From e0a4956cafcbb98bdf18c9a25fbf799e4de4a35e Mon Sep 17 00:00:00 2001 From: J08nY Date: Tue, 16 Jul 2019 11:44:17 +0200 Subject: Add option to use KeyBuilder. --- src/cz/crcs/ectester/applet/AppletBase.java | 22 ++++++++--- src/cz/crcs/ectester/applet/ECKeyGenerator.java | 34 ++++++++++++++-- src/cz/crcs/ectester/reader/ECTesterReader.java | 11 ++++-- src/cz/crcs/ectester/reader/command/Command.java | 11 +++++- .../crcs/ectester/standalone/libs/jni/c_timing.c | 4 ++ src/cz/crcs/ectester/standalone/libs/jni/c_utils.c | 8 ++++ src/cz/crcs/ectester/standalone/libs/jni/mscng.c | 45 +++++++++++++--------- 7 files changed, 102 insertions(+), 33 deletions(-) (limited to 'src') diff --git a/src/cz/crcs/ectester/applet/AppletBase.java b/src/cz/crcs/ectester/applet/AppletBase.java index 4669352..dc0f50d 100644 --- a/src/cz/crcs/ectester/applet/AppletBase.java +++ b/src/cz/crcs/ectester/applet/AppletBase.java @@ -39,6 +39,8 @@ public abstract class AppletBase extends Applet { public static final byte KEYPAIR_LOCAL = (byte) 0x01; public static final byte KEYPAIR_REMOTE = (byte) 0x02; public static final byte KEYPAIR_BOTH = KEYPAIR_LOCAL | KEYPAIR_REMOTE; + public static final byte BUILD_KEYPAIR = (byte) 0x00; + public static final byte BUILD_KEYBUILDER = (byte) 0x01; public static final byte EXPORT_TRUE = (byte) 0xff; public static final byte EXPORT_FALSE = (byte) 0x00; public static final byte MODE_NORMAL = (byte) 0xaa; @@ -352,17 +354,18 @@ public abstract class AppletBase extends Applet { * returns allocate SWs * * @param apdu P1 = byte keyPair (KEYPAIR_* | ...) - * P2 = + * P2 = byte build * DATA = short keyLength * byte keyClass * @return length of response */ private short insAllocate(APDU apdu) { byte keyPair = apduArray[ISO7816.OFFSET_P1]; + byte build = apduArray[ISO7816.OFFSET_P2]; short keyLength = Util.getShort(apduArray, cdata); byte keyClass = apduArray[(short) (cdata + 2)]; - return allocate(keyPair, keyLength, keyClass, apdu.getBuffer(), (short) 0); + return allocate(keyPair, build, keyLength, keyClass, apdu.getBuffer(), (short) 0); } /** @@ -657,22 +660,31 @@ public abstract class AppletBase extends Applet { /** * @param keyPair which keyPair to use, local/remote (KEYPAIR_* | ...) + * @param build whether to use KeyBuilder or Keypair alloc * @param keyLength key length to set * @param keyClass key class to allocate * @param outBuffer buffer to write sw to * @param outOffset offset into buffer * @return length of data written to the buffer */ - private short allocate(byte keyPair, short keyLength, byte keyClass, byte[] outBuffer, short outOffset) { + private short allocate(byte keyPair, byte build, short keyLength, byte keyClass, byte[] outBuffer, short outOffset) { short length = 0; if ((keyPair & KEYPAIR_LOCAL) != 0) { - localKeypair = keyGenerator.allocatePair(keyClass, keyLength); + if (build == BUILD_KEYPAIR) { + localKeypair = keyGenerator.allocatePair(keyClass, keyLength); + } else { + localKeypair = keyGenerator.constructPair(keyClass, keyLength); + } Util.setShort(outBuffer, outOffset, keyGenerator.getSW()); length += 2; } if ((keyPair & KEYPAIR_REMOTE) != 0) { - remoteKeypair = keyGenerator.allocatePair(keyClass, keyLength); + if (build == BUILD_KEYPAIR) { + remoteKeypair = keyGenerator.allocatePair(keyClass, keyLength); + } else { + remoteKeypair = keyGenerator.constructPair(keyClass, keyLength); + } Util.setShort(outBuffer, (short) (outOffset + length), keyGenerator.getSW()); length += 2; } diff --git a/src/cz/crcs/ectester/applet/ECKeyGenerator.java b/src/cz/crcs/ectester/applet/ECKeyGenerator.java index 30910ca..601654a 100644 --- a/src/cz/crcs/ectester/applet/ECKeyGenerator.java +++ b/src/cz/crcs/ectester/applet/ECKeyGenerator.java @@ -4,9 +4,7 @@ import javacard.framework.CardRuntimeException; import javacard.framework.ISO7816; import javacard.framework.ISOException; import javacard.framework.Util; -import javacard.security.ECPrivateKey; -import javacard.security.ECPublicKey; -import javacard.security.KeyPair; +import javacard.security.*; /** * @author Jan Jancar johny@neuromancer.sk @@ -41,6 +39,36 @@ public class ECKeyGenerator { return ecKeyPair; } + /** + * @param keyClass + * @param keyLength + * @return + */ + public KeyPair constructPair(byte keyClass, short keyLength) { + sw = ISO7816.SW_NO_ERROR; + KeyPair ecKeyPair = null; + byte privKeyType; + byte pubKeyType; + if (keyClass == KeyPair.ALG_EC_FP) { + privKeyType = KeyBuilder.TYPE_EC_FP_PRIVATE; + pubKeyType = KeyBuilder.TYPE_EC_FP_PUBLIC; + } else { + privKeyType = KeyBuilder.TYPE_EC_F2M_PRIVATE; + pubKeyType = KeyBuilder.TYPE_EC_F2M_PUBLIC; + } + try { + if (!dryRun) { + ECPrivateKey privateKey = (ECPrivateKey) KeyBuilder.buildKey(privKeyType, keyLength, false); + ECPublicKey publicKey = (ECPublicKey) KeyBuilder.buildKey(pubKeyType, keyLength, false); + + ecKeyPair = new KeyPair(publicKey, privateKey); + } + } catch (CardRuntimeException ce) { + sw = ce.getReason(); + } + return ecKeyPair; + } + /** * @param keypair * @param key diff --git a/src/cz/crcs/ectester/reader/ECTesterReader.java b/src/cz/crcs/ectester/reader/ECTesterReader.java index 6e34f6a..07bdb2f 100644 --- a/src/cz/crcs/ectester/reader/ECTesterReader.java +++ b/src/cz/crcs/ectester/reader/ECTesterReader.java @@ -327,6 +327,7 @@ public class ECTesterReader { opts.addOption(Option.builder("v").longOpt("verbose").desc("Turn on verbose logging.").build()); opts.addOption(Option.builder().longOpt("format").desc("Output format to use. One of: text,yml,xml.").hasArg().argName("format").build()); + opts.addOption(Option.builder("kb").longOpt("key-builder").desc("Allocate KeyPair using KeyBuilder.").build()); opts.addOption(Option.builder().longOpt("fixed").desc("Generate key(s) only once, keep them for later operations.").build()); opts.addOption(Option.builder().longOpt("fixed-private").desc("Generate private key only once, keep it for later ECDH.").build()); opts.addOption(Option.builder().longOpt("fixed-public").desc("Generate public key only once, keep it for later ECDH.").build()); @@ -394,7 +395,7 @@ public class ECTesterReader { byte keyClass = cfg.primeField ? KeyPair.ALG_EC_FP : KeyPair.ALG_EC_F2M; List sent = new LinkedList<>(); - sent.add(new Command.Allocate(cardManager, ECTesterApplet.KEYPAIR_LOCAL, cfg.bits, keyClass).send()); + sent.add(new Command.Allocate(cardManager, cfg.keyBuilder, ECTesterApplet.KEYPAIR_LOCAL, cfg.bits, keyClass).send()); //sent.add(new Command.Clear(cardManager, ECTesterApplet.KEYPAIR_LOCAL).send()); sent.add(new Command.Generate(cardManager, ECTesterApplet.KEYPAIR_LOCAL).send()); @@ -444,7 +445,7 @@ public class ECTesterReader { byte keyClass = cfg.primeField ? KeyPair.ALG_EC_FP : KeyPair.ALG_EC_F2M; Command curve = Command.prepareCurve(cardManager, cfg, ECTesterApplet.KEYPAIR_LOCAL, cfg.bits, keyClass); - Response allocate = new Command.Allocate(cardManager, ECTesterApplet.KEYPAIR_LOCAL, cfg.bits, keyClass).send(); + Response allocate = new Command.Allocate(cardManager, cfg.keyBuilder, ECTesterApplet.KEYPAIR_LOCAL, cfg.bits, keyClass).send(); respWriter.outputResponse(allocate); OutputStreamWriter keysFile = FileUtil.openFiles(cfg.outputs); @@ -577,7 +578,7 @@ public class ECTesterReader { Command curve = Command.prepareCurve(cardManager, cfg, ECTesterApplet.KEYPAIR_BOTH, cfg.bits, keyClass); List prepare = new LinkedList<>(); prepare.add(new Command.AllocateKeyAgreement(cardManager, cfg.ECKAType).send()); // Prepare KeyAgreement or required type - prepare.add(new Command.Allocate(cardManager, ECTesterApplet.KEYPAIR_BOTH, cfg.bits, keyClass).send()); + prepare.add(new Command.Allocate(cardManager, cfg.keyBuilder, ECTesterApplet.KEYPAIR_BOTH, cfg.bits, keyClass).send()); if (curve != null) prepare.add(curve.send()); @@ -703,7 +704,7 @@ public class ECTesterReader { byte keyClass = cfg.primeField ? KeyPair.ALG_EC_FP : KeyPair.ALG_EC_F2M; List prepare = new LinkedList<>(); prepare.add(new Command.AllocateSignature(cardManager, cfg.ECDSAType).send()); - prepare.add(new Command.Allocate(cardManager, ECTesterApplet.KEYPAIR_LOCAL, cfg.bits, keyClass).send()); + prepare.add(new Command.Allocate(cardManager, cfg.keyBuilder, ECTesterApplet.KEYPAIR_LOCAL, cfg.bits, keyClass).send()); Command curve = Command.prepareCurve(cardManager, cfg, ECTesterApplet.KEYPAIR_LOCAL, cfg.bits, keyClass); if (curve != null) prepare.add(curve.send()); @@ -835,6 +836,7 @@ public class ECTesterReader { public boolean fixedKey = false; public boolean fixedPrivate = false; public boolean fixedPublic = false; + public byte keyBuilder; public String log; @@ -894,6 +896,7 @@ public class ECTesterReader { fixedKey = cli.hasOption("fixed"); fixedPrivate = cli.hasOption("fixed-private"); fixedPublic = cli.hasOption("fixed-public"); + keyBuilder = cli.hasOption("key-builder") ? ECTesterApplet.BUILD_KEYBUILDER : ECTesterApplet.BUILD_KEYPAIR; if (cli.hasOption("log")) { log = cli.getOptionValue("log", String.format("ECTESTER_log_%d.log", System.currentTimeMillis() / 1000)); diff --git a/src/cz/crcs/ectester/reader/command/Command.java b/src/cz/crcs/ectester/reader/command/Command.java index 1789451..cd015df 100644 --- a/src/cz/crcs/ectester/reader/command/Command.java +++ b/src/cz/crcs/ectester/reader/command/Command.java @@ -255,6 +255,7 @@ public abstract class Command implements Cloneable { */ public static class Allocate extends Command { private byte keyPair; + private byte build; private short keyLength; private byte keyClass; @@ -263,18 +264,24 @@ public abstract class Command implements Cloneable { * * @param cardManager cardManager to send APDU through * @param keyPair which keyPair to use, local/remote (KEYPAIR_* | ...) + * @param build whether to use KeyBuilder or Keypair alloc * @param keyLength key length to set * @param keyClass key class to allocate */ - public Allocate(CardMngr cardManager, byte keyPair, short keyLength, byte keyClass) { + public Allocate(CardMngr cardManager, byte keyPair, byte build, short keyLength, byte keyClass) { super(cardManager); this.keyPair = keyPair; + this.build = build; this.keyLength = keyLength; this.keyClass = keyClass; byte[] data = new byte[]{0, 0, keyClass}; ByteUtil.setShort(data, 0, keyLength); - this.cmd = new CommandAPDU(ECTesterApplet.CLA_ECTESTERAPPLET, ECTesterApplet.INS_ALLOCATE, keyPair, 0x00, data); + this.cmd = new CommandAPDU(ECTesterApplet.CLA_ECTESTERAPPLET, ECTesterApplet.INS_ALLOCATE, keyPair, build, data); + } + + public Allocate(CardMngr cardManager, byte keyPair, short keyLength, byte keyClass) { + this(cardManager, keyPair, ECTesterApplet.BUILD_KEYPAIR, keyLength, keyClass); } @Override diff --git a/src/cz/crcs/ectester/standalone/libs/jni/c_timing.c b/src/cz/crcs/ectester/standalone/libs/jni/c_timing.c index a6ffc7e..941cee6 100644 --- a/src/cz/crcs/ectester/standalone/libs/jni/c_timing.c +++ b/src/cz/crcs/ectester/standalone/libs/jni/c_timing.c @@ -1,5 +1,9 @@ #include "c_timing.h" +#if __linux || __posix +#include +#endif + #if _POSIX_TIMERS > 0 #include diff --git a/src/cz/crcs/ectester/standalone/libs/jni/c_utils.c b/src/cz/crcs/ectester/standalone/libs/jni/c_utils.c index a5bc14d..46286fd 100644 --- a/src/cz/crcs/ectester/standalone/libs/jni/c_utils.c +++ b/src/cz/crcs/ectester/standalone/libs/jni/c_utils.c @@ -3,6 +3,10 @@ #include #include +#if defined(__WIN32__) || defined(_MSC_VER) +#include +#endif + jclass ec_parameter_spec_class; jclass ecgen_parameter_spec_class; jclass secret_key_spec_class; @@ -228,7 +232,11 @@ char *biginteger_to_hex(JNIEnv *env, jobject big, jint bytes) { jstring big_string = (*env)->CallObjectMethod(env, big, to_string, (jint) 16); jsize len = (*env)->GetStringUTFLength(env, big_string); +#if defined(__WIN32__) || defined(_MSC_VER) + char *raw_string = _alloca(len); +#else char raw_string[len]; +#endif (*env)->GetStringUTFRegion(env, big_string, 0, len, raw_string); char *result = calloc(bytes, 2); diff --git a/src/cz/crcs/ectester/standalone/libs/jni/mscng.c b/src/cz/crcs/ectester/standalone/libs/jni/mscng.c index 2b38860..7f3ff5d 100644 --- a/src/cz/crcs/ectester/standalone/libs/jni/mscng.c +++ b/src/cz/crcs/ectester/standalone/libs/jni/mscng.c @@ -1,12 +1,10 @@ -#include #include +#include #include "native.h" #include "c_timing.h" #include "c_utils.h" -#include - // BCRYPT and NT things. #define NT_SUCCESS(status) (((NTSTATUS)(status)) >= 0) #define NT_FAILURE(status) !NT_SUCCESS(status) @@ -17,8 +15,7 @@ typedef struct { ULONG dwVersion; // Version of the structure ECC_CURVE_TYPE_ENUM dwCurveType; // Supported curve types. - ECC_CURVE_ALG_ID_ENUM - dwCurveGenerationAlgId; // For X.592 verification purposes, if we include Seed we will need to include the algorithm ID. + ECC_CURVE_ALG_ID_ENUM dwCurveGenerationAlgId; // For X.592 verification purposes, if we include Seed we will need to include the algorithm ID. ULONG cbFieldLength; // Byte length of the fields P, A, B, X, Y. ULONG cbSubgroupOrder; // Byte length of the subgroup. ULONG cbCofactor; // Byte length of cofactor of G in E. @@ -1203,6 +1200,12 @@ JNIEXPORT jboolean JNICALL Java_cz_crcs_ectester_standalone_libs_jni_NativeSigna return JNI_FALSE; } (*env)->ReleaseByteArrayElements(env, pubkey_barray, pub_data, JNI_ABORT); + + jmethodID get_n = (*env)->GetMethodID(env, ec_parameter_spec_class, "getOrder", "()Ljava/math/BigInteger;"); + jobject n = (*env)->CallObjectMethod(env, params, get_n); + jmethodID get_bitlength = (*env)->GetMethodID(env, biginteger_class, "bitLength", "()I"); + jint ord_bits = (*env)->CallIntMethod(env, n, get_bitlength); + jint ord_bytes = (ord_bits + 7) / 8; jint sig_len = (*env)->GetArrayLength(env, sig); jbyte *sig_data = (*env)->GetByteArrayElements(env, sig, NULL); @@ -1224,20 +1227,24 @@ JNIEXPORT jboolean JNICALL Java_cz_crcs_ectester_standalone_libs_jni_NativeSigna jbyte *r_cpy = r; jbyte *s_cpy = s; - if (rlen > slen) { - r_cpy += rlen - slen; - rlen = slen; - } else if (slen > rlen) { - s_cpy += slen - rlen; - slen = rlen; - } else { - if (r[0] == 0 && s[0] == 0) { - r_cpy++; - s_cpy++; - rlen--; - slen--; - } - } + if (rlen > ord_bytes) { + r_cpy += ord_bytes - rlen; + } + if (slen > ord_bytes) { + s_cpy += ord_bytes - slen; + } + if (rlen < ord_bytes) { + r_cpy = _alloca(ord_bytes); + memset(r_cpy, 0, ord_bytes); + memcpy(r_cpy, r + (ord_bytes - rlen), ord_bytes); + } + if (slen < ord_bytes) { + s_cpy = _alloca(ord_bytes); + memset(s_cpy, 0, ord_bytes); + memcpy(s_cpy, s + (ord_bytes - slen), ord_bytes); + } + rlen = ord_bytes; + slen = ord_bytes; UCHAR *sig_full = calloc(rlen + slen, 1); memcpy(sig_full, r_cpy, rlen); -- cgit v1.2.3-70-g09d2