mbed TLS v3.1.0
rsa.h
Go to the documentation of this file.
1 
12 /*
13  * Copyright The Mbed TLS Contributors
14  * SPDX-License-Identifier: Apache-2.0
15  *
16  * Licensed under the Apache License, Version 2.0 (the "License"); you may
17  * not use this file except in compliance with the License.
18  * You may obtain a copy of the License at
19  *
20  * http://www.apache.org/licenses/LICENSE-2.0
21  *
22  * Unless required by applicable law or agreed to in writing, software
23  * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
24  * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
25  * See the License for the specific language governing permissions and
26  * limitations under the License.
27  */
28 #ifndef MBEDTLS_RSA_H
29 #define MBEDTLS_RSA_H
30 #include "mbedtls/private_access.h"
31 
32 #include "mbedtls/build_info.h"
33 
34 #include "mbedtls/bignum.h"
35 #include "mbedtls/md.h"
36 
37 #if defined(MBEDTLS_THREADING_C)
38 #include "mbedtls/threading.h"
39 #endif
40 
41 /*
42  * RSA Error codes
43  */
45 #define MBEDTLS_ERR_RSA_BAD_INPUT_DATA -0x4080
46 
47 #define MBEDTLS_ERR_RSA_INVALID_PADDING -0x4100
48 
49 #define MBEDTLS_ERR_RSA_KEY_GEN_FAILED -0x4180
50 
51 #define MBEDTLS_ERR_RSA_KEY_CHECK_FAILED -0x4200
52 
53 #define MBEDTLS_ERR_RSA_PUBLIC_FAILED -0x4280
54 
55 #define MBEDTLS_ERR_RSA_PRIVATE_FAILED -0x4300
56 
57 #define MBEDTLS_ERR_RSA_VERIFY_FAILED -0x4380
58 
59 #define MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE -0x4400
60 
61 #define MBEDTLS_ERR_RSA_RNG_FAILED -0x4480
62 
63 /*
64  * RSA constants
65  */
66 
67 #define MBEDTLS_RSA_PKCS_V15 0
68 #define MBEDTLS_RSA_PKCS_V21 1
70 #define MBEDTLS_RSA_SIGN 1
71 #define MBEDTLS_RSA_CRYPT 2
73 #define MBEDTLS_RSA_SALT_LEN_ANY -1
74 
75 /*
76  * The above constants may be used even if the RSA module is compile out,
77  * eg for alternative (PKCS#11) RSA implemenations in the PK layers.
78  */
79 
80 #ifdef __cplusplus
81 extern "C" {
82 #endif
83 
84 #if !defined(MBEDTLS_RSA_ALT)
85 // Regular implementation
86 //
87 
91 typedef struct mbedtls_rsa_context
92 {
93  int MBEDTLS_PRIVATE(ver);
97  size_t MBEDTLS_PRIVATE(len);
118  int MBEDTLS_PRIVATE(padding);
121  int MBEDTLS_PRIVATE(hash_id);
125 #if defined(MBEDTLS_THREADING_C)
126  /* Invariant: the mutex is initialized iff ver != 0. */
128 #endif
129 }
130 mbedtls_rsa_context;
131 
132 #else /* MBEDTLS_RSA_ALT */
133 #include "rsa_alt.h"
134 #endif /* MBEDTLS_RSA_ALT */
135 
146 void mbedtls_rsa_init( mbedtls_rsa_context *ctx );
147 
182 int mbedtls_rsa_set_padding( mbedtls_rsa_context *ctx, int padding,
183  mbedtls_md_type_t hash_id );
184 
214 int mbedtls_rsa_import( mbedtls_rsa_context *ctx,
215  const mbedtls_mpi *N,
216  const mbedtls_mpi *P, const mbedtls_mpi *Q,
217  const mbedtls_mpi *D, const mbedtls_mpi *E );
218 
253 int mbedtls_rsa_import_raw( mbedtls_rsa_context *ctx,
254  unsigned char const *N, size_t N_len,
255  unsigned char const *P, size_t P_len,
256  unsigned char const *Q, size_t Q_len,
257  unsigned char const *D, size_t D_len,
258  unsigned char const *E, size_t E_len );
259 
292 int mbedtls_rsa_complete( mbedtls_rsa_context *ctx );
293 
334 int mbedtls_rsa_export( const mbedtls_rsa_context *ctx,
336  mbedtls_mpi *D, mbedtls_mpi *E );
337 
385 int mbedtls_rsa_export_raw( const mbedtls_rsa_context *ctx,
386  unsigned char *N, size_t N_len,
387  unsigned char *P, size_t P_len,
388  unsigned char *Q, size_t Q_len,
389  unsigned char *D, size_t D_len,
390  unsigned char *E, size_t E_len );
391 
411 int mbedtls_rsa_export_crt( const mbedtls_rsa_context *ctx,
412  mbedtls_mpi *DP, mbedtls_mpi *DQ, mbedtls_mpi *QP );
413 
422 size_t mbedtls_rsa_get_len( const mbedtls_rsa_context *ctx );
423 
442 int mbedtls_rsa_gen_key( mbedtls_rsa_context *ctx,
443  int (*f_rng)(void *, unsigned char *, size_t),
444  void *p_rng,
445  unsigned int nbits, int exponent );
446 
461 int mbedtls_rsa_check_pubkey( const mbedtls_rsa_context *ctx );
462 
499 int mbedtls_rsa_check_privkey( const mbedtls_rsa_context *ctx );
500 
512 int mbedtls_rsa_check_pub_priv( const mbedtls_rsa_context *pub,
513  const mbedtls_rsa_context *prv );
514 
534 int mbedtls_rsa_public( mbedtls_rsa_context *ctx,
535  const unsigned char *input,
536  unsigned char *output );
537 
567 int mbedtls_rsa_private( mbedtls_rsa_context *ctx,
568  int (*f_rng)(void *, unsigned char *, size_t),
569  void *p_rng,
570  const unsigned char *input,
571  unsigned char *output );
572 
596 int mbedtls_rsa_pkcs1_encrypt( mbedtls_rsa_context *ctx,
597  int (*f_rng)(void *, unsigned char *, size_t),
598  void *p_rng,
599  size_t ilen,
600  const unsigned char *input,
601  unsigned char *output );
602 
623 int mbedtls_rsa_rsaes_pkcs1_v15_encrypt( mbedtls_rsa_context *ctx,
624  int (*f_rng)(void *, unsigned char *, size_t),
625  void *p_rng,
626  size_t ilen,
627  const unsigned char *input,
628  unsigned char *output );
629 
657 int mbedtls_rsa_rsaes_oaep_encrypt( mbedtls_rsa_context *ctx,
658  int (*f_rng)(void *, unsigned char *, size_t),
659  void *p_rng,
660  const unsigned char *label, size_t label_len,
661  size_t ilen,
662  const unsigned char *input,
663  unsigned char *output );
664 
696 int mbedtls_rsa_pkcs1_decrypt( mbedtls_rsa_context *ctx,
697  int (*f_rng)(void *, unsigned char *, size_t),
698  void *p_rng,
699  size_t *olen,
700  const unsigned char *input,
701  unsigned char *output,
702  size_t output_max_len );
703 
733 int mbedtls_rsa_rsaes_pkcs1_v15_decrypt( mbedtls_rsa_context *ctx,
734  int (*f_rng)(void *, unsigned char *, size_t),
735  void *p_rng,
736  size_t *olen,
737  const unsigned char *input,
738  unsigned char *output,
739  size_t output_max_len );
740 
774 int mbedtls_rsa_rsaes_oaep_decrypt( mbedtls_rsa_context *ctx,
775  int (*f_rng)(void *, unsigned char *, size_t),
776  void *p_rng,
777  const unsigned char *label, size_t label_len,
778  size_t *olen,
779  const unsigned char *input,
780  unsigned char *output,
781  size_t output_max_len );
782 
817 int mbedtls_rsa_pkcs1_sign( mbedtls_rsa_context *ctx,
818  int (*f_rng)(void *, unsigned char *, size_t),
819  void *p_rng,
820  mbedtls_md_type_t md_alg,
821  unsigned int hashlen,
822  const unsigned char *hash,
823  unsigned char *sig );
824 
849 int mbedtls_rsa_rsassa_pkcs1_v15_sign( mbedtls_rsa_context *ctx,
850  int (*f_rng)(void *, unsigned char *, size_t),
851  void *p_rng,
852  mbedtls_md_type_t md_alg,
853  unsigned int hashlen,
854  const unsigned char *hash,
855  unsigned char *sig );
856 
900 int mbedtls_rsa_rsassa_pss_sign_ext( mbedtls_rsa_context *ctx,
901  int (*f_rng)(void *, unsigned char *, size_t),
902  void *p_rng,
903  mbedtls_md_type_t md_alg,
904  unsigned int hashlen,
905  const unsigned char *hash,
906  int saltlen,
907  unsigned char *sig );
908 
950 int mbedtls_rsa_rsassa_pss_sign( mbedtls_rsa_context *ctx,
951  int (*f_rng)(void *, unsigned char *, size_t),
952  void *p_rng,
953  mbedtls_md_type_t md_alg,
954  unsigned int hashlen,
955  const unsigned char *hash,
956  unsigned char *sig );
957 
984 int mbedtls_rsa_pkcs1_verify( mbedtls_rsa_context *ctx,
985  mbedtls_md_type_t md_alg,
986  unsigned int hashlen,
987  const unsigned char *hash,
988  const unsigned char *sig );
989 
1009 int mbedtls_rsa_rsassa_pkcs1_v15_verify( mbedtls_rsa_context *ctx,
1010  mbedtls_md_type_t md_alg,
1011  unsigned int hashlen,
1012  const unsigned char *hash,
1013  const unsigned char *sig );
1014 
1044 int mbedtls_rsa_rsassa_pss_verify( mbedtls_rsa_context *ctx,
1045  mbedtls_md_type_t md_alg,
1046  unsigned int hashlen,
1047  const unsigned char *hash,
1048  const unsigned char *sig );
1049 
1084 int mbedtls_rsa_rsassa_pss_verify_ext( mbedtls_rsa_context *ctx,
1085  mbedtls_md_type_t md_alg,
1086  unsigned int hashlen,
1087  const unsigned char *hash,
1088  mbedtls_md_type_t mgf1_hash_id,
1089  int expected_salt_len,
1090  const unsigned char *sig );
1091 
1101 int mbedtls_rsa_copy( mbedtls_rsa_context *dst, const mbedtls_rsa_context *src );
1102 
1110 void mbedtls_rsa_free( mbedtls_rsa_context *ctx );
1111 
1112 #if defined(MBEDTLS_SELF_TEST)
1113 
1120 int mbedtls_rsa_self_test( int verbose );
1121 
1122 #endif /* MBEDTLS_SELF_TEST */
1123 
1124 #ifdef __cplusplus
1125 }
1126 #endif
1127 
1128 #endif /* rsa.h */
void mbedtls_rsa_init(mbedtls_rsa_context *ctx)
This function initializes an RSA context.
int mbedtls_rsa_self_test(int verbose)
The RSA checkup routine.
int mbedtls_rsa_export_raw(const mbedtls_rsa_context *ctx, unsigned char *N, size_t N_len, unsigned char *P, size_t P_len, unsigned char *Q, size_t Q_len, unsigned char *D, size_t D_len, unsigned char *E, size_t E_len)
This function exports core parameters of an RSA key in raw big-endian binary format.
int mbedtls_rsa_rsassa_pkcs1_v15_sign(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, unsigned char *sig)
This function performs a PKCS#1 v1.5 signature operation (RSASSA-PKCS1-v1_5-SIGN).
int mbedtls_rsa_public(mbedtls_rsa_context *ctx, const unsigned char *input, unsigned char *output)
This function performs an RSA public key operation.
int mbedtls_rsa_rsassa_pkcs1_v15_verify(mbedtls_rsa_context *ctx, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, const unsigned char *sig)
This function performs a PKCS#1 v1.5 verification operation (RSASSA-PKCS1-v1_5-VERIFY).
int mbedtls_rsa_import(mbedtls_rsa_context *ctx, const mbedtls_mpi *N, const mbedtls_mpi *P, const mbedtls_mpi *Q, const mbedtls_mpi *D, const mbedtls_mpi *E)
This function imports a set of core parameters into an RSA context.
#define MBEDTLS_PRIVATE(member)
int mbedtls_rsa_rsaes_pkcs1_v15_decrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, size_t *olen, const unsigned char *input, unsigned char *output, size_t output_max_len)
This function performs a PKCS#1 v1.5 decryption operation (RSAES-PKCS1-v1_5-DECRYPT).
int mbedtls_rsa_set_padding(mbedtls_rsa_context *ctx, int padding, mbedtls_md_type_t hash_id)
This function sets padding for an already initialized RSA context.
int mbedtls_rsa_pkcs1_sign(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, unsigned char *sig)
This function performs a private RSA operation to sign a message digest using PKCS#1.
int mbedtls_rsa_complete(mbedtls_rsa_context *ctx)
This function completes an RSA context from a set of imported core parameters.
Multi-precision integer library.
int mbedtls_rsa_import_raw(mbedtls_rsa_context *ctx, unsigned char const *N, size_t N_len, unsigned char const *P, size_t P_len, unsigned char const *Q, size_t Q_len, unsigned char const *D, size_t D_len, unsigned char const *E, size_t E_len)
This function imports core RSA parameters, in raw big-endian binary format, into an RSA context...
int mbedtls_rsa_rsaes_oaep_decrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, const unsigned char *label, size_t label_len, size_t *olen, const unsigned char *input, unsigned char *output, size_t output_max_len)
This function performs a PKCS#1 v2.1 OAEP decryption operation (RSAES-OAEP-DECRYPT).
int mbedtls_rsa_check_pub_priv(const mbedtls_rsa_context *pub, const mbedtls_rsa_context *prv)
This function checks a public-private RSA key pair.
Threading abstraction layer.
int mbedtls_rsa_rsassa_pss_verify(mbedtls_rsa_context *ctx, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, const unsigned char *sig)
This function performs a PKCS#1 v2.1 PSS verification operation (RSASSA-PSS-VERIFY).
int mbedtls_rsa_export(const mbedtls_rsa_context *ctx, mbedtls_mpi *N, mbedtls_mpi *P, mbedtls_mpi *Q, mbedtls_mpi *D, mbedtls_mpi *E)
This function exports the core parameters of an RSA key.
int mbedtls_rsa_pkcs1_encrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, size_t ilen, const unsigned char *input, unsigned char *output)
This function adds the message padding, then performs an RSA operation.
int mbedtls_rsa_private(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, const unsigned char *input, unsigned char *output)
This function performs an RSA private key operation.
int mbedtls_rsa_rsaes_oaep_encrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, const unsigned char *label, size_t label_len, size_t ilen, const unsigned char *input, unsigned char *output)
This function performs a PKCS#1 v2.1 OAEP encryption operation (RSAES-OAEP-ENCRYPT).
Macro wrapper for struct's memebrs.
int mbedtls_rsa_rsassa_pss_sign(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, unsigned char *sig)
This function performs a PKCS#1 v2.1 PSS signature operation (RSASSA-PSS-SIGN).
int mbedtls_rsa_export_crt(const mbedtls_rsa_context *ctx, mbedtls_mpi *DP, mbedtls_mpi *DQ, mbedtls_mpi *QP)
This function exports CRT parameters of a private RSA key.
int mbedtls_rsa_pkcs1_verify(mbedtls_rsa_context *ctx, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, const unsigned char *sig)
This function performs a public RSA operation and checks the message digest.
int mbedtls_rsa_rsassa_pss_sign_ext(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, int saltlen, unsigned char *sig)
This function performs a PKCS#1 v2.1 PSS signature operation (RSASSA-PSS-SIGN).
Build-time configuration info.
int mbedtls_rsa_rsaes_pkcs1_v15_encrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, size_t ilen, const unsigned char *input, unsigned char *output)
This function performs a PKCS#1 v1.5 encryption operation (RSAES-PKCS1-v1_5-ENCRYPT).
This file contains the generic message-digest wrapper.
size_t mbedtls_rsa_get_len(const mbedtls_rsa_context *ctx)
This function retrieves the length of RSA modulus in Bytes.
MPI structure.
Definition: bignum.h:189
int mbedtls_rsa_check_pubkey(const mbedtls_rsa_context *ctx)
This function checks if a context contains at least an RSA public key.
void mbedtls_rsa_free(mbedtls_rsa_context *ctx)
This function frees the components of an RSA key.
int mbedtls_rsa_gen_key(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, unsigned int nbits, int exponent)
This function generates an RSA keypair.
int mbedtls_rsa_copy(mbedtls_rsa_context *dst, const mbedtls_rsa_context *src)
This function copies the components of an RSA context.
int mbedtls_rsa_check_privkey(const mbedtls_rsa_context *ctx)
This function checks if a context contains an RSA private key and perform basic consistency checks...
int mbedtls_rsa_rsassa_pss_verify_ext(mbedtls_rsa_context *ctx, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, mbedtls_md_type_t mgf1_hash_id, int expected_salt_len, const unsigned char *sig)
This function performs a PKCS#1 v2.1 PSS verification operation (RSASSA-PSS-VERIFY).
mbedtls_md_type_t
Supported message digests.
Definition: md.h:55
int mbedtls_rsa_pkcs1_decrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, size_t *olen, const unsigned char *input, unsigned char *output, size_t output_max_len)
This function performs an RSA operation, then removes the message padding.