Botan 3.10.0
Crypto and TLS for C&
ffi_srp6.cpp
Go to the documentation of this file.
1/*
2* (C) 2022 Rostyslav Khudolii
3* 2023 Jack Lloyd
4*
5* Botan is released under the Simplified BSD License (see license.txt)
6*/
7
8#include <botan/ffi.h>
9
10#include <botan/internal/ffi_rng.h>
11#include <botan/internal/ffi_util.h>
12
13#if defined(BOTAN_HAS_SRP6)
14 #include <botan/bigint.h>
15 #include <botan/dl_group.h>
16 #include <botan/rng.h>
17 #include <botan/srp6.h>
18 #include <botan/symkey.h>
19#endif
20
21extern "C" {
22
23using namespace Botan_FFI;
24
25#if defined(BOTAN_HAS_SRP6)
26BOTAN_FFI_DECLARE_STRUCT(botan_srp6_server_session_struct, Botan::SRP6_Server_Session, 0x44F7425F);
27#else
28BOTAN_FFI_DECLARE_DUMMY_STRUCT(botan_srp6_server_session_struct, 0x44F7425F);
29#endif
30
32#if defined(BOTAN_HAS_SRP6)
33 return ffi_guard_thunk(
34 __func__, [=]() -> int { return ffi_new_object(srp6, std::make_unique<Botan::SRP6_Server_Session>()); });
35#else
36 BOTAN_UNUSED(srp6);
38#endif
39}
40
44
45int botan_srp6_group_size(const char* group_id, size_t* group_p_bytes) {
46#if defined(BOTAN_HAS_SRP6)
47 if(any_null_pointers(group_id, group_p_bytes)) {
49 }
50
51 return ffi_guard_thunk(__func__, [=]() -> int {
52 const auto group = Botan::DL_Group::from_name(group_id);
53 *group_p_bytes = group.p_bytes();
54 return BOTAN_FFI_SUCCESS;
55 });
56#else
57 BOTAN_UNUSED(group_id, group_p_bytes);
59#endif
60}
61
63 const uint8_t* verifier,
64 size_t verifier_len,
65 const char* group_id,
66 const char* hash_id,
67 botan_rng_t rng_obj,
68 uint8_t b_pub[],
69 size_t* b_pub_len) {
70#if defined(BOTAN_HAS_SRP6)
71 return BOTAN_FFI_VISIT(srp6, [=](auto& s) -> int {
72 if(any_null_pointers(verifier, group_id, hash_id, rng_obj)) {
74 }
75 try {
76 const auto group = Botan::DL_Group::from_name(group_id);
77 const auto rc = check_and_prepare_output_space(b_pub, b_pub_len, group.p_bytes());
78 if(rc != BOTAN_FFI_SUCCESS) {
79 return rc;
80 }
81
83 auto v_bn = Botan::BigInt::from_bytes(std::span{verifier, verifier_len});
84 auto b_pub_bn = s.step1(v_bn, group, hash_id, group.exponent_bits(), rng);
85 return write_vec_output(b_pub, b_pub_len, b_pub_bn.serialize(group.p_bytes()));
86 } catch(Botan::Decoding_Error&) {
88 } catch(Botan::Lookup_Error&) {
90 }
91 });
92#else
93 BOTAN_UNUSED(srp6, verifier, verifier_len, group_id, hash_id, rng_obj, b_pub, b_pub_len);
95#endif
96}
97
99 botan_srp6_server_session_t srp6, const uint8_t a[], size_t a_len, uint8_t key[], size_t* key_len) {
100#if defined(BOTAN_HAS_SRP6)
101 return BOTAN_FFI_VISIT(srp6, [=](auto& s) -> int {
102 if(!a) {
104 }
105 try {
106 Botan::BigInt a_bn = Botan::BigInt::from_bytes({a, a_len});
107 auto key_sk = s.step2(a_bn);
108 return write_vec_output(key, key_len, key_sk.bits_of());
109 } catch(Botan::Decoding_Error&) {
111 }
112 });
113#else
114 BOTAN_UNUSED(srp6, a, a_len, key, key_len);
116#endif
117}
118
119int botan_srp6_generate_verifier(const char* username,
120 const char* password,
121 const uint8_t salt[],
122 size_t salt_len,
123 const char* group_id,
124 const char* hash_id,
125 uint8_t verifier[],
126 size_t* verifier_len) {
127#if defined(BOTAN_HAS_SRP6)
128 return ffi_guard_thunk(__func__, [=]() -> int {
129 if(any_null_pointers(username, password, salt, group_id, hash_id)) {
131 }
132 try {
133 std::vector<uint8_t> salt_vec(salt, salt + salt_len);
134 const auto group = Botan::DL_Group::from_name(group_id);
135 const size_t p_bytes = group.p_bytes();
136 auto verifier_bn = Botan::srp6_generate_verifier(username, password, salt_vec, group, hash_id);
137 return write_vec_output(verifier, verifier_len, verifier_bn.serialize(p_bytes));
138 } catch(Botan::Lookup_Error&) {
140 }
141 });
142#else
143 BOTAN_UNUSED(username, password, group_id, hash_id);
144 BOTAN_UNUSED(salt, salt_len, verifier, verifier_len);
146#endif
147}
148
149int botan_srp6_client_agree(const char* identity,
150 const char* password,
151 const char* group_id,
152 const char* hash_id,
153 const uint8_t salt[],
154 size_t salt_len,
155 const uint8_t b[],
156 size_t b_len,
157 botan_rng_t rng_obj,
158 uint8_t A[],
159 size_t* A_len,
160 uint8_t K[],
161 size_t* K_len) {
162#if defined(BOTAN_HAS_SRP6)
163 return ffi_guard_thunk(__func__, [=]() -> int {
164 if(any_null_pointers(identity, password, salt, group_id, hash_id, b, rng_obj)) {
166 }
167 try {
168 std::vector<uint8_t> saltv(salt, salt + salt_len);
170 auto b_bn = Botan::BigInt::from_bytes({b, b_len});
171 const auto group = Botan::DL_Group::from_name(group_id);
172 const size_t a_bits = group.exponent_bits();
173 auto [A_bn, K_sk] = Botan::srp6_client_agree(identity, password, group, hash_id, saltv, b_bn, a_bits, rng);
174 auto ret_a = write_vec_output(A, A_len, A_bn.serialize(group.p_bytes()));
175 auto ret_k = write_vec_output(K, K_len, K_sk.bits_of());
176 if(ret_a != BOTAN_FFI_SUCCESS) {
177 return ret_a;
178 }
179 if(ret_k != BOTAN_FFI_SUCCESS) {
180 return ret_k;
181 }
182 return BOTAN_FFI_SUCCESS;
183 } catch(Botan::Lookup_Error&) {
185 }
186 });
187#else
188 BOTAN_UNUSED(identity, password, group_id, hash_id, rng_obj);
189 BOTAN_UNUSED(salt, salt_len, b, b_len, A, A_len, K, K_len);
191#endif
192}
193}
#define BOTAN_UNUSED
Definition assert.h:144
static BigInt from_bytes(std::span< const uint8_t > bytes)
Definition bigint.cpp:87
static DL_Group from_name(std::string_view name)
Definition dl_group.cpp:217
struct botan_srp6_server_session_struct * botan_srp6_server_session_t
Definition ffi.h:2410
struct botan_rng_struct * botan_rng_t
Definition ffi.h:289
@ BOTAN_FFI_ERROR_NOT_IMPLEMENTED
Definition ffi.h:138
@ BOTAN_FFI_ERROR_NULL_POINTER
Definition ffi.h:132
@ BOTAN_FFI_SUCCESS
Definition ffi.h:115
@ BOTAN_FFI_ERROR_BAD_PARAMETER
Definition ffi.h:133
int botan_srp6_server_session_step2(botan_srp6_server_session_t srp6, const uint8_t a[], size_t a_len, uint8_t key[], size_t *key_len)
Definition ffi_srp6.cpp:98
int botan_srp6_server_session_init(botan_srp6_server_session_t *srp6)
Definition ffi_srp6.cpp:31
int botan_srp6_server_session_destroy(botan_srp6_server_session_t srp6)
Definition ffi_srp6.cpp:41
int botan_srp6_group_size(const char *group_id, size_t *group_p_bytes)
Definition ffi_srp6.cpp:45
int botan_srp6_server_session_step1(botan_srp6_server_session_t srp6, const uint8_t *verifier, size_t verifier_len, const char *group_id, const char *hash_id, botan_rng_t rng_obj, uint8_t b_pub[], size_t *b_pub_len)
Definition ffi_srp6.cpp:62
int botan_srp6_generate_verifier(const char *username, const char *password, const uint8_t salt[], size_t salt_len, const char *group_id, const char *hash_id, uint8_t verifier[], size_t *verifier_len)
Definition ffi_srp6.cpp:119
int botan_srp6_client_agree(const char *identity, const char *password, const char *group_id, const char *hash_id, const uint8_t salt[], size_t salt_len, const uint8_t b[], size_t b_len, botan_rng_t rng_obj, uint8_t A[], size_t *A_len, uint8_t K[], size_t *K_len)
Definition ffi_srp6.cpp:149
#define BOTAN_FFI_VISIT(obj, lambda)
Definition ffi_util.h:158
#define BOTAN_FFI_CHECKED_DELETE(o)
Definition ffi_util.h:185
#define BOTAN_FFI_DECLARE_DUMMY_STRUCT(NAME, MAGIC)
Definition ffi_util.h:66
#define BOTAN_FFI_DECLARE_STRUCT(NAME, TYPE, MAGIC)
Definition ffi_util.h:61
T & safe_get(botan_struct< T, M > *p)
Definition ffi_util.h:79
BOTAN_FFI_ERROR ffi_new_object(T *obj, Args &&... args)
Definition ffi_util.h:178
int ffi_guard_thunk(const char *func_name, T thunk)
Definition ffi_util.h:95
int write_vec_output(uint8_t out[], size_t *out_len, std::span< const uint8_t > buf)
Definition ffi_util.h:261
int check_and_prepare_output_space(T out[], size_t *out_len, size_t required_len)
Definition ffi_util.h:227
bool any_null_pointers(Ptrs... ptr)
Definition mem_utils.h:23
std::pair< BigInt, SymmetricKey > srp6_client_agree(std::string_view identifier, std::string_view password, std::string_view group_id, std::string_view hash_id, const std::vector< uint8_t > &salt, const BigInt &B, RandomNumberGenerator &rng)
Definition srp6.cpp:65
BigInt srp6_generate_verifier(std::string_view identifier, std::string_view password, const std::vector< uint8_t > &salt, std::string_view group_id, std::string_view hash_id)
Definition srp6.cpp:128