ReactOS 0.4.17-dev-1005-g171e1de
tlsprf.c File Reference
#include "precomp.h"
Include dependency graph for tlsprf.c:

Go to the source code of this file.

Macros

#define SYMCRYPT_TLS_MAX_LABEL_AND_SEED_SIZE   (SYMCRYPT_TLS_MAX_LABEL_SIZE + SYMCRYPT_TLS_MAX_SEED_SIZE)
 
#define SYMCRYPT_TLS_1_1_CHUNK_SIZE   80
 

Functions

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_1ExpandKey (_Out_ PSYMCRYPT_TLSPRF1_1_EXPANDED_KEY pExpandedKey, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_2ExpandKey (_Out_ PSYMCRYPT_TLSPRF1_2_EXPANDED_KEY pExpandedKey, _In_ PCSYMCRYPT_MAC macAlgorithm, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
 
VOID SYMCRYPT_CALL SymCryptTlsPrfMac (_In_ PCSYMCRYPT_MAC pMacAlgorithm, _In_ PCSYMCRYPT_MAC_EXPANDED_KEY pMacExpandedKey, _In_reads_(cbAi) PCBYTE pbAi, _In_ SIZE_T cbAi, _In_reads_opt_(cbSeed) PCBYTE pbSeed, _In_ SIZE_T cbSeed, _Out_ PBYTE pbResult)
 
VOID SYMCRYPT_CALL SymCryptTlsPrfPHash (_In_ PCSYMCRYPT_MAC pMacAlgorithm, _In_ PCSYMCRYPT_MAC_EXPANDED_KEY pMacExpandedKey, _In_reads_(cbSeed) PCBYTE pbSeed, _In_ SIZE_T cbSeed, _In_reads_opt_(cbAiIn) PCBYTE pbAiIn, _In_ SIZE_T cbAiIn, _Out_writes_(cbResult) PBYTE pbResult, SIZE_T cbResult, _Out_writes_opt_(cbAiOut) PBYTE pbAiOut, SIZE_T cbAiOut)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_1Derive (_In_ PCSYMCRYPT_TLSPRF1_1_EXPANDED_KEY pExpandedKey, _In_reads_opt_(cbLabel) PCBYTE pbLabel, _In_ SIZE_T cbLabel, _In_reads_(cbSeed) PCBYTE pbSeed, _In_ SIZE_T cbSeed, _Out_writes_(cbResult) PBYTE pbResult, SIZE_T cbResult)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_2Derive (_In_ PCSYMCRYPT_TLSPRF1_2_EXPANDED_KEY pExpandedKey, _In_reads_opt_(cbLabel) PCBYTE pbLabel, _In_ SIZE_T cbLabel, _In_reads_(cbSeed) PCBYTE pbSeed, _In_ SIZE_T cbSeed, _Out_writes_(cbResult) PBYTE pbResult, SIZE_T cbResult)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_1 (_In_reads_(cbKey) PCBYTE pbKey, _In_ SIZE_T cbKey, _In_reads_opt_(cbLabel) PCBYTE pbLabel, _In_ SIZE_T cbLabel, _In_reads_(cbSeed) PCBYTE pbSeed, _In_ SIZE_T cbSeed, _Out_writes_(cbResult) PBYTE pbResult, SIZE_T cbResult)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_2 (_In_ PCSYMCRYPT_MAC pMacAlgorithm, _In_reads_(cbKey) PCBYTE pbKey, _In_ SIZE_T cbKey, _In_reads_opt_(cbLabel) PCBYTE pbLabel, _In_ SIZE_T cbLabel, _In_reads_(cbSeed) PCBYTE pbSeed, _In_ SIZE_T cbSeed, _Out_writes_(cbResult) PBYTE pbResult, SIZE_T cbResult)
 

Macro Definition Documentation

◆ SYMCRYPT_TLS_1_1_CHUNK_SIZE

#define SYMCRYPT_TLS_1_1_CHUNK_SIZE   80

Definition at line 23 of file tlsprf.c.

◆ SYMCRYPT_TLS_MAX_LABEL_AND_SEED_SIZE

#define SYMCRYPT_TLS_MAX_LABEL_AND_SEED_SIZE   (SYMCRYPT_TLS_MAX_LABEL_SIZE + SYMCRYPT_TLS_MAX_SEED_SIZE)

Definition at line 19 of file tlsprf.c.

Function Documentation

◆ SymCryptTlsPrf1_1()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_1 ( _In_reads_(cbKey) PCBYTE  pbKey,
_In_ SIZE_T  cbKey,
_In_reads_opt_(cbLabel) PCBYTE  pbLabel,
_In_ SIZE_T  cbLabel,
_In_reads_(cbSeed) PCBYTE  pbSeed,
_In_ SIZE_T  cbSeed,
_Out_writes_(cbResult) PBYTE  pbResult,
SIZE_T  cbResult 
)

Definition at line 484 of file tlsprf.c.

493{
494 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
496
497 // Create the expanded key
499 if (scError != SYMCRYPT_NO_ERROR)
500 {
501 goto cleanup;
502 }
503
504 // Derive the key
505 scError = SymCryptTlsPrf1_1Derive(
506 &key,
507 pbLabel,
508 cbLabel,
509 pbSeed,
510 cbSeed,
511 pbResult,
512 cbResult);
513 if (scError != SYMCRYPT_NO_ERROR)
514 {
515 goto cleanup;
516 }
517
518cleanup:
519 SymCryptWipeKnownSize(&key, sizeof(key));
520
521 return scError;
522}
static void cleanup(void)
Definition: main.c:1335
static const BYTE pbResult[]
Definition: copy.c:22
FORCEINLINE VOID SYMCRYPT_CALL SymCryptWipeKnownSize(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)
SYMCRYPT_ERROR
Definition: symcrypt.h:227
PCBYTE pbKey
PCBYTE SIZE_T cbKey
UINT32 cbSeed
PBYTE pbSeed
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_1ExpandKey(_Out_ PSYMCRYPT_TLSPRF1_1_EXPANDED_KEY pExpandedKey, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
Definition: tlsprf.c:58
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_1Derive(_In_ PCSYMCRYPT_TLSPRF1_1_EXPANDED_KEY pExpandedKey, _In_reads_opt_(cbLabel) PCBYTE pbLabel, _In_ SIZE_T cbLabel, _In_reads_(cbSeed) PCBYTE pbSeed, _In_ SIZE_T cbSeed, _Out_writes_(cbResult) PBYTE pbResult, SIZE_T cbResult)
Definition: tlsprf.c:299

◆ SymCryptTlsPrf1_1Derive()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_1Derive ( _In_ PCSYMCRYPT_TLSPRF1_1_EXPANDED_KEY  pExpandedKey,
_In_reads_opt_(cbLabel) PCBYTE  pbLabel,
_In_ SIZE_T  cbLabel,
_In_reads_(cbSeed) PCBYTE  pbSeed,
_In_ SIZE_T  cbSeed,
_Out_writes_(cbResult) PBYTE  pbResult,
SIZE_T  cbResult 
)

Definition at line 299 of file tlsprf.c.

307{
308 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
309
311 SIZE_T cbLabelAndSeed = 0;
312
315
318
319 BYTE * pbTmp = pbResult;
320 SIZE_T cbBytesToWrite = cbResult;
321
322 // Size checks
324 {
325 scError = SYMCRYPT_WRONG_DATA_SIZE;
326 goto cleanup;
327 }
328
329 // Concatenating the label and the seed
330 pbTmp = rbLabelAndSeed;
331 if( cbLabel > 0 )
332 {
333 memcpy(pbTmp, pbLabel, cbLabel);
334 pbTmp += cbLabel;
335 }
336 memcpy(pbTmp, pbSeed, cbSeed);
337 cbLabelAndSeed = cbLabel + cbSeed;
338
339 // Build A(1)'s
343 rbLabelAndSeed, // This is A(0)
344 cbLabelAndSeed,
345 NULL, // No "seed" part for A(i)'s
346 0,
347 rbAiMd5);
348
352 rbLabelAndSeed, // This is A(0)
353 cbLabelAndSeed,
354 NULL, // No "seed" part for A(i)'s
355 0,
356 rbAiSha1);
357
358 // Calculate the output
359 pbTmp = pbResult;
360 while (cbBytesToWrite > 0)
361 {
362 // Calculate the two P_Hashes up to SYMCRYPT_TLS_1_1_CHUNK_SIZE bytes
363
364 // P_MD5
368 rbLabelAndSeed,
369 cbLabelAndSeed,
370 rbAiMd5,
372 rbPartialResultMd5,
374 rbAiMd5,
376
377 // P_SHA1
381 rbLabelAndSeed,
382 cbLabelAndSeed,
383 rbAiSha1,
385 rbPartialResultSha1,
387 rbAiSha1,
389
390 // XOR the two into the output
392 rbPartialResultMd5,
393 rbPartialResultSha1,
394 pbTmp,
396
397 if (cbBytesToWrite <= SYMCRYPT_TLS_1_1_CHUNK_SIZE)
398 {
399 break;
400 }
401
402 cbBytesToWrite -= SYMCRYPT_TLS_1_1_CHUNK_SIZE;
404
405 }
406
407cleanup:
408 SymCryptWipeKnownSize(rbLabelAndSeed, sizeof(rbLabelAndSeed));
409 SymCryptWipeKnownSize(rbAiMd5, sizeof(rbAiMd5));
410 SymCryptWipeKnownSize(rbPartialResultMd5, sizeof(rbPartialResultMd5));
411 SymCryptWipeKnownSize(rbAiSha1, sizeof(rbAiSha1));
412 SymCryptWipeKnownSize(rbPartialResultSha1, sizeof(rbPartialResultSha1));
413
414 return scError;
415}
#define NULL
Definition: types.h:112
#define memcpy(s1, s2, n)
Definition: mkisofs.h:878
#define SYMCRYPT_HMAC_MD5_RESULT_SIZE
Definition: symcrypt.h:2660
const PCSYMCRYPT_MAC SymCryptHmacSha1Algorithm
Definition: hmacsha1.c:36
const PCSYMCRYPT_MAC SymCryptHmacMd5Algorithm
Definition: hmacmd5.c:29
VOID SYMCRYPT_CALL SymCryptXorBytes(_In_reads_(cbBytes) PCBYTE pbSrc1, _In_reads_(cbBytes) PCBYTE pbSrc2, _Out_writes_(cbBytes) PBYTE pbResult, SIZE_T cbBytes)
Definition: libmain.c:236
#define SYMCRYPT_HMAC_SHA1_RESULT_SIZE
Definition: symcrypt.h:2725
#define SYMCRYPT_TLS_MAX_LABEL_SIZE
Definition: symcrypt.h:5671
#define SYMCRYPT_TLS_MAX_SEED_SIZE
Definition: symcrypt.h:5672
#define SYMCRYPT_ALIGN
#define SYMCRYPT_MIN(_a, _b)
PCVOID pExpandedKey
VOID SYMCRYPT_CALL SymCryptTlsPrfPHash(_In_ PCSYMCRYPT_MAC pMacAlgorithm, _In_ PCSYMCRYPT_MAC_EXPANDED_KEY pMacExpandedKey, _In_reads_(cbSeed) PCBYTE pbSeed, _In_ SIZE_T cbSeed, _In_reads_opt_(cbAiIn) PCBYTE pbAiIn, _In_ SIZE_T cbAiIn, _Out_writes_(cbResult) PBYTE pbResult, SIZE_T cbResult, _Out_writes_opt_(cbAiOut) PBYTE pbAiOut, SIZE_T cbAiOut)
Definition: tlsprf.c:204
VOID SYMCRYPT_CALL SymCryptTlsPrfMac(_In_ PCSYMCRYPT_MAC pMacAlgorithm, _In_ PCSYMCRYPT_MAC_EXPANDED_KEY pMacExpandedKey, _In_reads_(cbAi) PCBYTE pbAi, _In_ SIZE_T cbAi, _In_reads_opt_(cbSeed) PCBYTE pbSeed, _In_ SIZE_T cbSeed, _Out_ PBYTE pbResult)
Definition: tlsprf.c:160
#define SYMCRYPT_TLS_1_1_CHUNK_SIZE
Definition: tlsprf.c:23
#define SYMCRYPT_TLS_MAX_LABEL_AND_SEED_SIZE
Definition: tlsprf.c:19
ULONG_PTR SIZE_T
Definition: typedefs.h:80
unsigned char BYTE
Definition: xxhash.c:193

Referenced by SymCryptTlsPrf1_1().

◆ SymCryptTlsPrf1_1ExpandKey()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_1ExpandKey ( _Out_ PSYMCRYPT_TLSPRF1_1_EXPANDED_KEY  pExpandedKey,
_In_reads_(cbKey) PCBYTE  pbKey,
SIZE_T  cbKey 
)

Definition at line 58 of file tlsprf.c.

62{
63 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
64
65 SIZE_T cbKeySize;
66 SIZE_T cbHalfSecret;
67 SIZE_T cbOdd;
68
69 // Calculating the two halves
70 cbHalfSecret = cbKey / 2;
71 cbOdd = cbKey % 2;
72 cbKeySize = cbHalfSecret + cbOdd;
73
74 //
75 // The bytes of the key material are split as following:
76 // cbOdd == 0 => cbKeySize == cbHalfSecret
77 //
78 // ********************************************
79 // <----cbHalfSecret----><----cbHalfSecret---->
80 // <----cbKeySize-------><----cbKeySize------->
81 //
82 //
83 // cbOdd == 1 => cbKeySize == cbHalfSecret + 1
84 //
85 // **********************$**********************
86 // <----cbHalfSecret----> <----cbHalfSecret---->
87 // <----cbKeySize-------->
88 // <----cbKeySize-------->
89 //
90 // Note that the middle byte of the key input might be
91 // read twice (when the key length is odd). This violates
92 // the standard rule that input data should only be read
93 // once. In this case, we do this for the following reasons:
94 // - Avoiding the dual-read is difficult; we'd have to buffer
95 // an arbitrary-size input, and SymCrypt avoids memory
96 // allocations for symmetric algorithms.
97 // - The dual-reading of inputs is a problem when the
98 // memory is double-mapped to a different (less trusted)
99 // security context. (E.g. a kernel-mode operation on
100 // memory that is also mapped into a user address space.)
101 // This PRF is used by TLS in LSA where that situation
102 // does not occur.
103 // - This is used for TLS 1.0 and TLS 1.1, both of which
104 // are on the deprecation path.
105 // - In the dual-read attack, the input is typically provided
106 // by the attacker, and then changed whilst the code is
107 // accessing it. But if the attacker is providing the input,
108 // she could just as well have provided an even-length key
109 // input that provides full freedom for choosing both HMAC
110 // keys; there is simply no reason to try and perform the
111 // dual-read attack.
112 // - Even if the dual-read problem were to occur, it does not
113 // seem to help an attacker in any way.
114
115 // MD5 Key Expansion
116 scError = SymCryptHmacMd5ExpandKey(&pExpandedKey->macMd5Key, pbKey, cbKeySize);
117 if (scError != SYMCRYPT_NO_ERROR)
118 {
119 goto cleanup;
120 }
121
122 // SHA1 Key Expansion
123 scError = SymCryptHmacSha1ExpandKey(&pExpandedKey->macSha1Key, pbKey + cbHalfSecret, cbKeySize);
124 if (scError != SYMCRYPT_NO_ERROR)
125 {
126 SymCryptWipeKnownSize(&pExpandedKey->macMd5Key, sizeof(pExpandedKey->macMd5Key));
127
128 goto cleanup;
129 }
130
131cleanup:
132 return scError;
133}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptHmacSha1ExpandKey(_Out_ PSYMCRYPT_HMAC_SHA1_EXPANDED_KEY pExpandedKey, _In_reads_opt_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptHmacMd5ExpandKey(_Out_ PSYMCRYPT_HMAC_MD5_EXPANDED_KEY pExpandedKey, _In_reads_opt_(cbKey) PCBYTE pbKey, SIZE_T cbKey)

Referenced by SymCryptTlsPrf1_1().

◆ SymCryptTlsPrf1_2()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_2 ( _In_ PCSYMCRYPT_MAC  pMacAlgorithm,
_In_reads_(cbKey) PCBYTE  pbKey,
_In_ SIZE_T  cbKey,
_In_reads_opt_(cbLabel) PCBYTE  pbLabel,
_In_ SIZE_T  cbLabel,
_In_reads_(cbSeed) PCBYTE  pbSeed,
_In_ SIZE_T  cbSeed,
_Out_writes_(cbResult) PBYTE  pbResult,
SIZE_T  cbResult 
)

Definition at line 530 of file tlsprf.c.

540{
541 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
543
544 // Create the expanded key
545 scError = SymCryptTlsPrf1_2ExpandKey(&key, pMacAlgorithm, pbKey, cbKey);
546 if (scError != SYMCRYPT_NO_ERROR)
547 {
548 goto cleanup;
549 }
550
551 // Derive the key
552 scError = SymCryptTlsPrf1_2Derive(
553 &key,
554 pbLabel,
555 cbLabel,
556 pbSeed,
557 cbSeed,
558 pbResult,
559 cbResult);
560 if (scError != SYMCRYPT_NO_ERROR)
561 {
562 goto cleanup;
563 }
564
565cleanup:
566 SymCryptWipeKnownSize(&key, sizeof(key));
567
568 return scError;
569}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_2Derive(_In_ PCSYMCRYPT_TLSPRF1_2_EXPANDED_KEY pExpandedKey, _In_reads_opt_(cbLabel) PCBYTE pbLabel, _In_ SIZE_T cbLabel, _In_reads_(cbSeed) PCBYTE pbSeed, _In_ SIZE_T cbSeed, _Out_writes_(cbResult) PBYTE pbResult, SIZE_T cbResult)
Definition: tlsprf.c:426
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_2ExpandKey(_Out_ PSYMCRYPT_TLSPRF1_2_EXPANDED_KEY pExpandedKey, _In_ PCSYMCRYPT_MAC macAlgorithm, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
Definition: tlsprf.c:137

◆ SymCryptTlsPrf1_2Derive()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_2Derive ( _In_ PCSYMCRYPT_TLSPRF1_2_EXPANDED_KEY  pExpandedKey,
_In_reads_opt_(cbLabel) PCBYTE  pbLabel,
_In_ SIZE_T  cbLabel,
_In_reads_(cbSeed) PCBYTE  pbSeed,
_In_ SIZE_T  cbSeed,
_Out_writes_(cbResult) PBYTE  pbResult,
SIZE_T  cbResult 
)

Definition at line 426 of file tlsprf.c.

434{
435 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
436
438 BYTE * pbTmp;
439
440 // Size checks
442 {
443 scError = SYMCRYPT_WRONG_DATA_SIZE;
444 goto cleanup;
445 }
446
447 // Concatenating the label and the seed
448 pbTmp = rbLabelAndSeed;
449 if( cbLabel > 0 )
450 {
451 memcpy(pbTmp, pbLabel, cbLabel);
452 pbTmp += cbLabel;
453 }
454 memcpy(pbTmp, pbSeed, cbSeed);
455
456 //
457 // According to RFC 2104 (HMAC), hash the secret if its length
458 // exceeds the basic compression block length. This is taken
459 // care by the specific HMAC inside SymCryptTlsPrfPHash.
460 //
462 pExpandedKey->macAlg,
463 &pExpandedKey->macKey,
464 rbLabelAndSeed,
465 cbLabel + cbSeed,
466 NULL,
467 0,
468 pbResult,
469 cbResult,
470 NULL,
471 0);
472
473cleanup:
474 SymCryptWipeKnownSize(rbLabelAndSeed, sizeof(rbLabelAndSeed));
475
476 return scError;
477}

Referenced by SymCryptTlsPrf1_2().

◆ SymCryptTlsPrf1_2ExpandKey()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptTlsPrf1_2ExpandKey ( _Out_ PSYMCRYPT_TLSPRF1_2_EXPANDED_KEY  pExpandedKey,
_In_ PCSYMCRYPT_MAC  macAlgorithm,
_In_reads_(cbKey) PCBYTE  pbKey,
SIZE_T  cbKey 
)

Definition at line 137 of file tlsprf.c.

142{
144
145 pExpandedKey->macAlg = macAlgorithm;
146 return macAlgorithm->expandKeyFunc( &pExpandedKey->macKey, pbKey, cbKey );
147}
PSYMCRYPT_MAC_EXPAND_KEY expandKeyFunc
#define SYMCRYPT_ASSERT(_x)
Definition: symcrypt.h:10807
PCSYMCRYPT_MAC macAlgorithm

Referenced by SymCryptTlsPrf1_2().

◆ SymCryptTlsPrfMac()

VOID SYMCRYPT_CALL SymCryptTlsPrfMac ( _In_ PCSYMCRYPT_MAC  pMacAlgorithm,
_In_ PCSYMCRYPT_MAC_EXPANDED_KEY  pMacExpandedKey,
_In_reads_(cbAi) PCBYTE  pbAi,
_In_ SIZE_T  cbAi,
_In_reads_opt_(cbSeed) PCBYTE  pbSeed,
_In_ SIZE_T  cbSeed,
_Out_ PBYTE  pbResult 
)

Definition at line 160 of file tlsprf.c.

168{
169 SYMCRYPT_MAC_STATE macState;
170
171 pMacAlgorithm->initFunc( &macState, pMacExpandedKey );
172 pMacAlgorithm->appendFunc(&macState, pbAi, cbAi);
173
174 if (cbSeed > 0)
175 {
176 pMacAlgorithm->appendFunc( &macState, pbSeed, cbSeed );
177 }
178
179 pMacAlgorithm->resultFunc( &macState, pbResult );
180
181 // No need to wipe the state. The resultFunc wipes it.
182}

Referenced by SymCryptTlsPrf1_1Derive(), and SymCryptTlsPrfPHash().

◆ SymCryptTlsPrfPHash()

VOID SYMCRYPT_CALL SymCryptTlsPrfPHash ( _In_ PCSYMCRYPT_MAC  pMacAlgorithm,
_In_ PCSYMCRYPT_MAC_EXPANDED_KEY  pMacExpandedKey,
_In_reads_(cbSeed) PCBYTE  pbSeed,
_In_ SIZE_T  cbSeed,
_In_reads_opt_(cbAiIn) PCBYTE  pbAiIn,
_In_ SIZE_T  cbAiIn,
_Out_writes_(cbResult) PBYTE  pbResult,
SIZE_T  cbResult,
_Out_writes_opt_(cbAiOut) PBYTE  pbAiOut,
SIZE_T  cbAiOut 
)

Definition at line 204 of file tlsprf.c.

215{
218 BYTE * pbTmp = pbResult;
219
220 SIZE_T cbMacResultSize = pMacAlgorithm->resultSize;
221 SIZE_T cbBytesToWrite = cbResult;
222
223 if (cbAiIn == 0)
224 {
225 // Build A(1)
227 pMacAlgorithm,
228 pMacExpandedKey,
229 pbSeed, // This is A(0)
230 cbSeed,
231 NULL, // No "seed" part for A(i)'s
232 0,
233 rbAi);
234 }
235 else
236 {
237 // Get the previous Ai
238 memcpy(rbAi, pbAiIn, SYMCRYPT_MIN(SYMCRYPT_MAC_MAX_RESULT_SIZE, cbAiIn));
239 }
240
241 while (cbBytesToWrite > 0)
242 {
243 // Build HMAC( secret, A(i) + seed)
245 pMacAlgorithm,
246 pMacExpandedKey,
247 rbAi, // this is A(i)
248 cbMacResultSize,
249 pbSeed, // the "seed" part
250 cbSeed,
251 rbPartialResult);
252
253 // Store it in the output buffer
254 memcpy(pbTmp, rbPartialResult, SYMCRYPT_MIN(cbBytesToWrite, cbMacResultSize));
255
256 // Build A(i+1)
258 pMacAlgorithm,
259 pMacExpandedKey,
260 rbAi, // This is A(i)
261 cbMacResultSize,
262 NULL, // No "seed" part for A(i)'s
263 0,
264 rbAi);
265
266 if (cbBytesToWrite <= cbMacResultSize)
267 {
268 break;
269 }
270
271 pbTmp += cbMacResultSize;
272 cbBytesToWrite -= cbMacResultSize;
273 }
274
275 // Store the next A(i) if needed
276 if (cbAiOut > 0)
277 {
278 memcpy(pbAiOut, rbAi, SYMCRYPT_MIN(cbAiOut,cbMacResultSize));
279 }
280
281 SymCryptWipeKnownSize(rbAi, sizeof(rbAi));
282 SymCryptWipeKnownSize(rbPartialResult, sizeof(rbPartialResult));
283}
#define SYMCRYPT_MAC_MAX_RESULT_SIZE

Referenced by SymCryptTlsPrf1_1Derive(), and SymCryptTlsPrf1_2Derive().