18d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/*
28d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * SHA1-based key derivation function (PBKDF2) for IEEE 802.11i
38d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Copyright (c) 2003-2005, Jouni Malinen <j@w1.fi>
48d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
5c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * This software may be distributed under the terms of the BSD license.
6c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * See README for more details.
78d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
88d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
98d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "includes.h"
108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "common.h"
128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "sha1.h"
138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
1461d9df3e62aaa0e87ad05452fcb95142159a17b6Dmitry Shmidtstatic int pbkdf2_sha1_f(const char *passphrase, const u8 *ssid,
158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			 size_t ssid_len, int iterations, unsigned int count,
168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			 u8 *digest)
178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	unsigned char tmp[SHA1_MAC_LEN], tmp2[SHA1_MAC_LEN];
198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	int i, j;
208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	unsigned char count_buf[4];
218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	const u8 *addr[2];
228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	size_t len[2];
238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	size_t passphrase_len = os_strlen(passphrase);
248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
2561d9df3e62aaa0e87ad05452fcb95142159a17b6Dmitry Shmidt	addr[0] = ssid;
268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	len[0] = ssid_len;
278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	addr[1] = count_buf;
288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	len[1] = 4;
298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	/* F(P, S, c, i) = U1 xor U2 xor ... Uc
318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * U1 = PRF(P, S || i)
328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * U2 = PRF(P, U1)
338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 * Uc = PRF(P, Uc-1)
348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	 */
358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	count_buf[0] = (count >> 24) & 0xff;
378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	count_buf[1] = (count >> 16) & 0xff;
388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	count_buf[2] = (count >> 8) & 0xff;
398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	count_buf[3] = count & 0xff;
408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	if (hmac_sha1_vector((u8 *) passphrase, passphrase_len, 2, addr, len,
418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			     tmp))
428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		return -1;
438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	os_memcpy(digest, tmp, SHA1_MAC_LEN);
448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	for (i = 1; i < iterations; i++) {
468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (hmac_sha1((u8 *) passphrase, passphrase_len, tmp,
478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			      SHA1_MAC_LEN, tmp2))
488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return -1;
498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_memcpy(tmp, tmp2, SHA1_MAC_LEN);
508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		for (j = 0; j < SHA1_MAC_LEN; j++)
518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			digest[j] ^= tmp2[j];
528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return 0;
558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/**
598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * pbkdf2_sha1 - SHA1-based key derivation function (PBKDF2) for IEEE 802.11i
608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @passphrase: ASCII passphrase
618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @ssid: SSID
628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @ssid_len: SSID length in bytes
638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @iterations: Number of iterations to run
648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @buf: Buffer for the generated key
658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @buflen: Length of the buffer in bytes
668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: 0 on success, -1 of failure
678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This function is used to derive PSK for WPA-PSK. For this protocol,
698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * iterations is set to 4096 and buflen to 32. This function is described in
708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * IEEE Std 802.11-2004, Clause H.4. The main construction is from PKCS#5 v2.0.
718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
7261d9df3e62aaa0e87ad05452fcb95142159a17b6Dmitry Shmidtint pbkdf2_sha1(const char *passphrase, const u8 *ssid, size_t ssid_len,
738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		int iterations, u8 *buf, size_t buflen)
748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{
758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	unsigned int count = 0;
768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	unsigned char *pos = buf;
778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	size_t left = buflen, plen;
788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	unsigned char digest[SHA1_MAC_LEN];
798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	while (left > 0) {
818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		count++;
828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		if (pbkdf2_sha1_f(passphrase, ssid, ssid_len, iterations,
838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt				  count, digest))
848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			return -1;
858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		plen = left > SHA1_MAC_LEN ? SHA1_MAC_LEN : left;
868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		os_memcpy(pos, digest, plen);
878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		pos += plen;
888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		left -= plen;
898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	}
908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	return 0;
928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}
93