Botan  2.13.0
Crypto and TLS for C++11
xmss_verification_operation.cpp
Go to the documentation of this file.
1 /*
2  * XMSS Verification Operation
3  * Provides signature verification capabilities for Extended Hash-Based
4  * Signatures (XMSS).
5  *
6  * (C) 2016,2017 Matthias Gierlings
7  *
8  * Botan is released under the Simplified BSD License (see license.txt)
9  **/
10 
11 #include <botan/internal/xmss_verification_operation.h>
12 
13 namespace Botan {
14 
16  const XMSS_PublicKey& public_key)
17  : XMSS_Common_Ops(public_key.xmss_oid()),
18  m_pub_key(public_key),
19  m_msg_buf(0)
20  {
21  }
22 
24 XMSS_Verification_Operation::root_from_signature(const XMSS_Signature& sig,
25  const secure_vector<uint8_t>& msg,
26  XMSS_Address& adrs,
27  const secure_vector<uint8_t>& seed)
28  {
29  const uint32_t next_index = static_cast<uint32_t>(sig.unused_leaf_index());
31  adrs.set_ots_address(next_index);
32 
33  XMSS_WOTS_PublicKey pub_key_ots(m_pub_key.wots_parameters().oid(),
34  msg,
35  sig.tree().ots_signature(),
36  adrs,
37  seed);
38 
40  adrs.set_ltree_address(next_index);
41 
42  std::array<secure_vector<uint8_t>, 2> node;
43  create_l_tree(node[0], pub_key_ots, adrs, seed);
44 
46  adrs.set_tree_index(next_index);
47 
48  for(size_t k = 0; k < m_xmss_params.tree_height(); k++)
49  {
50  adrs.set_tree_height(static_cast<uint32_t>(k));
51  if(((next_index / (static_cast<size_t>(1) << k)) & 0x01) == 0)
52  {
53  adrs.set_tree_index(adrs.get_tree_index() >> 1);
54  randomize_tree_hash(node[1],
55  node[0],
56  sig.tree().authentication_path()[k],
57  adrs,
58  seed);
59  }
60  else
61  {
62  adrs.set_tree_index((adrs.get_tree_index() - 1) >> 1);
63  randomize_tree_hash(node[1],
64  sig.tree().authentication_path()[k],
65  node[0],
66  adrs,
67  seed);
68  }
69  node[0] = node[1];
70  }
71  return node[0];
72  }
73 
74 bool
75 XMSS_Verification_Operation::verify(const XMSS_Signature& sig,
76  const secure_vector<uint8_t>& msg,
77  const XMSS_PublicKey& public_key)
78  {
79  XMSS_Address adrs;
80  secure_vector<uint8_t> index_bytes;
81  XMSS_Tools::concat(index_bytes,
82  sig.unused_leaf_index(),
84  secure_vector<uint8_t> msg_digest =
85  m_hash.h_msg(sig.randomness(),
86  public_key.root(),
87  index_bytes,
88  msg);
89 
90  secure_vector<uint8_t> node = root_from_signature(sig,
91  msg_digest,
92  adrs,
93  public_key.public_seed());
94 
95  return (node == public_key.root());
96  }
97 
98 // FIXME: XMSS signature verification requires the "randomness" parameter out
99 // of the XMSS signature, which is part of the prefix that is hashed before
100 // msg. Since the signature is unknown till sign() is called all message
101 // content has to be buffered. For large messages this can be inconvenient or
102 // impossible.
103 // Possible solution: Change PK_Ops::Verification interface to take the
104 // signature as constructor argument, make sign a parameterless member call.
105 void XMSS_Verification_Operation::update(const uint8_t msg[], size_t msg_len)
106  {
107  std::copy(msg, msg + msg_len, std::back_inserter(m_msg_buf));
108  }
109 
111  size_t sig_len)
112  {
113  try
114  {
115  XMSS_Signature signature(m_pub_key.xmss_parameters().oid(),
116  secure_vector<uint8_t>(sig, sig + sig_len));
117  bool result = verify(signature, m_msg_buf, m_pub_key);
118  m_msg_buf.clear();
119  return result;
120  }
121  catch(...)
122  {
123  m_msg_buf.clear();
124  return false;
125  }
126  }
127 
128 }
129 
size_t element_size() const
size_t unused_leaf_index() const
void set_ots_address(uint32_t value)
Definition: xmss_address.h:164
void set_tree_height(uint32_t value)
Definition: xmss_address.h:251
size_t tree_height() const
void set_ltree_address(uint32_t value)
Definition: xmss_address.h:194
bool is_valid_signature(const uint8_t sig[], size_t sig_len) override
void create_l_tree(secure_vector< uint8_t > &result, wots_keysig_t pk, XMSS_Address &adrs, const secure_vector< uint8_t > &seed, XMSS_Hash &hash)
secure_vector< uint8_t > h_msg(const secure_vector< uint8_t > &randomness, const secure_vector< uint8_t > &root, const secure_vector< uint8_t > &index_bytes, const secure_vector< uint8_t > &data)
Definition: xmss_hash.cpp:70
const XMSS_Parameters & xmss_parameters() const
xmss_algorithm_t oid() const
void update(const uint8_t msg[], size_t msg_len) override
std::vector< T, secure_allocator< T >> secure_vector
Definition: secmem.h:65
const wots_keysig_t & ots_signature() const
void set_type(Type type)
Definition: xmss_address.h:111
XMSS_Parameters m_xmss_params
Definition: alg_id.cpp:13
XMSS_Verification_Operation(const XMSS_PublicKey &public_key)
static void concat(secure_vector< uint8_t > &target, const T &src)
Definition: xmss_tools.h:63
const XMSS_WOTS_Parameters & wots_parameters() const
const XMSS_WOTS_PublicKey::TreeSignature & tree() const
uint32_t get_tree_index() const
Definition: xmss_address.h:297
void randomize_tree_hash(secure_vector< uint8_t > &result, const secure_vector< uint8_t > &left, const secure_vector< uint8_t > &right, XMSS_Address &adrs, const secure_vector< uint8_t > &seed, XMSS_Hash &hash)
void set_tree_index(uint32_t value)
Definition: xmss_address.h:313
ots_algorithm_t oid() const
const wots_keysig_t & authentication_path() const