1 /**********************************************************************
3 * Copyright (c) 2005-2006 Cryptocom LTD *
4 * This file is distributed under the same license as OpenSSL *
6 * Main file of GOST engine *
8 * Requires OpenSSL 0.9.9 for compilation *
9 **********************************************************************/
11 #include <openssl/crypto.h>
12 #include <openssl/err.h>
13 #include <openssl/evp.h>
14 #include <openssl/engine.h>
15 #include <openssl/obj_mac.h>
16 #include "e_gost_err.h"
19 #include "gost_grasshopper_cipher.h"
21 static const char* engine_gost_id = "gost";
23 static const char* engine_gost_name =
24 "Reference implementation of GOST engine";
26 /* Symmetric cipher and digest function registrar */
28 static int gost_ciphers(ENGINE* e, const EVP_CIPHER** cipher,
29 const int** nids, int nid);
31 static int gost_digests(ENGINE* e, const EVP_MD** digest,
32 const int** nids, int ind);
34 static int gost_pkey_meths(ENGINE* e, EVP_PKEY_METHOD** pmeth,
35 const int** nids, int nid);
37 static int gost_pkey_asn1_meths(ENGINE* e, EVP_PKEY_ASN1_METHOD** ameth,
38 const int** nids, int nid);
40 static int gost_cipher_nids[] = {
52 NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm,
53 #ifdef NID_kuznyechik_mgm
61 static int gost_digest_nids(const int** nids) {
62 static int digest_nids[10] = {0, 0, 0, 0, 0, 0, 0, 0, 0, 0};
68 if ((md = digest_gost()) != NULL)
69 digest_nids[pos++] = EVP_MD_type(md);
70 if ((md = imit_gost_cpa()) != NULL)
71 digest_nids[pos++] = EVP_MD_type(md);
72 if ((md = digest_gost2012_256()) != NULL)
73 digest_nids[pos++] = EVP_MD_type(md);
74 if ((md = digest_gost2012_512()) != NULL)
75 digest_nids[pos++] = EVP_MD_type(md);
76 if ((md = imit_gost_cp_12()) != NULL)
77 digest_nids[pos++] = EVP_MD_type(md);
78 if ((md = magma_omac()) != NULL)
79 digest_nids[pos++] = EVP_MD_type(md);
80 if ((md = grasshopper_omac()) != NULL)
81 digest_nids[pos++] = EVP_MD_type(md);
82 /* if ((md = magma_omac_acpkm()) != NULL)
83 digest_nids[pos++] = EVP_MD_type(md);*/
84 if ((md = grasshopper_omac_acpkm()) != NULL)
85 digest_nids[pos++] = EVP_MD_type(md);
94 static int gost_pkey_meth_nids[] = {
95 NID_id_GostR3410_2001,
96 NID_id_Gost28147_89_MAC,
97 NID_id_GostR3410_2012_256,
98 NID_id_GostR3410_2012_512,
102 NID_id_tc26_cipher_gostr3412_2015_magma_ctracpkm_omac,
103 NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm_omac,
107 static EVP_PKEY_METHOD* pmeth_GostR3410_2001 = NULL,
108 * pmeth_GostR3410_2012_256 = NULL,
109 * pmeth_GostR3410_2012_512 = NULL,
110 * pmeth_Gost28147_MAC = NULL, * pmeth_Gost28147_MAC_12 = NULL,
111 * pmeth_magma_mac = NULL, * pmeth_grasshopper_mac = NULL,
112 * pmeth_magma_mac_acpkm = NULL, * pmeth_grasshopper_mac_acpkm = NULL;
114 static EVP_PKEY_ASN1_METHOD* ameth_GostR3410_2001 = NULL,
115 * ameth_GostR3410_2012_256 = NULL,
116 * ameth_GostR3410_2012_512 = NULL,
117 * ameth_Gost28147_MAC = NULL, * ameth_Gost28147_MAC_12 = NULL,
118 * ameth_magma_mac = NULL, * ameth_grasshopper_mac = NULL,
119 * ameth_magma_mac_acpkm = NULL, * ameth_grasshopper_mac_acpkm = NULL;
121 static int gost_engine_init(ENGINE* e) {
125 static int gost_engine_finish(ENGINE* e) {
129 static int gost_engine_destroy(ENGINE* e) {
130 EVP_delete_digest_alias("streebog256");
131 EVP_delete_digest_alias("streebog512");
132 digest_gost_destroy();
133 digest_gost2012_256_destroy();
134 digest_gost2012_512_destroy();
136 imit_gost_cpa_destroy();
137 imit_gost_cp_12_destroy();
138 magma_omac_destroy();
139 grasshopper_omac_destroy();
140 grasshopper_omac_acpkm_destroy();
142 cipher_gost_destroy();
143 cipher_gost_grasshopper_destroy();
147 pmeth_GostR3410_2001 = NULL;
148 pmeth_Gost28147_MAC = NULL;
149 pmeth_GostR3410_2012_256 = NULL;
150 pmeth_GostR3410_2012_512 = NULL;
151 pmeth_Gost28147_MAC_12 = NULL;
152 pmeth_magma_mac = NULL;
153 pmeth_grasshopper_mac = NULL;
154 pmeth_magma_mac_acpkm = NULL;
155 pmeth_grasshopper_mac_acpkm = NULL;
157 ameth_GostR3410_2001 = NULL;
158 ameth_Gost28147_MAC = NULL;
159 ameth_GostR3410_2012_256 = NULL;
160 ameth_GostR3410_2012_512 = NULL;
161 ameth_Gost28147_MAC_12 = NULL;
162 ameth_magma_mac = NULL;
163 ameth_grasshopper_mac = NULL;
164 ameth_magma_mac_acpkm = NULL;
165 ameth_grasshopper_mac_acpkm = NULL;
167 ERR_unload_GOST_strings();
172 static int bind_gost(ENGINE* e, const char* id) {
174 if (id != NULL && strcmp(id, engine_gost_id) != 0)
176 if (ameth_GostR3410_2001) {
177 printf("GOST engine already loaded\n");
180 if (!ENGINE_set_id(e, engine_gost_id)) {
181 printf("ENGINE_set_id failed\n");
184 if (!ENGINE_set_name(e, engine_gost_name)) {
185 printf("ENGINE_set_name failed\n");
188 if (!ENGINE_set_digests(e, gost_digests)) {
189 printf("ENGINE_set_digests failed\n");
192 if (!ENGINE_set_ciphers(e, gost_ciphers)) {
193 printf("ENGINE_set_ciphers failed\n");
196 if (!ENGINE_set_pkey_meths(e, gost_pkey_meths)) {
197 printf("ENGINE_set_pkey_meths failed\n");
200 if (!ENGINE_set_pkey_asn1_meths(e, gost_pkey_asn1_meths)) {
201 printf("ENGINE_set_pkey_asn1_meths failed\n");
204 /* Control function and commands */
205 if (!ENGINE_set_cmd_defns(e, gost_cmds)) {
206 fprintf(stderr, "ENGINE_set_cmd_defns failed\n");
209 if (!ENGINE_set_ctrl_function(e, gost_control_func)) {
210 fprintf(stderr, "ENGINE_set_ctrl_func failed\n");
213 if (!ENGINE_set_destroy_function(e, gost_engine_destroy)
214 || !ENGINE_set_init_function(e, gost_engine_init)
215 || !ENGINE_set_finish_function(e, gost_engine_finish)) {
219 if (!register_ameth_gost
220 (NID_id_GostR3410_2001, &ameth_GostR3410_2001, "GOST2001",
221 "GOST R 34.10-2001"))
223 if (!register_ameth_gost
224 (NID_id_GostR3410_2012_256, &ameth_GostR3410_2012_256, "GOST2012_256",
225 "GOST R 34.10-2012 with 256 bit key"))
227 if (!register_ameth_gost
228 (NID_id_GostR3410_2012_512, &ameth_GostR3410_2012_512, "GOST2012_512",
229 "GOST R 34.10-2012 with 512 bit key"))
231 if (!register_ameth_gost(NID_id_Gost28147_89_MAC, &ameth_Gost28147_MAC,
232 "GOST-MAC", "GOST 28147-89 MAC"))
234 if (!register_ameth_gost(NID_gost_mac_12, &ameth_Gost28147_MAC_12,
236 "GOST 28147-89 MAC with 2012 params"))
238 if (!register_ameth_gost(NID_magma_mac, &ameth_magma_mac,
239 "MAGMA-MAC", "GOST R 34.13-2015 Magma MAC"))
241 if (!register_ameth_gost(NID_grasshopper_mac, &ameth_grasshopper_mac,
242 "GRASSHOPPER-MAC", "GOST R 34.13-2015 Grasshopper MAC"))
244 /* if (!register_ameth_gost(NID_id_tc26_cipher_gostr3412_2015_magma_ctracpkm_omac, &ameth_magma_mac_acpkm,
245 "ID-TC26-CIPHER-GOSTR3412-2015-MAGMA-CTRACPKM-OMAC", "GOST R 34.13-2015 Magma MAC ACPKM"))
247 if (!register_ameth_gost(NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm_omac, &ameth_grasshopper_mac_acpkm,
248 "ID-TC26-CIPHER-GOSTR3412-2015-KUZNYECHIK-CTRACPKM-OMAC", "GOST R 34.13-2015 Grasshopper MAC ACPKM"))
252 if (!register_pmeth_gost(NID_id_GostR3410_2001, &pmeth_GostR3410_2001, 0))
255 if (!register_pmeth_gost
256 (NID_id_GostR3410_2012_256, &pmeth_GostR3410_2012_256, 0))
258 if (!register_pmeth_gost
259 (NID_id_GostR3410_2012_512, &pmeth_GostR3410_2012_512, 0))
261 if (!register_pmeth_gost
262 (NID_id_Gost28147_89_MAC, &pmeth_Gost28147_MAC, 0))
264 if (!register_pmeth_gost(NID_gost_mac_12, &pmeth_Gost28147_MAC_12, 0))
266 if (!register_pmeth_gost(NID_magma_mac, &pmeth_magma_mac, 0))
268 if (!register_pmeth_gost(NID_grasshopper_mac, &pmeth_grasshopper_mac, 0))
270 /* if (!register_pmeth_gost(NID_magma_mac_acpkm, &pmeth_magma_mac_acpkm, 0))
272 if (!register_pmeth_gost(NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm_omac, &pmeth_grasshopper_mac_acpkm, 0))
274 if (!ENGINE_register_ciphers(e)
275 || !ENGINE_register_digests(e)
276 || !ENGINE_register_pkey_meths(e)
277 /* These two actually should go in LIST_ADD command */
278 || !EVP_add_cipher(cipher_gost())
279 || !EVP_add_cipher(cipher_gost_cbc())
280 || !EVP_add_cipher(cipher_gost_cpacnt())
281 || !EVP_add_cipher(cipher_gost_cpcnt_12())
282 || !EVP_add_cipher(cipher_gost_grasshopper_ecb())
283 || !EVP_add_cipher(cipher_gost_grasshopper_cbc())
284 || !EVP_add_cipher(cipher_gost_grasshopper_cfb())
285 || !EVP_add_cipher(cipher_gost_grasshopper_ofb())
286 || !EVP_add_cipher(cipher_gost_grasshopper_ctr())
287 || !EVP_add_cipher(cipher_gost_grasshopper_ctracpkm())
288 #ifdef NID_kuznyechik_mgm
289 || !EVP_add_cipher(cipher_gost_grasshopper_mgm())
291 || !EVP_add_cipher(cipher_magma_cbc())
292 || !EVP_add_cipher(cipher_magma_ctr())
293 || !EVP_add_digest(digest_gost())
294 || !EVP_add_digest(digest_gost2012_512())
295 || !EVP_add_digest(digest_gost2012_256())
296 || !EVP_add_digest(imit_gost_cpa())
297 || !EVP_add_digest(imit_gost_cp_12())
298 || !EVP_add_digest(magma_omac())
299 || !EVP_add_digest(grasshopper_omac())
300 /* || !EVP_add_digest(magma_omac_acpkm()) */
301 || !EVP_add_digest(grasshopper_omac_acpkm())
306 if(!EVP_add_digest_alias(SN_id_GostR3411_2012_256, "streebog256")
307 || !EVP_add_digest_alias(SN_id_GostR3411_2012_512, "streebog512")) {
311 ENGINE_register_all_complete();
313 ERR_load_GOST_strings();
319 #ifndef OPENSSL_NO_DYNAMIC_ENGINE
320 IMPLEMENT_DYNAMIC_BIND_FN(bind_gost)
321 IMPLEMENT_DYNAMIC_CHECK_FN()
322 #endif /* ndef OPENSSL_NO_DYNAMIC_ENGINE */
324 static int gost_digests(ENGINE* e, const EVP_MD** digest,
325 const int** nids, int nid) {
327 if (digest == NULL) {
328 return gost_digest_nids(nids);
330 if (nid == NID_id_GostR3411_94) {
331 *digest = digest_gost();
332 } else if (nid == NID_id_Gost28147_89_MAC) {
333 *digest = imit_gost_cpa();
334 } else if (nid == NID_id_GostR3411_2012_256) {
335 *digest = digest_gost2012_256();
336 } else if (nid == NID_id_GostR3411_2012_512) {
337 *digest = digest_gost2012_512();
338 } else if (nid == NID_gost_mac_12) {
339 *digest = imit_gost_cp_12();
340 } else if (nid == NID_magma_mac) {
341 *digest = magma_omac();
342 } else if (nid == NID_grasshopper_mac) {
343 *digest = grasshopper_omac();
344 } else if (nid == NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm_omac) {
345 *digest = grasshopper_omac_acpkm();
353 static int gost_ciphers(ENGINE* e, const EVP_CIPHER** cipher,
354 const int** nids, int nid) {
356 if (cipher == NULL) {
357 *nids = gost_cipher_nids;
358 return sizeof(gost_cipher_nids) / sizeof(gost_cipher_nids[0]) - 1;
361 if (nid == NID_id_Gost28147_89) {
362 *cipher = cipher_gost();
363 } else if (nid == NID_gost89_cnt) {
364 *cipher = cipher_gost_cpacnt();
365 } else if (nid == NID_gost89_cnt_12) {
366 *cipher = cipher_gost_cpcnt_12();
367 } else if (nid == NID_gost89_cbc) {
368 *cipher = cipher_gost_cbc();
369 } else if (nid == NID_grasshopper_ecb) {
370 *cipher = cipher_gost_grasshopper_ecb();
371 } else if (nid == NID_grasshopper_cbc) {
372 *cipher = cipher_gost_grasshopper_cbc();
373 } else if (nid == NID_grasshopper_cfb) {
374 *cipher = cipher_gost_grasshopper_cfb();
375 } else if (nid == NID_grasshopper_ofb) {
376 *cipher = cipher_gost_grasshopper_ofb();
377 } else if (nid == NID_grasshopper_ctr) {
378 *cipher = cipher_gost_grasshopper_ctr();
379 } else if (nid == NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm) {
380 *cipher = cipher_gost_grasshopper_ctracpkm();
381 #ifdef NID_kuznyechik_mgm
382 } else if (nid == NID_kuznyechik_mgm) {
383 *cipher = cipher_gost_grasshopper_mgm();
385 } else if (nid == NID_magma_cbc) {
386 *cipher = cipher_magma_cbc();
387 } else if (nid == NID_magma_ctr) {
388 *cipher = cipher_magma_ctr();
396 static int gost_pkey_meths(ENGINE* e, EVP_PKEY_METHOD** pmeth,
397 const int** nids, int nid) {
399 *nids = gost_pkey_meth_nids;
400 return sizeof(gost_pkey_meth_nids) / sizeof(gost_pkey_meth_nids[0]) - 1;
404 case NID_id_GostR3410_2001:
405 *pmeth = pmeth_GostR3410_2001;
407 case NID_id_GostR3410_2012_256:
408 *pmeth = pmeth_GostR3410_2012_256;
410 case NID_id_GostR3410_2012_512:
411 *pmeth = pmeth_GostR3410_2012_512;
413 case NID_id_Gost28147_89_MAC:
414 *pmeth = pmeth_Gost28147_MAC;
416 case NID_gost_mac_12:
417 *pmeth = pmeth_Gost28147_MAC_12;
420 *pmeth = pmeth_magma_mac;
422 case NID_grasshopper_mac:
423 *pmeth = pmeth_grasshopper_mac;
425 case NID_id_tc26_cipher_gostr3412_2015_magma_ctracpkm_omac:
426 *pmeth = pmeth_magma_mac_acpkm;
428 case NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm_omac:
429 *pmeth = pmeth_grasshopper_mac_acpkm;
439 static int gost_pkey_asn1_meths(ENGINE* e, EVP_PKEY_ASN1_METHOD** ameth,
440 const int** nids, int nid) {
442 *nids = gost_pkey_meth_nids;
443 return sizeof(gost_pkey_meth_nids) / sizeof(gost_pkey_meth_nids[0]) - 1;
447 case NID_id_GostR3410_2001:
448 *ameth = ameth_GostR3410_2001;
450 case NID_id_GostR3410_2012_256:
451 *ameth = ameth_GostR3410_2012_256;
453 case NID_id_GostR3410_2012_512:
454 *ameth = ameth_GostR3410_2012_512;
456 case NID_id_Gost28147_89_MAC:
457 *ameth = ameth_Gost28147_MAC;
459 case NID_gost_mac_12:
460 *ameth = ameth_Gost28147_MAC_12;
463 *ameth = ameth_magma_mac;
465 case NID_grasshopper_mac:
466 *ameth = ameth_grasshopper_mac;
468 case NID_id_tc26_cipher_gostr3412_2015_magma_ctracpkm_omac:
469 *ameth = ameth_magma_mac_acpkm;
471 case NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm_omac:
472 *ameth = ameth_grasshopper_mac_acpkm;
483 #ifdef OPENSSL_NO_DYNAMIC_ENGINE
485 static ENGINE* engine_gost(void) {
486 ENGINE* ret = ENGINE_new();
489 if (!bind_gost(ret, engine_gost_id)) {
496 void ENGINE_load_gost(void) {
498 if (pmeth_GostR3410_2001)
500 toadd = engine_gost();