blob: 40740c3bf14557761c05eea1f0777f8a6af1c52b [file] [log] [blame]
David Zeuthen21e95262016-07-27 17:58:40 -04001/*
2 * Copyright (C) 2016 The Android Open Source Project
3 *
David Zeuthenc612e2e2016-09-16 16:44:08 -04004 * Permission is hereby granted, free of charge, to any person
5 * obtaining a copy of this software and associated documentation
6 * files (the "Software"), to deal in the Software without
7 * restriction, including without limitation the rights to use, copy,
8 * modify, merge, publish, distribute, sublicense, and/or sell copies
9 * of the Software, and to permit persons to whom the Software is
10 * furnished to do so, subject to the following conditions:
David Zeuthen21e95262016-07-27 17:58:40 -040011 *
David Zeuthenc612e2e2016-09-16 16:44:08 -040012 * The above copyright notice and this permission notice shall be
13 * included in all copies or substantial portions of the Software.
David Zeuthen21e95262016-07-27 17:58:40 -040014 *
David Zeuthenc612e2e2016-09-16 16:44:08 -040015 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
16 * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
17 * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
18 * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
19 * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
20 * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
21 * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
22 * SOFTWARE.
David Zeuthen21e95262016-07-27 17:58:40 -040023 */
24
25#if !defined(AVB_INSIDE_LIBAVB_H) && !defined(AVB_COMPILATION)
26#error "Never include this file directly, include libavb.h instead."
27#endif
28
29#ifndef AVB_CRYPTO_H_
30#define AVB_CRYPTO_H_
31
32#include "avb_sysdeps.h"
33
34#ifdef __cplusplus
35extern "C" {
36#endif
37
38/* Algorithms that can be used in the vbmeta image for
39 * verification. An algorithm consists of a hash type and a signature
40 * type.
41 *
42 * The data used to calculate the hash is the three blocks mentioned
43 * in the documentation for |AvbVBMetaImageHeader| except for the data
44 * in the "Authentication data" block.
45 *
46 * For signatures with RSA keys, PKCS v1.5 padding is used. The public
47 * key data is stored in the auxiliary data block, see
48 * |AvbRSAPublicKeyHeader| for the serialization format.
49 *
50 * Each algorithm type is described below:
51 *
52 * AVB_ALGORITHM_TYPE_NONE: There is no hash, no signature of the
53 * data, and no public key. The data cannot be verified. The fields
54 * |hash_size|, |signature_size|, and |public_key_size| must be zero.
55 *
56 * AVB_ALGORITHM_TYPE_SHA256_RSA2048: The hash function used is
57 * SHA-256, resulting in 32 bytes of hash digest data. This hash is
58 * signed with a 2048-bit RSA key. The field |hash_size| must be 32,
59 * |signature_size| must be 256, and the public key data must have
60 * |key_num_bits| set to 2048.
61 *
62 * AVB_ALGORITHM_TYPE_SHA256_RSA4096: Like above, but only with
63 * a 4096-bit RSA key and |signature_size| set to 512.
64 *
65 * AVB_ALGORITHM_TYPE_SHA256_RSA8192: Like above, but only with
66 * a 8192-bit RSA key and |signature_size| set to 1024.
67 *
68 * AVB_ALGORITHM_TYPE_SHA512_RSA2048: The hash function used is
69 * SHA-512, resulting in 64 bytes of hash digest data. This hash is
70 * signed with a 2048-bit RSA key. The field |hash_size| must be 64,
71 * |signature_size| must be 256, and the public key data must have
72 * |key_num_bits| set to 2048.
73 *
74 * AVB_ALGORITHM_TYPE_SHA512_RSA4096: Like above, but only with
75 * a 4096-bit RSA key and |signature_size| set to 512.
76 *
77 * AVB_ALGORITHM_TYPE_SHA512_RSA8192: Like above, but only with
78 * a 8192-bit RSA key and |signature_size| set to 1024.
79 */
80typedef enum {
81 AVB_ALGORITHM_TYPE_NONE,
82 AVB_ALGORITHM_TYPE_SHA256_RSA2048,
83 AVB_ALGORITHM_TYPE_SHA256_RSA4096,
84 AVB_ALGORITHM_TYPE_SHA256_RSA8192,
85 AVB_ALGORITHM_TYPE_SHA512_RSA2048,
86 AVB_ALGORITHM_TYPE_SHA512_RSA4096,
87 AVB_ALGORITHM_TYPE_SHA512_RSA8192,
88 _AVB_ALGORITHM_NUM_TYPES
89} AvbAlgorithmType;
90
91/* The header for a serialized RSA public key.
92 *
93 * The size of the key is given by |key_num_bits|, for example 2048
94 * for a RSA-2048 key. By definition, a RSA public key is the pair (n,
95 * e) where |n| is the modulus (which can be represented in
96 * |key_num_bits| bits) and |e| is the public exponent. The exponent
97 * is not stored since it's assumed to always be 65537.
98 *
99 * To optimize verification, the key block includes two precomputed
100 * values, |n0inv| (fits in 32 bits) and |rr| and can always be
101 * represented in |key_num_bits|.
102
103 * The value |n0inv| is the value -1/n[0] (mod 2^32). The value |rr|
104 * is (2^key_num_bits)^2 (mod n).
105 *
106 * Following this header is |key_num_bits| bits of |n|, then
107 * |key_num_bits| bits of |rr|. Both values are stored with most
108 * significant bit first. Each serialized number takes up
109 * |key_num_bits|/8 bytes.
110 *
111 * All fields in this struct are stored in network byte order when
112 * serialized. To generate a copy with fields swapped to native byte
113 * order, use the function avb_rsa_public_key_header_validate_and_byteswap().
114 *
115 * The avb_rsa_verify() function expects a key in this serialized
116 * format.
117 *
118 * The 'avbtool extract_public_key' command can be used to generate a
119 * serialized RSA public key.
120 */
121typedef struct AvbRSAPublicKeyHeader {
122 uint32_t key_num_bits;
123 uint32_t n0inv;
124} AVB_ATTR_PACKED AvbRSAPublicKeyHeader;
125
126/* Copies |src| to |dest| and validates, byte-swapping fields in the
127 * process if needed. Returns true if valid, false if invalid.
128 */
129bool avb_rsa_public_key_header_validate_and_byteswap(
130 const AvbRSAPublicKeyHeader* src,
131 AvbRSAPublicKeyHeader* dest) AVB_ATTR_WARN_UNUSED_RESULT;
132
133#ifdef __cplusplus
134}
135#endif
136
137#endif /* AVB_CRYPTO_H_ */