mbed TLS v2.28.1
rsa.h
Go to the documentation of this file.
1 
12 /*
13  * Copyright The Mbed TLS Contributors
14  * SPDX-License-Identifier: Apache-2.0
15  *
16  * Licensed under the Apache License, Version 2.0 (the "License"); you may
17  * not use this file except in compliance with the License.
18  * You may obtain a copy of the License at
19  *
20  * http://www.apache.org/licenses/LICENSE-2.0
21  *
22  * Unless required by applicable law or agreed to in writing, software
23  * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
24  * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
25  * See the License for the specific language governing permissions and
26  * limitations under the License.
27  */
28 #ifndef MBEDTLS_RSA_H
29 #define MBEDTLS_RSA_H
30 
31 #if !defined(MBEDTLS_CONFIG_FILE)
32 #include "mbedtls/config.h"
33 #else
34 #include MBEDTLS_CONFIG_FILE
35 #endif
36 
37 #include "mbedtls/bignum.h"
38 #include "mbedtls/md.h"
39 
40 #if defined(MBEDTLS_THREADING_C)
41 #include "mbedtls/threading.h"
42 #endif
43 
44 /*
45  * RSA Error codes
46  */
48 #define MBEDTLS_ERR_RSA_BAD_INPUT_DATA -0x4080
50 #define MBEDTLS_ERR_RSA_INVALID_PADDING -0x4100
52 #define MBEDTLS_ERR_RSA_KEY_GEN_FAILED -0x4180
54 #define MBEDTLS_ERR_RSA_KEY_CHECK_FAILED -0x4200
56 #define MBEDTLS_ERR_RSA_PUBLIC_FAILED -0x4280
58 #define MBEDTLS_ERR_RSA_PRIVATE_FAILED -0x4300
60 #define MBEDTLS_ERR_RSA_VERIFY_FAILED -0x4380
62 #define MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE -0x4400
64 #define MBEDTLS_ERR_RSA_RNG_FAILED -0x4480
65 
66 /* MBEDTLS_ERR_RSA_UNSUPPORTED_OPERATION is deprecated and should not be used.
67  */
69 #define MBEDTLS_ERR_RSA_UNSUPPORTED_OPERATION -0x4500
70 
71 /* MBEDTLS_ERR_RSA_HW_ACCEL_FAILED is deprecated and should not be used. */
73 #define MBEDTLS_ERR_RSA_HW_ACCEL_FAILED -0x4580
74 
75 /*
76  * RSA constants
77  */
78 #define MBEDTLS_RSA_PUBLIC 0
79 #define MBEDTLS_RSA_PRIVATE 1
81 #define MBEDTLS_RSA_PKCS_V15 0
82 #define MBEDTLS_RSA_PKCS_V21 1
84 #define MBEDTLS_RSA_SIGN 1
85 #define MBEDTLS_RSA_CRYPT 2
87 #define MBEDTLS_RSA_SALT_LEN_ANY -1
88 
89 /*
90  * The above constants may be used even if the RSA module is compile out,
91  * eg for alternative (PKCS#11) RSA implementations in the PK layers.
92  */
93 
94 #ifdef __cplusplus
95 extern "C" {
96 #endif
97 
98 #if !defined(MBEDTLS_RSA_ALT)
99 // Regular implementation
100 //
101 
109 typedef struct mbedtls_rsa_context
110 {
111  int ver;
115  size_t len;
136  int padding;
139  int hash_id;
143 #if defined(MBEDTLS_THREADING_C)
144  /* Invariant: the mutex is initialized iff ver != 0. */
146 #endif
147 }
149 
150 #else /* MBEDTLS_RSA_ALT */
151 #include "rsa_alt.h"
152 #endif /* MBEDTLS_RSA_ALT */
153 
182  int padding,
183  int hash_id );
184 
215  const mbedtls_mpi *N,
216  const mbedtls_mpi *P, const mbedtls_mpi *Q,
217  const mbedtls_mpi *D, const mbedtls_mpi *E );
218 
254  unsigned char const *N, size_t N_len,
255  unsigned char const *P, size_t P_len,
256  unsigned char const *Q, size_t Q_len,
257  unsigned char const *D, size_t D_len,
258  unsigned char const *E, size_t E_len );
259 
293 
336  mbedtls_mpi *D, mbedtls_mpi *E );
337 
386  unsigned char *N, size_t N_len,
387  unsigned char *P, size_t P_len,
388  unsigned char *Q, size_t Q_len,
389  unsigned char *D, size_t D_len,
390  unsigned char *E, size_t E_len );
391 
412  mbedtls_mpi *DP, mbedtls_mpi *DQ, mbedtls_mpi *QP );
413 
424  int hash_id );
425 
435 
455  int (*f_rng)(void *, unsigned char *, size_t),
456  void *p_rng,
457  unsigned int nbits, int exponent );
458 
474 
512 
525  const mbedtls_rsa_context *prv );
526 
547  const unsigned char *input,
548  unsigned char *output );
549 
582  int (*f_rng)(void *, unsigned char *, size_t),
583  void *p_rng,
584  const unsigned char *input,
585  unsigned char *output );
586 
627  int (*f_rng)(void *, unsigned char *, size_t),
628  void *p_rng,
629  int mode, size_t ilen,
630  const unsigned char *input,
631  unsigned char *output );
632 
668  int (*f_rng)(void *, unsigned char *, size_t),
669  void *p_rng,
670  int mode, size_t ilen,
671  const unsigned char *input,
672  unsigned char *output );
673 
713  int (*f_rng)(void *, unsigned char *, size_t),
714  void *p_rng,
715  int mode,
716  const unsigned char *label, size_t label_len,
717  size_t ilen,
718  const unsigned char *input,
719  unsigned char *output );
720 
766  int (*f_rng)(void *, unsigned char *, size_t),
767  void *p_rng,
768  int mode, size_t *olen,
769  const unsigned char *input,
770  unsigned char *output,
771  size_t output_max_len );
772 
816  int (*f_rng)(void *, unsigned char *, size_t),
817  void *p_rng,
818  int mode, size_t *olen,
819  const unsigned char *input,
820  unsigned char *output,
821  size_t output_max_len );
822 
870  int (*f_rng)(void *, unsigned char *, size_t),
871  void *p_rng,
872  int mode,
873  const unsigned char *label, size_t label_len,
874  size_t *olen,
875  const unsigned char *input,
876  unsigned char *output,
877  size_t output_max_len );
878 
930  int (*f_rng)(void *, unsigned char *, size_t),
931  void *p_rng,
932  int mode,
933  mbedtls_md_type_t md_alg,
934  unsigned int hashlen,
935  const unsigned char *hash,
936  unsigned char *sig );
937 
978  int (*f_rng)(void *, unsigned char *, size_t),
979  void *p_rng,
980  int mode,
981  mbedtls_md_type_t md_alg,
982  unsigned int hashlen,
983  const unsigned char *hash,
984  unsigned char *sig );
985 
1033  int (*f_rng)(void *, unsigned char *, size_t),
1034  void *p_rng,
1035  mbedtls_md_type_t md_alg,
1036  unsigned int hashlen,
1037  const unsigned char *hash,
1038  int saltlen,
1039  unsigned char *sig );
1040 
1097  int (*f_rng)(void *, unsigned char *, size_t),
1098  void *p_rng,
1099  int mode,
1100  mbedtls_md_type_t md_alg,
1101  unsigned int hashlen,
1102  const unsigned char *hash,
1103  unsigned char *sig );
1104 
1150  int (*f_rng)(void *, unsigned char *, size_t),
1151  void *p_rng,
1152  int mode,
1153  mbedtls_md_type_t md_alg,
1154  unsigned int hashlen,
1155  const unsigned char *hash,
1156  const unsigned char *sig );
1157 
1196  int (*f_rng)(void *, unsigned char *, size_t),
1197  void *p_rng,
1198  int mode,
1199  mbedtls_md_type_t md_alg,
1200  unsigned int hashlen,
1201  const unsigned char *hash,
1202  const unsigned char *sig );
1203 
1252  int (*f_rng)(void *, unsigned char *, size_t),
1253  void *p_rng,
1254  int mode,
1255  mbedtls_md_type_t md_alg,
1256  unsigned int hashlen,
1257  const unsigned char *hash,
1258  const unsigned char *sig );
1259 
1305  int (*f_rng)(void *, unsigned char *, size_t),
1306  void *p_rng,
1307  int mode,
1308  mbedtls_md_type_t md_alg,
1309  unsigned int hashlen,
1310  const unsigned char *hash,
1311  mbedtls_md_type_t mgf1_hash_id,
1312  int expected_salt_len,
1313  const unsigned char *sig );
1314 
1325 
1334 
1335 #if defined(MBEDTLS_SELF_TEST)
1336 
1343 int mbedtls_rsa_self_test( int verbose );
1344 
1345 #endif /* MBEDTLS_SELF_TEST */
1346 
1347 #ifdef __cplusplus
1348 }
1349 #endif
1350 
1351 #endif /* rsa.h */
Multi-precision integer library.
Configuration options (set of defines)
This file contains the generic message-digest wrapper.
mbedtls_md_type_t
Supported message digests.
Definition: md.h:62
int mbedtls_rsa_pkcs1_encrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, size_t ilen, const unsigned char *input, unsigned char *output)
This function adds the message padding, then performs an RSA operation.
int mbedtls_rsa_complete(mbedtls_rsa_context *ctx)
This function completes an RSA context from a set of imported core parameters.
int mbedtls_rsa_pkcs1_verify(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, const unsigned char *sig)
This function performs a public RSA operation and checks the message digest.
void mbedtls_rsa_init(mbedtls_rsa_context *ctx, int padding, int hash_id)
This function initializes an RSA context.
int mbedtls_rsa_self_test(int verbose)
The RSA checkup routine.
int mbedtls_rsa_rsassa_pkcs1_v15_verify(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, const unsigned char *sig)
This function performs a PKCS#1 v1.5 verification operation (RSASSA-PKCS1-v1_5-VERIFY).
int mbedtls_rsa_import(mbedtls_rsa_context *ctx, const mbedtls_mpi *N, const mbedtls_mpi *P, const mbedtls_mpi *Q, const mbedtls_mpi *D, const mbedtls_mpi *E)
This function imports a set of core parameters into an RSA context.
int mbedtls_rsa_check_pub_priv(const mbedtls_rsa_context *pub, const mbedtls_rsa_context *prv)
This function checks a public-private RSA key pair.
int mbedtls_rsa_import_raw(mbedtls_rsa_context *ctx, unsigned char const *N, size_t N_len, unsigned char const *P, size_t P_len, unsigned char const *Q, size_t Q_len, unsigned char const *D, size_t D_len, unsigned char const *E, size_t E_len)
This function imports core RSA parameters, in raw big-endian binary format, into an RSA context.
int mbedtls_rsa_private(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, const unsigned char *input, unsigned char *output)
This function performs an RSA private key operation.
int mbedtls_rsa_gen_key(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, unsigned int nbits, int exponent)
This function generates an RSA keypair.
int mbedtls_rsa_pkcs1_sign(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, unsigned char *sig)
This function performs a private RSA operation to sign a message digest using PKCS#1.
size_t mbedtls_rsa_get_len(const mbedtls_rsa_context *ctx)
This function retrieves the length of RSA modulus in Bytes.
int mbedtls_rsa_rsaes_pkcs1_v15_encrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, size_t ilen, const unsigned char *input, unsigned char *output)
This function performs a PKCS#1 v1.5 encryption operation (RSAES-PKCS1-v1_5-ENCRYPT).
int mbedtls_rsa_rsaes_pkcs1_v15_decrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, size_t *olen, const unsigned char *input, unsigned char *output, size_t output_max_len)
This function performs a PKCS#1 v1.5 decryption operation (RSAES-PKCS1-v1_5-DECRYPT).
int mbedtls_rsa_pkcs1_decrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, size_t *olen, const unsigned char *input, unsigned char *output, size_t output_max_len)
This function performs an RSA operation, then removes the message padding.
struct mbedtls_rsa_context mbedtls_rsa_context
The RSA context structure.
int mbedtls_rsa_export(const mbedtls_rsa_context *ctx, mbedtls_mpi *N, mbedtls_mpi *P, mbedtls_mpi *Q, mbedtls_mpi *D, mbedtls_mpi *E)
This function exports the core parameters of an RSA key.
int mbedtls_rsa_export_raw(const mbedtls_rsa_context *ctx, unsigned char *N, size_t N_len, unsigned char *P, size_t P_len, unsigned char *Q, size_t Q_len, unsigned char *D, size_t D_len, unsigned char *E, size_t E_len)
This function exports core parameters of an RSA key in raw big-endian binary format.
int mbedtls_rsa_copy(mbedtls_rsa_context *dst, const mbedtls_rsa_context *src)
This function copies the components of an RSA context.
int mbedtls_rsa_rsassa_pss_verify(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, const unsigned char *sig)
This function performs a PKCS#1 v2.1 PSS verification operation (RSASSA-PSS-VERIFY).
void mbedtls_rsa_free(mbedtls_rsa_context *ctx)
This function frees the components of an RSA key.
int mbedtls_rsa_rsassa_pss_sign_ext(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, int saltlen, unsigned char *sig)
This function performs a PKCS#1 v2.1 PSS signature operation (RSASSA-PSS-SIGN).
int mbedtls_rsa_export_crt(const mbedtls_rsa_context *ctx, mbedtls_mpi *DP, mbedtls_mpi *DQ, mbedtls_mpi *QP)
This function exports CRT parameters of a private RSA key.
int mbedtls_rsa_public(mbedtls_rsa_context *ctx, const unsigned char *input, unsigned char *output)
This function performs an RSA public key operation.
int mbedtls_rsa_check_privkey(const mbedtls_rsa_context *ctx)
This function checks if a context contains an RSA private key and perform basic consistency checks.
int mbedtls_rsa_rsassa_pss_verify_ext(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, mbedtls_md_type_t mgf1_hash_id, int expected_salt_len, const unsigned char *sig)
This function performs a PKCS#1 v2.1 PSS verification operation (RSASSA-PSS-VERIFY).
int mbedtls_rsa_rsaes_oaep_encrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, const unsigned char *label, size_t label_len, size_t ilen, const unsigned char *input, unsigned char *output)
This function performs a PKCS#1 v2.1 OAEP encryption operation (RSAES-OAEP-ENCRYPT).
int mbedtls_rsa_check_pubkey(const mbedtls_rsa_context *ctx)
This function checks if a context contains at least an RSA public key.
void mbedtls_rsa_set_padding(mbedtls_rsa_context *ctx, int padding, int hash_id)
This function sets padding for an already initialized RSA context. See mbedtls_rsa_init() for details...
int mbedtls_rsa_rsassa_pss_sign(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, unsigned char *sig)
This function performs a PKCS#1 v2.1 PSS signature operation (RSASSA-PSS-SIGN).
int mbedtls_rsa_rsassa_pkcs1_v15_sign(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash, unsigned char *sig)
This function performs a PKCS#1 v1.5 signature operation (RSASSA-PKCS1-v1_5-SIGN).
int mbedtls_rsa_rsaes_oaep_decrypt(mbedtls_rsa_context *ctx, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng, int mode, const unsigned char *label, size_t label_len, size_t *olen, const unsigned char *input, unsigned char *output, size_t output_max_len)
This function performs a PKCS#1 v2.1 OAEP decryption operation (RSAES-OAEP-DECRYPT).
MPI structure.
Definition: bignum.h:193
The RSA context structure.
Definition: rsa.h:110
size_t len
Definition: rsa.h:115
mbedtls_threading_mutex_t mutex
Definition: rsa.h:145
mbedtls_mpi N
Definition: rsa.h:117
mbedtls_mpi RQ
Definition: rsa.h:131
mbedtls_mpi Vf
Definition: rsa.h:134
mbedtls_mpi RN
Definition: rsa.h:128
mbedtls_mpi Q
Definition: rsa.h:122
mbedtls_mpi DQ
Definition: rsa.h:125
mbedtls_mpi E
Definition: rsa.h:118
mbedtls_mpi QP
Definition: rsa.h:126
mbedtls_mpi RP
Definition: rsa.h:130
mbedtls_mpi DP
Definition: rsa.h:124
mbedtls_mpi P
Definition: rsa.h:121
mbedtls_mpi D
Definition: rsa.h:120
mbedtls_mpi Vi
Definition: rsa.h:133
Threading abstraction layer.