API C/C++
HSM Dinamo
Carregando...
Procurando...
Nenhuma entrada encontrado
gen_dh.c

Exemplo de geração de DH do HSM.

Veja Nota sobre os exemplos.
#include <string.h>
#include <stdlib.h>
#include <stdio.h>
#include <dinamo.h> /* header do Dinamo */
#define HOST_ADDR "127.0.0.1"
#define USER_ID "master"
#define USER_PWD "12345678"
/* RFC 7919 FFDHE2048 group */
#define DH_KEY_NAME "dh_key"
#define DH_PAIR_KEY_NAME "dh_pair_key"
#define DH_NEW_DERIVED_KEY "dh_derived_key"
#define DH_KEY_ALG (ALG_DH_RFC7919_2048)
int main()
{
int nRet = 0;
struct AUTH_PWD authPwd;
HSESSIONCTX hSession = NULL;
HKEYCTX hKey = NULL;
HKEYCTX hPairKey = NULL;
BYTE pbPubKey[4096] = {0};
DWORD dwPubKeyLen = sizeof(pbPubKey);
BYTE pbSecret[256] = {0};
DWORD dwSecretLen = sizeof(pbSecret);
nRet = DInitialize(0);
if(nRet)
{
printf("Falha na funcao: DInitialize \nCodigo de erro: %d\n", nRet);
goto clean;
}
printf("Bibliotecas inicializadas.\n");
strncpy(authPwd.szAddr, HOST_ADDR, sizeof(authPwd.szAddr));
authPwd.nPort = DEFAULT_PORT;
strncpy(authPwd.szUserId, USER_ID, sizeof(authPwd.szUserId));
strncpy(authPwd.szPassword, USER_PWD, sizeof(authPwd.szPassword));
nRet = DOpenSession(&hSession, SS_USER_PWD, (BYTE *)&authPwd, sizeof(authPwd), ENCRYPTED_CONN);
if(nRet)
{
printf("Falha na funcao: DOpenSession \nCodigo de erro: %d\n", nRet);
goto clean;
}
printf("Sessao com o Dinamo estabelecida.\n");
nRet = DGenerateKey(hSession, DH_KEY_NAME, DH_KEY_ALG, 0, &hKey);
if(nRet)
{
printf("Falha ao gerar chave principal.\n");
goto clean;
}
printf("Chave principal gerada com sucesso.\n");
nRet = DGenerateKey(hSession, DH_PAIR_KEY_NAME, DH_KEY_ALG, 0, &hPairKey);
if(nRet)
{
printf("Falha ao gerar chave do par.\n");
goto clean;
}
printf("Chave do par gerada com sucesso.\n");
nRet = DExportKey(hPairKey, NULL, PUBLICKEY_BLOB, 0, pbPubKey, &dwPubKeyLen);
if(nRet)
{
printf("Falha ao exportar chave publica do par.\n");
goto clean;
}
printf("Chave publica do par exportada com sucesso.\n");
/* Gera o segredo bruto DH (RFC 7919 / RFC 5114) */
nRet = DGenDhKey(hSession,
DH_KEY_NAME,
pbPubKey,
dwPubKeyLen,
pbSecret,
&dwSecretLen,
0);
if(nRet)
{
printf("Falha ao gerar DH RAW Secret.\n");
goto clean;
}
printf("Segredo DH RAW secret gerado com sucesso.\n");
{
BYTE pbKDFData[] = {0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,
0x11,0x12,0x13,0x14,0x15,0x16,0x17,0x18};
GEN_DH_KDF stDhKdfInfo;
memset(&stDhKdfInfo, 0, sizeof(stDhKdfInfo));
strncpy(stDhKdfInfo.szTargetKeyName, DH_NEW_DERIVED_KEY,
sizeof(stDhKdfInfo.szTargetKeyName));
stDhKdfInfo.dwTargetKeyAlg = ALG_AES_256;
stDhKdfInfo.dbPubKey.pvData = pbPubKey;
stDhKdfInfo.dbPubKey.dwDataLen = dwPubKeyLen;
stDhKdfInfo.dbKDFData.pvData = pbKDFData;
stDhKdfInfo.dbKDFData.dwDataLen = sizeof(pbKDFData);
/* Deriva chave AES-256 usando X9.63 SHA-256 */
nRet = DGenDhKey(hSession,
DH_KEY_NAME,
&stDhKdfInfo,
sizeof(stDhKdfInfo),
NULL,
NULL,
0);
if(nRet)
{
printf("Falha ao gerar chave DH derivada.\n");
goto clean;
}
printf("Chave DH derivada com sucesso.\n");
nRet = DRemoveObj(hSession, DH_NEW_DERIVED_KEY);
if(nRet)
{
printf("Falha ao remover chave derivada.\n");
goto clean;
}
printf("Chave derivada removida com sucesso.\n");
}
clean:
printf("Contexto das chaves foram liberados.\n");
DCloseSession(&hSession, 0);
printf("Sessao encerrada.\n");
printf("Bibliotecas finalizada.\n");
return nRet;
}
Application Programming Interface (API) do HSM Dinamo.
void * HSESSIONCTX
Definição dinamo.h:67
#define DN_DH_GEN_KEY_RAW_SECRET
Definição dinamo.h:2177
#define DEFAULT_PORT
Definição dinamo.h:2088
#define PUBLICKEY_BLOB
Definição dinamo.h:1498
#define ALG_AES_256
Definição dinamo.h:1083
#define TEMPORARY_KEY
Definição dinamo.h:1545
#define REMOVE_FROM_HSM
Definição dinamo.h:1585
unsigned char BYTE
Definição dinamo.h:44
unsigned int DWORD
Definição dinamo.h:45
#define DN_DH_GEN_KEY_X9_63_SHA256
Definição dinamo.h:2178
#define ENCRYPTED_CONN
Definição dinamo.h:584
#define SS_USER_PWD
Definição dinamo.h:575
void * HKEYCTX
Definição dinamo.h:69
#define EXPORTABLE_KEY
Definição dinamo.h:1543
int AAP_API DGenDhKey(HSESSIONCTX hSession, DWORD dwOP, char *szPriKey, void *pvInData, DWORD dwInDataLen, BYTE *pbOutData, DWORD *pdwOutDataLen, DWORD dwFlags)
int AAP_API DGenerateKey(HSESSIONCTX hSession, char *szKeyId, int nAlgId, DWORD dwFlags, HKEYCTX *phKey)
int AAP_API DDestroyKey(HKEYCTX *phKey, DWORD dwFlags)
int AAP_API DExportKey(HKEYCTX hKey, HKEYCTX hKEKey, DWORD dwBlobType, DWORD dwFlags, BYTE *pbData, DWORD *pdwDataLen)
int AAP_API DRemoveObj(HSESSIONCTX hSession, char *szObjId)
int AAP_API DOpenSession(HSESSIONCTX *phSession, DWORD dwParam, BYTE *pbData, DWORD dwDataLen, DWORD dwFlags)
int AAP_API DCloseSession(HSESSIONCTX *phSession, DWORD dwFlags)
int AAP_API DInitialize(DWORD dwReserved)
int AAP_API DFinalize()
Definição dinamo.h:3399
int nPort
Definição dinamo.h:3401
char szUserId[MAX_USR_LEN]
Definição dinamo.h:3402
char szAddr[MAX_ADDR_LEN]
Definição dinamo.h:3400
char szPassword[MAX_USR_PWD]
Definição dinamo.h:3403
void * pvData
Definição dinamo.h:2531
DWORD dwDataLen
Definição dinamo.h:2532
Definição dinamo.h:3740
DWORD dwTargetKeyAlg
Definição dinamo.h:3744
DWORD dwTargetKeyAttributes
Definição dinamo.h:3745
char szTargetKeyName[MAX_OBJ_ID_FQN_LEN]
Definição dinamo.h:3741
DBLOB dbPubKey
Definição dinamo.h:3746
DBLOB dbKDFData
Definição dinamo.h:3747