1 /**********************************************************************
3 * Copyright (c) 2005-2006 Cryptocom LTD *
4 * This file is distributed under the same license as OpenSSL *
6 * Implementation of CryptoPro key wrap algorithm, as defined in *
7 * RFC 4357 p 6.3 and 6.4 *
8 * Doesn't need OpenSSL *
9 **********************************************************************/
12 #include "gost_keywrap.h"
14 /* Diversifies key using random UserKey Material
15 * Implements RFC 4357 p 6.5 key diversification algorithm
17 * inputKey - 32byte key to be diversified
18 * ukm - 8byte user key material
19 * outputKey - 32byte buffer to store diversified key
22 void keyDiversifyCryptoPro(gost_ctx *ctx,const unsigned char *inputKey, const unsigned char *ukm, unsigned char *outputKey)
28 memcpy(outputKey,inputKey,32);
31 /* Make array of integers from key */
34 for (j=0,mask=1;j<8;j++,mask<<=1)
36 k=((u4)outputKey[4*j])|(outputKey[4*j+1]<<8)|
37 (outputKey[4*j+2]<<16)|(outputKey[4*j+3]<<24);
47 S[0]=s1&0xff; S[1]=(s1>>8)&0xff; S[2]=(s1>>16)&0xff; S[3]=(s1>>24)&0xff;
48 S[4]=s2&0xff; S[5]=(s2>>8)&0xff; S[6]=(s2>>16)&0xff; S[7]=(s2>>24)&0xff;
49 gost_key(ctx,outputKey);
50 gost_enc_cfb(ctx,S,outputKey,outputKey,4);
56 * Wraps key using RFC 4357 6.3
57 * ctx - gost encryption context, initialized with some S-boxes
58 * keyExchangeKey (KEK) 32-byte (256-bit) shared key
59 * ukm - 8 byte (64 bit) user key material,
60 * sessionKey - 32-byte (256-bit) key to be wrapped
61 * wrappedKey - 44-byte buffer to store wrapped key
64 int keyWrapCryptoPro(gost_ctx *ctx,const unsigned char *keyExchangeKey, const unsigned char *ukm,
65 const unsigned char *sessionKey, unsigned char *wrappedKey)
67 unsigned char kek_ukm[32];
68 keyDiversifyCryptoPro(ctx,keyExchangeKey,ukm,kek_ukm);
69 gost_key(ctx,kek_ukm);
70 memcpy(wrappedKey,ukm,8);
71 gost_enc(ctx,sessionKey,wrappedKey+8,4);
72 gost_mac_iv(ctx,32,ukm,sessionKey,32,wrappedKey+40);
76 * Unwraps key using RFC 4357 6.4
77 * ctx - gost encryption context, initialized with some S-boxes
78 * keyExchangeKey 32-byte shared key
79 * wrappedKey 44 byte key to be unwrapped (concatenation of 8-byte UKM,
80 * 32 byte encrypted key and 4 byte MAC
82 * sessionKEy - 32byte buffer to store sessionKey in
83 * Returns 1 if key is decrypted successfully, and 0 if MAC doesn't match
86 int keyUnwrapCryptoPro(gost_ctx *ctx,const unsigned char *keyExchangeKey,
87 const unsigned char *wrappedKey, unsigned char *sessionKey)
89 unsigned char kek_ukm[32],cek_mac[4];
90 keyDiversifyCryptoPro(ctx,keyExchangeKey,wrappedKey
91 /* First 8 bytes of wrapped Key is ukm */
93 gost_key(ctx,kek_ukm);
94 gost_dec(ctx,wrappedKey+8,sessionKey,4);
95 gost_mac_iv(ctx,32,wrappedKey,sessionKey,32,cek_mac);
96 if (memcmp(cek_mac,wrappedKey+40,4))