18d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/* 28d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * SHA1-based key derivation function (PBKDF2) for IEEE 802.11i 38d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Copyright (c) 2003-2005, Jouni Malinen <j@w1.fi> 48d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 5c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * This software may be distributed under the terms of the BSD license. 6c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * See README for more details. 78d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 88d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 98d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "includes.h" 108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "common.h" 128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "sha1.h" 138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1461d9df3e62aaa0e87ad05452fcb95142159a17b6Dmitry Shmidtstatic int pbkdf2_sha1_f(const char *passphrase, const u8 *ssid, 158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t ssid_len, int iterations, unsigned int count, 168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 *digest) 178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char tmp[SHA1_MAC_LEN], tmp2[SHA1_MAC_LEN]; 198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int i, j; 208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char count_buf[4]; 218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const u8 *addr[2]; 228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t len[2]; 238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t passphrase_len = os_strlen(passphrase); 248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2561d9df3e62aaa0e87ad05452fcb95142159a17b6Dmitry Shmidt addr[0] = ssid; 268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt len[0] = ssid_len; 278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt addr[1] = count_buf; 288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt len[1] = 4; 298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* F(P, S, c, i) = U1 xor U2 xor ... Uc 318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * U1 = PRF(P, S || i) 328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * U2 = PRF(P, U1) 338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Uc = PRF(P, Uc-1) 348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt count_buf[0] = (count >> 24) & 0xff; 378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt count_buf[1] = (count >> 16) & 0xff; 388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt count_buf[2] = (count >> 8) & 0xff; 398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt count_buf[3] = count & 0xff; 408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (hmac_sha1_vector((u8 *) passphrase, passphrase_len, 2, addr, len, 418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt tmp)) 428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(digest, tmp, SHA1_MAC_LEN); 448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt for (i = 1; i < iterations; i++) { 468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (hmac_sha1((u8 *) passphrase, passphrase_len, tmp, 478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt SHA1_MAC_LEN, tmp2)) 488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(tmp, tmp2, SHA1_MAC_LEN); 508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt for (j = 0; j < SHA1_MAC_LEN; j++) 518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt digest[j] ^= tmp2[j]; 528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/** 598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * pbkdf2_sha1 - SHA1-based key derivation function (PBKDF2) for IEEE 802.11i 608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @passphrase: ASCII passphrase 618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @ssid: SSID 628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @ssid_len: SSID length in bytes 638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @iterations: Number of iterations to run 648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @buf: Buffer for the generated key 658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @buflen: Length of the buffer in bytes 668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: 0 on success, -1 of failure 678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This function is used to derive PSK for WPA-PSK. For this protocol, 698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * iterations is set to 4096 and buflen to 32. This function is described in 708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * IEEE Std 802.11-2004, Clause H.4. The main construction is from PKCS#5 v2.0. 718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 7261d9df3e62aaa0e87ad05452fcb95142159a17b6Dmitry Shmidtint pbkdf2_sha1(const char *passphrase, const u8 *ssid, size_t ssid_len, 738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int iterations, u8 *buf, size_t buflen) 748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned int count = 0; 768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *pos = buf; 778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t left = buflen, plen; 788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char digest[SHA1_MAC_LEN]; 798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt while (left > 0) { 818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt count++; 828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (pbkdf2_sha1_f(passphrase, ssid, ssid_len, iterations, 838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt count, digest)) 848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt plen = left > SHA1_MAC_LEN ? SHA1_MAC_LEN : left; 868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(pos, digest, plen); 878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos += plen; 888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt left -= plen; 898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 93