypt.h>
  34. #ifdef NO_INLINE
  35. #include <wolfssl/wolfcrypt/misc.h>
  36. #else
  37. #define WOLFSSL_MISC_INCLUDED
  38. #include <wolfcrypt/src/misc.c>
  39. #endif
  40. /* Sign the message using the sphincs private key.
  41. *
  42. * in [in] Message to sign.
  43. * inLen [in] Length of the message in bytes.
  44. * out [in] Buffer to write signature into.
  45. * outLen [in/out] On in, size of buffer.
  46. * On out, the length of the signature in bytes.
  47. * key [in] Sphincs key to use when signing
  48. * returns BAD_FUNC_ARG when a parameter is NULL or public key not set,
  49. * BUFFER_E when outLen is less than SPHINCS_FAST_LEVEL1_SIG_SIZE,
  50. * 0 otherwise.
  51. */
  52. int wc_sphincs_sign_msg(const byte* in, word32 inLen, byte* out, word32 *outLen,
  53. sphincs_key* key)
  54. {
  55. int ret = 0;
  56. #ifdef HAVE_LIBOQS
  57. OQS_SIG *oqssig = NULL;
  58. size_t localOutLen = 0;
  59. /* sanity check on arguments */
  60. if ((in == NULL) || (out == NULL) || (outLen == NULL) || (key == NULL)) {
  61. ret = BAD_FUNC_ARG;
  62. }
  63. if ((ret == 0) && (!key->prvKeySet)) {
  64. ret = BAD_FUNC_ARG;
  65. }
  66. if (ret == 0) {
  67. if ((key->optim == FAST_VARIANT) && (key->level == 1)) {
  68. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_128f_simple);
  69. }
  70. else if ((key->optim == FAST_VARIANT) && (key->level == 3)) {
  71. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_192f_simple);
  72. }
  73. else if ((key->optim == FAST_VARIANT) && (key->level == 5)) {
  74. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_256f_simple);
  75. }
  76. else if ((key->optim == SMALL_VARIANT) && (key->level == 1)) {
  77. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_128s_simple);
  78. }
  79. else if ((key->optim == SMALL_VARIANT) && (key->level == 3)) {
  80. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_192s_simple);
  81. }
  82. else if ((key->optim == SMALL_VARIANT) && (key->level == 5)) {
  83. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_256s_simple);
  84. }
  85. if (oqssig == NULL) {
  86. ret = SIG_TYPE_E;
  87. }
  88. }
  89. /* check and set up out length */
  90. if (ret == 0) {
  91. if ((key->level == 1) && (key->optim == FAST_VARIANT) &&
  92. (*outLen < SPHINCS_FAST_LEVEL1_SIG_SIZE)) {
  93. *outLen = SPHINCS_FAST_LEVEL1_SIG_SIZE;
  94. ret = BUFFER_E;
  95. }
  96. else if ((key->level == 3) && (key->optim == FAST_VARIANT) &&
  97. (*outLen < SPHINCS_FAST_LEVEL3_SIG_SIZE)) {
  98. *outLen = SPHINCS_FAST_LEVEL3_SIG_SIZE;
  99. ret = BUFFER_E;
  100. }
  101. else if ((key->level == 5) && (key->optim == FAST_VARIANT) &&
  102. (*outLen < SPHINCS_FAST_LEVEL5_SIG_SIZE)) {
  103. *outLen = SPHINCS_FAST_LEVEL5_SIG_SIZE;
  104. ret = BUFFER_E;
  105. }
  106. else if ((key->level == 1) && (key->optim == SMALL_VARIANT) &&
  107. (*outLen < SPHINCS_SMALL_LEVEL1_SIG_SIZE)) {
  108. *outLen = SPHINCS_SMALL_LEVEL1_SIG_SIZE;
  109. ret = BUFFER_E;
  110. }
  111. else if ((key->level == 3) && (key->optim == SMALL_VARIANT) &&
  112. (*outLen < SPHINCS_SMALL_LEVEL3_SIG_SIZE)) {
  113. *outLen = SPHINCS_SMALL_LEVEL3_SIG_SIZE;
  114. ret = BUFFER_E;
  115. }
  116. else if ((key->level == 5) && (key->optim == SMALL_VARIANT) &&
  117. (*outLen < SPHINCS_SMALL_LEVEL5_SIG_SIZE)) {
  118. *outLen = SPHINCS_SMALL_LEVEL5_SIG_SIZE;
  119. ret = BUFFER_E;
  120. }
  121. localOutLen = *outLen;
  122. }
  123. if ((ret == 0) &&
  124. (OQS_SIG_sign(oqssig, out, &localOutLen, in, inLen, key->k)
  125. == OQS_ERROR)) {
  126. ret = BAD_FUNC_ARG;
  127. }
  128. if (ret == 0) {
  129. *outLen = (word32)localOutLen;
  130. }
  131. if (oqssig != NULL) {
  132. OQS_SIG_free(oqssig);
  133. }
  134. #else
  135. ret = NOT_COMPILED_IN;
  136. #endif
  137. return ret;
  138. }
  139. /* Verify the message using the sphincs public key.
  140. *
  141. * sig [in] Signature to verify.
  142. * sigLen [in] Size of signature in bytes.
  143. * msg [in] Message to verify.
  144. * msgLen [in] Length of the message in bytes.
  145. * res [out] *res is set to 1 on successful verification.
  146. * key [in] Sphincs key to use to verify.
  147. * returns BAD_FUNC_ARG when a parameter is NULL or contextLen is zero when and
  148. * BUFFER_E when sigLen is less than SPHINCS_FAST_LEVEL1_SIG_SIZE,
  149. * 0 otherwise.
  150. */
  151. int wc_sphincs_verify_msg(const byte* sig, word32 sigLen, const byte* msg,
  152. word32 msgLen, int* res, sphincs_key* key)
  153. {
  154. int ret = 0;
  155. #ifdef HAVE_LIBOQS
  156. OQS_SIG *oqssig = NULL;
  157. if (key == NULL || sig == NULL || msg == NULL || res == NULL) {
  158. ret = BAD_FUNC_ARG;
  159. }
  160. if ((ret == 0) && (!key->pubKeySet)) {
  161. ret = BAD_FUNC_ARG;
  162. }
  163. if (ret == 0) {
  164. if ((key->optim == FAST_VARIANT) && (key->level == 1)) {
  165. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_128f_simple);
  166. }
  167. else if ((key->optim == FAST_VARIANT) && (key->level == 3)) {
  168. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_192f_simple);
  169. }
  170. else if ((key->optim == FAST_VARIANT) && (key->level == 5)) {
  171. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_256f_simple);
  172. }
  173. else if ((key->optim == SMALL_VARIANT) && (key->level == 1)) {
  174. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_128s_simple);
  175. }
  176. else if ((key->optim == SMALL_VARIANT) && (key->level == 3)) {
  177. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_192s_simple);
  178. }
  179. else if ((key->optim == SMALL_VARIANT) && (key->level == 5)) {
  180. oqssig = OQS_SIG_new(OQS_SIG_alg_sphincs_shake_256s_simple);
  181. }
  182. if (oqssig == NULL) {
  183. ret = SIG_TYPE_E;
  184. }
  185. }
  186. if ((ret == 0) &&
  187. (OQS_SIG_verify(oqssig, msg, msgLen, sig, sigLen, key->p)
  188. == OQS_ERROR)) {
  189. ret = SIG_VERIFY_E;
  190. }
  191. if (ret == 0) {
  192. *res = 1;
  193. }
  194. if (oqssig != NULL) {
  195. OQS_SIG_free(oqssig);
  196. }
  197. #else
  198. ret = NOT_COMPILED_IN;
  199. #endif
  200. return ret;
  201. }
  202. /* Initialize the sphincs private/public key.
  203. *
  204. * key [in] Sphincs key.
  205. * returns BAD_FUNC_ARG when key is NULL
  206. */
  207. int wc_sphincs_init(sphincs_key* key)
  208. {
  209. if (key == NULL) {
  210. return BAD_FUNC_ARG;
  211. }
  212. ForceZero(key, sizeof(key));
  213. return 0;
  214. }
  215. /* Set the level of the sphincs private/public key.
  216. *
  217. * key [out] Sphincs key.
  218. * level [in] Either 1, 3 or 5.
  219. * optim [in] Either FAST_VARIANT or SMALL_VARIANT.
  220. * returns BAD_FUNC_ARG when key is NULL or level or optim are bad values.
  221. */
  222. int wc_sphincs_set_level_and_optim(sphincs_key* key, byte level, byte optim)
  223. {
  224. if (key == NULL) {
  225. return BAD_FUNC_ARG;
  226. }
  227. if (level != 1 && level != 3 && level != 5) {
  228. return BAD_FUNC_ARG;
  229. }
  230. if (optim != FAST_VARIANT && optim != SMALL_VARIANT) {
  231. return BAD_FUNC_ARG;
  232. }
  233. key->level = level;
  234. key->optim = optim;
  235. key->pubKeySet = 0;
  236. key->prvKeySet = 0;
  237. return 0;
  238. }
  239. /* Get the level and optimization variant of the sphincs private/public key.
  240. *
  241. * key [in] Sphincs key.
  242. * level [out] The level.
  243. * optim [out] The optimization variant. FAST_VARIANT or SMALL_VARIANT.
  244. * returns BAD_FUNC_ARG when key is NULL or level has not been set.
  245. */
  246. int wc_sphincs_get_level_and_optim(sphincs_key* key, byte* level, byte* optim)
  247. {
  248. if (key == NULL || level == NULL) {
  249. return BAD_FUNC_ARG;
  250. }
  251. if (key->level != 1 && key->level != 3 && key->level != 5) {
  252. return BAD_FUNC_ARG;
  253. }
  254. if (key->optim != FAST_VARIANT && key->optim != SMALL_VARIANT) {
  255. return BAD_FUNC_ARG;
  256. }
  257. *level = key->level;
  258. *optim = key->optim;
  259. return 0;
  260. }
  261. /* Clears the sphincs key data
  262. *
  263. * key [in] Sphincs key.
  264. */
  265. void wc_sphincs_free(sphincs_key* key)
  266. {
  267. if (key != NULL) {
  268. ForceZero(key, sizeof(key));
  269. }
  270. }
  271. /* Export the sphincs public key.
  272. *
  273. * key [in] Sphincs public key.
  274. * out [in] Array to hold public key.
  275. * outLen [in/out] On in, the number of bytes in array.
  276. * On out, the number bytes put into array.
  277. * returns BAD_FUNC_ARG when a parameter is NULL,
  278. * BUFFER_E when outLen is less than SPHINCS_FAST_LEVEL1_PUB_KEY_SIZE,
  279. * 0 otherwise.
  280. */
  281. int wc_sphincs_export_public(sphincs_key* key,
  282. byte* out, word32* outLen)
  283. {
  284. /* sanity check on arguments */
  285. if ((key == NULL) || (out == NULL) || (outLen == NULL)) {
  286. return BAD_FUNC_ARG;
  287. }
  288. if ((key->level != 1) && (key->level != 5)) {
  289. return BAD_FUNC_ARG;
  290. }
  291. if (!key->pubKeySet) {
  292. return BAD_FUNC_ARG;
  293. }
  294. /* check and set up out length */
  295. if ((key->level == 1) && (*outLen < SPHINCS_LEVEL1_PUB_KEY_SIZE)) {
  296. *outLen = SPHINCS_LEVEL1_PUB_KEY_SIZE;
  297. return BUFFER_E;
  298. }
  299. else if ((key->level == 3) && (*outLen < SPHINCS_LEVEL3_PUB_KEY_SIZE)) {
  300. *outLen = SPHINCS_LEVEL3_PUB_KEY_SIZE;
  301. return BUFFER_E;
  302. }
  303. else if ((key->level == 5) && (*outLen < SPHINCS_LEVEL5_PUB_KEY_SIZE)) {
  304. *outLen = SPHINCS_LEVEL5_PUB_KEY_SIZE;
  305. return BUFFER_E;
  306. }
  307. if (key->level == 1) {
  308. *outLen = SPHINCS_LEVEL1_PUB_KEY_SIZE;
  309. XMEMCPY(out, key->p, SPHINCS_LEVEL1_PUB_KEY_SIZE);
  310. }
  311. else if (key->level == 3) {
  312. *outLen = SPHINCS_LEVEL3_PUB_KEY_SIZE;
  313. XMEMCPY(out, key->p, SPHINCS_LEVEL3_PUB_KEY_SIZE);
  314. }
  315. else if (key->level == 5) {
  316. *outLen = SPHINCS_LEVEL5_PUB_KEY_SIZE;
  317. XMEMCPY(out, key->p, SPHINCS_LEVEL5_PUB_KEY_SIZE);
  318. }
  319. return 0;
  320. }
  321. /* Import a sphincs public key from a byte array.
  322. * Public key encoded in big-endian.
  323. *
  324. * in [in] Array holding public key.
  325. * inLen [in] Number of bytes of data in array.
  326. * key [in] Sphincs public key.
  327. * returns BAD_FUNC_ARG when a parameter is NULL or key format is not supported,
  328. * 0 otherwise.
  329. */
  330. int wc_sphincs_import_public(const byte* in, word32 inLen,
  331. sphincs_key* key)
  332. {
  333. /* sanity check on arguments */
  334. if ((in == NULL) || (key == NULL)) {
  335. return BAD_FUNC_ARG;
  336. }
  337. if ((key->level != 1) && (key->level != 3) && (key->level != 5)) {
  338. return BAD_FUNC_ARG;
  339. }
  340. if ((key->optim != FAST_VARIANT) && (key->optim != SMALL_VARIANT)) {
  341. return BAD_FUNC_ARG;
  342. }
  343. if ((key->level == 1) && (inLen != SPHINCS_LEVEL1_PUB_KEY_SIZE)) {
  344. return BAD_FUNC_ARG;
  345. }
  346. else if ((key->level == 3) && (inLen != SPHINCS_LEVEL3_PUB_KEY_SIZE)) {
  347. return BAD_FUNC_ARG;
  348. }
  349. else if ((key->level == 5) && (inLen != SPHINCS_LEVEL5_PUB_KEY_SIZE)) {
  350. return BAD_FUNC_ARG;
  351. }
  352. XMEMCPY(key->p, in, inLen);
  353. key->pubKeySet = 1;
  354. return 0;
  355. }
  356. static int parse_private_key(const byte* priv, word32 privSz,
  357. byte** out, word32 *outSz,
  358. sphincs_key* key) {
  359. word32 idx = 0;
  360. int ret = 0;
  361. int length = 0;
  362. /* sanity check on arguments */
  363. if ((priv == NULL) || (key == NULL)) {
  364. return BAD_FUNC_ARG;
  365. }
  366. if ((key->level != 1) && (key->level != 3) && (key->level != 5)) {
  367. return BAD_FUNC_ARG;
  368. }
  369. if ((key->optim != FAST_VARIANT) && (key->optim != SMALL_VARIANT)) {
  370. return BAD_FUNC_ARG;
  371. }
  372. /* At this point, it is still a PKCS8 private key. */
  373. if ((ret = ToTraditionalInline(priv, &idx, privSz)) < 0) {
  374. return ret;
  375. }
  376. /* Now it is a octet_string(concat(priv,pub)) */
  377. if ((ret = GetOctetString(priv, &idx, &length, privSz)) < 0) {
  378. return ret;
  379. }
  380. *out = (byte *)priv + idx;
  381. *outSz = privSz - idx;
  382. /* And finally it is concat(priv,pub). Key size check. */
  383. if ((key->level == 1) && (*outSz != SPHINCS_LEVEL1_KEY_SIZE +
  384. SPHINCS_LEVEL1_PUB_KEY_SIZE)) {
  385. return BAD_FUNC_ARG;
  386. }
  387. else if ((key->level == 3) && (*outSz != SPHINCS_LEVEL3_KEY_SIZE +
  388. SPHINCS_LEVEL3_PUB_KEY_SIZE)) {
  389. return BAD_FUNC_ARG;
  390. }
  391. else if ((key->level == 5) && (*outSz != SPHINCS_LEVEL5_KEY_SIZE +
  392. SPHINCS_LEVEL5_PUB_KEY_SIZE)) {
  393. return BAD_FUNC_ARG;
  394. }
  395. return 0;
  396. }
  397. /* Import a sphincs private key from a byte array.
  398. *
  399. * priv [in] Array holding private key.
  400. * privSz [in] Number of bytes of data in array.
  401. * key [in] Sphincs private key.
  402. * returns BAD_FUNC_ARG when a parameter is NULL or privSz is less than
  403. * SPHINCS_LEVEL1_KEY_SIZE,
  404. * 0 otherwise.
  405. */
  406. int wc_sphincs_import_private_only(const byte* priv, word32 privSz,
  407. sphincs_key* key)
  408. {
  409. int ret = 0;
  410. byte *newPriv = NULL;
  411. word32 newPrivSz = 0;
  412. if ((ret = parse_private_key(priv, privSz, &newPriv, &newPrivSz, key))
  413. != 0) {
  414. return ret;
  415. }
  416. if (key->level == 1) {
  417. XMEMCPY(key->k, newPriv, SPHINCS_LEVEL1_KEY_SIZE);
  418. }
  419. else if (key->level == 3) {
  420. XMEMCPY(key->k, newPriv, SPHINCS_LEVEL3_KEY_SIZE);
  421. }
  422. else if (key->level == 5) {
  423. XMEMCPY(key->k, newPriv, SPHINCS_LEVEL5_KEY_SIZE);
  424. }
  425. key->prvKeySet = 1;
  426. return 0;
  427. }
  428. /* Import a sphincs private and public keys from byte array(s).
  429. *
  430. * priv [in] Array holding private key or private+public keys
  431. * privSz [in] Number of bytes of data in private key array.
  432. * pub [in] Array holding public key (or NULL).
  433. * pubSz [in] Number of bytes of data in public key array (or 0).
  434. * key [in] Sphincs private/public key.
  435. * returns BAD_FUNC_ARG when a required parameter is NULL or an invalid
  436. * combination of keys/lengths is supplied, 0 otherwise.
  437. */
  438. int wc_sphincs_import_private_key(const byte* priv, word32 privSz,
  439. const byte* pub, word32 pubSz,
  440. sphincs_key* key)
  441. {
  442. int ret = 0;
  443. byte *newPriv = NULL;
  444. word32 newPrivSz = 0;
  445. if ((ret = parse_private_key(priv, privSz, &newPriv, &newPrivSz, key))
  446. != 0) {
  447. return ret;
  448. }
  449. if (pub == NULL) {
  450. if (pubSz != 0) {
  451. return BAD_FUNC_ARG;
  452. }
  453. if ((newPrivSz != SPHINCS_LEVEL1_PRV_KEY_SIZE) &&
  454. (newPrivSz != SPHINCS_LEVEL3_PRV_KEY_SIZE) &&
  455. (newPrivSz != SPHINCS_LEVEL5_PRV_KEY_SIZE)) {
  456. return BAD_FUNC_ARG;
  457. }
  458. if (key->level == 1) {
  459. pub = newPriv + SPHINCS_LEVEL1_KEY_SIZE;
  460. pubSz = SPHINCS_LEVEL1_PUB_KEY_SIZE;
  461. }
  462. else if (key->level == 3) {
  463. pub = newPriv + SPHINCS_LEVEL3_KEY_SIZE;
  464. pubSz = SPHINCS_LEVEL3_PUB_KEY_SIZE;
  465. }
  466. else if (key->level == 5) {
  467. pub = newPriv + SPHINCS_LEVEL5_KEY_SIZE;
  468. pubSz = SPHINCS_LEVEL5_PUB_KEY_SIZE;
  469. }
  470. }
  471. else if ((pubSz != SPHINCS_LEVEL1_PUB_KEY_SIZE) &&
  472. (pubSz != SPHINCS_LEVEL3_PUB_KEY_SIZE) &&
  473. (pubSz != SPHINCS_LEVEL5_PUB_KEY_SIZE)) {
  474. return BAD_FUNC_ARG;
  475. }
  476. /* import public key */
  477. ret = wc_sphincs_import_public(pub, pubSz, key);
  478. if (ret == 0) {
  479. /* make the private key (priv + pub) */
  480. if (key->level == 1) {
  481. XMEMCPY(key->k, newPriv, SPHINCS_LEVEL1_KEY_SIZE);
  482. }
  483. else if (key->level == 3) {
  484. XMEMCPY(key->k, newPriv, SPHINCS_LEVEL3_KEY_SIZE);
  485. }
  486. else if (key->level == 5) {
  487. XMEMCPY(key->k, newPriv, SPHINCS_LEVEL5_KEY_SIZE);
  488. }
  489. key->prvKeySet = 1;
  490. }
  491. return ret;
  492. }
  493. /* Export the sphincs private key.
  494. *
  495. * key [in] Sphincs private key.
  496. * out [in] Array to hold private key.
  497. * outLen [in/out] On in, the number of bytes in array.
  498. * On out, the number bytes put into array.
  499. * returns BAD_FUNC_ARG when a parameter is NULL,
  500. * BUFFER_E when outLen is less than SPHINCS_LEVEL1_KEY_SIZE,
  501. * 0 otherwise.
  502. */
  503. int wc_sphincs_export_private_only(sphincs_key* key, byte* out, word32* outLen)
  504. {
  505. /* sanity checks on arguments */
  506. if ((key == NULL) || (out == NULL) || (outLen == NULL)) {
  507. return BAD_FUNC_ARG;
  508. }
  509. if ((key->level != 1) && (key->level != 3) && (key->level != 5)) {
  510. return BAD_FUNC_ARG;
  511. }
  512. if ((key->optim != FAST_VARIANT) && (key->optim != SMALL_VARIANT)) {
  513. return BAD_FUNC_ARG;
  514. }
  515. /* check and set up out length */
  516. if ((key->level == 1) && (*outLen < SPHINCS_LEVEL1_KEY_SIZE)) {
  517. *outLen = SPHINCS_LEVEL1_KEY_SIZE;
  518. return BUFFER_E;
  519. }
  520. else if ((key->level == 3) && (*outLen < SPHINCS_LEVEL3_KEY_SIZE)) {
  521. *outLen = SPHINCS_LEVEL3_KEY_SIZE;
  522. return BUFFER_E;
  523. }
  524. else if ((key->level == 5) && (*outLen < SPHINCS_LEVEL5_KEY_SIZE)) {
  525. *outLen = SPHINCS_LEVEL5_KEY_SIZE;
  526. return BUFFER_E;
  527. }
  528. if (key->level == 1) {
  529. *outLen = SPHINCS_LEVEL1_KEY_SIZE;
  530. }
  531. else if (key->level == 3) {
  532. *outLen = SPHINCS_LEVEL3_KEY_SIZE;
  533. }
  534. else if (key->level == 5) {
  535. *outLen = SPHINCS_LEVEL5_KEY_SIZE;
  536. }
  537. XMEMCPY(out, key->k, *outLen);
  538. return 0;
  539. }
  540. /* Export the sphincs private and public key.
  541. *
  542. * key [in] Sphincs private/public key.
  543. * out [in] Array to hold private and public key.
  544. * outLen [in/out] On in, the number of bytes in array.
  545. * On out, the number bytes put into array.
  546. * returns BAD_FUNC_ARG when a parameter is NULL,
  547. * BUFFER_E when outLen is less than required, 0 otherwise.
  548. */
  549. int wc_sphincs_export_private(sphincs_key* key, byte* out, word32* outLen)
  550. {
  551. /* sanity checks on arguments */
  552. if ((key == NULL) || (out == NULL) || (outLen == NULL)) {
  553. return BAD_FUNC_ARG;
  554. }
  555. if ((key->level != 1) && (key->level != 3) && (key->level != 5)) {
  556. return BAD_FUNC_ARG;
  557. }
  558. if ((key->optim != FAST_VARIANT) && (key->optim != SMALL_VARIANT)) {
  559. return BAD_FUNC_ARG;
  560. }
  561. if ((key->level == 1) && (*outLen < SPHINCS_LEVEL1_PRV_KEY_SIZE)) {
  562. *outLen = SPHINCS_LEVEL1_PRV_KEY_SIZE;
  563. return BUFFER_E;
  564. }
  565. else if ((key->level == 3) && (*outLen < SPHINCS_LEVEL3_PRV_KEY_SIZE)) {
  566. *outLen = SPHINCS_LEVEL3_PRV_KEY_SIZE;
  567. return BUFFER_E;
  568. }
  569. else if ((key->level == 5) && (*outLen < SPHINCS_LEVEL5_PRV_KEY_SIZE)) {
  570. *outLen = SPHINCS_LEVEL5_PRV_KEY_SIZE;
  571. return BUFFER_E;
  572. }
  573. if (key->level == 1) {
  574. *outLen = SPHINCS_LEVEL1_PRV_KEY_SIZE;
  575. XMEMCPY(out, key->k, SPHINCS_LEVEL1_PRV_KEY_SIZE);
  576. XMEMCPY(out + SPHINCS_LEVEL1_PRV_KEY_SIZE, key->p,
  577. SPHINCS_LEVEL1_PUB_KEY_SIZE);
  578. }
  579. else if (key->level == 3) {
  580. *outLen = SPHINCS_LEVEL3_PRV_KEY_SIZE;
  581. XMEMCPY(out, key->k, SPHINCS_LEVEL3_PRV_KEY_SIZE);
  582. XMEMCPY(out + SPHINCS_LEVEL3_PRV_KEY_SIZE, key->p,
  583. SPHINCS_LEVEL3_PUB_KEY_SIZE);
  584. }
  585. else if (key->level == 5) {
  586. *outLen = SPHINCS_LEVEL5_PRV_KEY_SIZE;
  587. XMEMCPY(out, key->k, SPHINCS_LEVEL5_PRV_KEY_SIZE);
  588. XMEMCPY(out + SPHINCS_LEVEL5_PRV_KEY_SIZE, key->p,
  589. SPHINCS_LEVEL5_PUB_KEY_SIZE);
  590. }
  591. return 0;
  592. }
  593. /* Export the sphincs private and public key.
  594. *
  595. * key [in] Sphincs private/public key.
  596. * priv [in] Array to hold private key.
  597. * privSz [in/out] On in, the number of bytes in private key array.
  598. * pub [in] Array to hold public key.
  599. * pubSz [in/out] On in, the number of bytes in public key array.
  600. * On out, the number bytes put into array.
  601. * returns BAD_FUNC_ARG when a parameter is NULL,
  602. * BUFFER_E when privSz is or pubSz is less than required,
  603. * 0 otherwise.
  604. */
  605. int wc_sphincs_export_key(sphincs_key* key, byte* priv, word32 *privSz,
  606. byte* pub, word32 *pubSz)
  607. {
  608. int ret = 0;
  609. /* export private part */
  610. ret = wc_sphincs_export_private(key, priv, privSz);
  611. if (ret == 0) {
  612. /* export public part */
  613. ret = wc_sphincs_export_public(key, pub, pubSz);
  614. }
  615. return ret;
  616. }
  617. /* Check the public key of the sphincs key matches the private key.
  618. *
  619. * key [in] Sphincs private/public key.
  620. * returns BAD_FUNC_ARG when key is NULL,
  621. * PUBLIC_KEY_E when the public key is not set or doesn't match,
  622. * other -ve value on hash failure,
  623. * 0 otherwise.
  624. */
  625. int wc_sphincs_check_key(sphincs_key* key)
  626. {
  627. if (key == NULL) {
  628. return BAD_FUNC_ARG;
  629. }
  630. /* Assume everything is fine. */
  631. return 0;
  632. }
  633. /* Returns the size of a sphincs private key.
  634. *
  635. * key [in] Sphincs private/public key.
  636. * returns BAD_FUNC_ARG when key is NULL,
  637. * SPHINCS_LEVELn_KEY_SIZE otherwise.
  638. */
  639. int wc_sphincs_size(sphincs_key* key)
  640. {
  641. if (key == NULL) {
  642. return BAD_FUNC_ARG;
  643. }
  644. if (key->level == 1) {
  645. return SPHINCS_LEVEL1_KEY_SIZE;
  646. }
  647. else if (key->level == 3) {
  648. return SPHINCS_LEVEL3_KEY_SIZE;
  649. }
  650. else if (key->level == 5) {
  651. return SPHINCS_LEVEL5_KEY_SIZE;
  652. }
  653. return BAD_FUNC_ARG;
  654. }
  655. /* Returns the size of a sphincs private plus public key.
  656. *
  657. * key [in] Sphincs private/public key.
  658. * returns BAD_FUNC_ARG when key is NULL,
  659. * SPHINCS_LEVELn_PRV_KEY_SIZE otherwise.
  660. */
  661. int wc_sphincs_priv_size(sphincs_key* key)
  662. {
  663. if (key == NULL) {
  664. return BAD_FUNC_ARG;
  665. }
  666. if (key->level == 1) {
  667. return SPHINCS_LEVEL1_PRV_KEY_SIZE;
  668. }
  669. else if (key->level == 3) {
  670. return SPHINCS_LEVEL3_PRV_KEY_SIZE;
  671. }
  672. else if (key->level == 5) {
  673. return SPHINCS_LEVEL5_PRV_KEY_SIZE;
  674. }
  675. return BAD_FUNC_ARG;
  676. }
  677. /* Returns the size of a sphincs public key.
  678. *
  679. * key [in] Sphincs private/public key.
  680. * returns BAD_FUNC_ARG when key is NULL,
  681. * SPHINCS_FAST_LEVEL1_PUB_KEY_SIZE otherwise.
  682. */
  683. int wc_sphincs_pub_size(sphincs_key* key)
  684. {
  685. if (key == NULL) {
  686. return BAD_FUNC_ARG;
  687. }
  688. if (key->level == 1) {
  689. return SPHINCS_LEVEL1_PUB_KEY_SIZE;
  690. }
  691. else if (key->level == 3) {
  692. return SPHINCS_LEVEL3_PUB_KEY_SIZE;
  693. }
  694. else if (key->level == 5) {
  695. return SPHINCS_LEVEL5_PUB_KEY_SIZE;
  696. }
  697. return BAD_FUNC_ARG;
  698. }
  699. /* Returns the size of a sphincs signature.
  700. *
  701. * key [in] Sphincs private/public key.
  702. * returns BAD_FUNC_ARG when key is NULL,
  703. * SPHINCS_FAST_LEVEL1_SIG_SIZE otherwise.
  704. */
  705. int wc_sphincs_sig_size(sphincs_key* key)
  706. {
  707. if (key == NULL) {
  708. return BAD_FUNC_ARG;
  709. }
  710. if ((key->level == 1) && (key->optim == FAST_VARIANT)) {
  711. return SPHINCS_FAST_LEVEL1_SIG_SIZE;
  712. }
  713. else if ((key->level == 3) && (key->optim == FAST_VARIANT)) {
  714. return SPHINCS_FAST_LEVEL3_SIG_SIZE;
  715. }
  716. else if ((key->level == 5) && (key->optim == FAST_VARIANT)) {
  717. return SPHINCS_FAST_LEVEL5_SIG_SIZE;
  718. }
  719. else if ((key->level == 1) && (key->optim == SMALL_VARIANT)) {
  720. return SPHINCS_SMALL_LEVEL1_SIG_SIZE;
  721. }
  722. else if ((key->level == 3) && (key->optim == SMALL_VARIANT)) {
  723. return SPHINCS_SMALL_LEVEL3_SIG_SIZE;
  724. }
  725. else if ((key->level == 5) && (key->optim == SMALL_VARIANT)) {
  726. return SPHINCS_SMALL_LEVEL5_SIG_SIZE;
  727. }
  728. return BAD_FUNC_ARG;
  729. }
  730. int wc_Sphincs_PrivateKeyDecode(const byte* input, word32* inOutIdx,
  731. sphincs_key* key, word32 inSz)
  732. {
  733. int ret = 0;
  734. byte privKey[SPHINCS_MAX_KEY_SIZE], pubKey[SPHINCS_MAX_PUB_KEY_SIZE];
  735. word32 privKeyLen = (word32)sizeof(privKey);
  736. word32 pubKeyLen = (word32)sizeof(pubKey);
  737. int keytype = 0;
  738. if (input == NULL || inOutIdx == NULL || key == NULL || inSz == 0) {
  739. return BAD_FUNC_ARG;
  740. }
  741. if ((key->level == 1) && (key->optim == FAST_VARIANT)) {
  742. keytype = SPHINCS_FAST_LEVEL1k;
  743. }
  744. else if ((key->level == 3) && (key->optim == FAST_VARIANT)) {
  745. keytype = SPHINCS_FAST_LEVEL3k;
  746. }
  747. else if ((key->level == 5) && (key->optim == FAST_VARIANT)) {
  748. keytype = SPHINCS_FAST_LEVEL5k;
  749. }
  750. if ((key->level == 1) && (key->optim == SMALL_VARIANT)) {
  751. keytype = SPHINCS_SMALL_LEVEL1k;
  752. }
  753. else if ((key->level == 3) && (key->optim == SMALL_VARIANT)) {
  754. keytype = SPHINCS_SMALL_LEVEL3k;
  755. }
  756. else if ((key->level == 5) && (key->optim == SMALL_VARIANT)) {
  757. keytype = SPHINCS_SMALL_LEVEL5k;
  758. }
  759. else {
  760. return BAD_FUNC_ARG;
  761. }
  762. ret = DecodeAsymKey(input, inOutIdx, inSz, privKey, &privKeyLen,
  763. pubKey, &pubKeyLen, keytype);
  764. if (ret == 0) {
  765. if (pubKeyLen == 0) {
  766. ret = wc_sphincs_import_private_only(input, inSz, key);
  767. }
  768. else {
  769. ret = wc_sphincs_import_private_key(privKey, privKeyLen,
  770. pubKey, pubKeyLen, key);
  771. }
  772. }
  773. return ret;
  774. }
  775. int wc_Sphincs_PublicKeyDecode(const byte* input, word32* inOutIdx,
  776. sphincs_key* key, word32 inSz)
  777. {
  778. int ret = 0;
  779. byte pubKey[SPHINCS_MAX_PUB_KEY_SIZE];
  780. word32 pubKeyLen = (word32)sizeof(pubKey);
  781. int keytype = 0;
  782. if (input == NULL || inOutIdx == NULL || key == NULL || inSz == 0) {
  783. return BAD_FUNC_ARG;
  784. }
  785. if ((key->level == 1) && (key->optim == FAST_VARIANT)) {
  786. keytype = SPHINCS_FAST_LEVEL1k;
  787. }
  788. else if ((key->level == 3) && (key->optim == FAST_VARIANT)) {
  789. keytype = SPHINCS_FAST_LEVEL3k;
  790. }
  791. else if ((key->level == 5) && (key->optim == FAST_VARIANT)) {
  792. keytype = SPHINCS_FAST_LEVEL5k;
  793. }
  794. if ((key->level == 1) && (key->optim == SMALL_VARIANT)) {
  795. keytype = SPHINCS_SMALL_LEVEL1k;
  796. }
  797. else if ((key->level == 3) && (key->optim == SMALL_VARIANT)) {
  798. keytype = SPHINCS_SMALL_LEVEL3k;
  799. }
  800. else if ((key->level == 5) && (key->optim == SMALL_VARIANT)) {
  801. keytype = SPHINCS_SMALL_LEVEL5k;
  802. }
  803. else {
  804. return BAD_FUNC_ARG;
  805. }
  806. ret = DecodeAsymKeyPublic(input, inOutIdx, inSz, pubKey, &pubKeyLen,
  807. keytype);
  808. if (ret == 0) {
  809. ret = wc_sphincs_import_public(pubKey, pubKeyLen, key);
  810. }
  811. return ret;
  812. }
  813. #ifdef WC_ENABLE_ASYM_KEY_EXPORT
  814. /* Encode the public part of an Sphincs key in DER.
  815. *
  816. * Pass NULL for output to get the size of the encoding.
  817. *
  818. * @param [in] key Sphincs key object.
  819. * @param [out] output Buffer to put encoded data in.
  820. * @param [in] outLen Size of buffer in bytes.
  821. * @param [in] withAlg Whether to use SubjectPublicKeyInfo format.
  822. * @return Size of encoded data in bytes on success.
  823. * @return BAD_FUNC_ARG when key is NULL.
  824. * @return MEMORY_E when dynamic memory allocation failed.
  825. */
  826. int wc_Sphincs_PublicKeyToDer(sphincs_key* key, byte* output, word32 inLen,
  827. int withAlg)
  828. {
  829. int ret;
  830. byte pubKey[SPHINCS_MAX_PUB_KEY_SIZE];
  831. word32 pubKeyLen = (word32)sizeof(pubKey);
  832. int keytype = 0;
  833. if (key == NULL || output == NULL) {
  834. return BAD_FUNC_ARG;
  835. }
  836. if ((key->level == 1) && (key->optim == FAST_VARIANT)) {
  837. keytype = SPHINCS_FAST_LEVEL1k;
  838. }
  839. else if ((key->level == 3) && (key->optim == FAST_VARIANT)) {
  840. keytype = SPHINCS_FAST_LEVEL3k;
  841. }
  842. else if ((key->level == 5) && (key->optim == FAST_VARIANT)) {
  843. keytype = SPHINCS_FAST_LEVEL5k;
  844. }
  845. if ((key->level == 1) && (key->optim == SMALL_VARIANT)) {
  846. keytype = SPHINCS_SMALL_LEVEL1k;
  847. }
  848. else if ((key->level == 3) && (key->optim == SMALL_VARIANT)) {
  849. keytype = SPHINCS_SMALL_LEVEL3k;
  850. }
  851. else if ((key->level == 5) && (key->optim == SMALL_VARIANT)) {
  852. keytype = SPHINCS_SMALL_LEVEL5k;
  853. }
  854. else {
  855. return BAD_FUNC_ARG;
  856. }
  857. ret = wc_sphincs_export_public(key, pubKey, &pubKeyLen);
  858. if (ret == 0) {
  859. ret = SetAsymKeyDerPublic(pubKey, pubKeyLen, output, inLen, keytype,
  860. withAlg);
  861. }
  862. return ret;
  863. }
  864. #endif
  865. int wc_Sphincs_KeyToDer(sphincs_key* key, byte* output, word32 inLen)
  866. {
  867. if (key == NULL) {
  868. return BAD_FUNC_ARG;
  869. }
  870. if ((key->level == 1) && (key->optim == FAST_VARIANT)) {
  871. return SetAsymKeyDer(key->k, SPHINCS_LEVEL1_KEY_SIZE, key->p,
  872. SPHINCS_LEVEL1_KEY_SIZE, output, inLen,
  873. SPHINCS_FAST_LEVEL1k);
  874. }
  875. else if ((key->level == 3) && (key->optim == FAST_VARIANT)) {
  876. return SetAsymKeyDer(key->k, SPHINCS_LEVEL3_KEY_SIZE, key->p,
  877. SPHINCS_LEVEL3_KEY_SIZE, output, inLen,
  878. SPHINCS_FAST_LEVEL3k);
  879. }
  880. else if ((key->level == 5) && (key->optim == FAST_VARIANT)) {
  881. return SetAsymKeyDer(key->k, SPHINCS_LEVEL5_KEY_SIZE, key->p,
  882. SPHINCS_LEVEL5_KEY_SIZE, output, inLen,
  883. SPHINCS_FAST_LEVEL5k);
  884. }
  885. else if ((key->level == 1) && (key->optim == SMALL_VARIANT)) {
  886. return SetAsymKeyDer(key->k, SPHINCS_LEVEL1_KEY_SIZE, key->p,
  887. SPHINCS_LEVEL1_KEY_SIZE, output, inLen,
  888. SPHINCS_SMALL_LEVEL1k);
  889. }
  890. else if ((key->level == 3) && (key->optim == SMALL_VARIANT)) {
  891. return SetAsymKeyDer(key->k, SPHINCS_LEVEL3_KEY_SIZE, key->p,
  892. SPHINCS_LEVEL3_KEY_SIZE, output, inLen,
  893. SPHINCS_SMALL_LEVEL3k);
  894. }
  895. else if ((key->level == 5) && (key->optim == SMALL_VARIANT)) {
  896. return SetAsymKeyDer(key->k, SPHINCS_LEVEL5_KEY_SIZE, key->p,
  897. SPHINCS_LEVEL5_KEY_SIZE, output, inLen,
  898. SPHINCS_SMALL_LEVEL5k);
  899. }
  900. return BAD_FUNC_ARG;
  901. }
  902. int wc_Sphincs_PrivateKeyToDer(sphincs_key* key, byte* output, word32 inLen)
  903. {
  904. if (key == NULL) {
  905. return BAD_FUNC_ARG;
  906. }
  907. if ((key->level == 1) && (key->optim == FAST_VARIANT)) {
  908. return SetAsymKeyDer(key->k, SPHINCS_LEVEL1_KEY_SIZE, NULL, 0, output,
  909. inLen, SPHINCS_FAST_LEVEL1k);
  910. }
  911. else if ((key->level == 3) && (key->optim == FAST_VARIANT)) {
  912. return SetAsymKeyDer(key->k, SPHINCS_LEVEL3_KEY_SIZE, NULL, 0, output,
  913. inLen, SPHINCS_FAST_LEVEL3k);
  914. }
  915. else if ((key->level == 5) && (key->optim == FAST_VARIANT)) {
  916. return SetAsymKeyDer(key->k, SPHINCS_LEVEL5_KEY_SIZE, NULL, 0, output,
  917. inLen, SPHINCS_FAST_LEVEL5k);
  918. }
  919. else if ((key->level == 1) && (key->optim == SMALL_VARIANT)) {
  920. return SetAsymKeyDer(key->k, SPHINCS_LEVEL1_KEY_SIZE, NULL, 0, output,
  921. inLen, SPHINCS_SMALL_LEVEL1k);
  922. }
  923. else if ((key->level == 3) && (key->optim == SMALL_VARIANT)) {
  924. return SetAsymKeyDer(key->k, SPHINCS_LEVEL3_KEY_SIZE, NULL, 0, output,
  925. inLen, SPHINCS_SMALL_LEVEL3k);
  926. }
  927. else if ((key->level == 5) && (key->optim == SMALL_VARIANT)) {
  928. return SetAsymKeyDer(key->k, SPHINCS_LEVEL5_KEY_SIZE, NULL, 0, output,
  929. inLen, SPHINCS_SMALL_LEVEL5k);
  930. }
  931. return BAD_FUNC_ARG;
  932. }
  933. #endif /* HAVE_PQC && HAVE_SPHINCS */