1*3ff40c12SJohn Marino /*
2*3ff40c12SJohn Marino * SHA1-based key derivation function (PBKDF2) for IEEE 802.11i
3*3ff40c12SJohn Marino * Copyright (c) 2003-2005, Jouni Malinen <j@w1.fi>
4*3ff40c12SJohn Marino *
5*3ff40c12SJohn Marino * This software may be distributed under the terms of the BSD license.
6*3ff40c12SJohn Marino * See README for more details.
7*3ff40c12SJohn Marino */
8*3ff40c12SJohn Marino
9*3ff40c12SJohn Marino #include "includes.h"
10*3ff40c12SJohn Marino
11*3ff40c12SJohn Marino #include "common.h"
12*3ff40c12SJohn Marino #include "sha1.h"
13*3ff40c12SJohn Marino
pbkdf2_sha1_f(const char * passphrase,const u8 * ssid,size_t ssid_len,int iterations,unsigned int count,u8 * digest)14*3ff40c12SJohn Marino static int pbkdf2_sha1_f(const char *passphrase, const u8 *ssid,
15*3ff40c12SJohn Marino size_t ssid_len, int iterations, unsigned int count,
16*3ff40c12SJohn Marino u8 *digest)
17*3ff40c12SJohn Marino {
18*3ff40c12SJohn Marino unsigned char tmp[SHA1_MAC_LEN], tmp2[SHA1_MAC_LEN];
19*3ff40c12SJohn Marino int i, j;
20*3ff40c12SJohn Marino unsigned char count_buf[4];
21*3ff40c12SJohn Marino const u8 *addr[2];
22*3ff40c12SJohn Marino size_t len[2];
23*3ff40c12SJohn Marino size_t passphrase_len = os_strlen(passphrase);
24*3ff40c12SJohn Marino
25*3ff40c12SJohn Marino addr[0] = ssid;
26*3ff40c12SJohn Marino len[0] = ssid_len;
27*3ff40c12SJohn Marino addr[1] = count_buf;
28*3ff40c12SJohn Marino len[1] = 4;
29*3ff40c12SJohn Marino
30*3ff40c12SJohn Marino /* F(P, S, c, i) = U1 xor U2 xor ... Uc
31*3ff40c12SJohn Marino * U1 = PRF(P, S || i)
32*3ff40c12SJohn Marino * U2 = PRF(P, U1)
33*3ff40c12SJohn Marino * Uc = PRF(P, Uc-1)
34*3ff40c12SJohn Marino */
35*3ff40c12SJohn Marino
36*3ff40c12SJohn Marino count_buf[0] = (count >> 24) & 0xff;
37*3ff40c12SJohn Marino count_buf[1] = (count >> 16) & 0xff;
38*3ff40c12SJohn Marino count_buf[2] = (count >> 8) & 0xff;
39*3ff40c12SJohn Marino count_buf[3] = count & 0xff;
40*3ff40c12SJohn Marino if (hmac_sha1_vector((u8 *) passphrase, passphrase_len, 2, addr, len,
41*3ff40c12SJohn Marino tmp))
42*3ff40c12SJohn Marino return -1;
43*3ff40c12SJohn Marino os_memcpy(digest, tmp, SHA1_MAC_LEN);
44*3ff40c12SJohn Marino
45*3ff40c12SJohn Marino for (i = 1; i < iterations; i++) {
46*3ff40c12SJohn Marino if (hmac_sha1((u8 *) passphrase, passphrase_len, tmp,
47*3ff40c12SJohn Marino SHA1_MAC_LEN, tmp2))
48*3ff40c12SJohn Marino return -1;
49*3ff40c12SJohn Marino os_memcpy(tmp, tmp2, SHA1_MAC_LEN);
50*3ff40c12SJohn Marino for (j = 0; j < SHA1_MAC_LEN; j++)
51*3ff40c12SJohn Marino digest[j] ^= tmp2[j];
52*3ff40c12SJohn Marino }
53*3ff40c12SJohn Marino
54*3ff40c12SJohn Marino return 0;
55*3ff40c12SJohn Marino }
56*3ff40c12SJohn Marino
57*3ff40c12SJohn Marino
58*3ff40c12SJohn Marino /**
59*3ff40c12SJohn Marino * pbkdf2_sha1 - SHA1-based key derivation function (PBKDF2) for IEEE 802.11i
60*3ff40c12SJohn Marino * @passphrase: ASCII passphrase
61*3ff40c12SJohn Marino * @ssid: SSID
62*3ff40c12SJohn Marino * @ssid_len: SSID length in bytes
63*3ff40c12SJohn Marino * @iterations: Number of iterations to run
64*3ff40c12SJohn Marino * @buf: Buffer for the generated key
65*3ff40c12SJohn Marino * @buflen: Length of the buffer in bytes
66*3ff40c12SJohn Marino * Returns: 0 on success, -1 of failure
67*3ff40c12SJohn Marino *
68*3ff40c12SJohn Marino * This function is used to derive PSK for WPA-PSK. For this protocol,
69*3ff40c12SJohn Marino * iterations is set to 4096 and buflen to 32. This function is described in
70*3ff40c12SJohn Marino * IEEE Std 802.11-2004, Clause H.4. The main construction is from PKCS#5 v2.0.
71*3ff40c12SJohn Marino */
pbkdf2_sha1(const char * passphrase,const u8 * ssid,size_t ssid_len,int iterations,u8 * buf,size_t buflen)72*3ff40c12SJohn Marino int pbkdf2_sha1(const char *passphrase, const u8 *ssid, size_t ssid_len,
73*3ff40c12SJohn Marino int iterations, u8 *buf, size_t buflen)
74*3ff40c12SJohn Marino {
75*3ff40c12SJohn Marino unsigned int count = 0;
76*3ff40c12SJohn Marino unsigned char *pos = buf;
77*3ff40c12SJohn Marino size_t left = buflen, plen;
78*3ff40c12SJohn Marino unsigned char digest[SHA1_MAC_LEN];
79*3ff40c12SJohn Marino
80*3ff40c12SJohn Marino while (left > 0) {
81*3ff40c12SJohn Marino count++;
82*3ff40c12SJohn Marino if (pbkdf2_sha1_f(passphrase, ssid, ssid_len, iterations,
83*3ff40c12SJohn Marino count, digest))
84*3ff40c12SJohn Marino return -1;
85*3ff40c12SJohn Marino plen = left > SHA1_MAC_LEN ? SHA1_MAC_LEN : left;
86*3ff40c12SJohn Marino os_memcpy(pos, digest, plen);
87*3ff40c12SJohn Marino pos += plen;
88*3ff40c12SJohn Marino left -= plen;
89*3ff40c12SJohn Marino }
90*3ff40c12SJohn Marino
91*3ff40c12SJohn Marino return 0;
92*3ff40c12SJohn Marino }
93