mbedtls_util.c 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260
  1. #include "stm32f10x.h"
  2. #include "mbedtls_util.h"
  3. #include <string.h>
  4. #include "mbedtls/sha1.h"
  5. #include "mbedtls/sha256.h"
  6. #include "mbedtls/aes.h"
  7. #include "mbedtls/cipher.h"
  8. #include "mbedtls/base64.h"
  9. #include "sys.h"
  10. #include <stdio.h>
  11. #define KEY_IOPAD_SIZE 64
  12. #define SHA1_DIGEST_SIZE 20
  13. #define SHA256_DIGEST_SIZE 32
  14. #define AES_LEN_SIZE 256
  15. #define AES_BLOCK_SIZE 16
  16. /**
  17. * 填充源码,返回填充后的数据长度
  18. */
  19. static int fillAESPKCS7Data(char* data)
  20. {
  21. int left= 0;
  22. int len = strlen(data);
  23. if(len%AES_BLOCK_SIZE != 0)
  24. {
  25. left = AES_BLOCK_SIZE-strlen(data)%AES_BLOCK_SIZE;
  26. }
  27. else
  28. {
  29. left = AES_BLOCK_SIZE;
  30. }
  31. memset(data+strlen(data),left,left);
  32. len+=left;
  33. return len;
  34. }
  35. static int fillAESPKCS7DataWithLength(uint8_t * data, uint16_t data_length)
  36. {
  37. int left= 0;
  38. int len = data_length;
  39. if(len%AES_BLOCK_SIZE != 0)
  40. {
  41. left = AES_BLOCK_SIZE - data_length%AES_BLOCK_SIZE;
  42. }
  43. else
  44. {
  45. left = AES_BLOCK_SIZE;
  46. }
  47. memset(data + data_length, left, left);
  48. len += left;
  49. return len;
  50. }
  51. /**
  52. * 去除源码无效数据
  53. */
  54. static void cutAESPKCS7Data(char* data)
  55. {
  56. int i= 0;
  57. int size = strlen(data);
  58. for(i=size-1;data[i]>0&&data[i]<AES_BLOCK_SIZE;i--)
  59. {
  60. data[i]=0;
  61. }
  62. }
  63. void utils_hmac_sha1_str(const char *msg, int msg_len, char *digest, const char *key, int key_len)
  64. {
  65. //对函数参数判空
  66. if((NULL == msg) || (NULL == digest) || (NULL == key)) {
  67. return;
  68. }
  69. //限制密钥长度
  70. if(key_len > KEY_IOPAD_SIZE) {
  71. return;
  72. }
  73. //hmac sha1加密处理
  74. mbedtls_sha1_context context;
  75. unsigned char k_ipad[KEY_IOPAD_SIZE]; /* inner padding - key XORd with ipad */
  76. unsigned char k_opad[KEY_IOPAD_SIZE]; /* outer padding - key XORd with opad */
  77. unsigned char out[SHA1_DIGEST_SIZE];
  78. int i;
  79. /* start out by storing key in pads */
  80. memset(k_ipad, 0, sizeof(k_ipad));
  81. memset(k_opad, 0, sizeof(k_opad));
  82. memcpy(k_ipad, key, key_len);
  83. memcpy(k_opad, key, key_len);
  84. /* XOR key with ipad and opad values */
  85. for (i = 0; i < KEY_IOPAD_SIZE; i++) {
  86. k_ipad[i] ^= 0x36;
  87. k_opad[i] ^= 0x5c;
  88. }
  89. /* perform inner MD5 */
  90. mbedtls_sha1_init(&context); /* init context for 1st pass */
  91. mbedtls_sha1_starts(&context); /* setup context for 1st pass */
  92. mbedtls_sha1_update(&context, k_ipad, KEY_IOPAD_SIZE); /* start with inner pad */
  93. mbedtls_sha1_update(&context, (unsigned char *) msg, msg_len); /* then text of datagram */
  94. mbedtls_sha1_finish(&context, out); /* finish up 1st pass */
  95. /* perform outer MD5 */
  96. mbedtls_sha1_init(&context); /* init context for 2nd pass */
  97. mbedtls_sha1_starts(&context); /* setup context for 2nd pass */
  98. mbedtls_sha1_update(&context, k_opad, KEY_IOPAD_SIZE); /* start with outer pad */
  99. mbedtls_sha1_update(&context, out, SHA1_DIGEST_SIZE); /* then results of 1st hash */
  100. mbedtls_sha1_finish(&context, out); /* finish up 2nd pass */
  101. //加密后的数据16进制输出
  102. byteToHexStr(out,digest,SHA1_DIGEST_SIZE);
  103. }
  104. void utils_sha256(const char *msg, int msg_len, char * digest)
  105. {
  106. //hmac sha1加密处理
  107. mbedtls_sha256_context context;
  108. /* perform inner MD5 */
  109. mbedtls_sha256_init(&context); /* init context for 1st pass */
  110. mbedtls_sha256_starts(&context,0); /* setup context for 1st pass */
  111. mbedtls_sha256_update(&context, (unsigned char *) msg, msg_len); /* then text of datagram */
  112. mbedtls_sha256_finish(&context, (unsigned char *) digest); /* finish up 1st pass */
  113. }
  114. void utils_sha256_str(const char *msg, int msg_len, char *digest)
  115. {
  116. //hmac sha1加密处理
  117. //mbedtls_sha256_context context;
  118. unsigned char out[SHA256_DIGEST_SIZE];
  119. utils_sha256(msg,msg_len, (char * )out);
  120. //加密后的数据16进制输出
  121. byteToHexStr(out,digest,SHA256_DIGEST_SIZE);
  122. }
  123. /**
  124. *AES CBC加密 , plaintext:源数据,ciphertext:加密数据, 返回加密长度
  125. */
  126. int utils_aes128_cbc_enc(char *aes_key, char *iv, char *plaintext, char *ciphertext)
  127. {
  128. char iv_use[16] = {0};
  129. char data[AES_LEN_SIZE]= {0};
  130. mbedtls_aes_context aes_ctx;
  131. if(strlen(plaintext)+16 > AES_LEN_SIZE) return 0;
  132. memcpy(iv_use,iv,16);
  133. memcpy(data,plaintext,strlen(plaintext));
  134. int len = fillAESPKCS7Data(data);
  135. mbedtls_aes_init(&aes_ctx);
  136. //setkey_dec
  137. mbedtls_aes_setkey_enc(&aes_ctx, (unsigned char * )aes_key, 128);
  138. mbedtls_aes_crypt_cbc(&aes_ctx, MBEDTLS_AES_ENCRYPT, len, (unsigned char * )iv_use, (unsigned char * )data, (unsigned char * )ciphertext);
  139. mbedtls_aes_free(&aes_ctx);
  140. return len; //OK
  141. }
  142. int utils_aes128_cbc_enc_with_length(char *aes_key, char *iv, uint8_t * plaintext, uint16_t plaintext_length, uint8_t * ciphertext)
  143. {
  144. char iv_use[16] = {0};
  145. uint8_t data[AES_LEN_SIZE]= {0};
  146. mbedtls_aes_context aes_ctx;
  147. if(plaintext_length + 16 > AES_LEN_SIZE) return -1;
  148. memcpy(iv_use,iv,16);
  149. memcpy(data, plaintext, plaintext_length);
  150. int len = fillAESPKCS7DataWithLength(data, plaintext_length);
  151. mbedtls_aes_init(&aes_ctx);
  152. //setkey_dec
  153. mbedtls_aes_setkey_enc(&aes_ctx, (unsigned char * )aes_key, 128);
  154. mbedtls_aes_crypt_cbc(&aes_ctx, MBEDTLS_AES_ENCRYPT, len, (unsigned char * )iv_use, (unsigned char * )data, (unsigned char * )ciphertext);
  155. mbedtls_aes_free(&aes_ctx);
  156. return len; //OK
  157. }
  158. /**
  159. *AES CBC解密 ciphertext:加密数据, len:加密数据长度,plaintext:解密到的数据
  160. */
  161. int utils_aes128_cbc_dec(char *aes_key, char *iv, char *ciphertext, int len, char *plaintext)
  162. {
  163. char iv_use[16] = {0};
  164. mbedtls_aes_context aes_ctx;
  165. if(len%16&&len>AES_LEN_SIZE) return 0;
  166. memcpy(iv_use,iv,16);
  167. mbedtls_aes_init(&aes_ctx);
  168. //setkey_dec
  169. mbedtls_aes_setkey_dec(&aes_ctx, (unsigned char * )aes_key, 128);
  170. mbedtls_aes_crypt_cbc(&aes_ctx, MBEDTLS_AES_DECRYPT, len, (unsigned char * )iv_use, (unsigned char * )ciphertext, (unsigned char * )plaintext);
  171. cutAESPKCS7Data(plaintext);
  172. mbedtls_aes_free(&aes_ctx);
  173. return strlen(plaintext); //OK
  174. }
  175. /**
  176. *AES CBC加密 , src:源数据,dataLen:数据长度,ciphertext:加密数据, 返回加密长度
  177. */
  178. int utils_aes128_cbc_base64_enc(char *aes_key, char *iv, uint8_t *src,int dataLen, char *ciphertext)
  179. {
  180. size_t len;
  181. unsigned char buffer[AES_LEN_SIZE*2]={0};
  182. if(dataLen+16 > AES_LEN_SIZE) return 0;
  183. int ret = mbedtls_base64_encode( buffer, sizeof( buffer ), &len, src, dataLen );
  184. printf("base64_encode:%s\r\n",buffer);
  185. if(ret)
  186. {
  187. printf("base64 encode err:%d",ret);
  188. return 0;
  189. }
  190. return utils_aes128_cbc_enc(aes_key,iv,(char * )buffer,ciphertext);
  191. }
  192. /**
  193. *AES CBC解密 ciphertext:加密数据, len:加密数据长度,plaintext:解密到的数据
  194. */
  195. int utils_aes128_cbc_base64_dec(char *aes_key, char *iv, char *ciphertext, int dataLen, char *plaintext,int plainLen)
  196. {
  197. size_t len = 0;
  198. unsigned char buffer[AES_LEN_SIZE*2]={0};
  199. int retlen = utils_aes128_cbc_dec(aes_key,iv,ciphertext,dataLen,(char * )buffer);
  200. if(retlen)
  201. {
  202. printf("base64_encode2:%s\r\n",buffer);
  203. int ret = mbedtls_base64_decode((unsigned char * )plaintext, plainLen, &len, buffer, retlen);
  204. if(ret)
  205. {
  206. printf("base64 decode err:%d,%d",ret,retlen);
  207. len = 0;
  208. }
  209. }
  210. return len;
  211. }