Linux cryptographic layer development
 help / color / mirror / Atom feed
* [PATCH 1/2] crypto: ecdh - zeroize crpytographic keys after use
@ 2024-04-11 23:51 Hailey Mothershead
  2024-04-11 23:51 ` [PATCH 2/2] crypto: aead,cipher - zeroize key buffer " Hailey Mothershead
  2024-04-12  2:55 ` [PATCH 1/2] crypto: ecdh - zeroize crpytographic keys " Herbert Xu
  0 siblings, 2 replies; 4+ messages in thread
From: Hailey Mothershead @ 2024-04-11 23:51 UTC (permalink / raw)
  To: herbert; +Cc: davem, linux-crypto, linux-kernel, hailmo

Fips 140-3 specifies that Sensitive Security Parameters (SSPs) must be
zeroized after use and that overwriting these variables with a new SSP
is not sufficient for zeroization. So explicitly zeroize the private key
before it is overwritten in ecdh_set_secret.

It also requires that variables used in the creation of SSPs
be zeroized once they are no longer in use. Zeroize the public key as it
is used in the creation of the shared secret.

Signed-off-by: Hailey Mothershead <hailmo@amazon.com>
---
 crypto/ecdh.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/crypto/ecdh.c b/crypto/ecdh.c
index 80afee3234fb..71599cadf0bc 100644
--- a/crypto/ecdh.c
+++ b/crypto/ecdh.c
@@ -33,6 +33,8 @@ static int ecdh_set_secret(struct crypto_kpp *tfm, const void *buf,
 	    params.key_size > sizeof(u64) * ctx->ndigits)
 		return -EINVAL;
 
+	memset(ctx->private_key, 0, sizeof(ctx->private_key));
+
 	if (!params.key || !params.key_size)
 		return ecc_gen_privkey(ctx->curve_id, ctx->ndigits,
 				       ctx->private_key);
@@ -111,7 +113,7 @@ static int ecdh_compute_value(struct kpp_request *req)
 free_all:
 	kfree_sensitive(shared_secret);
 free_pubkey:
-	kfree(public_key);
+	kfree_sensitive(public_key);
 	return ret;
 }
 
-- 
2.40.1


^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2024-04-12  2:55 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-04-11 23:51 [PATCH 1/2] crypto: ecdh - zeroize crpytographic keys after use Hailey Mothershead
2024-04-11 23:51 ` [PATCH 2/2] crypto: aead,cipher - zeroize key buffer " Hailey Mothershead
2024-04-12  2:54   ` Herbert Xu
2024-04-12  2:55 ` [PATCH 1/2] crypto: ecdh - zeroize crpytographic keys " Herbert Xu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox