All of lore.kernel.org
 help / color / mirror / Atom feed
From: Philippe Reynes <philippe.reynes@softathome.com>
To: sjg+nodisclaimer@chromium.org, raymond.mao+nodisclaimer@linaro.org
Cc: u-boot+nodisclaimer@lists.denx.de,
	Philippe Reynes <philippe.reynes@softathome.com>
Subject: [PATCH v6 7/9] lib: mbedtls: sha256: add support of key derivation
Date: Tue, 17 Dec 2024 22:36:11 +0100	[thread overview]
Message-ID: <20241217213613.286813-8-philippe.reynes@softathome.com> (raw)
In-Reply-To: <20241217213613.286813-1-philippe.reynes@softathome.com>

Adds the support of key derivation using the scheme hkdf.
This scheme is defined in rfc5869.

Signed-off-by: Philippe Reynes <philippe.reynes@softathome.com>
---
 include/u-boot/sha256.h | 20 ++++++++++++++++++++
 lib/mbedtls/sha256.c    | 23 +++++++++++++++++++++++
 2 files changed, 43 insertions(+)

diff --git a/include/u-boot/sha256.h b/include/u-boot/sha256.h
index 99cf78e204c..d7a3403270b 100644
--- a/include/u-boot/sha256.h
+++ b/include/u-boot/sha256.h
@@ -1,6 +1,8 @@
 #ifndef _SHA256_H
 #define _SHA256_H
 
+#include <linux/compiler_attributes.h>
+#include <linux/errno.h>
 #include <linux/kconfig.h>
 #include <linux/types.h>
 
@@ -49,4 +51,22 @@ int sha256_hmac(const unsigned char *key, int keylen,
 		const unsigned char *input, unsigned int ilen,
 		unsigned char *output);
 
+#if CONFIG_IS_ENABLED(HKDF_MBEDTLS)
+int sha256_hkdf(const unsigned char *salt, int saltlen,
+		const unsigned char *ikm, int ikmlen,
+		const unsigned char *info, int infolen,
+		unsigned char *output, int outputlen);
+#else
+static inline int sha256_hkdf(const unsigned char __always_unused *salt,
+			      int __always_unused saltlen,
+			      const unsigned char __always_unused *ikm,
+			      int __always_unused ikmlen,
+			      const unsigned char __always_unused *info,
+			      int __always_unused infolen,
+			      unsigned char __always_unused *output,
+			      int __always_unused outputlen) {
+	return -EOPNOTSUPP;
+}
+#endif
+
 #endif /* _SHA256_H */
diff --git a/lib/mbedtls/sha256.c b/lib/mbedtls/sha256.c
index 7d456a82017..59edcb517df 100644
--- a/lib/mbedtls/sha256.c
+++ b/lib/mbedtls/sha256.c
@@ -12,6 +12,10 @@
 
 #include <mbedtls/md.h>
 
+#if CONFIG_IS_ENABLED(HKDF_MBEDTLS)
+#include <mbedtls/hkdf.h>
+#endif
+
 const u8 sha256_der_prefix[SHA256_DER_LEN] = {
 	0x30, 0x31, 0x30, 0x0d, 0x06, 0x09, 0x60, 0x86,
 	0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x01, 0x05,
@@ -48,3 +52,22 @@ int sha256_hmac(const unsigned char *key, int keylen,
 
 	return mbedtls_md_hmac(md, key, keylen, input, ilen, output);
 }
+
+#if CONFIG_IS_ENABLED(HKDF_MBEDTLS)
+int sha256_hkdf(const unsigned char *salt, int saltlen,
+		const unsigned char *ikm, int ikmlen,
+		const unsigned char *info, int infolen,
+		unsigned char *output, int outputlen)
+{
+	const mbedtls_md_info_t *md;
+
+	md = mbedtls_md_info_from_type(MBEDTLS_MD_SHA256);
+	if (!md)
+		return MBEDTLS_ERR_MD_FEATURE_UNAVAILABLE;
+
+	return mbedtls_hkdf(md, salt, saltlen,
+			    ikm, ikmlen,
+			    info, infolen,
+			    output, outputlen);
+}
+#endif
-- 
2.25.1


  parent reply	other threads:[~2024-12-17 21:37 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-12-17 21:36 [PATCH v6 0/9] add the support of sha256_hmac and sha256_hkdf Philippe Reynes
2024-12-17 21:36 ` [PATCH v6 1/9] tools: kwbimage.h: use linux/compiler_attributes.h Philippe Reynes
2024-12-17 21:36 ` [PATCH v6 2/9] tools: renesas_spkgimage.h: " Philippe Reynes
2024-12-17 21:36 ` [PATCH v6 3/9] mbedtls: enable support of hkdf Philippe Reynes
2024-12-17 21:36 ` [PATCH v6 4/9] lib: sha256: move common function to sha256_common.c Philippe Reynes
2024-12-17 21:36 ` [PATCH v6 5/9] lib: sha256: add feature sha256_hmac Philippe Reynes
2024-12-17 21:36 ` [PATCH v6 6/9] test: lib: add test for sha256_hmac Philippe Reynes
2024-12-17 21:36 ` Philippe Reynes [this message]
2024-12-17 21:36 ` [PATCH v6 8/9] test: lib: add test for key derivation Philippe Reynes
2024-12-17 21:36 ` [PATCH v6 9/9] configs: sandbox: enable mbedtls Philippe Reynes
2024-12-18 15:23 ` [PATCH v6 0/9] add the support of sha256_hmac and sha256_hkdf Raymond Mao
2024-12-19 12:21   ` Philippe REYNES

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20241217213613.286813-8-philippe.reynes@softathome.com \
    --to=philippe.reynes@softathome.com \
    --cc=raymond.mao+nodisclaimer@linaro.org \
    --cc=sjg+nodisclaimer@chromium.org \
    --cc=u-boot+nodisclaimer@lists.denx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.