1*03f9172cSAndroid Build Coastguard Worker /*
2*03f9172cSAndroid Build Coastguard Worker * SHA1-based key derivation function (PBKDF2) for IEEE 802.11i
3*03f9172cSAndroid Build Coastguard Worker * Copyright (c) 2003-2005, Jouni Malinen <[email protected]>
4*03f9172cSAndroid Build Coastguard Worker *
5*03f9172cSAndroid Build Coastguard Worker * This software may be distributed under the terms of the BSD license.
6*03f9172cSAndroid Build Coastguard Worker * See README for more details.
7*03f9172cSAndroid Build Coastguard Worker */
8*03f9172cSAndroid Build Coastguard Worker
9*03f9172cSAndroid Build Coastguard Worker #include "includes.h"
10*03f9172cSAndroid Build Coastguard Worker
11*03f9172cSAndroid Build Coastguard Worker #include "common.h"
12*03f9172cSAndroid Build Coastguard Worker #include "sha1.h"
13*03f9172cSAndroid Build Coastguard Worker
pbkdf2_sha1_f(const char * passphrase,const u8 * ssid,size_t ssid_len,int iterations,unsigned int count,u8 * digest)14*03f9172cSAndroid Build Coastguard Worker static int pbkdf2_sha1_f(const char *passphrase, const u8 *ssid,
15*03f9172cSAndroid Build Coastguard Worker size_t ssid_len, int iterations, unsigned int count,
16*03f9172cSAndroid Build Coastguard Worker u8 *digest)
17*03f9172cSAndroid Build Coastguard Worker {
18*03f9172cSAndroid Build Coastguard Worker unsigned char tmp[SHA1_MAC_LEN], tmp2[SHA1_MAC_LEN];
19*03f9172cSAndroid Build Coastguard Worker int i, j;
20*03f9172cSAndroid Build Coastguard Worker unsigned char count_buf[4];
21*03f9172cSAndroid Build Coastguard Worker const u8 *addr[2];
22*03f9172cSAndroid Build Coastguard Worker size_t len[2];
23*03f9172cSAndroid Build Coastguard Worker size_t passphrase_len = os_strlen(passphrase);
24*03f9172cSAndroid Build Coastguard Worker
25*03f9172cSAndroid Build Coastguard Worker addr[0] = ssid;
26*03f9172cSAndroid Build Coastguard Worker len[0] = ssid_len;
27*03f9172cSAndroid Build Coastguard Worker addr[1] = count_buf;
28*03f9172cSAndroid Build Coastguard Worker len[1] = 4;
29*03f9172cSAndroid Build Coastguard Worker
30*03f9172cSAndroid Build Coastguard Worker /* F(P, S, c, i) = U1 xor U2 xor ... Uc
31*03f9172cSAndroid Build Coastguard Worker * U1 = PRF(P, S || i)
32*03f9172cSAndroid Build Coastguard Worker * U2 = PRF(P, U1)
33*03f9172cSAndroid Build Coastguard Worker * Uc = PRF(P, Uc-1)
34*03f9172cSAndroid Build Coastguard Worker */
35*03f9172cSAndroid Build Coastguard Worker
36*03f9172cSAndroid Build Coastguard Worker count_buf[0] = (count >> 24) & 0xff;
37*03f9172cSAndroid Build Coastguard Worker count_buf[1] = (count >> 16) & 0xff;
38*03f9172cSAndroid Build Coastguard Worker count_buf[2] = (count >> 8) & 0xff;
39*03f9172cSAndroid Build Coastguard Worker count_buf[3] = count & 0xff;
40*03f9172cSAndroid Build Coastguard Worker if (hmac_sha1_vector((u8 *) passphrase, passphrase_len, 2, addr, len,
41*03f9172cSAndroid Build Coastguard Worker tmp))
42*03f9172cSAndroid Build Coastguard Worker return -1;
43*03f9172cSAndroid Build Coastguard Worker os_memcpy(digest, tmp, SHA1_MAC_LEN);
44*03f9172cSAndroid Build Coastguard Worker
45*03f9172cSAndroid Build Coastguard Worker for (i = 1; i < iterations; i++) {
46*03f9172cSAndroid Build Coastguard Worker if (hmac_sha1((u8 *) passphrase, passphrase_len, tmp,
47*03f9172cSAndroid Build Coastguard Worker SHA1_MAC_LEN, tmp2))
48*03f9172cSAndroid Build Coastguard Worker return -1;
49*03f9172cSAndroid Build Coastguard Worker os_memcpy(tmp, tmp2, SHA1_MAC_LEN);
50*03f9172cSAndroid Build Coastguard Worker for (j = 0; j < SHA1_MAC_LEN; j++)
51*03f9172cSAndroid Build Coastguard Worker digest[j] ^= tmp2[j];
52*03f9172cSAndroid Build Coastguard Worker }
53*03f9172cSAndroid Build Coastguard Worker forced_memzero(tmp, SHA1_MAC_LEN);
54*03f9172cSAndroid Build Coastguard Worker forced_memzero(tmp2, SHA1_MAC_LEN);
55*03f9172cSAndroid Build Coastguard Worker
56*03f9172cSAndroid Build Coastguard Worker return 0;
57*03f9172cSAndroid Build Coastguard Worker }
58*03f9172cSAndroid Build Coastguard Worker
59*03f9172cSAndroid Build Coastguard Worker
60*03f9172cSAndroid Build Coastguard Worker /**
61*03f9172cSAndroid Build Coastguard Worker * pbkdf2_sha1 - SHA1-based key derivation function (PBKDF2) for IEEE 802.11i
62*03f9172cSAndroid Build Coastguard Worker * @passphrase: ASCII passphrase
63*03f9172cSAndroid Build Coastguard Worker * @ssid: SSID
64*03f9172cSAndroid Build Coastguard Worker * @ssid_len: SSID length in bytes
65*03f9172cSAndroid Build Coastguard Worker * @iterations: Number of iterations to run
66*03f9172cSAndroid Build Coastguard Worker * @buf: Buffer for the generated key
67*03f9172cSAndroid Build Coastguard Worker * @buflen: Length of the buffer in bytes
68*03f9172cSAndroid Build Coastguard Worker * Returns: 0 on success, -1 of failure
69*03f9172cSAndroid Build Coastguard Worker *
70*03f9172cSAndroid Build Coastguard Worker * This function is used to derive PSK for WPA-PSK. For this protocol,
71*03f9172cSAndroid Build Coastguard Worker * iterations is set to 4096 and buflen to 32. This function is described in
72*03f9172cSAndroid Build Coastguard Worker * IEEE Std 802.11-2004, Clause H.4. The main construction is from PKCS#5 v2.0.
73*03f9172cSAndroid Build Coastguard Worker */
pbkdf2_sha1(const char * passphrase,const u8 * ssid,size_t ssid_len,int iterations,u8 * buf,size_t buflen)74*03f9172cSAndroid Build Coastguard Worker int pbkdf2_sha1(const char *passphrase, const u8 *ssid, size_t ssid_len,
75*03f9172cSAndroid Build Coastguard Worker int iterations, u8 *buf, size_t buflen)
76*03f9172cSAndroid Build Coastguard Worker {
77*03f9172cSAndroid Build Coastguard Worker unsigned int count = 0;
78*03f9172cSAndroid Build Coastguard Worker unsigned char *pos = buf;
79*03f9172cSAndroid Build Coastguard Worker size_t left = buflen, plen;
80*03f9172cSAndroid Build Coastguard Worker unsigned char digest[SHA1_MAC_LEN];
81*03f9172cSAndroid Build Coastguard Worker
82*03f9172cSAndroid Build Coastguard Worker while (left > 0) {
83*03f9172cSAndroid Build Coastguard Worker count++;
84*03f9172cSAndroid Build Coastguard Worker if (pbkdf2_sha1_f(passphrase, ssid, ssid_len, iterations,
85*03f9172cSAndroid Build Coastguard Worker count, digest))
86*03f9172cSAndroid Build Coastguard Worker return -1;
87*03f9172cSAndroid Build Coastguard Worker plen = left > SHA1_MAC_LEN ? SHA1_MAC_LEN : left;
88*03f9172cSAndroid Build Coastguard Worker os_memcpy(pos, digest, plen);
89*03f9172cSAndroid Build Coastguard Worker pos += plen;
90*03f9172cSAndroid Build Coastguard Worker left -= plen;
91*03f9172cSAndroid Build Coastguard Worker }
92*03f9172cSAndroid Build Coastguard Worker forced_memzero(digest, SHA1_MAC_LEN);
93*03f9172cSAndroid Build Coastguard Worker
94*03f9172cSAndroid Build Coastguard Worker return 0;
95*03f9172cSAndroid Build Coastguard Worker }
96