1 /*
2 * Copyright (c) 2022 Huawei Device Co., Ltd.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at
6 *
7 * http://www.apache.org/licenses/LICENSE-2.0
8 *
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
14 */
15
16 #include "scrypt.h"
17 #include <openssl/ossl_typ.h>
18 #include <openssl/kdf.h>
19 #include "securec.h"
20 #include <unordered_map>
21 #include "iam_logger.h"
22
23 #define LOG_LABEL OHOS::UserIam::Common::LABEL_PIN_AUTH_SDK
24
25 namespace OHOS {
26 namespace UserIam {
27 namespace PinAuth {
28 namespace {
29 constexpr uint32_t OUT_LENGTH = 64;
30 constexpr uint32_t SCRYPT_N_V0 = 32768;
31 constexpr uint32_t SCRYPT_N_V1 = 2048;
32 constexpr uint32_t SCRYPT_R = 8;
33 constexpr uint32_t SCRYPT_P = 1;
34
35 struct ScryptParameters {
36 int32_t scryptN;
37 int32_t scryptR;
38 int32_t scryptP;
39 };
40
41 std::unordered_map<uint32_t, ScryptParameters> g_version2Param_ = {
42 { ALGO_VERSION_V0, { SCRYPT_N_V0, SCRYPT_R, SCRYPT_P } },
43 { ALGO_VERSION_V1, { SCRYPT_N_V1, SCRYPT_R, SCRYPT_P } },
44 { ALGO_VERSION_V2, { SCRYPT_N_V1, SCRYPT_R, SCRYPT_P } }
45 };
46 }
47
DoScrypt(std::vector<uint8_t> data,uint32_t algoVersion,EVP_PKEY_CTX * pctx)48 bool Scrypt::DoScrypt(std::vector<uint8_t> data, uint32_t algoVersion, EVP_PKEY_CTX *pctx)
49 {
50 auto index = g_version2Param_.find(algoVersion);
51 if (index == g_version2Param_.end()) {
52 IAM_LOGE("version is not in g_version2Param_");
53 return false;
54 }
55 ScryptParameters scryptParameters = index->second;
56 if (EVP_PKEY_CTX_set1_pbe_pass(pctx, reinterpret_cast<const char *>(data.data()), data.size()) <= 0) {
57 IAM_LOGE("EVP_PKEY_CTX_set1_pbe_pass fail");
58 return false;
59 }
60 if (EVP_PKEY_CTX_set1_scrypt_salt(pctx, algoParameter_.data(), algoParameter_.size()) <= 0) {
61 IAM_LOGE("EVP_PKEY_CTX_set1_scrypt_salt fail");
62 return false;
63 }
64 if (EVP_PKEY_CTX_set_scrypt_N(pctx, scryptParameters.scryptN) <= 0) {
65 IAM_LOGE("EVP_PKEY_CTX_set_scrypt_N fail");
66 return false;
67 }
68 if (EVP_PKEY_CTX_set_scrypt_r(pctx, scryptParameters.scryptR) <= 0) {
69 IAM_LOGE("EVP_PKEY_CTX_set_scrypt_r fail");
70 return false;
71 }
72 if (EVP_PKEY_CTX_set_scrypt_p(pctx, scryptParameters.scryptP) <= 0) {
73 IAM_LOGE("EVP_PKEY_CTX_set_scrypt_p fail");
74 return false;
75 }
76
77 return true;
78 }
79
ClearPinData(std::vector<uint8_t> & data)80 void Scrypt::ClearPinData(std::vector<uint8_t> &data)
81 {
82 // Delete the data in the vector completely
83 (void)memset_s(data.data(), data.size(), 0, data.size());
84 data.clear();
85 (void)memset_s(algoParameter_.data(), algoParameter_.size(), 0, algoParameter_.size());
86 algoParameter_.clear();
87 }
88
GetScrypt(std::vector<uint8_t> data,uint32_t algoVersion)89 std::vector<uint8_t> Scrypt::GetScrypt(std::vector<uint8_t> data, uint32_t algoVersion)
90 {
91 IAM_LOGI("start");
92 EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_SCRYPT, NULL);
93 if (EVP_PKEY_derive_init(pctx) <= 0) {
94 ClearPinData(data);
95 IAM_LOGE("EVP_PKEY_derive_init fail");
96 return {};
97 }
98
99 if (!DoScrypt(data, algoVersion, pctx)) {
100 IAM_LOGE("DoScrypt fail");
101 ClearPinData(data);
102 EVP_PKEY_CTX_free(pctx);
103 return {};
104 }
105 std::vector<uint8_t> out(OUT_LENGTH);
106 size_t outlen = out.size();
107 if (EVP_PKEY_derive(pctx, out.data(), &outlen) <= 0) {
108 IAM_LOGE("EVP_PKEY_derive fail");
109 ClearPinData(data);
110 EVP_PKEY_CTX_free(pctx);
111 return {};
112 }
113
114 ClearPinData(data);
115 EVP_PKEY_CTX_free(pctx);
116 return out;
117 }
118 } // namespace PinAuth
119 } // namespace UserIam
120 } // namespace OHOS