1 1.1 christos =pod 2 1.1 christos 3 1.1 christos =head1 NAME 4 1.1 christos 5 1.1 christos EVP_PKEY-FFC - EVP_PKEY DSA and DH/DHX shared FFC parameters. 6 1.1 christos 7 1.1 christos =head1 DESCRIPTION 8 1.1 christos 9 1.1 christos Finite field cryptography (FFC) is a method of implementing discrete logarithm 10 1.1 christos cryptography using finite field mathematics. DSA is an example of FFC and 11 1.1 christos Diffie-Hellman key establishment algorithms specified in SP800-56A can also be 12 1.1 christos implemented as FFC. 13 1.1 christos 14 1.1 christos The B<DSA>, B<DH> and B<DHX> keytypes are implemented in OpenSSL's default and 15 1.1 christos FIPS providers. 16 1.1 christos The implementations support the basic DSA, DH and DHX keys, containing the public 17 1.1 christos and private keys I<pub> and I<priv> as well as the three main domain parameters 18 1.1 christos I<p>, I<q> and I<g>. 19 1.1 christos 20 1.1 christos For B<DSA> (and B<DH> that is not a named group) the FIPS186-4 standard 21 1.1 christos specifies that the values used for FFC parameter generation are also required 22 1.1 christos for parameter validation. 23 1.1 christos This means that optional FFC domain parameter values for I<seed>, I<pcounter> 24 1.1 christos and I<gindex> may need to be stored for validation purposes. 25 1.1 christos For B<DH> the I<seed> and I<pcounter> can be stored in ASN1 data 26 1.1 christos (but the I<gindex> is not). For B<DSA> however, these fields are not stored in 27 1.1 christos the ASN1 data so they need to be stored externally if validation is required. 28 1.1 christos 29 1.1 christos The B<DH> key type uses PKCS#3 format which saves p and g, but not the 'q' value. 30 1.1 christos The B<DHX> key type uses X9.42 format which saves the value of 'q' and this 31 1.1 christos must be used for FIPS186-4. 32 1.1 christos 33 1.1 christos =head2 FFC parameters 34 1.1 christos 35 1.1 christos In addition to the common parameters that all keytypes should support (see 36 1.1 christos L<provider-keymgmt(7)/Common parameters>), the B<DSA>, B<DH> and B<DHX> keytype 37 1.1 christos implementations support the following. 38 1.1 christos 39 1.1 christos =over 4 40 1.1 christos 41 1.1 christos =item "pub" (B<OSSL_PKEY_PARAM_PUB_KEY>) <unsigned integer> 42 1.1 christos 43 1.1 christos The public key value. 44 1.1 christos 45 1.1 christos =item "priv" (B<OSSL_PKEY_PARAM_PRIV_KEY>) <unsigned integer> 46 1.1 christos 47 1.1 christos The private key value. 48 1.1 christos 49 1.1 christos =back 50 1.1 christos 51 1.1 christos =head2 FFC DSA, DH and DHX domain parameters 52 1.1 christos 53 1.1 christos =over 4 54 1.1 christos 55 1.1 christos =item "p" (B<OSSL_PKEY_PARAM_FFC_P>) <unsigned integer> 56 1.1 christos 57 1.1 christos A DSA or Diffie-Hellman prime "p" value. 58 1.1 christos 59 1.1 christos =item "g" (B<OSSL_PKEY_PARAM_FFC_G>) <unsigned integer> 60 1.1 christos 61 1.1 christos A DSA or Diffie-Hellman generator "g" value. 62 1.1 christos 63 1.1 christos =back 64 1.1 christos 65 1.1 christos =head2 FFC DSA and DHX domain parameters 66 1.1 christos 67 1.1 christos =over 4 68 1.1 christos 69 1.1 christos =item "q" (B<OSSL_PKEY_PARAM_FFC_Q>) <unsigned integer> 70 1.1 christos 71 1.1 christos A DSA or Diffie-Hellman prime "q" value. 72 1.1 christos 73 1.1 christos =item "seed" (B<OSSL_PKEY_PARAM_FFC_SEED>) <octet string> 74 1.1 christos 75 1.1 christos An optional domain parameter I<seed> value used during generation and validation 76 1.1 christos of I<p>, I<q> and canonical I<g>. 77 1.1 christos For validation this needs to set the I<seed> that was produced during generation. 78 1.1 christos 79 1.1 christos =item "gindex" (B<OSSL_PKEY_PARAM_FFC_GINDEX>) <integer> 80 1.1 christos 81 1.1 christos Sets the index to use for canonical generation and verification of the generator 82 1.1 christos I<g>. 83 1.1 christos Set this to a positive value from 0..FF to use this mode. This I<gindex> can 84 1.1 christos then be reused during key validation to verify the value of I<g>. If this value 85 1.1 christos is not set or is -1 then unverifiable generation of the generator I<g> will be 86 1.1 christos used. 87 1.1 christos 88 1.1 christos =item "pcounter" (B<OSSL_PKEY_PARAM_FFC_PCOUNTER>) <integer> 89 1.1 christos 90 1.1 christos An optional domain parameter I<counter> value that is output during generation 91 1.1 christos of I<p>. This value must be saved if domain parameter validation is required. 92 1.1 christos 93 1.1 christos =item "hindex" (B<OSSL_PKEY_PARAM_FFC_H>) <integer> 94 1.1 christos 95 1.1 christos For unverifiable generation of the generator I<g> this value is output during 96 1.1 christos generation of I<g>. Its value is the first integer larger than one that 97 1.1 christos satisfies g = h^j mod p (where g != 1 and "j" is the cofactor). 98 1.1 christos 99 1.1 christos =item "j" (B<OSSL_PKEY_PARAM_FFC_COFACTOR>) <unsigned integer> 100 1.1 christos 101 1.1 christos An optional informational cofactor parameter that should equal to (p - 1) / q. 102 1.1 christos 103 1.1 christos =item "validate-pq" (B<OSSL_PKEY_PARAM_FFC_VALIDATE_PQ>) <unsigned integer> 104 1.1 christos 105 1.1 christos =item "validate-g" (B<OSSL_PKEY_PARAM_FFC_VALIDATE_G>) <unsigned integer> 106 1.1 christos 107 1.1 christos These boolean values are used during FIPS186-4 or FIPS186-2 key validation checks 108 1.1 christos (See L<EVP_PKEY_param_check(3)>) to select validation options. By default 109 1.1 christos I<validate-pq> and I<validate-g> are both set to 1 to check that p,q and g are 110 1.1 christos valid. Either of these may be set to 0 to skip a test, which is mainly useful 111 1.1 christos for testing purposes. 112 1.1 christos 113 1.1 christos =item "validate-legacy" (B<OSSL_PKEY_PARAM_FFC_VALIDATE_LEGACY>) <unsigned integer> 114 1.1 christos 115 1.1 christos This boolean value is used during key validation checks 116 1.1 christos (See L<EVP_PKEY_param_check(3)>) to select the validation type. The default 117 1.1 christos value of 0 selects FIPS186-4 validation. Setting this value to 1 selects 118 1.1 christos FIPS186-2 validation. 119 1.1 christos 120 1.1 christos =back 121 1.1 christos 122 1.1 christos =head2 FFC key generation parameters 123 1.1 christos 124 1.1 christos The following key generation types are available for DSA and DHX algorithms: 125 1.1 christos 126 1.1 christos =over 4 127 1.1 christos 128 1.1 christos =item "type" (B<OSSL_PKEY_PARAM_FFC_TYPE>) <UTF8 string> 129 1.1 christos 130 1.1 christos Sets the type of parameter generation. The shared valid values are: 131 1.1 christos 132 1.1 christos =over 4 133 1.1 christos 134 1.1 christos =item "fips186_4" 135 1.1 christos 136 1.1 christos The current standard. 137 1.1 christos 138 1.1 christos =item "fips186_2" 139 1.1 christos 140 1.1 christos The old standard that should only be used for legacy purposes. 141 1.1 christos 142 1.1 christos =item "default" 143 1.1 christos 144 1.1 christos This can choose one of "fips186_4" or "fips186_2" depending on other 145 1.1 christos parameters set for parameter generation. 146 1.1 christos 147 1.1 christos =back 148 1.1 christos 149 1.1 christos =item "pbits" (B<OSSL_PKEY_PARAM_FFC_PBITS>) <unsigned integer> 150 1.1 christos 151 1.1 christos Sets the size (in bits) of the prime 'p'. 152 1.1 christos 153 1.1 christos =item "qbits" (B<OSSL_PKEY_PARAM_FFC_QBITS>) <unsigned integer> 154 1.1 christos 155 1.1 christos Sets the size (in bits) of the prime 'q'. 156 1.1 christos 157 1.1 christos For "fips186_4" this can be either 224 or 256. 158 1.1 christos For "fips186_2" this has a size of 160. 159 1.1 christos 160 1.1 christos =item "digest" (B<OSSL_PKEY_PARAM_FFC_DIGEST>) <UTF8 string> 161 1.1 christos 162 1.1 christos Sets the Digest algorithm to be used as part of the Key Generation Function 163 1.1 christos associated with the given Key Generation I<ctx>. 164 1.1 christos This must also be set for key validation. 165 1.1 christos 166 1.1 christos =item "properties" (B<OSSL_PKEY_PARAM_FFC_DIGEST_PROPS>) <UTF8 string> 167 1.1 christos 168 1.1 christos Sets properties to be used upon look up of the implementation for the selected 169 1.1 christos Digest algorithm for the Key Generation Function associated with the given key 170 1.1 christos generation I<ctx>. This may also be set for key validation. 171 1.1 christos 172 1.1 christos =item "seed" (B<OSSL_PKEY_PARAM_FFC_SEED>) <octet string> 173 1.1 christos 174 1.1 christos For "fips186_4" or "fips186_2" generation this sets the I<seed> data to use 175 1.1 christos instead of generating a random seed internally. This should be used for 176 1.1 christos testing purposes only. This will either produce fixed values for the generated 177 1.1 christos parameters OR it will fail if the seed did not generate valid primes. 178 1.1 christos 179 1.1 christos =item "gindex" (B<OSSL_PKEY_PARAM_FFC_GINDEX>) <integer> 180 1.1 christos 181 1.1 christos =item "pcounter" (B<OSSL_PKEY_PARAM_FFC_PCOUNTER>) <integer> 182 1.1 christos 183 1.1 christos =item "hindex" (B<OSSL_PKEY_PARAM_FFC_H>) <integer> 184 1.1 christos 185 1.1 christos These types are described above. 186 1.1 christos 187 1.1 christos =back 188 1.1 christos 189 1.1 christos =head1 CONFORMING TO 190 1.1 christos 191 1.1 christos The following sections of SP800-56Ar3: 192 1.1 christos 193 1.1 christos =over 4 194 1.1 christos 195 1.1 christos =item 5.5.1.1 FFC Domain Parameter Selection/Generation 196 1.1 christos 197 1.1 christos =back 198 1.1 christos 199 1.1 christos The following sections of FIPS186-4: 200 1.1 christos 201 1.1 christos =over 4 202 1.1 christos 203 1.1 christos =item A.1.1.2 Generation of Probable Primes p and q Using an Approved Hash Function. 204 1.1 christos 205 1.1 christos =item A.2.3 Generation of canonical generator g. 206 1.1 christos 207 1.1 christos =item A.2.1 Unverifiable Generation of the Generator g. 208 1.1 christos 209 1.1 christos =back 210 1.1 christos 211 1.1 christos =head1 SEE ALSO 212 1.1 christos 213 1.1 christos L<EVP_PKEY-DSA(7)>, 214 1.1 christos L<EVP_PKEY-DH(7)>, 215 1.1 christos L<EVP_SIGNATURE-DSA(7)>, 216 1.1.1.2 christos L<EVP_KEYEXCH-DH(7)>, 217 1.1 christos L<EVP_KEYMGMT(3)>, 218 1.1 christos L<EVP_PKEY(3)>, 219 1.1 christos L<provider-keymgmt(7)>, 220 1.1 christos L<OSSL_PROVIDER-default(7)>, 221 1.1 christos L<OSSL_PROVIDER-FIPS(7)>, 222 1.1 christos 223 1.1 christos =head1 COPYRIGHT 224 1.1 christos 225 1.1.1.2 christos Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. 226 1.1 christos 227 1.1 christos Licensed under the Apache License 2.0 (the "License"). You may not use 228 1.1 christos this file except in compliance with the License. You can obtain a copy 229 1.1 christos in the file LICENSE in the source distribution or at 230 1.1 christos L<https://www.openssl.org/source/license.html>. 231 1.1 christos 232 1.1 christos =cut 233