CommonCryptorSPI.h 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315
  1. /*
  2. * Copyright (c) 2010 Apple Inc. All Rights Reserved.
  3. *
  4. * @APPLE_LICENSE_HEADER_START@
  5. *
  6. * This file contains Original Code and/or Modifications of Original Code
  7. * as defined in and that are subject to the Apple Public Source License
  8. * Version 2.0 (the 'License'). You may not use this file except in
  9. * compliance with the License. Please obtain a copy of the License at
  10. * http://www.opensource.apple.com/apsl/ and read it before using this
  11. * file.
  12. *
  13. * The Original Code and all software distributed under the License are
  14. * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
  15. * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
  16. * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
  17. * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
  18. * Please see the License for the specific language governing rights and
  19. * limitations under the License.
  20. *
  21. * @APPLE_LICENSE_HEADER_END@
  22. */
  23. #ifndef _CC_CryptorSPI_H_
  24. #define _CC_CryptorSPI_H_
  25. #include <sys/types.h>
  26. #include <sys/param.h>
  27. #include <stdint.h>
  28. #include <string.h>
  29. #ifdef KERNEL
  30. #include <machine/limits.h>
  31. #else
  32. #include <limits.h>
  33. #include <stdlib.h>
  34. #endif /* KERNEL */
  35. #include <Availability.h>
  36. #ifdef __cplusplus
  37. extern "C" {
  38. #endif
  39. /*
  40. This is an SPI header. It includes some work in progress implementation notes that
  41. will be removed when this is promoted to an API set.
  42. */
  43. /*
  44. Private Ciphers
  45. */
  46. /* Lion SPI name for no padding. Defining for compatibility. Is now
  47. ccNoPadding in CommonCryptor.h
  48. */
  49. enum {
  50. ccDefaultPadding = 0,
  51. };
  52. enum {
  53. kCCAlgorithmAES128NoHardware = 20,
  54. kCCAlgorithmAES128WithHardware = 21
  55. };
  56. /*
  57. Private Modes
  58. */
  59. enum {
  60. kCCModeGCM = 11,
  61. };
  62. /*
  63. Private Paddings
  64. */
  65. enum {
  66. ccCBCCTS1 = 10,
  67. ccCBCCTS2 = 11,
  68. ccCBCCTS3 = 12,
  69. };
  70. /*
  71. Private Cryptor direction (op)
  72. */
  73. enum {
  74. kCCBoth = 3,
  75. };
  76. /*
  77. Supports a mode call of
  78. int mode_setup(int cipher, const unsigned char *IV, const unsigned char *key, int keylen,
  79. const unsigned char *tweak, int tweaklen, int num_rounds, int options, mode_context *ctx);
  80. */
  81. /* User supplied space for the CryptorRef */
  82. CCCryptorStatus CCCryptorCreateFromDataWithMode(
  83. CCOperation op, /* kCCEncrypt, kCCEncrypt, kCCBoth (default for BlockMode) */
  84. CCMode mode,
  85. CCAlgorithm alg,
  86. CCPadding padding,
  87. const void *iv, /* optional initialization vector */
  88. const void *key, /* raw key material */
  89. size_t keyLength,
  90. const void *tweak, /* raw tweak material */
  91. size_t tweakLength,
  92. int numRounds,
  93. CCModeOptions options,
  94. const void *data, /* caller-supplied memory */
  95. size_t dataLength, /* length of data in bytes */
  96. CCCryptorRef *cryptorRef, /* RETURNED */
  97. size_t *dataUsed) /* optional, RETURNED */
  98. __OSX_AVAILABLE_STARTING(__MAC_10_7, __IPHONE_5_0);
  99. /*
  100. Assuming we can use existing CCCryptorCreateFromData for all modes serviced by these:
  101. int mode_encrypt(const unsigned char *pt, unsigned char *ct, unsigned long len, mode_context *ctx);
  102. int mode_decrypt(const unsigned char *ct, unsigned char *pt, unsigned long len, mode_context *ctx);
  103. */
  104. /*
  105. Block mode encrypt and decrypt interfaces for IV tweaked blocks (XTS and CBC)
  106. int mode_encrypt_tweaked(const unsigned char *pt, unsigned long len, unsigned char *ct, const unsigned char *tweak, mode_context *ctx);
  107. int mode_decrypt_tweaked(const unsigned char *ct, unsigned long len, unsigned char *pt, const unsigned char *tweak, mode_context *ctx);
  108. */
  109. CCCryptorStatus CCCryptorEncryptDataBlock(
  110. CCCryptorRef cryptorRef,
  111. const void *iv,
  112. const void *dataIn,
  113. size_t dataInLength,
  114. void *dataOut)
  115. __OSX_AVAILABLE_STARTING(__MAC_10_7, __IPHONE_5_0);
  116. CCCryptorStatus CCCryptorDecryptDataBlock(
  117. CCCryptorRef cryptorRef,
  118. const void *iv,
  119. const void *dataIn,
  120. size_t dataInLength,
  121. void *dataOut)
  122. __OSX_AVAILABLE_STARTING(__MAC_10_7, __IPHONE_5_0);
  123. /*
  124. Assuming we can use the existing CCCryptorRelease() interface for
  125. int mode_done(mode_context *ctx);
  126. */
  127. /*
  128. Not surfacing these other than with CCCryptorReset()
  129. int mode_setiv(const unsigned char *IV, unsigned long len, mode_context *ctx);
  130. int mode_getiv(const unsigned char *IV, unsigned long *len, mode_context *ctx);
  131. */
  132. /*
  133. DES key utilities
  134. */
  135. CCCryptorStatus CCDesIsWeakKey(
  136. void *key,
  137. size_t Length)
  138. __OSX_AVAILABLE_STARTING(__MAC_10_7, __IPHONE_5_0);
  139. void CCDesSetOddParity(
  140. void *key,
  141. size_t Length)
  142. __OSX_AVAILABLE_STARTING(__MAC_10_7, __IPHONE_5_0);
  143. uint32_t CCDesCBCCksum(void *input, void *output,
  144. size_t length, void *key, size_t keylen,
  145. void *ivec)
  146. __OSX_AVAILABLE_STARTING(__MAC_10_7, __IPHONE_5_0);
  147. /*
  148. * returns a cipher blocksize length iv in the provided iv buffer.
  149. */
  150. CCCryptorStatus
  151. CCCryptorGetIV(CCCryptorRef cryptorRef, void *iv)
  152. __OSX_AVAILABLE_STARTING(__MAC_10_7, __IPHONE_5_0);
  153. /*
  154. GCM Support Interfaces
  155. Use CCCryptorCreateWithMode() with the kCCModeGCM selector to initialize
  156. a CryptoRef. Only kCCAlgorithmAES128 can be used with GCM and these
  157. functions. IV Setting etc will be ignored from CCCryptorCreateWithMode().
  158. Use the CCCryptorGCMAddIV() routine below for IV setup.
  159. */
  160. /*
  161. This adds the initial vector octets from iv of length ivLen to the GCM
  162. CCCryptorRef. You can call this function as many times as required to
  163. process the entire IV.
  164. */
  165. CCCryptorStatus
  166. CCCryptorGCMAddIV(CCCryptorRef cryptorRef,
  167. const void *iv,
  168. size_t ivLen)
  169. __OSX_AVAILABLE_STARTING(__MAC_10_8, __IPHONE_5_0);
  170. /*
  171. Additional Authentication Data
  172. After the entire IV has been processed, the additional authentication
  173. data can be processed. Unlike the IV, a packet/session does not require
  174. additional authentication data (AAD) for security. The AAD is meant to
  175. be used as side–channel data you want to be authenticated with the packet.
  176. Note: once you begin adding AAD to the GCM CCCryptorRef you cannot return
  177. to adding IV data until the state has been reset.
  178. */
  179. CCCryptorStatus
  180. CCCryptorGCMAddAAD(CCCryptorRef cryptorRef,
  181. const void *aData,
  182. size_t aDataLen)
  183. __OSX_AVAILABLE_STARTING(__MAC_10_8, __IPHONE_6_0);
  184. // Maintain the old symbol with incorrect camel-case for now.
  185. CCCryptorStatus
  186. CCCryptorGCMaddAAD(CCCryptorRef cryptorRef,
  187. const void *aData,
  188. size_t aDataLen)
  189. __OSX_AVAILABLE_STARTING(__MAC_10_8, __IPHONE_6_0);
  190. // This is for old iOS5 clients
  191. CCCryptorStatus
  192. CCCryptorGCMAddADD(CCCryptorRef cryptorRef,
  193. const void *aData,
  194. size_t aDataLen)
  195. __OSX_AVAILABLE_STARTING(__MAC_10_8, __IPHONE_5_0);
  196. CCCryptorStatus CCCryptorGCMEncrypt(
  197. CCCryptorRef cryptorRef,
  198. const void *dataIn,
  199. size_t dataInLength,
  200. void *dataOut)
  201. __OSX_AVAILABLE_STARTING(__MAC_10_8, __IPHONE_5_0);
  202. CCCryptorStatus CCCryptorGCMDecrypt(
  203. CCCryptorRef cryptorRef,
  204. const void *dataIn,
  205. size_t dataInLength,
  206. void *dataOut)
  207. __OSX_AVAILABLE_STARTING(__MAC_10_8, __IPHONE_5_0);
  208. /*
  209. This terminates the GCM state gcm and stores the tag in tag of length
  210. taglen octets.
  211. */
  212. CCCryptorStatus CCCryptorGCMFinal(
  213. CCCryptorRef cryptorRef,
  214. const void *tag,
  215. size_t *tagLength)
  216. __OSX_AVAILABLE_STARTING(__MAC_10_8, __IPHONE_5_0);
  217. /*
  218. This will reset the GCM CCCryptorRef to the state that CCCryptorCreateWithMode()
  219. left it. The user would then call CCCryptorGCMAddIV(), CCCryptorGCMaddAAD(), etc.
  220. */
  221. CCCryptorStatus CCCryptorGCMReset(
  222. CCCryptorRef cryptorRef)
  223. __OSX_AVAILABLE_STARTING(__MAC_10_8, __IPHONE_5_0);
  224. /*
  225. This will initialize the GCM state with the given key, IV and AAD value
  226. then proceed to encrypt or decrypt the message text and store the final
  227. message tag. The definition of the variables is the same as it is for all
  228. the manual functions. If you are processing many packets under the same
  229. key you shouldn’t use this function as it invokes the pre–computation
  230. with each call.
  231. */
  232. CCCryptorStatus CCCryptorGCM(
  233. CCOperation op, /* kCCEncrypt, kCCDecrypt */
  234. CCAlgorithm alg,
  235. const void *key, /* raw key material */
  236. size_t keyLength,
  237. const void *iv,
  238. size_t ivLen,
  239. const void *aData,
  240. size_t aDataLen,
  241. const void *dataIn,
  242. size_t dataInLength,
  243. void *dataOut,
  244. const void *tag,
  245. size_t *tagLength)
  246. __OSX_AVAILABLE_STARTING(__MAC_10_8, __IPHONE_5_0);
  247. void CC_RC4_set_key(void *ctx, int len, const unsigned char *data)
  248. __OSX_AVAILABLE_STARTING(__MAC_10_4, __IPHONE_5_0);
  249. void CC_RC4(void *ctx, unsigned long len, const unsigned char *indata,
  250. unsigned char *outdata)
  251. __OSX_AVAILABLE_STARTING(__MAC_10_4, __IPHONE_5_0);
  252. #ifdef __cplusplus
  253. }
  254. #endif
  255. #endif /* _CC_CryptorSPI_H_ */