1 | /*
|
---|
2 | * Copyright 2016-2019 The OpenSSL Project Authors. All Rights Reserved.
|
---|
3 | *
|
---|
4 | * Licensed under the OpenSSL license (the "License"). You may not use
|
---|
5 | * this file except in compliance with the License. You can obtain a copy
|
---|
6 | * in the file LICENSE in the source distribution or at
|
---|
7 | * https://www.openssl.org/source/license.html
|
---|
8 | */
|
---|
9 |
|
---|
10 | /*
|
---|
11 | * Licensed under the OpenSSL licenses, (the "License");
|
---|
12 | * you may not use this file except in compliance with the License.
|
---|
13 | * You may obtain a copy of the License at
|
---|
14 | * https://www.openssl.org/source/license.html
|
---|
15 | * or in the file LICENSE in the source distribution.
|
---|
16 | */
|
---|
17 |
|
---|
18 | #ifndef OSSL_CRYPTO_RAND_H
|
---|
19 | # define OSSL_CRYPTO_RAND_H
|
---|
20 |
|
---|
21 | # include <openssl/rand.h>
|
---|
22 |
|
---|
23 | /* forward declaration */
|
---|
24 | typedef struct rand_pool_st RAND_POOL;
|
---|
25 |
|
---|
26 | void rand_cleanup_int(void);
|
---|
27 | void rand_drbg_cleanup_int(void);
|
---|
28 | void drbg_delete_thread_state(void);
|
---|
29 |
|
---|
30 | /* Hardware-based seeding functions. */
|
---|
31 | size_t rand_acquire_entropy_from_tsc(RAND_POOL *pool);
|
---|
32 | size_t rand_acquire_entropy_from_cpu(RAND_POOL *pool);
|
---|
33 |
|
---|
34 | /* DRBG entropy callbacks. */
|
---|
35 | size_t rand_drbg_get_entropy(RAND_DRBG *drbg,
|
---|
36 | unsigned char **pout,
|
---|
37 | int entropy, size_t min_len, size_t max_len,
|
---|
38 | int prediction_resistance);
|
---|
39 | void rand_drbg_cleanup_entropy(RAND_DRBG *drbg,
|
---|
40 | unsigned char *out, size_t outlen);
|
---|
41 | size_t rand_drbg_get_nonce(RAND_DRBG *drbg,
|
---|
42 | unsigned char **pout,
|
---|
43 | int entropy, size_t min_len, size_t max_len);
|
---|
44 | void rand_drbg_cleanup_nonce(RAND_DRBG *drbg,
|
---|
45 | unsigned char *out, size_t outlen);
|
---|
46 |
|
---|
47 | size_t rand_drbg_get_additional_data(RAND_POOL *pool, unsigned char **pout);
|
---|
48 |
|
---|
49 | void rand_drbg_cleanup_additional_data(RAND_POOL *pool, unsigned char *out);
|
---|
50 |
|
---|
51 | /*
|
---|
52 | * RAND_POOL functions
|
---|
53 | */
|
---|
54 | RAND_POOL *rand_pool_new(int entropy_requested, int secure,
|
---|
55 | size_t min_len, size_t max_len);
|
---|
56 | RAND_POOL *rand_pool_attach(const unsigned char *buffer, size_t len,
|
---|
57 | size_t entropy);
|
---|
58 | void rand_pool_free(RAND_POOL *pool);
|
---|
59 |
|
---|
60 | const unsigned char *rand_pool_buffer(RAND_POOL *pool);
|
---|
61 | unsigned char *rand_pool_detach(RAND_POOL *pool);
|
---|
62 | void rand_pool_reattach(RAND_POOL *pool, unsigned char *buffer);
|
---|
63 |
|
---|
64 | size_t rand_pool_entropy(RAND_POOL *pool);
|
---|
65 | size_t rand_pool_length(RAND_POOL *pool);
|
---|
66 |
|
---|
67 | size_t rand_pool_entropy_available(RAND_POOL *pool);
|
---|
68 | size_t rand_pool_entropy_needed(RAND_POOL *pool);
|
---|
69 | /* |entropy_factor| expresses how many bits of data contain 1 bit of entropy */
|
---|
70 | size_t rand_pool_bytes_needed(RAND_POOL *pool, unsigned int entropy_factor);
|
---|
71 | size_t rand_pool_bytes_remaining(RAND_POOL *pool);
|
---|
72 |
|
---|
73 | int rand_pool_add(RAND_POOL *pool,
|
---|
74 | const unsigned char *buffer, size_t len, size_t entropy);
|
---|
75 | unsigned char *rand_pool_add_begin(RAND_POOL *pool, size_t len);
|
---|
76 | int rand_pool_add_end(RAND_POOL *pool, size_t len, size_t entropy);
|
---|
77 |
|
---|
78 |
|
---|
79 | /*
|
---|
80 | * Add random bytes to the pool to acquire requested amount of entropy
|
---|
81 | *
|
---|
82 | * This function is platform specific and tries to acquire the requested
|
---|
83 | * amount of entropy by polling platform specific entropy sources.
|
---|
84 | *
|
---|
85 | * If the function succeeds in acquiring at least |entropy_requested| bits
|
---|
86 | * of entropy, the total entropy count is returned. If it fails, it returns
|
---|
87 | * an entropy count of 0.
|
---|
88 | */
|
---|
89 | size_t rand_pool_acquire_entropy(RAND_POOL *pool);
|
---|
90 |
|
---|
91 | /*
|
---|
92 | * Add some application specific nonce data
|
---|
93 | *
|
---|
94 | * This function is platform specific and adds some application specific
|
---|
95 | * data to the nonce used for instantiating the drbg.
|
---|
96 | *
|
---|
97 | * This data currently consists of the process and thread id, and a high
|
---|
98 | * resolution timestamp. The data does not include an atomic counter,
|
---|
99 | * because that is added by the calling function rand_drbg_get_nonce().
|
---|
100 | *
|
---|
101 | * Returns 1 on success and 0 on failure.
|
---|
102 | */
|
---|
103 | int rand_pool_add_nonce_data(RAND_POOL *pool);
|
---|
104 |
|
---|
105 |
|
---|
106 | /*
|
---|
107 | * Add some platform specific additional data
|
---|
108 | *
|
---|
109 | * This function is platform specific and adds some random noise to the
|
---|
110 | * additional data used for generating random bytes and for reseeding
|
---|
111 | * the drbg.
|
---|
112 | *
|
---|
113 | * Returns 1 on success and 0 on failure.
|
---|
114 | */
|
---|
115 | int rand_pool_add_additional_data(RAND_POOL *pool);
|
---|
116 |
|
---|
117 | /*
|
---|
118 | * Initialise the random pool reseeding sources.
|
---|
119 | *
|
---|
120 | * Returns 1 on success and 0 on failure.
|
---|
121 | */
|
---|
122 | int rand_pool_init(void);
|
---|
123 |
|
---|
124 | /*
|
---|
125 | * Finalise the random pool reseeding sources.
|
---|
126 | */
|
---|
127 | void rand_pool_cleanup(void);
|
---|
128 |
|
---|
129 | /*
|
---|
130 | * Control the random pool use of open file descriptors.
|
---|
131 | */
|
---|
132 | void rand_pool_keep_random_devices_open(int keep);
|
---|
133 |
|
---|
134 | #endif
|
---|