From 7f136a655c94f5162fba00634196aa346afa9b66 Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Wed, 9 Sep 2026 14:51:02 -0600 Subject: [PATCH 01/12] Zeroize EdDSA scalars and KDF blocks; reject non-canonical Ed448 keys ISO/IEC 19790:2012 7.9.7 and FIPS 186-5 7.7 step 1. --- wolfcrypt/src/ed25519.c | 12 ++++++++++++ wolfcrypt/src/ed448.c | 14 +++++++++++++- wolfcrypt/src/kdf.c | 4 ++++ 3 files changed, 29 insertions(+), 1 deletion(-) diff --git a/wolfcrypt/src/ed25519.c b/wolfcrypt/src/ed25519.c index 037210efaa9..a06ad891c68 100644 --- a/wolfcrypt/src/ed25519.c +++ b/wolfcrypt/src/ed25519.c @@ -418,6 +418,11 @@ int wc_ed25519_make_public(ed25519_key* key, unsigned char* pubKey, } #endif /* WOLF_CRYPTO_CB_ONLY_ED25519 */ +#ifndef WOLF_CRYPTO_CB_ONLY_ED25519 + /* az holds the clamped secret scalar (ISO/IEC 19790:2012 7.9.7). The + * crypto-callback return above happens before az is written. */ + ForceZero(az, sizeof(az)); +#endif return ret; } @@ -472,6 +477,13 @@ int wc_ed25519_make_key(WC_RNG* rng, int keySz, ed25519_key* key) if (ret == 0) { ret = ed25519_pairwise_consistency_test(key, rng); } + if (ret != 0) { + /* Do not hand back a key that failed its check or PCT. */ + key->privKeySet = 0; + key->pubKeySet = 0; + ForceZero(key->k, ED25519_PRV_KEY_SIZE); + ForceZero(key->p, ED25519_PUB_KEY_SIZE); + } #endif return ret; diff --git a/wolfcrypt/src/ed448.c b/wolfcrypt/src/ed448.c index 89fef5f51c3..fe4362d40da 100644 --- a/wolfcrypt/src/ed448.c +++ b/wolfcrypt/src/ed448.c @@ -419,6 +419,9 @@ int wc_ed448_make_public(ed448_key* key, unsigned char* pubKey, word32 pubKeySz) key->pubKeySet = 1; } + /* az holds the clamped secret scalar (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(az, sizeof(az)); + return ret; } @@ -467,6 +470,13 @@ int wc_ed448_make_key(WC_RNG* rng, int keySz, ed448_key* key) if (ret == 0) { ret = ed448_pairwise_consistency_test(key, rng); } + if (ret != 0) { + /* Do not hand back a key that failed its check or PCT. */ + key->privKeySet = 0; + key->pubKeySet = 0; + ForceZero(key->k, ED448_PRV_KEY_SIZE); + ForceZero(key->p, ED448_PUB_KEY_SIZE); + } } #endif @@ -662,7 +672,8 @@ int wc_ed448_sign_msg_ex(const byte* in, word32 inLen, byte* out, #endif } #ifndef WOLFSSL_ED448_PERSISTENT_SHA - WC_FREE_VAR_EX(sha, key->heap, DYNAMIC_TYPE_HASHES); + /* key may be NULL here and XFREE evaluates its heap argument. */ + WC_FREE_VAR_EX(sha, key ? key->heap : NULL, DYNAMIC_TYPE_HASHES); #endif if (ret == 0) { @@ -925,6 +936,7 @@ static int ed448_verify_msg_final_with_sha(const byte* sig, word32 sigLen, return BAD_FUNC_ARG; } + /* uncompress A (public key), test if valid, and negate it */ if (ge448_from_bytes_negate_vartime(&A, key->p) != 0) return BAD_FUNC_ARG; diff --git a/wolfcrypt/src/kdf.c b/wolfcrypt/src/kdf.c index 1f5df72556a..2c4d3776f2a 100644 --- a/wolfcrypt/src/kdf.c +++ b/wolfcrypt/src/kdf.c @@ -846,6 +846,8 @@ int wc_SSH_KDF(byte hashId, byte keyId, byte* key, word32 keySz, ret = _HashFinal(enmhashId, &hash, lastBlock); if (ret == 0) XMEMCPY(key, lastBlock, remainder); + /* lastBlock held derived key material (ISO/IEC 19790 7.9). */ + ForceZero(lastBlock, sizeof(lastBlock)); } } else { @@ -891,6 +893,8 @@ int wc_SSH_KDF(byte hashId, byte keyId, byte* key, word32 keySz, ret = _HashFinal(enmhashId, &hash, lastBlock); if (ret == 0) XMEMCPY(key + runningKeySz, lastBlock, remainder); + /* lastBlock held derived key material (ISO/IEC 19790 7.9). */ + ForceZero(lastBlock, sizeof(lastBlock)); } } } From 44d34065fa04177b87af0f0ed6e53a77f9bef16d Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Wed, 9 Sep 2026 15:28:31 -0600 Subject: [PATCH 02/12] Zeroize temporary SSPs in the FIPS v7 boundary wc_Sha3Free and wc_ShaFree now clear their state; also DRBG, RSA MGF1, AES KW, XMSS, LMS, SLH-DSA, ML-KEM and X25519/X448 paths. --- wolfcrypt/src/aes.c | 32 ++++++++++++++++++------------ wolfcrypt/src/curve25519.c | 6 ++++++ wolfcrypt/src/curve448.c | 3 +++ wolfcrypt/src/ecc.c | 10 ++++++++++ wolfcrypt/src/kdf.c | 2 ++ wolfcrypt/src/random.c | 4 ++++ wolfcrypt/src/rsa.c | 22 +++++++++++++++++++++ wolfcrypt/src/sha.c | 4 ++++ wolfcrypt/src/sha3.c | 14 ++++++++++--- wolfcrypt/src/wc_lms_impl.c | 10 ++++++++++ wolfcrypt/src/wc_mlkem.c | 12 ++++++++++++ wolfcrypt/src/wc_slhdsa.c | 27 +++++++++++++++++++++++++ wolfcrypt/src/wc_xmss.c | 38 ++++++++++++++++++++++++++++-------- wolfcrypt/src/wc_xmss_impl.c | 3 +++ 14 files changed, 164 insertions(+), 23 deletions(-) diff --git a/wolfcrypt/src/aes.c b/wolfcrypt/src/aes.c index 1bbaa31b974..e9674584eb3 100644 --- a/wolfcrypt/src/aes.c +++ b/wolfcrypt/src/aes.c @@ -1084,6 +1084,7 @@ static WC_INLINE void wc_Stm32_CrypAesBlock(const byte* in, byte* out) if (AES_set_encrypt_key_AESNI(userKey,bits,temp_key) == WC_NO_ERR_TRACE(BAD_FUNC_ARG)) { + ForceZero(temp_key, sizeof(Aes)); WC_FREE_VAR_EX(temp_key, aes->heap, DYNAMIC_TYPE_AES); return BAD_FUNC_ARG; } @@ -1117,6 +1118,9 @@ static WC_INLINE void wc_Stm32_CrypAesBlock(const byte* in, byte* out) Key_Schedule[0] = Temp_Key_Schedule[nr]; + /* temp_key holds the expanded key schedule + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(temp_key, sizeof(Aes)); WC_FREE_VAR_EX(temp_key, aes->heap, DYNAMIC_TYPE_AES); return 0; @@ -17718,13 +17722,14 @@ static int AesKeyWrapRaw(Aes* aes, word32 inSz, byte* out, const byte* aiv) VECTOR_REGISTERS_POP; #endif - if (ret != 0) - return ret; - - /* C[0] = A */ - XMEMCPY(out, tmp, KEYWRAP_BLOCK_SIZE); + if (ret == 0) { + /* C[0] = A */ + XMEMCPY(out, tmp, KEYWRAP_BLOCK_SIZE); + } + /* tmp holds A || P[i] on an encrypt failure (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(tmp, sizeof(tmp)); - return 0; + return ret; } int wc_AesKeyWrap_ex(Aes *aes, const byte* in, word32 inSz, byte* out, @@ -17886,13 +17891,16 @@ static int AesKeyUnWrapRaw(Aes* aes, const byte* in, word32 inSz, byte* out, VECTOR_REGISTERS_POP; #endif - if (ret != 0) - return ret; - - /* return recovered A */ - XMEMCPY(aOut, tmp, KEYWRAP_BLOCK_SIZE); + if (ret == 0) { + /* return recovered A */ + XMEMCPY(aOut, tmp, KEYWRAP_BLOCK_SIZE); + } + /* tmp ends holding the first 8 bytes of the recovered key + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(tmp, sizeof(tmp)); + ForceZero(t, sizeof(t)); - return 0; + return ret; } int wc_AesKeyUnWrap_ex(Aes *aes, const byte* in, word32 inSz, byte* out, diff --git a/wolfcrypt/src/curve25519.c b/wolfcrypt/src/curve25519.c index 93ff76d0cdd..9ba273338b1 100644 --- a/wolfcrypt/src/curve25519.c +++ b/wolfcrypt/src/curve25519.c @@ -792,6 +792,12 @@ int wc_curve25519_make_key(WC_RNG* rng, int keysize, curve25519_key* key) } #endif key->pubSet = (ret == 0); + if (ret != 0) { + /* Public half failed: drop the scalar too + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(key->k, sizeof(key->k)); + key->privSet = 0; + } } } #endif /* !WOLFSSL_SE050 */ diff --git a/wolfcrypt/src/curve448.c b/wolfcrypt/src/curve448.c index 851db3bdda3..89c912b713f 100644 --- a/wolfcrypt/src/curve448.c +++ b/wolfcrypt/src/curve448.c @@ -291,6 +291,9 @@ int wc_curve448_make_key(WC_RNG* rng, int keysize, curve448_key* key) else { ForceZero(key->k, sizeof(key->k)); XMEMSET(key->p, 0, sizeof(key->p)); + /* A zeroised SSP shall not be reusable + * (ISO/IEC 19790:2012 7.9.7 [09.29]). */ + key->privSet = 0; } } #endif /* WOLF_CRYPTO_CB_ONLY_CURVE448 */ diff --git a/wolfcrypt/src/ecc.c b/wolfcrypt/src/ecc.c index b863459fe53..4d421cc6afd 100644 --- a/wolfcrypt/src/ecc.c +++ b/wolfcrypt/src/ecc.c @@ -12502,6 +12502,16 @@ static int _ecc_import_private_key_ex(const byte* priv, word32 privSz, #endif + if (ret != 0) { + /* Rejected scalar must not stay in the key + * (ISO/IEC 19790:2012 7.9.7). */ + mp_forcezero(key->k); + #ifdef WOLFSSL_ECC_BLIND_K + mp_forcezero(key->kb); + mp_forcezero(key->ku); + #endif + } + #ifdef WOLFSSL_MAXQ10XX_CRYPTO if ((ret == 0) && (key->devId != INVALID_DEVID)) { ret = wc_MAXQ10XX_EccSetKey(key, key->dp->size); diff --git a/wolfcrypt/src/kdf.c b/wolfcrypt/src/kdf.c index 2c4d3776f2a..2c09de13225 100644 --- a/wolfcrypt/src/kdf.c +++ b/wolfcrypt/src/kdf.c @@ -900,6 +900,8 @@ int wc_SSH_KDF(byte hashId, byte keyId, byte* key, word32 keySz, } _HashFree(enmhashId, &hash); + /* hash absorbed the shared secret K (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(&hash, sizeof(hash)); return ret; } diff --git a/wolfcrypt/src/random.c b/wolfcrypt/src/random.c index 93e7802b977..fb2dfecd297 100644 --- a/wolfcrypt/src/random.c +++ b/wolfcrypt/src/random.c @@ -1529,6 +1529,8 @@ static WARN_UNUSED_RESULT int Hash_gen(DRBG_internal* drbg, byte* out, defined(WOLFSSL_CHECK_MEM_ZERO) wc_MemZero_Check(data, DRBG_SEED_LEN); #endif + /* digest holds the last output block (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(digest, WC_SHA256_DIGEST_SIZE); #ifndef WOLFSSL_SMALL_STACK_CACHE WC_FREE_VAR_EX(digest, drbg->heap, DYNAMIC_TYPE_DIGEST); @@ -2195,6 +2197,8 @@ static WARN_UNUSED_RESULT int Hash512_gen(DRBG_SHA512_internal* drbg, defined(WOLFSSL_CHECK_MEM_ZERO) wc_MemZero_Check(data, DRBG_SHA512_SEED_LEN); #endif + /* See Hash_gen. */ + ForceZero(digest, WC_SHA512_DIGEST_SIZE); #ifndef WOLFSSL_SMALL_STACK_CACHE WC_FREE_VAR_EX(digest, drbg->heap, DYNAMIC_TYPE_DIGEST); diff --git a/wolfcrypt/src/rsa.c b/wolfcrypt/src/rsa.c index 0630d057b93..59f10dd300a 100644 --- a/wolfcrypt/src/rsa.c +++ b/wolfcrypt/src/rsa.c @@ -1174,6 +1174,17 @@ static int RsaMGF1(enum wc_HashType hType, byte* seed, word32 seedSz, ret = wc_Hash(hType, tmp, (seedSz + 4), tmp, tmpSz); #endif if (ret != 0) { + /* tmp holds the OAEP seed (ISO/IEC 19790:2012 7.9.7). */ +#if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_NO_MALLOC) + if (tmpF) { + ForceZero(tmp, tmpSz); + } + else { + ForceZero(tmpA, sizeof(tmpA)); + } +#else + ForceZero(tmp, sizeof(tmp)); +#endif /* check for if dynamic memory was needed, then free */ #ifdef WOLFSSL_SMALL_STACK_CACHE wc_HashFree(hash, hType); @@ -1192,6 +1203,17 @@ static int RsaMGF1(enum wc_HashType hType, byte* seed, word32 seedSz, } counter++; } while (idx < outSz); + /* tmp holds the OAEP seed (ISO/IEC 19790:2012 7.9.7). */ +#if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_NO_MALLOC) + if (tmpF) { + ForceZero(tmp, tmpSz); + } + else { + ForceZero(tmpA, sizeof(tmpA)); + } +#else + ForceZero(tmp, sizeof(tmp)); +#endif #if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_NO_MALLOC) /* check for if dynamic memory was needed, then free */ if (tmpF) { diff --git a/wolfcrypt/src/sha.c b/wolfcrypt/src/sha.c index d65766313e5..816f0b94ca0 100644 --- a/wolfcrypt/src/sha.c +++ b/wolfcrypt/src/sha.c @@ -1182,6 +1182,10 @@ void wc_ShaFree(wc_Sha* sha) #if defined(PSOC6_HASH_SHA1) wc_Psoc6_Sha_Free(); #endif + + /* digest and buffer hold keyed material for HMAC-SHA1 and the SSH KDF + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(sha, sizeof(*sha)); } #endif /* !MAX3266X_SHA */ diff --git a/wolfcrypt/src/sha3.c b/wolfcrypt/src/sha3.c index e7db61ad48c..b87fb7478e8 100644 --- a/wolfcrypt/src/sha3.c +++ b/wolfcrypt/src/sha3.c @@ -1597,12 +1597,10 @@ static void wc_Sha3Free(wc_Sha3* sha3) int ret = 0; #endif - (void)sha3; - -#if defined(WOLF_CRYPTO_CB) && defined(WOLF_CRYPTO_CB_FREE) if (sha3 == NULL) return; +#if defined(WOLF_CRYPTO_CB) && defined(WOLF_CRYPTO_CB_FREE) #ifndef WOLF_CRYPTO_CB_FIND if (sha3->devId != INVALID_DEVID) #endif @@ -1632,6 +1630,10 @@ static void wc_Sha3Free(wc_Sha3* sha3) #if defined(PSOC6_HASH_SHA3) wc_Psoc6_Sha_Free(); #endif + + /* s and t hold absorbed keys and seeds for Ed448, ML-KEM, ML-DSA, + * SLH-DSA, LMS, XMSS and HMAC-SHA3 (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(sha3, sizeof(*sha3)); } /* Reset a SHA-3/SHAKE context to its freshly initialized state, reusing its @@ -2308,6 +2310,9 @@ int wc_Shake128_Absorb(wc_Shake* shake, const byte* data, word32 len) byte hash[1]; ret = Sha3Final(shake, 0x1f, hash, WC_SHA3_128_COUNT, 0); } + /* Sha3Final does not clear t; the absorbed seed would stay for the + * squeeze lifetime (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(shake->t, sizeof(shake->t)); /* No partial data. */ shake->i = 0; @@ -2632,6 +2637,9 @@ int wc_Shake256_Absorb(wc_Shake* shake, const byte* data, word32 len) byte hash[1]; ret = Sha3Final(shake, 0x1f, hash, WC_SHA3_256_COUNT, 0); } + /* Sha3Final does not clear t; the absorbed seed would stay for the + * squeeze lifetime (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(shake->t, sizeof(shake->t)); /* No partial data. */ shake->i = 0; diff --git a/wolfcrypt/src/wc_lms_impl.c b/wolfcrypt/src/wc_lms_impl.c index 74535332084..d0295f796f7 100644 --- a/wolfcrypt/src/wc_lms_impl.c +++ b/wolfcrypt/src/wc_lms_impl.c @@ -504,6 +504,8 @@ static WC_INLINE int wc_lms_sha256_192_hash_block(wc_Sha256* sha256, if (ret == 0) { XMEMCPY(hash, output, WC_SHA256_192_DIGEST_SIZE); } + /* Prefix is x_q[i] or a child SEED (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(output, sizeof(output)); return ret; } @@ -567,6 +569,8 @@ static WC_INLINE int wc_lms_hash_sha256_192(wc_Sha256* sha256, byte* data, } } #endif /* !WC_LMS_FULL_HASH */ + /* Prefix is x_q[i] or a child SEED (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(output, sizeof(output)); return ret; } @@ -611,6 +615,8 @@ static WC_INLINE int wc_lms_hash_sha256_192_final(wc_Sha256* sha256, byte* hash) sha256->hiLen = 0; sha256->loLen = 0; } + /* Prefix is x_q[i] or a child SEED (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(output, sizeof(output)); return ret; #else @@ -621,6 +627,8 @@ static WC_INLINE int wc_lms_hash_sha256_192_final(wc_Sha256* sha256, byte* hash) if (ret == 0) { XMEMCPY(hash, output, WC_SHA256_192_DIGEST_SIZE); } + /* Prefix is x_q[i] or a child SEED (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(output, sizeof(output)); return ret; #endif @@ -4432,6 +4440,8 @@ static int wc_hss_derive_seed_i(LmsState* state, const byte* id, /* Copy part of hash as new I into private key. */ XMEMCPY(seed_i, tmp, LMS_I_LEN); } + /* buffer held the parent SEED (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(buffer, sizeof(buffer)); return ret; } diff --git a/wolfcrypt/src/wc_mlkem.c b/wolfcrypt/src/wc_mlkem.c index 84207e24cca..e0b441261c8 100644 --- a/wolfcrypt/src/wc_mlkem.c +++ b/wolfcrypt/src/wc_mlkem.c @@ -996,6 +996,18 @@ int wc_MlKemKey_MakeKeyWithRandom(MlKemKey* key, const unsigned char* rand, key->flags |= MLKEM_FLAG_A_SET; #endif } + else if (key != NULL) { + /* Keygen failed after s and z were written; key is NULL on the + * argument-check path (ISO/IEC 19790:2012 7.9.7). */ +#ifdef WOLFSSL_MLKEM_DYNAMIC_KEYS + if (key->priv != NULL) { + ForceZero(key->priv, key->privAllocSz); + } +#else + ForceZero(key->priv, sizeof(key->priv)); +#endif + ForceZero(key->z, sizeof(key->z)); + } /* Zeroize the secret seed material in rho||sigma (sigma) before return. */ ForceZero(buf, sizeof(buf)); diff --git a/wolfcrypt/src/wc_slhdsa.c b/wolfcrypt/src/wc_slhdsa.c index b84566db954..dfed7971989 100644 --- a/wolfcrypt/src/wc_slhdsa.c +++ b/wolfcrypt/src/wc_slhdsa.c @@ -6555,6 +6555,8 @@ static int slhdsakey_hash_f_ti_x4(const byte* pk_seed, byte* addr, byte* node, slhdsakey_shake256_get_hash_x4(state, node, n); } + /* state holds four FORS secret leaves (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(state, sizeof(word64) * SLHDSA_SHAKE_X4_STATE_W); WC_FREE_VAR_EX(state, heap, DYNAMIC_TYPE_SLHDSA); } @@ -6932,6 +6934,10 @@ static int slhdsakey_fors_node_x4_z0(SlhDsaKey* key, const byte* sk_seed, ret = HASH_F(key, pk_seed, adrs, node, n, node); } + if (ret != 0) { + /* node may still hold the FORS secret leaf. */ + ForceZero(node, n); + } return ret; } @@ -7004,6 +7010,8 @@ static int slhdsakey_fors_node_x4_z1(SlhDsaKey* key, const byte* sk_seed, ret = HASH_H(key, pk_seed, adrs, nodes, n, node); } + /* nodes held two FORS secret leaves (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(nodes, sizeof(nodes)); return ret; } @@ -7137,6 +7145,10 @@ static int slhdsakey_fors_node_x4_low(SlhDsaKey* key, const byte* sk_seed, ret = HASH_H(key, pk_seed, adrs, nodes, n, node); } + /* nodes may still hold FORS secret leaves (ISO/IEC 19790:2012 7.9.7). */ + if (WC_VAR_OK(nodes)) { + ForceZero(nodes, (1 << SLHDSA_MAX_FORS_NODE_DEPTH) * SLHDSA_MAX_N); + } WC_FREE_VAR_EX(nodes, key->heap, DYNAMIC_TYPE_SLHDSA); return ret; } @@ -7371,6 +7383,10 @@ static int slhdsakey_fors_node_c(SlhDsaKey* key, const byte* sk_seed, word32 i, /* Step 5: Compute node from public key seed, address and value. */ ret = HASH_F(key, pk_seed, adrs, node, n, node); } + if (ret != 0) { + /* node may still hold the FORS secret leaf. */ + ForceZero(node, n); + } } /* Step 6: Non leaf node. */ else { @@ -7440,6 +7456,11 @@ static int slhdsakey_fors_node_c(SlhDsaKey* key, const byte* sk_seed, word32 i, } } + /* nodes may still hold FORS secret leaves + * (ISO/IEC 19790:2012 7.9.7). */ + if (WC_VAR_OK(nodes)) { + ForceZero(nodes, (SLHDSA_MAX_A + 1) * SLHDSA_MAX_N); + } WC_FREE_VAR_EX(nodes, key->heap, DYNAMIC_TYPE_SLHDSA); } @@ -7495,6 +7516,10 @@ static int slhdsakey_fors_node_c(SlhDsaKey* key, const byte* sk_seed, word32 i, /* Step 5: Compute node from public key seed, address and value. */ ret = HASH_F(key, pk_seed, adrs, node, n, node); } + if (ret != 0) { + /* node may still hold the FORS secret leaf. */ + ForceZero(node, n); + } } else { byte nodes[2 * SLHDSA_MAX_N]; @@ -7515,6 +7540,8 @@ static int slhdsakey_fors_node_c(SlhDsaKey* key, const byte* sk_seed, word32 i, /* Step 11: Compute node from public key seed, address and nodes. */ ret = HASH_H(key, pk_seed, adrs, nodes, n, node); } + /* nodes held two FORS secret leaves (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(nodes, sizeof(nodes)); } return ret; diff --git a/wolfcrypt/src/wc_xmss.c b/wolfcrypt/src/wc_xmss.c index cd12dd43efd..2ccb010cb70 100644 --- a/wolfcrypt/src/wc_xmss.c +++ b/wolfcrypt/src/wc_xmss.c @@ -794,6 +794,9 @@ static WC_INLINE int wc_xmsskey_signupdate(XmssKey* key, byte* sig, /* Free state after use. */ wc_xmss_state_free(state); } + /* State holds S_XMSS, SK_PRF and WOTS+ secrets + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(state, sizeof(XmssState)); WC_FREE_VAR_EX(state, key->heap, DYNAMIC_TYPE_TMP_BUFFER); } } @@ -1291,10 +1294,14 @@ int wc_XmssKey_MakeKey(XmssKey* key, WC_RNG* rng) if (ret != 0) { WOLFSSL_MSG("error: XMSS keygen failed"); key->state = WC_XMSS_STATE_BAD; + ForceZero(key->sk, key->sk_len); } /* Free state after use. */ wc_xmss_state_free(state); } + /* State holds S_XMSS, SK_PRF and WOTS+ secrets + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(state, sizeof(XmssState)); WC_FREE_VAR_EX(state, key->heap, DYNAMIC_TYPE_TMP_BUFFER); } } @@ -1317,6 +1324,14 @@ int wc_XmssKey_MakeKey(XmssKey* key, WC_RNG* rng) key->pubSet = 1; } + /* seed came straight from the DRBG (ISO/IEC 19790:2012 7.9.7). */ +#ifdef WOLFSSL_SMALL_STACK + if (seed != NULL) { + ForceZero(seed, 3U * key->params->n); + } +#else + ForceZero(seed, sizeof(seed)); +#endif WC_FREE_VAR_EX(seed, key->heap, DYNAMIC_TYPE_TMP_BUFFER); return ret; } @@ -1581,15 +1596,19 @@ int wc_XmssKey_SigsLeft(XmssKey* key) WOLFSSL_MSG("error: can't sign, XMSS key not in good state"); ret = 0; } - /* Read the current secret key from NV storage.*/ - else if (key->read_private_key(key->sk, key->sk_len, key->context) != - WC_XMSS_RC_READ_TO_MEMORY) { - WOLFSSL_MSG("error: XMSS read_private_key failed"); - ret = 0; - } else { - /* Ask implementation to check index in private key. */ - ret = wc_xmss_sigsleft(key->params, key->sk); + /* Read the current secret key from NV storage.*/ + if (key->read_private_key(key->sk, key->sk_len, key->context) != + WC_XMSS_RC_READ_TO_MEMORY) { + WOLFSSL_MSG("error: XMSS read_private_key failed"); + ret = 0; + } + else { + /* Ask implementation to check index in private key. */ + ret = wc_xmss_sigsleft(key->params, key->sk); + } + /* Only the index was needed (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(key->sk, key->sk_len); } return ret; @@ -2077,6 +2096,9 @@ int wc_XmssKey_Verify(XmssKey* key, const byte* sig, word32 sigLen, /* Free state after use. */ wc_xmss_state_free(state); } + /* State holds S_XMSS, SK_PRF and WOTS+ secrets + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(state, sizeof(XmssState)); WC_FREE_VAR_EX(state, key->heap, DYNAMIC_TYPE_TMP_BUFFER); } } diff --git a/wolfcrypt/src/wc_xmss_impl.c b/wolfcrypt/src/wc_xmss_impl.c index e6101974427..baee867a589 100644 --- a/wolfcrypt/src/wc_xmss_impl.c +++ b/wolfcrypt/src/wc_xmss_impl.c @@ -677,6 +677,9 @@ static WC_INLINE void wc_xmss_hash(XmssState* state, const byte* in, if (ret == 0) { XMEMCPY(out, buf, params->n); } + /* Prefix may be a WOTS+ secret element + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(buf, sizeof(buf)); } #endif else From da9d9ca23bbc9df216914b2710a8f392ad996ac6 Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Wed, 9 Sep 2026 16:18:27 -0600 Subject: [PATCH 03/12] SP: zero-free scalar copies, ECDH points and modexp buffers SP_FREE_VAR left k, priv, point, b and m in place. The generator needs the same change. --- wolfcrypt/src/sp_arm32.c | 96 +++++++++++++++----------- wolfcrypt/src/sp_arm64.c | 96 +++++++++++++++----------- wolfcrypt/src/sp_armthumb.c | 96 +++++++++++++++----------- wolfcrypt/src/sp_c32.c | 120 ++++++++++++++++---------------- wolfcrypt/src/sp_c64.c | 134 ++++++++++++++++++------------------ wolfcrypt/src/sp_cortexm.c | 96 +++++++++++++++----------- wolfcrypt/src/sp_riscv64.c | 96 +++++++++++++++----------- wolfcrypt/src/sp_x86_64.c | 96 +++++++++++++------------- 8 files changed, 455 insertions(+), 375 deletions(-) diff --git a/wolfcrypt/src/sp_arm32.c b/wolfcrypt/src/sp_arm32.c index 1b85225729a..6dc7293f2cc 100644 --- a/wolfcrypt/src/sp_arm32.c +++ b/wolfcrypt/src/sp_arm32.c @@ -18285,7 +18285,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 64, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 64 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -18482,7 +18482,9 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -19083,7 +19085,9 @@ int sp_DhExp_2048(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -19138,7 +19142,9 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, mp_clamp(res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -46343,7 +46349,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 96, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 96 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -46540,7 +46546,9 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -47333,7 +47341,9 @@ int sp_DhExp_3072(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -47388,7 +47398,9 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, mp_clamp(res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -62168,7 +62180,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 128, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 128 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -62365,7 +62377,9 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -63350,7 +63364,9 @@ int sp_DhExp_4096(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -77152,7 +77168,7 @@ int sp_ecc_mulmod_256(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -77213,7 +77229,7 @@ int sp_ecc_mulmod_add_256(const mp_int* km, const ecc_point* gm, err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8 + 8 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -78669,7 +78685,7 @@ int sp_ecc_mulmod_base_256(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -78728,7 +78744,7 @@ int sp_ecc_mulmod_base_add_256(const mp_int* km, const ecc_point* am, err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8 + 8 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -78922,7 +78938,7 @@ int sp_ecc_make_key_256(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_256_point_to_ecc_point_8(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -79081,8 +79097,8 @@ int sp_ecc_secret_gen_256(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 32; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_256, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -81936,7 +81952,7 @@ int sp_ecc_check_key_256(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 8, heap, DYNAMIC_TYPE_ECC); return err; } @@ -95472,7 +95488,7 @@ int sp_ecc_mulmod_384(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -95533,7 +95549,7 @@ int sp_ecc_mulmod_add_384(const mp_int* km, const ecc_point* gm, err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12 + 12 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -96989,7 +97005,7 @@ int sp_ecc_mulmod_base_384(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -97048,7 +97064,7 @@ int sp_ecc_mulmod_base_add_384(const mp_int* km, const ecc_point* am, err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12 + 12 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -97248,7 +97264,7 @@ int sp_ecc_make_key_384(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_384_point_to_ecc_point_12(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -97407,8 +97423,8 @@ int sp_ecc_secret_gen_384(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 48; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_384, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -100484,7 +100500,7 @@ int sp_ecc_check_key_384(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 12, heap, DYNAMIC_TYPE_ECC); return err; } @@ -122918,7 +122934,7 @@ int sp_ecc_mulmod_521(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -122979,7 +122995,7 @@ int sp_ecc_mulmod_add_521(const mp_int* km, const ecc_point* gm, err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17 + 17 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -124979,7 +124995,7 @@ int sp_ecc_mulmod_base_521(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -125038,7 +125054,7 @@ int sp_ecc_mulmod_base_add_521(const mp_int* km, const ecc_point* am, err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17 + 17 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -125248,7 +125264,7 @@ int sp_ecc_make_key_521(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_521_point_to_ecc_point_17(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -125409,8 +125425,8 @@ int sp_ecc_secret_gen_521(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 66; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_521, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -129712,7 +129728,7 @@ int sp_ecc_check_key_521(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 17, heap, DYNAMIC_TYPE_ECC); return err; } @@ -152872,7 +152888,7 @@ int sp_ecc_mulmod_1024(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_1024_point_to_ecc_point_32(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -156496,7 +156512,7 @@ int sp_ecc_mulmod_base_1024(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_1024_point_to_ecc_point_32(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -156555,7 +156571,7 @@ int sp_ecc_mulmod_base_add_1024(const mp_int* km, const ecc_point* am, err = sp_1024_point_to_ecc_point_32(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32 + 32 * 2 * 37, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -156686,7 +156702,7 @@ int sp_ecc_mulmod_table_1024(const mp_int* km, const ecc_point* gm, byte* table, } SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32, heap, DYNAMIC_TYPE_ECC); return err; } @@ -160320,7 +160336,7 @@ int sp_ecc_check_key_1024(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 32, heap, DYNAMIC_TYPE_ECC); return err; } diff --git a/wolfcrypt/src/sp_arm64.c b/wolfcrypt/src/sp_arm64.c index 4f013db6c94..9fbb9e87dc5 100644 --- a/wolfcrypt/src/sp_arm64.c +++ b/wolfcrypt/src/sp_arm64.c @@ -6996,7 +6996,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 32, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 32 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -7193,7 +7193,9 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -7586,7 +7588,9 @@ int sp_DhExp_2048(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -7641,7 +7645,9 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, mp_clamp(res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -17091,7 +17097,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 48, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 48 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -17288,7 +17294,9 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -17777,7 +17785,9 @@ int sp_DhExp_3072(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -17832,7 +17842,9 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, mp_clamp(res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -22486,7 +22498,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 64, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 64 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -22683,7 +22695,9 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -23268,7 +23282,9 @@ int sp_DhExp_4096(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -27098,7 +27114,7 @@ int sp_ecc_mulmod_256(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_256_point_to_ecc_point_4(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -27159,7 +27175,7 @@ int sp_ecc_mulmod_add_256(const mp_int* km, const ecc_point* gm, err = sp_256_point_to_ecc_point_4(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4 + 4 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -55502,7 +55518,7 @@ int sp_ecc_mulmod_base_256(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_256_point_to_ecc_point_4(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -55561,7 +55577,7 @@ int sp_ecc_mulmod_base_add_256(const mp_int* km, const ecc_point* am, err = sp_256_point_to_ecc_point_4(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4 + 4 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -55814,7 +55830,7 @@ int sp_ecc_make_key_256(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_256_point_to_ecc_point_4(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -55979,8 +55995,8 @@ int sp_ecc_secret_gen_256(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 32; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_256, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -58282,7 +58298,7 @@ int sp_ecc_check_key_256(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 4, heap, DYNAMIC_TYPE_ECC); return err; } @@ -62359,7 +62375,7 @@ int sp_ecc_mulmod_384(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_384_point_to_ecc_point_6(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -62420,7 +62436,7 @@ int sp_ecc_mulmod_add_384(const mp_int* km, const ecc_point* gm, err = sp_384_point_to_ecc_point_6(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6 + 6 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -82122,7 +82138,7 @@ int sp_ecc_mulmod_base_384(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_384_point_to_ecc_point_6(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -82181,7 +82197,7 @@ int sp_ecc_mulmod_base_add_384(const mp_int* km, const ecc_point* am, err = sp_384_point_to_ecc_point_6(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6 + 6 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -82438,7 +82454,7 @@ int sp_ecc_make_key_384(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_384_point_to_ecc_point_6(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -82603,8 +82619,8 @@ int sp_ecc_secret_gen_384(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 48; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_384, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -84197,7 +84213,7 @@ int sp_ecc_check_key_384(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 6, heap, DYNAMIC_TYPE_ECC); return err; } @@ -90666,7 +90682,7 @@ int sp_ecc_mulmod_521(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -90727,7 +90743,7 @@ int sp_ecc_mulmod_add_521(const mp_int* km, const ecc_point* gm, err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9 + 9 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -127143,7 +127159,7 @@ int sp_ecc_mulmod_base_521(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -127202,7 +127218,7 @@ int sp_ecc_mulmod_base_add_521(const mp_int* km, const ecc_point* am, err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9 + 9 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -127468,7 +127484,7 @@ int sp_ecc_make_key_521(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_521_point_to_ecc_point_9(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -127635,8 +127651,8 @@ int sp_ecc_secret_gen_521(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 66; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_521, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -129014,7 +129030,7 @@ int sp_ecc_check_key_521(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 9, heap, DYNAMIC_TYPE_ECC); return err; } @@ -134006,7 +134022,7 @@ int sp_ecc_mulmod_1024(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_1024_point_to_ecc_point_16(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -137391,7 +137407,7 @@ int sp_ecc_mulmod_base_1024(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_1024_point_to_ecc_point_16(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -137450,7 +137466,7 @@ int sp_ecc_mulmod_base_add_1024(const mp_int* km, const ecc_point* am, err = sp_1024_point_to_ecc_point_16(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16 + 16 * 2 * 37, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -137581,7 +137597,7 @@ int sp_ecc_mulmod_table_1024(const mp_int* km, const ecc_point* gm, byte* table, } SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16, heap, DYNAMIC_TYPE_ECC); return err; } @@ -141034,7 +141050,7 @@ int sp_ecc_check_key_1024(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 16, heap, DYNAMIC_TYPE_ECC); return err; } diff --git a/wolfcrypt/src/sp_armthumb.c b/wolfcrypt/src/sp_armthumb.c index 0a77bddf1c4..e94fe2ce369 100644 --- a/wolfcrypt/src/sp_armthumb.c +++ b/wolfcrypt/src/sp_armthumb.c @@ -28526,7 +28526,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 64, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 64 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -28723,7 +28723,9 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -30506,7 +30508,9 @@ int sp_DhExp_2048(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -30561,7 +30565,9 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, mp_clamp(res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -81037,7 +81043,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 96, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 96 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -81234,7 +81240,9 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -83815,7 +83823,9 @@ int sp_DhExp_3072(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -83870,7 +83880,9 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, mp_clamp(res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -93684,7 +93696,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 128, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 128 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -93881,7 +93893,9 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -97250,7 +97264,9 @@ int sp_DhExp_4096(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -102774,7 +102790,7 @@ int sp_ecc_mulmod_256(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -102835,7 +102851,7 @@ int sp_ecc_mulmod_add_256(const mp_int* km, const ecc_point* gm, err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8 + 8 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -104291,7 +104307,7 @@ int sp_ecc_mulmod_base_256(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -104350,7 +104366,7 @@ int sp_ecc_mulmod_base_add_256(const mp_int* km, const ecc_point* am, err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8 + 8 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -104592,7 +104608,7 @@ int sp_ecc_make_key_256(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_256_point_to_ecc_point_8(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -104751,8 +104767,8 @@ int sp_ecc_secret_gen_256(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 32; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_256, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -108447,7 +108463,7 @@ int sp_ecc_check_key_256(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 8, heap, DYNAMIC_TYPE_ECC); return err; } @@ -113524,7 +113540,7 @@ int sp_ecc_mulmod_384(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -113585,7 +113601,7 @@ int sp_ecc_mulmod_add_384(const mp_int* km, const ecc_point* gm, err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12 + 12 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -115041,7 +115057,7 @@ int sp_ecc_mulmod_base_384(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -115100,7 +115116,7 @@ int sp_ecc_mulmod_base_add_384(const mp_int* km, const ecc_point* am, err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12 + 12 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -115378,7 +115394,7 @@ int sp_ecc_make_key_384(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_384_point_to_ecc_point_12(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -115537,8 +115553,8 @@ int sp_ecc_secret_gen_384(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 48; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_384, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -119498,7 +119514,7 @@ int sp_ecc_check_key_384(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 12, heap, DYNAMIC_TYPE_ECC); return err; } @@ -127071,7 +127087,7 @@ int sp_ecc_mulmod_521(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -127132,7 +127148,7 @@ int sp_ecc_mulmod_add_521(const mp_int* km, const ecc_point* gm, err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17 + 17 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -129132,7 +129148,7 @@ int sp_ecc_mulmod_base_521(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -129191,7 +129207,7 @@ int sp_ecc_mulmod_base_add_521(const mp_int* km, const ecc_point* am, err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17 + 17 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -129515,7 +129531,7 @@ int sp_ecc_make_key_521(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_521_point_to_ecc_point_17(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -129676,8 +129692,8 @@ int sp_ecc_secret_gen_521(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 66; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_521, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -136349,7 +136365,7 @@ int sp_ecc_check_key_521(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 17, heap, DYNAMIC_TYPE_ECC); return err; } @@ -211520,7 +211536,7 @@ int sp_ecc_mulmod_1024(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_1024_point_to_ecc_point_32(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -215144,7 +215160,7 @@ int sp_ecc_mulmod_base_1024(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_1024_point_to_ecc_point_32(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -215203,7 +215219,7 @@ int sp_ecc_mulmod_base_add_1024(const mp_int* km, const ecc_point* am, err = sp_1024_point_to_ecc_point_32(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32 + 32 * 2 * 37, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -215334,7 +215350,7 @@ int sp_ecc_mulmod_table_1024(const mp_int* km, const ecc_point* gm, byte* table, } SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32, heap, DYNAMIC_TYPE_ECC); return err; } @@ -218968,7 +218984,7 @@ int sp_ecc_check_key_1024(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 32, heap, DYNAMIC_TYPE_ECC); return err; } diff --git a/wolfcrypt/src/sp_c32.c b/wolfcrypt/src/sp_c32.c index 570ca98a00b..871c3c102aa 100644 --- a/wolfcrypt/src/sp_c32.c +++ b/wolfcrypt/src/sp_c32.c @@ -4302,7 +4302,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 72, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 72 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -4353,7 +4353,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 72, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 72 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -4748,7 +4748,7 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 72U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 72 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -4790,7 +4790,7 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 72U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 72 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -5236,7 +5236,7 @@ int sp_DhExp_2048(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 72U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 72 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -5403,7 +5403,7 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 72U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 36 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -5446,7 +5446,7 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 72U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 36 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -8136,7 +8136,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 106, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 106 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -8187,7 +8187,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 106, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 106 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -8582,7 +8582,7 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 106U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 106 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -8624,7 +8624,7 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 106U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 106 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -8920,7 +8920,7 @@ int sp_DhExp_3072(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 106U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 106 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -9087,7 +9087,7 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 106U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 53 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -9130,7 +9130,7 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 106U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 53 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -12518,7 +12518,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 112, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 112 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -12569,7 +12569,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 112, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 112 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -12864,7 +12864,7 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 112U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 112 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -12906,7 +12906,7 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 112U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 112 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -13333,7 +13333,7 @@ int sp_DhExp_3072(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 112U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 112 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -13393,7 +13393,7 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 112U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 56 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -13436,7 +13436,7 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 112U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 56 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -16137,7 +16137,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 142, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 142 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -16188,7 +16188,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 142, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 142 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -16583,7 +16583,7 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 142U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 142 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -16625,7 +16625,7 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 142U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 142 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -16921,7 +16921,7 @@ int sp_DhExp_4096(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 142U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 142 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -20449,7 +20449,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 162, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 162 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -20500,7 +20500,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 162, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 162 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -20795,7 +20795,7 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 162U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 162 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -20837,7 +20837,7 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 162U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 162 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -21364,7 +21364,7 @@ int sp_DhExp_4096(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 162U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 162 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -24669,7 +24669,7 @@ int sp_ecc_mulmod_256(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_256_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -24730,7 +24730,7 @@ int sp_ecc_mulmod_add_256(const mp_int* km, const ecc_point* gm, err = sp_256_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9 + 9 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -26123,7 +26123,7 @@ int sp_ecc_mulmod_base_256(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_256_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -26182,7 +26182,7 @@ int sp_ecc_mulmod_base_add_256(const mp_int* km, const ecc_point* am, err = sp_256_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9 + 9 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -26336,7 +26336,7 @@ int sp_ecc_make_key_256(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_256_point_to_ecc_point_9(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -26523,8 +26523,8 @@ int sp_ecc_secret_gen_256(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 32; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_256, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -28069,7 +28069,7 @@ int sp_ecc_check_key_256(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 9, heap, DYNAMIC_TYPE_ECC); return err; } @@ -32090,7 +32090,7 @@ int sp_ecc_mulmod_384(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_384_point_to_ecc_point_15(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 15, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -32151,7 +32151,7 @@ int sp_ecc_mulmod_add_384(const mp_int* km, const ecc_point* gm, err = sp_384_point_to_ecc_point_15(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 15 + 15 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -34056,7 +34056,7 @@ int sp_ecc_mulmod_base_384(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_384_point_to_ecc_point_15(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 15, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -34115,7 +34115,7 @@ int sp_ecc_mulmod_base_add_384(const mp_int* km, const ecc_point* am, err = sp_384_point_to_ecc_point_15(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 15 + 15 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -34269,7 +34269,7 @@ int sp_ecc_make_key_384(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_384_point_to_ecc_point_15(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 15, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -34456,8 +34456,8 @@ int sp_ecc_secret_gen_384(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 48; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 15, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_384, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -36017,7 +36017,7 @@ int sp_ecc_check_key_384(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 15, heap, DYNAMIC_TYPE_ECC); return err; } @@ -39576,7 +39576,7 @@ int sp_ecc_mulmod_521(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_521_point_to_ecc_point_21(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 21, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -39637,7 +39637,7 @@ int sp_ecc_mulmod_add_521(const mp_int* km, const ecc_point* gm, err = sp_521_point_to_ecc_point_21(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 21 + 21 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -42052,7 +42052,7 @@ int sp_ecc_mulmod_base_521(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_521_point_to_ecc_point_21(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 21, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -42111,7 +42111,7 @@ int sp_ecc_mulmod_base_add_521(const mp_int* km, const ecc_point* am, err = sp_521_point_to_ecc_point_21(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 21 + 21 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -42266,7 +42266,7 @@ int sp_ecc_make_key_521(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_521_point_to_ecc_point_21(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 21, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -42453,8 +42453,8 @@ int sp_ecc_secret_gen_521(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 66; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 21, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_521, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -44074,7 +44074,7 @@ int sp_ecc_check_key_521(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 21, heap, DYNAMIC_TYPE_ECC); return err; } @@ -48067,7 +48067,7 @@ int sp_ecc_mulmod_1024(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_1024_point_to_ecc_point_42(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 42, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -52016,7 +52016,7 @@ int sp_ecc_mulmod_base_1024(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_1024_point_to_ecc_point_42(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 42, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -52075,7 +52075,7 @@ int sp_ecc_mulmod_base_add_1024(const mp_int* km, const ecc_point* am, err = sp_1024_point_to_ecc_point_42(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 42 + 42 * 2 * 37, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -52206,7 +52206,7 @@ int sp_ecc_mulmod_table_1024(const mp_int* km, const ecc_point* gm, byte* table, } SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 42, heap, DYNAMIC_TYPE_ECC); return err; } @@ -55828,7 +55828,7 @@ int sp_ecc_check_key_1024(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 42, heap, DYNAMIC_TYPE_ECC); return err; } diff --git a/wolfcrypt/src/sp_c64.c b/wolfcrypt/src/sp_c64.c index dcd7951d707..935038be9b5 100644 --- a/wolfcrypt/src/sp_c64.c +++ b/wolfcrypt/src/sp_c64.c @@ -2885,7 +2885,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 34, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 34 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -2936,7 +2936,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 34, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 34 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -3331,7 +3331,7 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 34U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 34 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -3373,7 +3373,7 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 34U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 34 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -3670,7 +3670,7 @@ int sp_DhExp_2048(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 34U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 34 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -3837,7 +3837,7 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 34U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 17 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -3880,7 +3880,7 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 34U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 17 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -6749,7 +6749,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 36, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 36 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -6800,7 +6800,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 36, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 36 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -7095,7 +7095,7 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 36U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 36 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -7137,7 +7137,7 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 36U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 36 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -7413,7 +7413,7 @@ int sp_DhExp_2048(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 36U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 36 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -7473,7 +7473,7 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 36U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 18 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -7516,7 +7516,7 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 36U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 18 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -10111,7 +10111,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 52, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 52 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -10162,7 +10162,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 52, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 52 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -10557,7 +10557,7 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 52U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 52 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -10599,7 +10599,7 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 52U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 52 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -10896,7 +10896,7 @@ int sp_DhExp_3072(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 52U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 52 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -11063,7 +11063,7 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 52U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 26 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -11106,7 +11106,7 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 52U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 26 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -14136,7 +14136,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 54, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 54 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -14187,7 +14187,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 54, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 54 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -14482,7 +14482,7 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 54U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 54 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -14524,7 +14524,7 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 54U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 54 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -14836,7 +14836,7 @@ int sp_DhExp_3072(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 54U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 54 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -14896,7 +14896,7 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 54U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 27 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -14939,7 +14939,7 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 54U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 27 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -17535,7 +17535,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 70, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 70 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -17586,7 +17586,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 70, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 70 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -17981,7 +17981,7 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 70U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 70 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -18023,7 +18023,7 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 70U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 70 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -18320,7 +18320,7 @@ int sp_DhExp_4096(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 70U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 70 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -21659,7 +21659,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 78, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 78 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -21710,7 +21710,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 78, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 78 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #endif /* WOLFSSL_SP_SMALL */ @@ -22005,7 +22005,7 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 78U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 78 * 4, NULL, DYNAMIC_TYPE_DH); return err; #else @@ -22047,7 +22047,7 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 78U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 78 * 4, NULL, DYNAMIC_TYPE_DH); return err; #endif @@ -22407,7 +22407,7 @@ int sp_DhExp_4096(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_ZEROFREE_VAR_ALT(sp_digit, b, e, 78U, NULL, DYNAMIC_TYPE_DH); + SP_ZEROFREE_VAR(sp_digit, b, 78 * 4, NULL, DYNAMIC_TYPE_DH); return err; } @@ -25459,7 +25459,7 @@ int sp_ecc_mulmod_256(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_256_point_to_ecc_point_5(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 5, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -25520,7 +25520,7 @@ int sp_ecc_mulmod_add_256(const mp_int* km, const ecc_point* gm, err = sp_256_point_to_ecc_point_5(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 5 + 5 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -26913,7 +26913,7 @@ int sp_ecc_mulmod_base_256(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_256_point_to_ecc_point_5(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 5, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -26972,7 +26972,7 @@ int sp_ecc_mulmod_base_add_256(const mp_int* km, const ecc_point* am, err = sp_256_point_to_ecc_point_5(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 5 + 5 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -27126,7 +27126,7 @@ int sp_ecc_make_key_256(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_256_point_to_ecc_point_5(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 5, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -27313,8 +27313,8 @@ int sp_ecc_secret_gen_256(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 32; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 5, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_256, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -28844,7 +28844,7 @@ int sp_ecc_check_key_256(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 5, heap, DYNAMIC_TYPE_ECC); return err; } @@ -32305,7 +32305,7 @@ int sp_ecc_mulmod_384(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_384_point_to_ecc_point_7(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 7, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -32366,7 +32366,7 @@ int sp_ecc_mulmod_add_384(const mp_int* km, const ecc_point* gm, err = sp_384_point_to_ecc_point_7(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 7 + 7 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -34269,7 +34269,7 @@ int sp_ecc_mulmod_base_384(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_384_point_to_ecc_point_7(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 7, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -34328,7 +34328,7 @@ int sp_ecc_mulmod_base_add_384(const mp_int* km, const ecc_point* am, err = sp_384_point_to_ecc_point_7(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 7 + 7 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -34482,7 +34482,7 @@ int sp_ecc_make_key_384(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_384_point_to_ecc_point_7(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 7, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -34669,8 +34669,8 @@ int sp_ecc_secret_gen_384(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 48; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 7, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_384, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -36179,7 +36179,7 @@ int sp_ecc_check_key_384(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 7, heap, DYNAMIC_TYPE_ECC); return err; } @@ -39629,7 +39629,7 @@ int sp_ecc_mulmod_521(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -39690,7 +39690,7 @@ int sp_ecc_mulmod_add_521(const mp_int* km, const ecc_point* gm, err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9 + 9 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -41593,7 +41593,7 @@ int sp_ecc_mulmod_base_521(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -41652,7 +41652,7 @@ int sp_ecc_mulmod_base_add_521(const mp_int* km, const ecc_point* am, err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9 + 9 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -41807,7 +41807,7 @@ int sp_ecc_make_key_521(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_521_point_to_ecc_point_9(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -41994,8 +41994,8 @@ int sp_ecc_secret_gen_521(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 66; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_521, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -43546,7 +43546,7 @@ int sp_ecc_check_key_521(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 9, heap, DYNAMIC_TYPE_ECC); return err; } @@ -47290,7 +47290,7 @@ int sp_ecc_mulmod_1024(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_1024_point_to_ecc_point_18(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 18, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -50725,7 +50725,7 @@ int sp_ecc_mulmod_base_1024(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_1024_point_to_ecc_point_18(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 18, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -50784,7 +50784,7 @@ int sp_ecc_mulmod_base_add_1024(const mp_int* km, const ecc_point* am, err = sp_1024_point_to_ecc_point_18(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 18 + 18 * 2 * 37, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -50915,7 +50915,7 @@ int sp_ecc_mulmod_table_1024(const mp_int* km, const ecc_point* gm, byte* table, } SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 18, heap, DYNAMIC_TYPE_ECC); return err; } @@ -54281,7 +54281,7 @@ int sp_ecc_check_key_1024(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 18, heap, DYNAMIC_TYPE_ECC); return err; } diff --git a/wolfcrypt/src/sp_cortexm.c b/wolfcrypt/src/sp_cortexm.c index 8f8ca66052a..f9342ec2eb5 100644 --- a/wolfcrypt/src/sp_cortexm.c +++ b/wolfcrypt/src/sp_cortexm.c @@ -9705,7 +9705,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 64, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 64 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -9902,7 +9902,9 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -10503,7 +10505,9 @@ int sp_DhExp_2048(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -10558,7 +10562,9 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, mp_clamp(res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -22882,7 +22888,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 96, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 96 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -23079,7 +23085,9 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -23872,7 +23880,9 @@ int sp_DhExp_3072(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -23927,7 +23937,9 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, mp_clamp(res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -31559,7 +31571,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 128, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 128 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -31756,7 +31768,9 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -32741,7 +32755,9 @@ int sp_DhExp_4096(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -39262,7 +39278,7 @@ int sp_ecc_mulmod_256(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -39323,7 +39339,7 @@ int sp_ecc_mulmod_add_256(const mp_int* km, const ecc_point* gm, err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8 + 8 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -40779,7 +40795,7 @@ int sp_ecc_mulmod_base_256(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -40838,7 +40854,7 @@ int sp_ecc_mulmod_base_add_256(const mp_int* km, const ecc_point* am, err = sp_256_point_to_ecc_point_8(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8 + 8 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -41032,7 +41048,7 @@ int sp_ecc_make_key_256(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_256_point_to_ecc_point_8(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -41191,8 +41207,8 @@ int sp_ecc_secret_gen_256(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 32; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 8, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_256, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -43440,7 +43456,7 @@ int sp_ecc_check_key_256(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 8, heap, DYNAMIC_TYPE_ECC); return err; } @@ -49650,7 +49666,7 @@ int sp_ecc_mulmod_384(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -49711,7 +49727,7 @@ int sp_ecc_mulmod_add_384(const mp_int* km, const ecc_point* gm, err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12 + 12 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -51167,7 +51183,7 @@ int sp_ecc_mulmod_base_384(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -51226,7 +51242,7 @@ int sp_ecc_mulmod_base_add_384(const mp_int* km, const ecc_point* am, err = sp_384_point_to_ecc_point_12(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12 + 12 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -51426,7 +51442,7 @@ int sp_ecc_make_key_384(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_384_point_to_ecc_point_12(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -51585,8 +51601,8 @@ int sp_ecc_secret_gen_384(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 48; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 12, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_384, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -53805,7 +53821,7 @@ int sp_ecc_check_key_384(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 12, heap, DYNAMIC_TYPE_ECC); return err; } @@ -61927,7 +61943,7 @@ int sp_ecc_mulmod_521(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -61988,7 +62004,7 @@ int sp_ecc_mulmod_add_521(const mp_int* km, const ecc_point* gm, err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17 + 17 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -63988,7 +64004,7 @@ int sp_ecc_mulmod_base_521(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -64047,7 +64063,7 @@ int sp_ecc_mulmod_base_add_521(const mp_int* km, const ecc_point* am, err = sp_521_point_to_ecc_point_17(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17 + 17 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -64257,7 +64273,7 @@ int sp_ecc_make_key_521(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_521_point_to_ecc_point_17(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -64418,8 +64434,8 @@ int sp_ecc_secret_gen_521(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 66; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 17, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_521, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -67500,7 +67516,7 @@ int sp_ecc_check_key_521(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 17, heap, DYNAMIC_TYPE_ECC); return err; } @@ -76592,7 +76608,7 @@ int sp_ecc_mulmod_1024(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_1024_point_to_ecc_point_32(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -80216,7 +80232,7 @@ int sp_ecc_mulmod_base_1024(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_1024_point_to_ecc_point_32(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -80275,7 +80291,7 @@ int sp_ecc_mulmod_base_add_1024(const mp_int* km, const ecc_point* am, err = sp_1024_point_to_ecc_point_32(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32 + 32 * 2 * 37, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -80406,7 +80422,7 @@ int sp_ecc_mulmod_table_1024(const mp_int* km, const ecc_point* gm, byte* table, } SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 32, heap, DYNAMIC_TYPE_ECC); return err; } @@ -84040,7 +84056,7 @@ int sp_ecc_check_key_1024(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 32, heap, DYNAMIC_TYPE_ECC); return err; } diff --git a/wolfcrypt/src/sp_riscv64.c b/wolfcrypt/src/sp_riscv64.c index 1f9309b0791..1045472f144 100644 --- a/wolfcrypt/src/sp_riscv64.c +++ b/wolfcrypt/src/sp_riscv64.c @@ -15895,7 +15895,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 32, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 32 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -16092,7 +16092,9 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -16518,7 +16520,9 @@ int sp_DhExp_2048(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -16573,7 +16577,9 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, mp_clamp(res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -28169,7 +28175,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 48, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 48 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -28366,7 +28372,9 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -28904,7 +28912,9 @@ int sp_DhExp_3072(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -28959,7 +28969,9 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, mp_clamp(res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -35918,7 +35930,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - SP_ZEROFREE_VAR_ALT(sp_digit, d, a, 64, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 64 * 4, NULL, DYNAMIC_TYPE_RSA); return err; #else @@ -36115,7 +36127,9 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -36765,7 +36779,9 @@ int sp_DhExp_4096(const mp_int* base, const byte* exp, word32 expLen, } - XMEMSET(e, 0, sizeof(e)); + ForceZero(e, sizeof(e)); + ForceZero(b, sizeof(b)); + ForceZero(m, sizeof(m)); return err; } @@ -41134,7 +41150,7 @@ int sp_ecc_mulmod_256(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_256_point_to_ecc_point_4(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -41195,7 +41211,7 @@ int sp_ecc_mulmod_add_256(const mp_int* km, const ecc_point* gm, err = sp_256_point_to_ecc_point_4(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4 + 4 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -42651,7 +42667,7 @@ int sp_ecc_mulmod_base_256(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_256_point_to_ecc_point_4(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -42710,7 +42726,7 @@ int sp_ecc_mulmod_base_add_256(const mp_int* km, const ecc_point* am, err = sp_256_point_to_ecc_point_4(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4 + 4 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -42908,7 +42924,7 @@ int sp_ecc_make_key_256(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_256_point_to_ecc_point_4(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -43071,8 +43087,8 @@ int sp_ecc_secret_gen_256(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 32; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_256, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -44649,7 +44665,7 @@ int sp_ecc_check_key_256(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 4, heap, DYNAMIC_TYPE_ECC); return err; } @@ -51269,7 +51285,7 @@ int sp_ecc_mulmod_384(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_384_point_to_ecc_point_6(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -51330,7 +51346,7 @@ int sp_ecc_mulmod_add_384(const mp_int* km, const ecc_point* gm, err = sp_384_point_to_ecc_point_6(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6 + 6 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -52786,7 +52802,7 @@ int sp_ecc_mulmod_base_384(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_384_point_to_ecc_point_6(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -52845,7 +52861,7 @@ int sp_ecc_mulmod_base_add_384(const mp_int* km, const ecc_point* am, err = sp_384_point_to_ecc_point_6(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6 + 6 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -53051,7 +53067,7 @@ int sp_ecc_make_key_384(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_384_point_to_ecc_point_6(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -53214,8 +53230,8 @@ int sp_ecc_secret_gen_384(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 48; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_384, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -54795,7 +54811,7 @@ int sp_ecc_check_key_384(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 6, heap, DYNAMIC_TYPE_ECC); return err; } @@ -61374,7 +61390,7 @@ int sp_ecc_mulmod_521(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -61435,7 +61451,7 @@ int sp_ecc_mulmod_add_521(const mp_int* km, const ecc_point* gm, err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9 + 9 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -63431,7 +63447,7 @@ int sp_ecc_mulmod_base_521(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -63490,7 +63506,7 @@ int sp_ecc_mulmod_base_add_521(const mp_int* km, const ecc_point* am, err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9 + 9 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -63709,7 +63725,7 @@ int sp_ecc_make_key_521(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_521_point_to_ecc_point_9(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -63874,8 +63890,8 @@ int sp_ecc_secret_gen_521(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 66; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_521, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -65207,7 +65223,7 @@ int sp_ecc_check_key_521(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 9, heap, DYNAMIC_TYPE_ECC); return err; } @@ -75757,7 +75773,7 @@ int sp_ecc_mulmod_1024(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_1024_point_to_ecc_point_16(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -79377,7 +79393,7 @@ int sp_ecc_mulmod_base_1024(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_1024_point_to_ecc_point_16(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -79436,7 +79452,7 @@ int sp_ecc_mulmod_base_add_1024(const mp_int* km, const ecc_point* am, err = sp_1024_point_to_ecc_point_16(point, r); } - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16 + 16 * 2 * 37, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -79567,7 +79583,7 @@ int sp_ecc_mulmod_table_1024(const mp_int* km, const ecc_point* gm, byte* table, } SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16, heap, DYNAMIC_TYPE_ECC); return err; } @@ -82957,7 +82973,7 @@ int sp_ecc_check_key_1024(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 16, heap, DYNAMIC_TYPE_ECC); return err; } diff --git a/wolfcrypt/src/sp_x86_64.c b/wolfcrypt/src/sp_x86_64.c index c5bb7fda462..64c8043020a 100644 --- a/wolfcrypt/src/sp_x86_64.c +++ b/wolfcrypt/src/sp_x86_64.c @@ -2288,7 +2288,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, } /* only zeroing private "d" */ - SP_ZEROFREE_VAR(sp_digit, d, 32, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 32 * 4, NULL, DYNAMIC_TYPE_RSA); return err; } @@ -2586,9 +2586,9 @@ int sp_ModExp_2048(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_FREE_VAR(m, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, m, 32, NULL, DYNAMIC_TYPE_TMP_BUFFER); SP_ZEROFREE_VAR(sp_digit, e, 32, NULL, DYNAMIC_TYPE_TMP_BUFFER); - SP_FREE_VAR(b, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, b, 64, NULL, DYNAMIC_TYPE_TMP_BUFFER); return err; } @@ -2932,9 +2932,9 @@ int sp_DhExp_2048(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_FREE_VAR(m, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, m, 32, NULL, DYNAMIC_TYPE_TMP_BUFFER); SP_ZEROFREE_VAR(sp_digit, e, 32, NULL, DYNAMIC_TYPE_TMP_BUFFER); - SP_FREE_VAR(b, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, b, 64, NULL, DYNAMIC_TYPE_TMP_BUFFER); return err; } @@ -3002,9 +3002,9 @@ int sp_ModExp_1024(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_2048_to_mp(r, res); } - SP_FREE_VAR(m, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, m, 16, NULL, DYNAMIC_TYPE_TMP_BUFFER); SP_ZEROFREE_VAR(sp_digit, e, 16, NULL, DYNAMIC_TYPE_TMP_BUFFER); - SP_FREE_VAR(b, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, b, 32, NULL, DYNAMIC_TYPE_TMP_BUFFER); return err; } @@ -5072,7 +5072,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, } /* only zeroing private "d" */ - SP_ZEROFREE_VAR(sp_digit, d, 48, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 48 * 4, NULL, DYNAMIC_TYPE_RSA); return err; } @@ -5370,9 +5370,9 @@ int sp_ModExp_3072(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_FREE_VAR(m, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, m, 48, NULL, DYNAMIC_TYPE_TMP_BUFFER); SP_ZEROFREE_VAR(sp_digit, e, 48, NULL, DYNAMIC_TYPE_TMP_BUFFER); - SP_FREE_VAR(b, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, b, 96, NULL, DYNAMIC_TYPE_TMP_BUFFER); return err; } @@ -5716,9 +5716,9 @@ int sp_DhExp_3072(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_FREE_VAR(m, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, m, 48, NULL, DYNAMIC_TYPE_TMP_BUFFER); SP_ZEROFREE_VAR(sp_digit, e, 48, NULL, DYNAMIC_TYPE_TMP_BUFFER); - SP_FREE_VAR(b, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, b, 96, NULL, DYNAMIC_TYPE_TMP_BUFFER); return err; } @@ -5786,9 +5786,9 @@ int sp_ModExp_1536(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_3072_to_mp(r, res); } - SP_FREE_VAR(m, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, m, 24, NULL, DYNAMIC_TYPE_TMP_BUFFER); SP_ZEROFREE_VAR(sp_digit, e, 24, NULL, DYNAMIC_TYPE_TMP_BUFFER); - SP_FREE_VAR(b, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, b, 48, NULL, DYNAMIC_TYPE_TMP_BUFFER); return err; } @@ -7083,7 +7083,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, } /* only zeroing private "d" */ - SP_ZEROFREE_VAR(sp_digit, d, 64, NULL, DYNAMIC_TYPE_RSA); + SP_ZEROFREE_VAR(sp_digit, d, 64 * 4, NULL, DYNAMIC_TYPE_RSA); return err; } @@ -7381,9 +7381,9 @@ int sp_ModExp_4096(const mp_int* base, const mp_int* exp, const mp_int* mod, err = sp_4096_to_mp(r, res); } - SP_FREE_VAR(m, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, m, 64, NULL, DYNAMIC_TYPE_TMP_BUFFER); SP_ZEROFREE_VAR(sp_digit, e, 64, NULL, DYNAMIC_TYPE_TMP_BUFFER); - SP_FREE_VAR(b, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, b, 128, NULL, DYNAMIC_TYPE_TMP_BUFFER); return err; } @@ -7727,9 +7727,9 @@ int sp_DhExp_4096(const mp_int* base, const byte* exp, word32 expLen, XMEMMOVE(out, out + i, *outLen); } - SP_FREE_VAR(m, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, m, 64, NULL, DYNAMIC_TYPE_TMP_BUFFER); SP_ZEROFREE_VAR(sp_digit, e, 64, NULL, DYNAMIC_TYPE_TMP_BUFFER); - SP_FREE_VAR(b, NULL, DYNAMIC_TYPE_TMP_BUFFER); + SP_ZEROFREE_VAR(sp_digit, b, 128, NULL, DYNAMIC_TYPE_TMP_BUFFER); return err; } @@ -11277,7 +11277,7 @@ int sp_ecc_mulmod_256(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_256_point_to_ecc_point_4(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -11365,7 +11365,7 @@ int sp_ecc_mulmod_add_256(const mp_int* km, const ecc_point* gm, RESTORE_VECTOR_REGISTERS(); #endif - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4 + 4 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -24049,7 +24049,7 @@ int sp_ecc_mulmod_base_256(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_256_point_to_ecc_point_4(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -24135,7 +24135,7 @@ int sp_ecc_mulmod_base_add_256(const mp_int* km, const ecc_point* am, RESTORE_VECTOR_REGISTERS(); #endif - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4 + 4 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -24312,7 +24312,7 @@ int sp_ecc_make_key_256(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_256_point_to_ecc_point_4(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -24498,8 +24498,8 @@ int sp_ecc_secret_gen_256(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 32; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 4, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_256, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -26289,7 +26289,7 @@ int sp_ecc_check_key_256(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 4, heap, DYNAMIC_TYPE_ECC); return err; } @@ -30311,7 +30311,7 @@ int sp_ecc_mulmod_384(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_384_point_to_ecc_point_6(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -30399,7 +30399,7 @@ int sp_ecc_mulmod_add_384(const mp_int* km, const ecc_point* gm, RESTORE_VECTOR_REGISTERS(); #endif - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6 + 6 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -48897,7 +48897,7 @@ int sp_ecc_mulmod_base_384(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_384_point_to_ecc_point_6(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -48983,7 +48983,7 @@ int sp_ecc_mulmod_base_add_384(const mp_int* km, const ecc_point* am, RESTORE_VECTOR_REGISTERS(); #endif - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6 + 6 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -49160,7 +49160,7 @@ int sp_ecc_make_key_384(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_384_point_to_ecc_point_6(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -49346,8 +49346,8 @@ int sp_ecc_secret_gen_384(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 48; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 6, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_384, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -51105,7 +51105,7 @@ int sp_ecc_check_key_384(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 6, heap, DYNAMIC_TYPE_ECC); return err; } @@ -55072,7 +55072,7 @@ int sp_ecc_mulmod_521(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -55160,7 +55160,7 @@ int sp_ecc_mulmod_add_521(const mp_int* km, const ecc_point* gm, RESTORE_VECTOR_REGISTERS(); #endif - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9 + 9 * 2 * 6, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -89844,7 +89844,7 @@ int sp_ecc_mulmod_base_521(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_521_point_to_ecc_point_9(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -89930,7 +89930,7 @@ int sp_ecc_mulmod_base_add_521(const mp_int* km, const ecc_point* am, RESTORE_VECTOR_REGISTERS(); #endif - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9 + 9 * 2 * 6, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -90108,7 +90108,7 @@ int sp_ecc_make_key_521(WC_RNG* rng, mp_int* priv, ecc_point* pub, void* heap) err = sp_521_point_to_ecc_point_9(point, pub); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); /* point is not sensitive, so no need to zeroize */ SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); @@ -90294,8 +90294,8 @@ int sp_ecc_secret_gen_521(const mp_int* priv, const ecc_point* pub, byte* out, *outLen = 66; } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 9, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_point_521, point, 1, heap, DYNAMIC_TYPE_ECC); return err; } @@ -92126,7 +92126,7 @@ int sp_ecc_check_key_521(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 9, heap, DYNAMIC_TYPE_ECC); return err; } @@ -96140,7 +96140,7 @@ int sp_ecc_mulmod_1024(const mp_int* km, const ecc_point* gm, ecc_point* r, err = sp_1024_point_to_ecc_point_16(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -99562,7 +99562,7 @@ int sp_ecc_mulmod_base_1024(const mp_int* km, ecc_point* r, int map, void* heap) err = sp_1024_point_to_ecc_point_16(point, r); } - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16, heap, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); return err; @@ -99648,7 +99648,7 @@ int sp_ecc_mulmod_base_add_1024(const mp_int* km, const ecc_point* am, RESTORE_VECTOR_REGISTERS(); #endif - SP_FREE_VAR(k, NULL, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16 + 16 * 2 * 37, NULL, DYNAMIC_TYPE_ECC); SP_FREE_VAR(point, NULL, DYNAMIC_TYPE_ECC); return err; @@ -99803,7 +99803,7 @@ int sp_ecc_mulmod_table_1024(const mp_int* km, const ecc_point* gm, byte* table, } SP_FREE_VAR(point, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(k, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, k, 16, heap, DYNAMIC_TYPE_ECC); return err; } @@ -104894,7 +104894,7 @@ int sp_ecc_check_key_1024(const mp_int* pX, const mp_int* pY, } SP_FREE_VAR(pub, heap, DYNAMIC_TYPE_ECC); - SP_FREE_VAR(priv, heap, DYNAMIC_TYPE_ECC); + SP_ZEROFREE_VAR(sp_digit, priv, 16, heap, DYNAMIC_TYPE_ECC); return err; } From 85019436af603211f4ba284319a72c26f9e13363 Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Wed, 9 Sep 2026 16:18:27 -0600 Subject: [PATCH 04/12] Zeroize remaining temporaries and failure paths Hash Free callback returns, GetHash copies, RSA/ECC/DH/EdDSA/PQC error paths, AES KW/XTS/GCM scratch. --- wolfcrypt/src/aes.c | 19 ++++++++++++-- wolfcrypt/src/cmac.c | 2 ++ wolfcrypt/src/curve25519.c | 13 +++++++++- wolfcrypt/src/dh.c | 20 +++++++++++++- wolfcrypt/src/ecc.c | 22 +++++++++++----- wolfcrypt/src/ed25519.c | 8 ++++++ wolfcrypt/src/ed448.c | 8 ++++++ wolfcrypt/src/hmac.c | 2 +- wolfcrypt/src/kdf.c | 3 +++ wolfcrypt/src/pwdbased.c | 3 +++ wolfcrypt/src/random.c | 3 +++ wolfcrypt/src/rsa.c | 52 ++++++++++++++++++++++++++++--------- wolfcrypt/src/sha.c | 5 +++- wolfcrypt/src/sha256.c | 21 ++++++++++++--- wolfcrypt/src/sha3.c | 7 ++++- wolfcrypt/src/sha512.c | 30 +++++++++++++++++---- wolfcrypt/src/wc_mldsa.c | 14 ++++++++++ wolfcrypt/src/wc_mlkem.c | 6 ++--- wolfcrypt/src/wc_slhdsa.c | 14 +++++++++- wolfcrypt/src/wolfentropy.c | 4 +++ 20 files changed, 217 insertions(+), 39 deletions(-) diff --git a/wolfcrypt/src/aes.c b/wolfcrypt/src/aes.c index e9674584eb3..2c1eedf3d85 100644 --- a/wolfcrypt/src/aes.c +++ b/wolfcrypt/src/aes.c @@ -9177,6 +9177,7 @@ void GHASH(Gcm* gcm, const byte* a, word32 aSz, const byte* c, /* Copy the result into s. */ XMEMCPY(s, x, sSz); + ForceZero(x, sizeof(x)); } #ifdef WOLFSSL_AESGCM_STREAM @@ -9277,6 +9278,7 @@ void GHASH(Gcm* gcm, const byte* a, word32 aSz, const byte* c, /* Copy the result into s. */ XMEMCPY(s, x, sSz); + ForceZero(x, sizeof(x)); } #ifdef WOLFSSL_AESGCM_STREAM @@ -9660,6 +9662,7 @@ void GHASH(Gcm* gcm, const byte* a, word32 aSz, const byte* c, /* Copy the result into s. */ XMEMCPY(s, x, sSz); + ForceZero(x, sizeof(x)); } #ifdef WOLFSSL_AESGCM_STREAM @@ -10162,6 +10165,7 @@ void GHASH(Gcm* gcm, const byte* a, word32 aSz, const byte* c, /* Copy the result into s. */ XMEMCPY(s, x, sSz); + ForceZero(x, sizeof(x)); } #ifdef WOLFSSL_AESGCM_STREAM @@ -10338,6 +10342,7 @@ void GHASH(Gcm* gcm, const byte* a, word32 aSz, const byte* c, ByteReverseWords64(x, x, WC_AES_BLOCK_SIZE); #endif XMEMCPY(s, x, sSz); + ForceZero(x, sizeof(x)); } #endif /* !FREESCALE_LTC_AES_GCM */ @@ -10645,6 +10650,7 @@ void GHASH(Gcm* gcm, const byte* a, word32 aSz, const byte* c, ByteReverseWords(x, x, WC_AES_BLOCK_SIZE); #endif XMEMCPY(s, x, sSz); + ForceZero(x, sizeof(x)); } #ifdef WOLFSSL_AESGCM_STREAM @@ -12808,10 +12814,13 @@ static WARN_UNUSED_RESULT int AesGcmCryptUpdate_C( IncrementGcmCounter(AES_COUNTER(aes)); /* Encrypt counter into a buffer. */ ret = wc_AesEncrypt(aes, AES_COUNTER(aes), scratch); - if (ret != 0) + if (ret != 0) { + ForceZero(scratch, sizeof(scratch)); return ret; + } /* XOR plain text into encrypted counter into cipher text buffer. */ xorbufout(out, scratch, in, WC_AES_BLOCK_SIZE); + ForceZero(scratch, sizeof(scratch)); /* Data complete. */ in += WC_AES_BLOCK_SIZE; out += WC_AES_BLOCK_SIZE; @@ -16381,8 +16390,10 @@ void wc_AesFree(Aes* aes) aes->keyInstalled = 0; /* If callback wants standard free, it can set devId to INVALID_DEVID. * Otherwise assume the callback handled cleanup. */ - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + ForceZero(aes, sizeof(Aes)); return; + } /* fall-through when unavailable */ } #endif /* WOLF_CRYPTO_CB && WOLF_CRYPTO_CB_FREE */ @@ -17944,6 +17955,7 @@ int wc_AesKeyUnWrap_ex(Aes *aes, const byte* in, word32 inSz, byte* out, ret = AesKeyUnWrapRaw(aes, in, inSz, out, a); if (ret != 0) { + ForceZero(out, inSz - KEYWRAP_BLOCK_SIZE); return ret; } @@ -18181,6 +18193,7 @@ int wc_AesKeyUnWrap_Pad_ex(Aes* aes, const byte* in, word32 inSz, byte* out, ret = AesKeyUnWrapRaw(aes, in, inSz, out, a); } if (ret != 0) { + ForceZero(out, inSz - KEYWRAP_BLOCK_SIZE); return ret; } @@ -18770,6 +18783,7 @@ static int AesXtsEncrypt_sw(XtsAes* xaes, byte* out, const byte* in, word32 sz, if (ret == 0) ret = AesXtsEncryptUpdate_sw(xaes, out, in, sz, tweak_block); WC_AES_ARM64_SVR_END(); + ForceZero(tweak_block, sizeof(tweak_block)); return ret; } @@ -19374,6 +19388,7 @@ static int AesXtsDecrypt_sw(XtsAes* xaes, byte* out, const byte* in, word32 sz, if (ret == 0) ret = AesXtsDecryptUpdate_sw(xaes, out, in, sz, tweak_block); WC_AES_ARM64_SVR_END(); + ForceZero(tweak_block, sizeof(tweak_block)); return ret; } diff --git a/wolfcrypt/src/cmac.c b/wolfcrypt/src/cmac.c index 28a8b50e824..aeafea14049 100644 --- a/wolfcrypt/src/cmac.c +++ b/wolfcrypt/src/cmac.c @@ -591,6 +591,7 @@ int wc_AesCmacGenerate(byte* out, word32* outSz, #ifdef WOLFSSL_SMALL_STACK + ForceZero(cmac, sizeof(Cmac)); XFREE(cmac, NULL, DYNAMIC_TYPE_CMAC); #elif defined(WOLFSSL_CHECK_MEM_ZERO) wc_MemZero_Check(cmac, sizeof(Cmac)); @@ -676,6 +677,7 @@ int wc_AesCmacVerify(const byte* check, word32 checkSz, INVALID_DEVID); #ifdef WOLFSSL_SMALL_STACK + ForceZero(cmac, sizeof(Cmac)); XFREE(cmac, NULL, DYNAMIC_TYPE_CMAC); #elif defined(WOLFSSL_CHECK_MEM_ZERO) wc_MemZero_Check(cmac, sizeof(Cmac)); diff --git a/wolfcrypt/src/curve25519.c b/wolfcrypt/src/curve25519.c index 9ba273338b1..bbbb57bdf19 100644 --- a/wolfcrypt/src/curve25519.c +++ b/wolfcrypt/src/curve25519.c @@ -704,6 +704,12 @@ static int wc_curve25519_make_key_nb(WC_RNG* rng, int keysize, if (ret == 0) { key->pubSet = 1; } + else if (ret != FP_WOULDBLOCK) { + /* Public half failed: drop the scalar too + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(key->k, sizeof(key->k)); + key->privSet = 0; + } } return ret; @@ -717,7 +723,7 @@ int wc_curve25519_set_nonblock(curve25519_key* key, x25519_nb_ctx_t* ctx) /* If a different context is already set, clear it before replacing. * The caller is responsible for freeing any heap-allocated context. */ if (key->nb_ctx != NULL && key->nb_ctx != ctx) { - XMEMSET(key->nb_ctx, 0, sizeof(x25519_nb_ctx_t)); + ForceZero(key->nb_ctx, sizeof(x25519_nb_ctx_t)); } if (ctx != NULL) { XMEMSET(ctx, 0, sizeof(x25519_nb_ctx_t)); @@ -1436,6 +1442,11 @@ void wc_curve25519_free(curve25519_key* key) #ifdef WOLFSSL_SE050 se050_curve25519_free_key(key); #endif +#ifdef WC_X25519_NONBLOCK + if (key->nb_ctx != NULL) { + ForceZero(key->nb_ctx, sizeof(*key->nb_ctx)); + } +#endif ForceZero(key, sizeof(*key)); diff --git a/wolfcrypt/src/dh.c b/wolfcrypt/src/dh.c index 7aa02588153..58e347b0f9a 100644 --- a/wolfcrypt/src/dh.c +++ b/wolfcrypt/src/dh.c @@ -1021,7 +1021,10 @@ int wc_DhSetNonBlock(DhKey* key, DhNb* nb) return BAD_FUNC_ARG; if (nb != NULL) { - XMEMSET(nb, 0, sizeof(DhNb)); + ForceZero(nb, sizeof(DhNb)); + } + if ((key->nb != NULL) && (key->nb != nb)) { + ForceZero(key->nb, sizeof(DhNb)); } /* Pass NULL to disable non-blocking mode. */ @@ -1049,6 +1052,11 @@ int wc_FreeDhKey(DhKey* key) #ifdef WOLFSSL_KCAPI_DH KcapiDh_Free(key); #endif + #ifdef WC_DH_NONBLOCK + if (key->nb != NULL) { + ForceZero(key->nb, sizeof(DhNb)); + } + #endif #ifdef WOLFSSL_CHECK_MEM_ZERO /* Deregister any mem-zero entries covering this key (e.g. key->priv * registered by wc_DhImportKeyPair) now that its fields are zeroed. @@ -1495,6 +1503,7 @@ static int wc_DhGenerateKeyPair_Sync(DhKey* key, WC_RNG* rng, byte* priv, word32* privSz, byte* pub, word32* pubSz) { int ret; + int privWritten; if (key == NULL || rng == NULL || priv == NULL || privSz == NULL || pub == NULL || pubSz == NULL) { @@ -1502,6 +1511,8 @@ static int wc_DhGenerateKeyPair_Sync(DhKey* key, WC_RNG* rng, } ret = GeneratePrivateDh(key, rng, priv, privSz); + /* From here *privSz is the length actually written. */ + privWritten = (ret == 0); if (ret == 0) ret = GeneratePublicDh(key, priv, *privSz, pub, pubSz); @@ -1511,6 +1522,11 @@ static int wc_DhGenerateKeyPair_Sync(DhKey* key, WC_RNG* rng, if (ret == 0) ret = _ffc_pairwise_consistency_test(key, pub, *pubSz, priv, *privSz); #endif /* FIPS V5 or later || WOLFSSL_VALIDATE_DH_KEYGEN */ + if (privWritten && (ret != 0)) { + /* A failed pair is not handed back (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(priv, *privSz); + *privSz = 0; + } return ret; } @@ -2563,6 +2579,8 @@ int wc_DhImportKeyPair(DhKey* key, const byte* priv, word32 privSz, if (priv[0] == 0) { privSz--; priv++; } + /* Never overwrite one SSP with another (ISO/IEC 19790:2012 [09.31]). */ + mp_forcezero(&key->priv); if (mp_init(&key->priv) != MP_OKAY) havePriv = 0; } diff --git a/wolfcrypt/src/ecc.c b/wolfcrypt/src/ecc.c index 4d421cc6afd..b8a53ad9ff1 100644 --- a/wolfcrypt/src/ecc.c +++ b/wolfcrypt/src/ecc.c @@ -3435,6 +3435,8 @@ static int ecc_mulmod(const mp_int* k, ecc_point* P, ecc_point* Q, err = mp_cond_swap_ct_ex(R[0]->z, R[1]->z, (int)modulus->used, (int)b, tmp); } + /* tmp holds a scalar bit (ISO/IEC 19790:2012 7.9.7). */ + mp_forcezero(tmp); #endif } @@ -7190,6 +7192,7 @@ static int deterministic_sign_helper(const byte* in, word32 inlen, ecc_key* key) if (wc_ecc_gen_deterministic_k(in, inlen, key->hashType, ecc_get_k(key), key->sign_k, curve->order, key->heap) != 0) { + mp_forcezero(key->sign_k); mp_free(key->sign_k); XFREE(key->sign_k, key->heap, DYNAMIC_TYPE_ECC); key->sign_k = NULL; @@ -7208,6 +7211,7 @@ static int deterministic_sign_helper(const byte* in, word32 inlen, ecc_key* key) key->sign_k_set = 0; if (wc_ecc_gen_deterministic_k(in, inlen, key->hashType, ecc_get_k(key), key->sign_k, curve->order, key->heap) != 0) { + mp_forcezero(key->sign_k); err = ECC_PRIV_KEY_E; } else { @@ -7457,12 +7461,10 @@ static int ecc_sign_hash_sw(ecc_key* key, ecc_key* pubkey, WC_RNG* rng, } #endif -#ifdef WOLFSSL_HAVE_SP_ECC #if defined(WOLFSSL_ECDSA_SET_K) || defined(WOLFSSL_ECDSA_SET_K_ONE_LOOP) || \ defined(WOLFSSL_ECDSA_DETERMINISTIC_K) || \ defined(WOLFSSL_ECDSA_DETERMINISTIC_K_VARIANT) -/* SP only resets the logical length of k, leaving its digits in the backing - * store. Clear it the way the software path does. */ +/* The nonce is consumed by every sign result; SP only resets its length. */ static void ecc_sign_k_forcezero(ecc_key* key) { #ifndef WOLFSSL_NO_MALLOC @@ -7473,14 +7475,13 @@ static void ecc_sign_k_forcezero(ecc_key* key) key->sign_k = NULL; } #else - if (key->sign_k_set) { - mp_forcezero(key->sign_k); - key->sign_k_set = 0; - } + mp_forcezero(key->sign_k); + key->sign_k_set = 0; #endif } #endif +#ifdef WOLFSSL_HAVE_SP_ECC static int ecc_sign_hash_sp(const byte* in, word32 inlen, WC_RNG* rng, ecc_key* key, mp_int *r, mp_int *s) { @@ -7887,6 +7888,12 @@ int wc_ecc_sign_hash_ex(const byte* in, word32 inlen, WC_RNG* rng, } } } +#if defined(WOLFSSL_ECDSA_SET_K) || defined(WOLFSSL_ECDSA_SET_K_ONE_LOOP) || \ + defined(WOLFSSL_ECDSA_DETERMINISTIC_K) || \ + defined(WOLFSSL_ECDSA_DETERMINISTIC_K_VARIANT) + /* The nonce is consumed whatever the result. */ + ecc_sign_k_forcezero(key); +#endif mp_clear(e); wc_ecc_curve_free(curve); @@ -8283,6 +8290,7 @@ int wc_ecc_sign_set_k(const byte* k, word32 klen, ecc_key* key) } if (ret == 0 && mp_cmp(key->sign_k, curve->order) != MP_LT) { ret = MP_VAL; + ecc_sign_k_forcezero(key); } #ifdef WOLFSSL_NO_MALLOC if (ret == 0) { diff --git a/wolfcrypt/src/ed25519.c b/wolfcrypt/src/ed25519.c index a06ad891c68..9d72826f05e 100644 --- a/wolfcrypt/src/ed25519.c +++ b/wolfcrypt/src/ed25519.c @@ -1773,10 +1773,18 @@ int wc_ed25519_export_key(const ed25519_key* key, int ret; /* export 'full' private part */ + /* Check the public arguments before anything is written to priv. */ + if ((pub == NULL) || (pubSz == NULL)) { + return BAD_FUNC_ARG; + } ret = wc_ed25519_export_private(key, priv, privSz); if (ret == 0) { /* export public part */ ret = wc_ed25519_export_public(key, pub, pubSz); + if (ret != 0) { + /* Public export failed: do not hand back the private key. */ + ForceZero(priv, *privSz); + } } return ret; diff --git a/wolfcrypt/src/ed448.c b/wolfcrypt/src/ed448.c index fe4362d40da..d6eb1b34027 100644 --- a/wolfcrypt/src/ed448.c +++ b/wolfcrypt/src/ed448.c @@ -1600,10 +1600,18 @@ int wc_ed448_export_key(const ed448_key* key, byte* priv, word32 *privSz, int ret = 0; /* export 'full' private part */ + /* Check the public arguments before anything is written to priv. */ + if ((pub == NULL) || (pubSz == NULL)) { + return BAD_FUNC_ARG; + } ret = wc_ed448_export_private(key, priv, privSz); if (ret == 0) { /* export public part */ ret = wc_ed448_export_public(key, pub, pubSz); + if (ret != 0) { + /* Public export failed: do not hand back the private key. */ + ForceZero(priv, *privSz); + } } return ret; diff --git a/wolfcrypt/src/hmac.c b/wolfcrypt/src/hmac.c index ddcc550bea5..f9749a7becd 100644 --- a/wolfcrypt/src/hmac.c +++ b/wolfcrypt/src/hmac.c @@ -1756,7 +1756,7 @@ void wc_HmacFree(Hmac* hmac) byte finalHash[WC_HMAC_BLOCK_SIZE]; ret = wc_CryptoCb_Hmac(hmac, hmac->macType, NULL, 0, finalHash); (void)ret; /* must ignore return code here */ - (void)finalHash; + ForceZero(finalHash, sizeof(finalHash)); } #endif diff --git a/wolfcrypt/src/kdf.c b/wolfcrypt/src/kdf.c index 2c09de13225..14548d633a4 100644 --- a/wolfcrypt/src/kdf.c +++ b/wolfcrypt/src/kdf.c @@ -282,6 +282,7 @@ int wc_PRF_TLSv1(byte* digest, word32 digLen, const byte* secret, } } + ForceZero(sha_result, MAX_PRF_DIG); #if defined(WOLFSSL_CHECK_MEM_ZERO) wc_MemZero_Check(sha_result, MAX_PRF_DIG); #endif @@ -1590,6 +1591,7 @@ int wc_KDA_KDF_twostep_cmac(const byte * salt, word32 salt_len, #ifdef WOLFSSL_SMALL_STACK if (cmac) { + ForceZero(cmac, sizeof(Cmac)); XFREE(cmac, heap, DYNAMIC_TYPE_CMAC); cmac = NULL; } @@ -1763,6 +1765,7 @@ int wc_KDA_KDF_PRF_cmac(const byte* Kin, word32 KinSz, #ifdef WOLFSSL_SMALL_STACK if (cmac) { + ForceZero(cmac, sizeof(Cmac)); XFREE(cmac, heap, DYNAMIC_TYPE_CMAC); cmac = NULL; } diff --git a/wolfcrypt/src/pwdbased.c b/wolfcrypt/src/pwdbased.c index 1c2c4acbc42..f4b22424217 100644 --- a/wolfcrypt/src/pwdbased.c +++ b/wolfcrypt/src/pwdbased.c @@ -590,6 +590,7 @@ int wc_PKCS12_PBKDF_ex(byte* output, const byte* passwd, int passLen, byte tmp[WC_MAX_BLOCK_SIZE + 1]; ret = mp_to_unsigned_bin(res, tmp); XMEMCPY(I + i, tmp + 1, v); + ForceZero(tmp, sizeof(tmp)); } else if (outSz < (int)v) { XMEMSET(I + i, 0, v - (word32)outSz); @@ -895,6 +896,7 @@ static void scryptSalsa(word32* out, word32* in) for (i = 0; i < 16; i++) out[i] = ByteReverseWord32(ByteReverseWord32(in[i]) + x[i]); #endif + ForceZero(x, sizeof(x)); } /* Mix a block using Salsa20/8. @@ -948,6 +950,7 @@ static void scryptBlockMix(byte* b, byte* y, int r) } #endif } + ForceZero(x, sizeof(x)); } /* Random oracles mix. diff --git a/wolfcrypt/src/random.c b/wolfcrypt/src/random.c index fb2dfecd297..133ab3042ca 100644 --- a/wolfcrypt/src/random.c +++ b/wolfcrypt/src/random.c @@ -2671,6 +2671,7 @@ int wc_RNG_TestSeed(const byte* seed, word32 seedSz) /* Accumulate failure flag - once set, stays set */ rctFailed |= (repCount >= WC_RNG_SEED_RCT_CUTOFF); } + ForceZero(&prevByte, sizeof(prevByte)); } /* SP800-90B 4.4.2 - Adaptive Proportion Test (APT) @@ -2728,6 +2729,8 @@ int wc_RNG_TestSeed(const byte* seed, word32 seedSz) WC_RNG_SEED_APT_CUTOFF); } + /* Histogram of the live seed (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(byteCounts, MAX_ENTROPY_BITS * sizeof(word16)); #if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_SMALL_STACK_CACHE) XFREE(byteCounts, NULL, DYNAMIC_TYPE_TMP_BUFFER); #endif diff --git a/wolfcrypt/src/rsa.c b/wolfcrypt/src/rsa.c index 59f10dd300a..00267d90831 100644 --- a/wolfcrypt/src/rsa.c +++ b/wolfcrypt/src/rsa.c @@ -647,6 +647,20 @@ int wc_RsaGetKeyId(RsaKey* key, word32* keyId) } #endif /* WOLFSSL_SE050 */ +#ifndef WOLFSSL_RSA_PUBLIC_ONLY +static void RsaForceZeroPriv(RsaKey* key) +{ +#if defined(WOLFSSL_KEY_GEN) || defined(OPENSSL_EXTRA) || !defined(RSA_LOW_MEM) + mp_forcezero(&key->u); + mp_forcezero(&key->dQ); + mp_forcezero(&key->dP); +#endif + mp_forcezero(&key->q); + mp_forcezero(&key->p); + mp_forcezero(&key->d); +} +#endif + int wc_FreeRsaKey(RsaKey* key) { int ret = 0; @@ -664,8 +678,13 @@ int wc_FreeRsaKey(RsaKey* key) WC_PK_TYPE_RSA, 0, key); /* If callback wants standard free, it returns CRYPTOCB_UNAVAILABLE. * Otherwise assume the callback handled cleanup. */ - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + wc_RsaCleanup(key); + #ifndef WOLFSSL_RSA_PUBLIC_ONLY + RsaForceZeroPriv(key); + #endif return ret; + } /* fall-through to software cleanup */ ret = 0; } @@ -682,17 +701,8 @@ int wc_FreeRsaKey(RsaKey* key) #endif #ifndef WOLFSSL_RSA_PUBLIC_ONLY - /* Forcezero all private key fields that are present in this build - * configuration, since they may contain residual sensitive data even when - * key->type is not RSA_PRIVATE (e.g., after a partial key decode failure). */ -#if defined(WOLFSSL_KEY_GEN) || defined(OPENSSL_EXTRA) || !defined(RSA_LOW_MEM) - mp_forcezero(&key->u); - mp_forcezero(&key->dQ); - mp_forcezero(&key->dP); -#endif - mp_forcezero(&key->q); - mp_forcezero(&key->p); - mp_forcezero(&key->d); + /* Private fields may hold residue even when type is not RSA_PRIVATE. */ + RsaForceZeroPriv(key); #endif /* WOLFSSL_RSA_PUBLIC_ONLY */ /* public part */ @@ -1507,12 +1517,14 @@ static int RsaPad_OAEP(const byte* input, word32 inputLen, byte* pkcsBlock, } #else if (pkcsBlockLen - hLen - 1 > sizeof(dbMask)) { + ForceZero(seed, hLen); return MEMORY_E; } #endif XMEMSET(dbMask, 0, pkcsBlockLen - hLen - 1); /* help static analyzer */ ret = RsaMGF(mgf, seed, hLen, dbMask, pkcsBlockLen - hLen - 1, heap); if (ret != 0) { + ForceZero(dbMask, pkcsBlockLen - hLen - 1); WC_FREE_VAR_EX(dbMask, heap, DYNAMIC_TYPE_RSA); WC_FREE_VAR_EX(lHash, heap, DYNAMIC_TYPE_RSA_BUFFER); ForceZero(seed, hLen); @@ -1522,6 +1534,8 @@ static int RsaPad_OAEP(const byte* input, word32 inputLen, byte* pkcsBlock, xorbuf(pkcsBlock + hLen + 1, dbMask,pkcsBlockLen - hLen - 1); + /* dbMask is derived from the seed (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(dbMask, pkcsBlockLen - hLen - 1); WC_FREE_VAR_EX(dbMask, heap, DYNAMIC_TYPE_RSA); /* create maskedSeed from seedMask */ @@ -3997,6 +4011,10 @@ static int RsaPublicEncryptEx(const byte* in, word32 inLen, byte* out, hash, mgf, label, labelSz, saltLen, mp_count_bits(&key->n), key->heap); if (ret < 0) { + if (rsa_type == RSA_PUBLIC_ENCRYPT) { + /* Padding failed with the secret already copied in. */ + ForceZero(out, (word32)sz); + } break; } @@ -4013,6 +4031,16 @@ static int RsaPublicEncryptEx(const byte* in, word32 inLen, byte* out, key->state = RSA_STATE_ENCRYPT_RES; } if (ret < 0) { + /* out holds the padded secret (ISO/IEC 19790:2012 7.9.7); a + * pending or would-block result still needs it. */ + if ((rsa_type == RSA_PUBLIC_ENCRYPT) && + (ret != WC_NO_ERR_TRACE(WC_PENDING_E)) + #ifdef WC_RSA_NONBLOCK + && (ret != FP_WOULDBLOCK) + #endif + ) { + ForceZero(out, (word32)sz); + } break; } diff --git a/wolfcrypt/src/sha.c b/wolfcrypt/src/sha.c index 816f0b94ca0..8be5f859e39 100644 --- a/wolfcrypt/src/sha.c +++ b/wolfcrypt/src/sha.c @@ -850,6 +850,7 @@ int wc_ShaFinalRaw(wc_Sha* sha, byte* hash) ByteReverseWords((word32*)digest, (word32*)sha->digest, WC_SHA_DIGEST_SIZE); } XMEMCPY(hash, (byte *)&digest[0], WC_SHA_DIGEST_SIZE); + ForceZero(digest, sizeof(digest)); #else XMEMCPY(hash, sha->digest, WC_SHA_DIGEST_SIZE); #endif @@ -1135,8 +1136,10 @@ void wc_ShaFree(wc_Sha* sha) /* If they want the standard free, they can call it themselves */ /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + ForceZero(sha, sizeof(*sha)); return; + } /* fall-through when unavailable */ } diff --git a/wolfcrypt/src/sha256.c b/wolfcrypt/src/sha256.c index b2f198491fe..f3b2f262082 100644 --- a/wolfcrypt/src/sha256.c +++ b/wolfcrypt/src/sha256.c @@ -2346,6 +2346,7 @@ static WC_INLINE int Transform_Sha256_Len(wc_Sha256* sha256, const byte* data, WC_SHA256_DIGEST_SIZE); } XMEMCPY(hash, digest, WC_SHA256_DIGEST_SIZE); + ForceZero(digest, sizeof(digest)); #else XMEMCPY(hash, sha256->digest, WC_SHA256_DIGEST_SIZE); #endif @@ -2424,13 +2425,16 @@ static WC_INLINE int Transform_Sha256_Len(wc_Sha256* sha256, const byte* data, #endif { byte buffer[WC_SHA256_BLOCK_SIZE]; + int tret; ByteReverseWords((word32*)buffer, (word32*)data, WC_SHA256_BLOCK_SIZE); #ifdef __aarch64__ - return Transform_Sha256_aarch64(sha256, buffer); + tret = Transform_Sha256_aarch64(sha256, buffer); #else - return Transform_Sha256(sha256, buffer); + tret = Transform_Sha256(sha256, buffer); #endif + ForceZero(buffer, sizeof(buffer)); + return tret; } #else return Transform_Sha256(sha256, data); @@ -3071,8 +3075,10 @@ int wc_Sha224Reset(wc_Sha224* sha224) { /* If they want the standard free, they can call it themselves */ /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + ForceZero(sha224, sizeof(*sha224)); return; + } /* fall-through when unavailable */ } @@ -3148,8 +3154,10 @@ void wc_Sha256Free(wc_Sha256* sha256) /* If they want the standard free, they can call it themselves */ /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + ForceZero(sha256, sizeof(*sha256)); return; + } /* fall-through when unavailable */ } @@ -3360,6 +3368,8 @@ int wc_Sha224Reset(wc_Sha224* sha224) { wc_Sha224Free(tmpSha224); } + ForceZero(tmpSha224, sizeof(*tmpSha224)); + WC_FREE_VAR_EX(tmpSha224, NULL, DYNAMIC_TYPE_TMP_BUFFER); return ret; } @@ -3509,6 +3519,9 @@ int wc_Sha256GetHash(wc_Sha256* sha256, byte* hash) } + ForceZero(tmpSha256, sizeof(*tmpSha256)); + + WC_FREE_VAR_EX(tmpSha256, NULL, DYNAMIC_TYPE_TMP_BUFFER); return ret; diff --git a/wolfcrypt/src/sha3.c b/wolfcrypt/src/sha3.c index b87fb7478e8..7c0fe925a0d 100644 --- a/wolfcrypt/src/sha3.c +++ b/wolfcrypt/src/sha3.c @@ -1610,8 +1610,11 @@ static void wc_Sha3Free(wc_Sha3* sha3) /* If they want the standard free, they can call it themselves */ /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + ForceZero(sha3->s, sizeof(sha3->s)); + ForceZero(sha3->t, sizeof(sha3->t)); return; + } /* fall-through when unavailable */ } @@ -1763,6 +1766,8 @@ static int wc_Sha3GetHash(wc_Sha3* sha3, byte* hash, word32 p, word32 len) ret = wc_Sha3Final(tmpSha3, hash, p, len); } + ForceZero(tmpSha3, sizeof(*tmpSha3)); + WC_FREE_VAR_EX(tmpSha3, sha3->heap, DYNAMIC_TYPE_TMP_BUFFER); return ret; } diff --git a/wolfcrypt/src/sha512.c b/wolfcrypt/src/sha512.c index 12b884eea04..4faae6187ff 100644 --- a/wolfcrypt/src/sha512.c +++ b/wolfcrypt/src/sha512.c @@ -507,8 +507,10 @@ void wc_Sha512Free(wc_Sha512* sha512) /* If they want the standard free, they can call it themselves */ /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + ForceZero(sha512, sizeof(*sha512)); return; + } /* fall-through when unavailable */ } @@ -536,6 +538,8 @@ int wc_Sha512GetHash(wc_Sha512* sha512, byte* hash) wc_Sha512Free(tmpSha512); } + ForceZero(tmpSha512, sizeof(*tmpSha512)); + WC_FREE_VAR_EX(tmpSha512, NULL, DYNAMIC_TYPE_TMP_BUFFER); return ret; @@ -649,6 +653,8 @@ int wc_Sha512_224GetHash(wc_Sha512* sha512, byte* hash) wc_Sha512_224Free(tmpSha512); } + ForceZero(tmpSha512, sizeof(*tmpSha512)); + WC_FREE_VAR_EX(tmpSha512, NULL, DYNAMIC_TYPE_TMP_BUFFER); return ret; @@ -729,6 +735,8 @@ int wc_Sha512_256GetHash(wc_Sha512* sha512, byte* hash) wc_Sha512_256Free(tmpSha512); } + ForceZero(tmpSha512, sizeof(*tmpSha512)); + WC_FREE_VAR_EX(tmpSha512, NULL, DYNAMIC_TYPE_TMP_BUFFER); return ret; @@ -829,8 +837,10 @@ void wc_Sha384Free(wc_Sha384* sha384) /* If they want the standard free, they can call it themselves */ /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + ForceZero(sha384, sizeof(*sha384)); return; + } /* fall-through when unavailable */ } @@ -858,6 +868,8 @@ int wc_Sha384GetHash(wc_Sha384* sha384, byte* hash) wc_Sha384Free(tmpSha384); } + ForceZero(tmpSha384, sizeof(*tmpSha384)); + WC_FREE_VAR_EX(tmpSha384, NULL, DYNAMIC_TYPE_TMP_BUFFER); return ret; @@ -2683,8 +2695,10 @@ void wc_Sha512Free(wc_Sha512* sha512) /* If they want the standard free, they can call it themselves */ /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + ForceZero(sha512, sizeof(*sha512)); return; + } /* fall-through when unavailable */ } @@ -2793,8 +2807,8 @@ int wc_Sha512Transform(wc_Sha512* sha, const unsigned char* data) XMEMCPY(sha->buffer, buffer, WC_SHA512_BLOCK_SIZE); #endif -#if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_SMALL_STACK_CACHE) ForceZero(buffer, WC_SHA512_BLOCK_SIZE); +#if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_SMALL_STACK_CACHE) XFREE(buffer, sha->heap, DYNAMIC_TYPE_TMP_BUFFER); #endif return ret; @@ -3180,8 +3194,10 @@ void wc_Sha384Free(wc_Sha384* sha384) /* If they want the standard free, they can call it themselves */ /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + ForceZero(sha384, sizeof(*sha384)); return; + } /* fall-through when unavailable */ } @@ -3272,6 +3288,8 @@ static int Sha512_Family_GetHash(wc_Sha512* sha512, byte* hash, wc_Sha512Free(tmpSha512); } + ForceZero(tmpSha512, sizeof(*tmpSha512)); + WC_FREE_VAR_EX(tmpSha512, NULL, DYNAMIC_TYPE_TMP_BUFFER); return ret; @@ -3718,6 +3736,8 @@ int wc_Sha384GetHash(wc_Sha384* sha384, byte* hash) wc_Sha384Free(tmpSha384); } + ForceZero(tmpSha384, sizeof(*tmpSha384)); + WC_FREE_VAR_EX(tmpSha384, NULL, DYNAMIC_TYPE_TMP_BUFFER); return ret; diff --git a/wolfcrypt/src/wc_mldsa.c b/wolfcrypt/src/wc_mldsa.c index 8fade7cfb5f..890dcf3955c 100644 --- a/wolfcrypt/src/wc_mldsa.c +++ b/wolfcrypt/src/wc_mldsa.c @@ -9630,6 +9630,10 @@ static int mldsa_sign_with_seed_mu(wc_MlDsaKey* key, } /* Step 11: Check we have a valid signature. */ while ((ret == 0) && (!valid)); + if (ret != 0) { + /* sig holds a rejected candidate (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(sig, params->sigSz); + } } if (ret == 0) { byte* ze = sig + params->lambda / 4; @@ -10211,6 +10215,10 @@ static int mldsa_sign_with_seed_mu(wc_MlDsaKey* key, } /* Step 11: Check we have a valid signature. */ while ((ret == 0) && (!valid)); + if (ret != 0) { + /* sig holds a rejected candidate (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(sig, params->sigSz); + } } ForceZero(priv_rand_seed, sizeof(priv_rand_seed)); @@ -12350,6 +12358,12 @@ int wc_MlDsaKey_SetParams(wc_MlDsaKey* key, byte level) } #endif +#if !defined(WOLFSSL_MLDSA_DYNAMIC_KEYS) && \ + !defined(WOLFSSL_MLDSA_ASSIGN_KEY) && !defined(WOLFSSL_MLDSA_VERIFY_ONLY) + if (key->prvKeySet) { + ForceZero(key->k, sizeof(key->k)); + } +#endif /* Store level and indicate public and private key are not set. */ key->level = level % WC_ML_DSA_DRAFT; key->pubKeySet = 0; diff --git a/wolfcrypt/src/wc_mlkem.c b/wolfcrypt/src/wc_mlkem.c index e0b441261c8..22bb2716522 100644 --- a/wolfcrypt/src/wc_mlkem.c +++ b/wolfcrypt/src/wc_mlkem.c @@ -996,9 +996,9 @@ int wc_MlKemKey_MakeKeyWithRandom(MlKemKey* key, const unsigned char* rand, key->flags |= MLKEM_FLAG_A_SET; #endif } - else if (key != NULL) { - /* Keygen failed after s and z were written; key is NULL on the - * argument-check path (ISO/IEC 19790:2012 7.9.7). */ + else if ((key != NULL) && (k != 0)) { + /* Keygen failed after s and z were written; k is 0 until the + * argument checks passed (ISO/IEC 19790:2012 7.9.7). */ #ifdef WOLFSSL_MLKEM_DYNAMIC_KEYS if (key->priv != NULL) { ForceZero(key->priv, key->privAllocSz); diff --git a/wolfcrypt/src/wc_slhdsa.c b/wolfcrypt/src/wc_slhdsa.c index dfed7971989..c0f62c83c03 100644 --- a/wolfcrypt/src/wc_slhdsa.c +++ b/wolfcrypt/src/wc_slhdsa.c @@ -9042,11 +9042,17 @@ int wc_SlhDsaKey_MakeKeyWithRandom(SlhDsaKey* key, const byte* sk_seed, { /* The seeds are now staged in the key as the contiguous * SK.seed || SK.prf || PK.seed the callback expects. */ + key->flags &= (word16)~WC_SLHDSA_FLAG_BOTH_KEYS; ret = wc_CryptoCb_MakePqcSignatureKeyEx(NULL, WC_PQC_SIG_TYPE_SLHDSA, (int)key->params->param, key->sk, 3U * key->params->n, key); - if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) + if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + if ((key->flags & WC_SLHDSA_FLAG_PRIVATE) == 0) { + /* Device owns the key (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(key->sk, 2U * key->params->n); + } return ret; + } /* fall-through when unavailable */ ret = 0; } @@ -9154,6 +9160,7 @@ static int slhdsakey_sign(SlhDsaKey* key, byte* md, byte* sig) word32 l; byte pk_fors[SLHDSA_MAX_N]; byte n = key->params->n; + byte* sigFors = sig; /* Steps 1, 7-13: Set address based on message digest. */ slhdsakey_set_ha_from_md(key, md, adrs, t, &l); @@ -9172,6 +9179,11 @@ static int slhdsakey_sign(SlhDsaKey* key, byte* md, byte* sig) ret = slhdsakey_ht_sign(key, pk_fors, key->sk, key->sk + 2 * n, t, l, sig); } + if (ret != 0) { + /* Unreleased FORS secrets may be in sig + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(sigFors, key->params->k * (1 + key->params->a) * n); + } return ret; } diff --git a/wolfcrypt/src/wolfentropy.c b/wolfcrypt/src/wolfentropy.c index 3932d652247..f05a362bdc0 100644 --- a/wolfcrypt/src/wolfentropy.c +++ b/wolfcrypt/src/wolfentropy.c @@ -836,6 +836,7 @@ static int Entropy_Condition(byte* output, word32 len, byte* noise, if (ret == 0) { XMEMCPY(output, hash, len); } + ForceZero(hash, sizeof(hash)); } } @@ -945,6 +946,9 @@ int wc_Entropy_Get(int bits, unsigned char* entropy, word32 len) #endif if (ret != WC_NO_ERR_TRACE(BAD_MUTEX_E)) { + /* Raw samples were conditioned into the seed + * (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(noise, sizeof(noise)); /* Unlock mutex now we are done. */ wc_UnLockMutex(&entropy_mutex); } From ddfb90ccc03a43e7406fc74a953bf1249182c50a Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Thu, 10 Sep 2026 08:09:08 -0600 Subject: [PATCH 05/12] SHA Free: release msg and W before the callback-path wipe --- wolfcrypt/src/sha.c | 8 ++++++++ wolfcrypt/src/sha256.c | 32 ++++++++++++++++++++++++++++++++ wolfcrypt/src/sha512.c | 32 ++++++++++++++++++++++++++++++++ 3 files changed, 72 insertions(+) diff --git a/wolfcrypt/src/sha.c b/wolfcrypt/src/sha.c index 8be5f859e39..720a4b7f11f 100644 --- a/wolfcrypt/src/sha.c +++ b/wolfcrypt/src/sha.c @@ -1137,6 +1137,14 @@ void wc_ShaFree(wc_Sha* sha) /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + /* Release heap state first; the wipe drops its pointers. */ + #ifdef WOLFSSL_HASH_KEEP + if (sha->msg != NULL) { + ForceZero(sha->msg, sha->len); + XFREE(sha->msg, sha->heap, DYNAMIC_TYPE_TMP_BUFFER); + sha->msg = NULL; + } + #endif ForceZero(sha, sizeof(*sha)); return; } diff --git a/wolfcrypt/src/sha256.c b/wolfcrypt/src/sha256.c index f3b2f262082..33d8a791c26 100644 --- a/wolfcrypt/src/sha256.c +++ b/wolfcrypt/src/sha256.c @@ -3076,6 +3076,22 @@ int wc_Sha224Reset(wc_Sha224* sha224) { /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + /* Release heap state first; the wipe drops its pointers. */ + #ifdef WOLFSSL_SMALL_STACK_CACHE + if (sha224->W != NULL) { + ForceZero(sha224->W, + sizeof(word32) * WC_SHA224_BLOCK_SIZE); + XFREE(sha224->W, sha224->heap, DYNAMIC_TYPE_DIGEST); + sha224->W = NULL; + } + #endif + #ifdef WOLFSSL_HASH_KEEP + if (sha224->msg != NULL) { + ForceZero(sha224->msg, sha224->len); + XFREE(sha224->msg, sha224->heap, DYNAMIC_TYPE_TMP_BUFFER); + sha224->msg = NULL; + } + #endif ForceZero(sha224, sizeof(*sha224)); return; } @@ -3155,6 +3171,22 @@ void wc_Sha256Free(wc_Sha256* sha256) /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + /* Release heap state first; the wipe drops its pointers. */ + #ifdef WOLFSSL_SMALL_STACK_CACHE + if (sha256->W != NULL) { + ForceZero(sha256->W, + sizeof(word32) * WC_SHA256_BLOCK_SIZE); + XFREE(sha256->W, sha256->heap, DYNAMIC_TYPE_DIGEST); + sha256->W = NULL; + } + #endif + #ifdef WOLFSSL_HASH_KEEP + if (sha256->msg != NULL) { + ForceZero(sha256->msg, sha256->len); + XFREE(sha256->msg, sha256->heap, DYNAMIC_TYPE_TMP_BUFFER); + sha256->msg = NULL; + } + #endif ForceZero(sha256, sizeof(*sha256)); return; } diff --git a/wolfcrypt/src/sha512.c b/wolfcrypt/src/sha512.c index 4faae6187ff..d3cfa8698c6 100644 --- a/wolfcrypt/src/sha512.c +++ b/wolfcrypt/src/sha512.c @@ -2696,6 +2696,22 @@ void wc_Sha512Free(wc_Sha512* sha512) /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + /* Release heap state first; the wipe drops its pointers. */ + #ifdef WOLFSSL_SMALL_STACK_CACHE + if (sha512->W != NULL) { + ForceZero(sha512->W, + (sizeof(word64) * 16) + WC_SHA512_BLOCK_SIZE); + XFREE(sha512->W, sha512->heap, DYNAMIC_TYPE_DIGEST); + sha512->W = NULL; + } + #endif + #ifdef WOLFSSL_HASH_KEEP + if (sha512->msg != NULL) { + ForceZero(sha512->msg, sha512->len); + XFREE(sha512->msg, sha512->heap, DYNAMIC_TYPE_TMP_BUFFER); + sha512->msg = NULL; + } + #endif ForceZero(sha512, sizeof(*sha512)); return; } @@ -3195,6 +3211,22 @@ void wc_Sha384Free(wc_Sha384* sha384) /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + /* Release heap state first; the wipe drops its pointers. */ + #ifdef WOLFSSL_SMALL_STACK_CACHE + if (sha384->W != NULL) { + ForceZero(sha384->W, + (sizeof(word64) * 16) + WC_SHA512_BLOCK_SIZE); + XFREE(sha384->W, sha384->heap, DYNAMIC_TYPE_DIGEST); + sha384->W = NULL; + } + #endif + #ifdef WOLFSSL_HASH_KEEP + if (sha384->msg != NULL) { + ForceZero(sha384->msg, sha384->len); + XFREE(sha384->msg, sha384->heap, DYNAMIC_TYPE_TMP_BUFFER); + sha384->msg = NULL; + } + #endif ForceZero(sha384, sizeof(*sha384)); return; } From c6fed2e36673636e03fed3454f0317435cefd62b Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Thu, 10 Sep 2026 16:11:41 -0600 Subject: [PATCH 06/12] Address review: keep destructors off caller-owned contexts, fix entropy include wc_curve25519_free and wc_FreeDhKey no longer wipe the non-blocking context (TLS frees it first); wolfentropy.c pulls in misc.c; GCM scratch wiped once per call; KW wipe only after out is written; wc_AesFree releases streamData before the wipe; test_digest.h freed src instead of dst. --- tests/api/test_digest.h | 4 ++-- wolfcrypt/src/aes.c | 19 +++++++++++++++---- wolfcrypt/src/curve25519.c | 6 ------ wolfcrypt/src/dh.c | 5 ----- wolfcrypt/src/sha3.c | 3 +-- wolfcrypt/src/sp_x86_64.c | 6 +++--- wolfcrypt/src/wc_slhdsa.c | 2 +- wolfcrypt/src/wc_xmss.c | 3 +-- wolfcrypt/src/wolfentropy.c | 6 ++++++ 9 files changed, 29 insertions(+), 25 deletions(-) diff --git a/tests/api/test_digest.h b/tests/api/test_digest.h index 78ce499dd80..db458652422 100644 --- a/tests/api/test_digest.h +++ b/tests/api/test_digest.h @@ -574,7 +574,7 @@ do { \ ExpectIntEQ(wc_##name##_Final(&dst, hashDst, WC_##upper##_COUNT * 8), 0); \ ExpectBufEQ(hashSrc, emptyHash, WC_##upper##_COUNT * 8); \ ExpectBufEQ(hashDst, emptyHash, WC_##upper##_COUNT * 8); \ - wc_##name##_Free(&src); \ + wc_##name##_Free(&dst); \ \ /* Test buffered data is copied. */ \ ExpectIntEQ(wc_##name##_Update(&src, (byte*)"abc", 3), 0); \ @@ -583,7 +583,7 @@ do { \ ExpectIntEQ(wc_##name##_Final(&dst, hashDst, WC_##upper##_COUNT * 8), 0); \ ExpectBufEQ(hashSrc, abcHash, WC_##upper##_COUNT * 8); \ ExpectBufEQ(hashDst, abcHash, WC_##upper##_COUNT * 8); \ - wc_##name##_Free(&src); \ + wc_##name##_Free(&dst); \ \ /* Test count of length is copied. */ \ ExpectIntEQ(wc_##name##_Update(&src, data, sizeof(data)), 0); \ diff --git a/wolfcrypt/src/aes.c b/wolfcrypt/src/aes.c index 2c1eedf3d85..004b4f36751 100644 --- a/wolfcrypt/src/aes.c +++ b/wolfcrypt/src/aes.c @@ -12808,9 +12808,9 @@ static WARN_UNUSED_RESULT int AesGcmCryptUpdate_C( else #endif /* HAVE_AES_ECB */ { + ALIGN32 byte scratch[WC_AES_BLOCK_SIZE]; /* Encrypt block by block. */ while (blocks--) { - ALIGN32 byte scratch[WC_AES_BLOCK_SIZE]; IncrementGcmCounter(AES_COUNTER(aes)); /* Encrypt counter into a buffer. */ ret = wc_AesEncrypt(aes, AES_COUNTER(aes), scratch); @@ -12820,11 +12820,11 @@ static WARN_UNUSED_RESULT int AesGcmCryptUpdate_C( } /* XOR plain text into encrypted counter into cipher text buffer. */ xorbufout(out, scratch, in, WC_AES_BLOCK_SIZE); - ForceZero(scratch, sizeof(scratch)); /* Data complete. */ in += WC_AES_BLOCK_SIZE; out += WC_AES_BLOCK_SIZE; } + ForceZero(scratch, sizeof(scratch)); } if (partial != 0) { @@ -16391,6 +16391,15 @@ void wc_AesFree(Aes* aes) /* If callback wants standard free, it can set devId to INVALID_DEVID. * Otherwise assume the callback handled cleanup. */ if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { + /* Release heap state first; the wipe drops its pointers. */ + #if defined(WOLFSSL_AESGCM_STREAM) && defined(WOLFSSL_SMALL_STACK) && \ + !defined(WOLFSSL_AESNI) + if (aes->streamData != NULL) { + ForceZero(aes->streamData, aes->streamData_sz); + XFREE(aes->streamData, aes->heap, DYNAMIC_TYPE_AES); + aes->streamData = NULL; + } + #endif ForceZero(aes, sizeof(Aes)); return; } @@ -17906,6 +17915,10 @@ static int AesKeyUnWrapRaw(Aes* aes, const byte* in, word32 inSz, byte* out, /* return recovered A */ XMEMCPY(aOut, tmp, KEYWRAP_BLOCK_SIZE); } + else { + /* Partially recovered plaintext (ISO/IEC 19790:2012 7.9.7). */ + ForceZero(out, inSz - KEYWRAP_BLOCK_SIZE); + } /* tmp ends holding the first 8 bytes of the recovered key * (ISO/IEC 19790:2012 7.9.7). */ ForceZero(tmp, sizeof(tmp)); @@ -17955,7 +17968,6 @@ int wc_AesKeyUnWrap_ex(Aes *aes, const byte* in, word32 inSz, byte* out, ret = AesKeyUnWrapRaw(aes, in, inSz, out, a); if (ret != 0) { - ForceZero(out, inSz - KEYWRAP_BLOCK_SIZE); return ret; } @@ -18193,7 +18205,6 @@ int wc_AesKeyUnWrap_Pad_ex(Aes* aes, const byte* in, word32 inSz, byte* out, ret = AesKeyUnWrapRaw(aes, in, inSz, out, a); } if (ret != 0) { - ForceZero(out, inSz - KEYWRAP_BLOCK_SIZE); return ret; } diff --git a/wolfcrypt/src/curve25519.c b/wolfcrypt/src/curve25519.c index bbbb57bdf19..301836d9b07 100644 --- a/wolfcrypt/src/curve25519.c +++ b/wolfcrypt/src/curve25519.c @@ -1442,12 +1442,6 @@ void wc_curve25519_free(curve25519_key* key) #ifdef WOLFSSL_SE050 se050_curve25519_free_key(key); #endif -#ifdef WC_X25519_NONBLOCK - if (key->nb_ctx != NULL) { - ForceZero(key->nb_ctx, sizeof(*key->nb_ctx)); - } -#endif - ForceZero(key, sizeof(*key)); #ifdef WOLFSSL_CHECK_MEM_ZERO diff --git a/wolfcrypt/src/dh.c b/wolfcrypt/src/dh.c index 58e347b0f9a..dce11a6c6a2 100644 --- a/wolfcrypt/src/dh.c +++ b/wolfcrypt/src/dh.c @@ -1052,11 +1052,6 @@ int wc_FreeDhKey(DhKey* key) #ifdef WOLFSSL_KCAPI_DH KcapiDh_Free(key); #endif - #ifdef WC_DH_NONBLOCK - if (key->nb != NULL) { - ForceZero(key->nb, sizeof(DhNb)); - } - #endif #ifdef WOLFSSL_CHECK_MEM_ZERO /* Deregister any mem-zero entries covering this key (e.g. key->priv * registered by wc_DhImportKeyPair) now that its fields are zeroed. diff --git a/wolfcrypt/src/sha3.c b/wolfcrypt/src/sha3.c index 7c0fe925a0d..586199a185f 100644 --- a/wolfcrypt/src/sha3.c +++ b/wolfcrypt/src/sha3.c @@ -1611,8 +1611,7 @@ static void wc_Sha3Free(wc_Sha3* sha3) /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { - ForceZero(sha3->s, sizeof(sha3->s)); - ForceZero(sha3->t, sizeof(sha3->t)); + ForceZero(sha3, sizeof(*sha3)); return; } /* fall-through when unavailable */ diff --git a/wolfcrypt/src/sp_x86_64.c b/wolfcrypt/src/sp_x86_64.c index 64c8043020a..47525ea6964 100644 --- a/wolfcrypt/src/sp_x86_64.c +++ b/wolfcrypt/src/sp_x86_64.c @@ -2287,7 +2287,7 @@ int sp_RsaPrivate_2048(const byte* in, word32 inLen, const mp_int* dm, *outLen = 256; } - /* only zeroing private "d" */ + /* zero the whole work buffer: d, a/r and m */ SP_ZEROFREE_VAR(sp_digit, d, 32 * 4, NULL, DYNAMIC_TYPE_RSA); return err; @@ -5071,7 +5071,7 @@ int sp_RsaPrivate_3072(const byte* in, word32 inLen, const mp_int* dm, *outLen = 384; } - /* only zeroing private "d" */ + /* zero the whole work buffer: d, a/r and m */ SP_ZEROFREE_VAR(sp_digit, d, 48 * 4, NULL, DYNAMIC_TYPE_RSA); return err; @@ -7082,7 +7082,7 @@ int sp_RsaPrivate_4096(const byte* in, word32 inLen, const mp_int* dm, *outLen = 512; } - /* only zeroing private "d" */ + /* zero the whole work buffer: d, a/r and m */ SP_ZEROFREE_VAR(sp_digit, d, 64 * 4, NULL, DYNAMIC_TYPE_RSA); return err; diff --git a/wolfcrypt/src/wc_slhdsa.c b/wolfcrypt/src/wc_slhdsa.c index c0f62c83c03..bbb83cebda0 100644 --- a/wolfcrypt/src/wc_slhdsa.c +++ b/wolfcrypt/src/wc_slhdsa.c @@ -9042,7 +9042,7 @@ int wc_SlhDsaKey_MakeKeyWithRandom(SlhDsaKey* key, const byte* sk_seed, { /* The seeds are now staged in the key as the contiguous * SK.seed || SK.prf || PK.seed the callback expects. */ - key->flags &= (word16)~WC_SLHDSA_FLAG_BOTH_KEYS; + key->flags &= ~((int)WC_SLHDSA_FLAG_BOTH_KEYS); ret = wc_CryptoCb_MakePqcSignatureKeyEx(NULL, WC_PQC_SIG_TYPE_SLHDSA, (int)key->params->param, key->sk, 3U * key->params->n, key); diff --git a/wolfcrypt/src/wc_xmss.c b/wolfcrypt/src/wc_xmss.c index 2ccb010cb70..3da8d4fb598 100644 --- a/wolfcrypt/src/wc_xmss.c +++ b/wolfcrypt/src/wc_xmss.c @@ -2096,8 +2096,7 @@ int wc_XmssKey_Verify(XmssKey* key, const byte* sig, word32 sigLen, /* Free state after use. */ wc_xmss_state_free(state); } - /* State holds S_XMSS, SK_PRF and WOTS+ secrets - * (ISO/IEC 19790:2012 7.9.7). */ + /* Scratch state; no SSPs on the verify path. */ ForceZero(state, sizeof(XmssState)); WC_FREE_VAR_EX(state, key->heap, DYNAMIC_TYPE_TMP_BUFFER); } diff --git a/wolfcrypt/src/wolfentropy.c b/wolfcrypt/src/wolfentropy.c index f05a362bdc0..6f1c1590d30 100644 --- a/wolfcrypt/src/wolfentropy.c +++ b/wolfcrypt/src/wolfentropy.c @@ -46,6 +46,12 @@ data, use this implementation to seed and re-seed the DRBG. #endif #include +#ifdef NO_INLINE + #include +#else + #define WOLFSSL_MISC_INCLUDED + #include +#endif #if defined(__APPLE__) || defined(__MACH__) #include #endif From b90b5b2462737c56c98c77f9859155110d99788a Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Thu, 10 Sep 2026 17:04:03 -0600 Subject: [PATCH 07/12] Use ForceZero where XMEMSET wiped sensitive data XMEMSET is a dead store the compiler may drop. Covers HMAC and SHA-2 Copy failure paths, X25519/ECC nonblocking contexts, ECC keyRaw, and CCM plaintext on tag mismatch. --- wolfcrypt/src/aes.c | 4 ++-- wolfcrypt/src/curve25519.c | 2 +- wolfcrypt/src/ecc.c | 4 ++-- wolfcrypt/src/hmac.c | 2 +- wolfcrypt/src/sha256.c | 4 ++-- wolfcrypt/src/sha512.c | 4 ++-- 6 files changed, 10 insertions(+), 10 deletions(-) diff --git a/wolfcrypt/src/aes.c b/wolfcrypt/src/aes.c index 004b4f36751..2f47ec02529 100644 --- a/wolfcrypt/src/aes.c +++ b/wolfcrypt/src/aes.c @@ -15582,7 +15582,7 @@ int wc_AesCcmDecrypt(Aes* aes, byte* out, const byte* in, word32 inSz, wolfSSL_CryptHwMutexUnLock(); if (status != kStatus_Success) { - XMEMSET(out, 0, inSz); + ForceZero(out, inSz); return AES_CCM_AUTH_E; } return 0; @@ -16075,7 +16075,7 @@ int wc_AesCcmDecrypt(Aes* aes, byte* out, const byte* in, word32 inSz, WOLFSSL_MSG("Preserve output for vector responses"); #else if (inSz > 0) - XMEMSET(out, 0, inSz); + ForceZero(out, inSz); #endif ret = AES_CCM_AUTH_E; } diff --git a/wolfcrypt/src/curve25519.c b/wolfcrypt/src/curve25519.c index 301836d9b07..3683d166d60 100644 --- a/wolfcrypt/src/curve25519.c +++ b/wolfcrypt/src/curve25519.c @@ -879,7 +879,7 @@ static int wc_curve25519_shared_secret_nb(curve25519_key* privKey, } if (ret != FP_WOULDBLOCK) { - XMEMSET(privKey->nb_ctx, 0, sizeof(x25519_nb_ctx_t)); + ForceZero(privKey->nb_ctx, sizeof(x25519_nb_ctx_t)); } return ret; diff --git a/wolfcrypt/src/ecc.c b/wolfcrypt/src/ecc.c index b8a53ad9ff1..922d656a7f7 100644 --- a/wolfcrypt/src/ecc.c +++ b/wolfcrypt/src/ecc.c @@ -6105,7 +6105,7 @@ static int _ecc_make_key_ex(WC_RNG* rng, int keysize, ecc_key* key, err = mp_set(key->pubkey.z, 1); if (err) { key->privKey = NULL; - XMEMSET(key->keyRaw, 0, sizeof(key->keyRaw)); + ForceZero(key->keyRaw, sizeof(key->keyRaw)); return err; } @@ -17560,7 +17560,7 @@ int wc_ecc_set_nonblock(ecc_key *key, ecc_nb_ctx_t* ctx) /* If a different context is already set, clear it before replacing. * The caller is responsible for freeing any heap-allocated context. */ if (key->nb_ctx != NULL && key->nb_ctx != ctx) { - XMEMSET(key->nb_ctx, 0, sizeof(ecc_nb_ctx_t)); + ForceZero(key->nb_ctx, sizeof(ecc_nb_ctx_t)); } if (ctx != NULL) { XMEMSET(ctx, 0, sizeof(ecc_nb_ctx_t)); diff --git a/wolfcrypt/src/hmac.c b/wolfcrypt/src/hmac.c index f9749a7becd..3e56667fdd3 100644 --- a/wolfcrypt/src/hmac.c +++ b/wolfcrypt/src/hmac.c @@ -536,7 +536,7 @@ int wc_HmacCopy(Hmac* src, Hmac* dst) { if (hashes_copied >= 3) HmacKeyFreeHash(src->macType, &dst->o_hash); #endif - XMEMSET(dst, 0, sizeof(*dst)); + ForceZero(dst, sizeof(*dst)); } return ret; } diff --git a/wolfcrypt/src/sha256.c b/wolfcrypt/src/sha256.c index 33d8a791c26..e66f322162d 100644 --- a/wolfcrypt/src/sha256.c +++ b/wolfcrypt/src/sha256.c @@ -3438,7 +3438,7 @@ int wc_Sha224Reset(wc_Sha224* sha224) { dst->W = (word32*)XMALLOC(sizeof(word32) * WC_SHA256_BLOCK_SIZE, dst->heap, DYNAMIC_TYPE_DIGEST); if (dst->W == NULL) { - XMEMSET(dst, 0, sizeof(wc_Sha224)); + ForceZero(dst, sizeof(wc_Sha224)); return MEMORY_E; } #endif @@ -3595,7 +3595,7 @@ int wc_Sha256Copy(wc_Sha256* src, wc_Sha256* dst) dst->W = (word32*)XMALLOC(sizeof(word32) * WC_SHA256_BLOCK_SIZE, dst->heap, DYNAMIC_TYPE_DIGEST); if (dst->W == NULL) { - XMEMSET(dst, 0, sizeof(wc_Sha256)); + ForceZero(dst, sizeof(wc_Sha256)); return MEMORY_E; } #endif diff --git a/wolfcrypt/src/sha512.c b/wolfcrypt/src/sha512.c index d3cfa8698c6..a49ee40d370 100644 --- a/wolfcrypt/src/sha512.c +++ b/wolfcrypt/src/sha512.c @@ -3367,7 +3367,7 @@ int wc_Sha512Copy(wc_Sha512* src, wc_Sha512* dst) dst->W = (word64 *)XMALLOC((sizeof(word64) * 16) + WC_SHA512_BLOCK_SIZE, dst->heap, DYNAMIC_TYPE_DIGEST); if (dst->W == NULL) { - XMEMSET(dst, 0, sizeof(wc_Sha512)); + ForceZero(dst, sizeof(wc_Sha512)); return MEMORY_E; } #endif @@ -3811,7 +3811,7 @@ int wc_Sha384Copy(wc_Sha384* src, wc_Sha384* dst) dst->W = (word64 *)XMALLOC((sizeof(word64) * 16) + WC_SHA384_BLOCK_SIZE, dst->heap, DYNAMIC_TYPE_DIGEST); if (dst->W == NULL) { - XMEMSET(dst, 0, sizeof(wc_Sha384)); + ForceZero(dst, sizeof(wc_Sha384)); return MEMORY_E; } #endif From 02d237fb79e43ab9814675007ee740435344e2a0 Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Thu, 10 Sep 2026 18:05:45 -0600 Subject: [PATCH 08/12] NoiseSrc: ForceZero the health-test state on free --- wolfcrypt/src/random.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/wolfcrypt/src/random.c b/wolfcrypt/src/random.c index 133ab3042ca..9b4b709aee8 100644 --- a/wolfcrypt/src/random.c +++ b/wolfcrypt/src/random.c @@ -7671,7 +7671,7 @@ void wc_NoiseSrc_Free(wc_NoiseSrc* src) if (src->work != NULL && src->workSz > 0) { ForceZero(src->work, src->workSz); } - XMEMSET(src->health, 0, sizeof(src->health)); + ForceZero(src->health, sizeof(src->health)); src->chunkCtr = 0; src->failed = 0; src->degraded = 0; From 85d7ad3db3ac508ef548c4d0d49b4f09d358b337 Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Tue, 15 Sep 2026 15:07:08 -0400 Subject: [PATCH 09/12] SHA-3 Free: wipe state only; RSA even-mod test expects the wiped buffer Whole-object wipe nulled the per-object block function under WC_C_DYNAMIC_FALLBACK, which SLH-DSA reuses after HASH_T_FREE. --- wolfcrypt/src/sha3.c | 18 ++++++++++++++++-- wolfcrypt/test/test.c | 8 ++++++++ 2 files changed, 24 insertions(+), 2 deletions(-) diff --git a/wolfcrypt/src/sha3.c b/wolfcrypt/src/sha3.c index 586199a185f..36022e32e5f 100644 --- a/wolfcrypt/src/sha3.c +++ b/wolfcrypt/src/sha3.c @@ -1591,6 +1591,20 @@ static int wc_Sha3Final(wc_Sha3* sha3, byte* hash, word32 p, word32 len) * sha3 wc_Sha3 object holding state. * returns 0 on success. */ +/* Wipe the SSP-bearing state but keep the object usable: SLH-DSA reuses it + * after Free and the block function pointers live in it under + * WC_C_DYNAMIC_FALLBACK. */ +static void wc_Sha3Wipe(wc_Sha3* sha3) +{ +#ifdef PSOC6_HASH_SHA3 + ForceZero(sha3, sizeof(*sha3)); +#else + ForceZero(sha3->s, sizeof(sha3->s)); + ForceZero(sha3->t, sizeof(sha3->t)); + sha3->i = 0; +#endif +} + static void wc_Sha3Free(wc_Sha3* sha3) { #if defined(WOLF_CRYPTO_CB) && defined(WOLF_CRYPTO_CB_FREE) @@ -1611,7 +1625,7 @@ static void wc_Sha3Free(wc_Sha3* sha3) /* via their callback setting devId to INVALID_DEVID */ /* otherwise assume the callback handled it */ if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) { - ForceZero(sha3, sizeof(*sha3)); + wc_Sha3Wipe(sha3); return; } /* fall-through when unavailable */ @@ -1635,7 +1649,7 @@ static void wc_Sha3Free(wc_Sha3* sha3) /* s and t hold absorbed keys and seeds for Ed448, ML-KEM, ML-DSA, * SLH-DSA, LMS, XMSS and HMAC-SHA3 (ISO/IEC 19790:2012 7.9.7). */ - ForceZero(sha3, sizeof(*sha3)); + wc_Sha3Wipe(sha3); } /* Reset a SHA-3/SHAKE context to its freshly initialized state, reusing its diff --git a/wolfcrypt/test/test.c b/wolfcrypt/test/test.c index c248b5cbf18..d9b9024de52 100644 --- a/wolfcrypt/test/test.c +++ b/wolfcrypt/test/test.c @@ -36461,6 +36461,14 @@ static wc_test_ret_t rsa_even_mod_test(WC_RNG* rng, RsaKey* key) { ERROR_OUT(WC_TEST_RET_ENC_EC(ret), exit_rsa_even_mod); } + /* The failed encrypt wipes out; check that, then give the decrypt an + * in-range value so it still reaches the even modulus private op. */ + for (idx = 0; idx < outSz; idx++) { + if (out[idx] != 0) { + ERROR_OUT(WC_TEST_RET_ENC_NC, exit_rsa_even_mod); + } + } + XMEMSET(out, 0x01, outSz); #endif /* WOLFSSL_RSA_VERIFY_ONLY */ #ifndef WOLFSSL_RSA_PUBLIC_ONLY From 70f400579ca5f99e5fc1be919529496110e52335 Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Tue, 22 Sep 2026 11:26:08 -0600 Subject: [PATCH 10/12] RSA even-mod test: only expect the wiped buffer from FIPS v7 or non-FIPS builds --- wolfcrypt/test/test.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/wolfcrypt/test/test.c b/wolfcrypt/test/test.c index d9b9024de52..8893cf2a233 100644 --- a/wolfcrypt/test/test.c +++ b/wolfcrypt/test/test.c @@ -36461,14 +36461,16 @@ static wc_test_ret_t rsa_even_mod_test(WC_RNG* rng, RsaKey* key) { ERROR_OUT(WC_TEST_RET_ENC_EC(ret), exit_rsa_even_mod); } - /* The failed encrypt wipes out; check that, then give the decrypt an - * in-range value so it still reaches the even modulus private op. */ +#if !defined(HAVE_FIPS) || FIPS_VERSION3_GE(7,0,0) + /* v7+ wipes out on the failed encrypt; check, then refill in range so + * the decrypt still reaches the even modulus private op. */ for (idx = 0; idx < outSz; idx++) { if (out[idx] != 0) { ERROR_OUT(WC_TEST_RET_ENC_NC, exit_rsa_even_mod); } } XMEMSET(out, 0x01, outSz); +#endif #endif /* WOLFSSL_RSA_VERIFY_ONLY */ #ifndef WOLFSSL_RSA_PUBLIC_ONLY From 816a091a7091cc8013d9998e3f9e0e455faa4bef Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Thu, 1 Oct 2026 14:16:55 -0600 Subject: [PATCH 11/12] SHA-3: keep the C Keccak round scratch in the context The C block function wrote its round scratch to its own stack frame on every block, where nothing could wipe it. The context now owns the scratch and wc_Sha3Free wipes it with the state (ISO/IEC 19790:2012 7.9.7). About 1% on the C lane; the asm lanes are unchanged. --- wolfcrypt/src/sha3.c | 129 ++++++++++++++++++++++---------- wolfcrypt/src/wc_frodokem_mat.c | 4 +- wolfcrypt/src/wc_mldsa.c | 16 ++-- wolfcrypt/src/wc_mlkem_poly.c | 36 ++++----- wolfcrypt/src/wc_slhdsa.c | 4 +- wolfssl/wolfcrypt/sha3.h | 45 ++++++++++- 6 files changed, 161 insertions(+), 73 deletions(-) diff --git a/wolfcrypt/src/sha3.c b/wolfcrypt/src/sha3.c index 36022e32e5f..2f25eebbf49 100644 --- a/wolfcrypt/src/sha3.c +++ b/wolfcrypt/src/sha3.c @@ -122,7 +122,7 @@ #define SHA3_BLOCK (sha3->sha3_block) #define SHA3_BLOCK_N (sha3->sha3_block_n) #else - void (*sha3_block)(word64 *s) = NULL; + WC_SHA3_BLOCK_FN sha3_block = NULL; void (*sha3_block_n)(word64 *s, const byte* data, word32 n, word64 c) = NULL; #define SHA3_BLOCK sha3_block @@ -131,6 +131,25 @@ #endif #ifdef USE_INTEL_SPEEDUP +#ifdef WC_SHA3_SCRATCH_W +/* The asm block functions keep no round scratch; give them the C signature + * so one function pointer type serves both. */ +static void sha3_block_avx2_scr(word64* s, void* scratch) +{ + (void)scratch; + sha3_block_avx2(s); +} +static void sha3_block_bmi2_scr(word64* s, void* scratch) +{ + (void)scratch; + sha3_block_bmi2(s); +} + #define SHA3_BLOCK_AVX2_FN sha3_block_avx2_scr + #define SHA3_BLOCK_BMI2_FN sha3_block_bmi2_scr +#else + #define SHA3_BLOCK_AVX2_FN sha3_block_avx2 + #define SHA3_BLOCK_BMI2_FN sha3_block_bmi2 +#endif /* Block-function selection when USE_INTEL_SPEEDUP: AVX2 on Intel, else * BMI2, else the C block. Measured single-instance Keccak-f[1600] * (Ethereum "Optimizing Keccak"; OpenSSL keccak1600-x86_64.pl): AVX2 is @@ -148,7 +167,7 @@ #ifdef WOLFSSL_SHA3_NO_AVX2 #define SHA3_BLOCK_VREGS(f) 0 #else - #define SHA3_BLOCK_VREGS(f) ((f) == sha3_block_avx2) + #define SHA3_BLOCK_VREGS(f) ((f) == SHA3_BLOCK_AVX2_FN) #endif #endif @@ -163,6 +182,19 @@ #if !defined(WOLFSSL_ARMASM) && !defined(WOLFSSL_RISCV_ASM) && \ !defined(WOLFSSL_PPC64_ASM) && !defined(WOLFSSL_PPC32_ASM) +/* The state and the scratch never overlap; tell the compiler so the lanes can + * stay in registers across the round macros as they did with local arrays. */ +#if defined(__GNUC__) || defined(__clang__) + #define WC_SHA3_RESTRICT __restrict__ +#elif defined(_MSC_VER) + #define WC_SHA3_RESTRICT __restrict +#elif defined(__STDC_VERSION__) && (__STDC_VERSION__ >= 199901L) + #define WC_SHA3_RESTRICT restrict +#else + #define WC_SHA3_RESTRICT +#endif + + #ifdef WOLFSSL_SHA3_SMALL /* Rotate a 64-bit value left. * @@ -328,11 +360,19 @@ while (0) * * s The state. */ +#ifdef WC_SHA3_SCRATCH_W +void BlockSha3(word64* WC_SHA3_RESTRICT s, void* scratch) +{ + byte i, x, y; + word64 t0, t1; + word64* WC_SHA3_RESTRICT b = (word64*)scratch; +#else void BlockSha3(word64* s) { byte i, x, y; word64 t0, t1; word64 b[5]; +#endif for (i = 0; i < 24; i++) { @@ -725,18 +765,30 @@ while (0) WC_SHA3_CHI(DL, DH, 20); \ } while (0) -void BlockSha3(word64* s) +#ifdef WC_SHA3_SCRATCH_W +void BlockSha3(word64* WC_SHA3_RESTRICT s, void* scratch) { /* Process the 25 little-endian lanes as 32-bit halves to avoid 64-bit * helper calls. XMEMCPY in/out (aliasing s through word32* is strict- * aliasing UB); st[2k] is lane k's low half, st[2k+1] the high half. * Round constants are split with shifts for the same reason. */ + word32* WC_SHA3_RESTRICT st = (word32*)scratch; + word32* WC_SHA3_RESTRICT sl = st + 50; + word32* WC_SHA3_RESTRICT sh = st + 75; + word32* WC_SHA3_RESTRICT nl = st + 100; + word32* WC_SHA3_RESTRICT nh = st + 125; + word32* WC_SHA3_RESTRICT bl = st + 150; + word32* WC_SHA3_RESTRICT bh = st + 155; +#else +void BlockSha3(word64* s) +{ word32 st[50]; word32 sl[25], sh[25], nl[25], nh[25], bl[5], bh[5]; +#endif word32 i, k; word64 rc; - XMEMCPY(st, s, sizeof(st)); + XMEMCPY(st, s, 25 * sizeof(word64)); for (k = 0; k < 25; k++) { sl[k] = st[2 * k]; sh[k] = st[2 * k + 1]; @@ -755,7 +807,7 @@ void BlockSha3(word64* s) st[2 * k] = sl[k]; st[2 * k + 1] = sh[k]; } - XMEMCPY(s, st, sizeof(st)); + XMEMCPY(s, st, 25 * sizeof(word64)); } #undef WC_SHA3_RL @@ -765,10 +817,17 @@ void BlockSha3(word64* s) #else /* !WC_SHA3_SPLIT64 */ +#ifdef WC_SHA3_SCRATCH_W +void BlockSha3(word64* WC_SHA3_RESTRICT s, void* scratch) +{ + word64* WC_SHA3_RESTRICT n = (word64*)scratch; + word64* WC_SHA3_RESTRICT b = n + 25; +#else void BlockSha3(word64* s) { word64 n[25]; word64 b[5]; +#endif word64 t0; #ifndef SHA3_BY_SPEC word64 t1; @@ -927,11 +986,11 @@ static int InitSha3(wc_Sha3* sha3) #endif /* See the selection comment above: AVX2 on Intel, otherwise BMI2. */ if (SHA3_USE_AVX2(cpuid_flags)) { - SHA3_BLOCK = sha3_block_avx2; + SHA3_BLOCK = SHA3_BLOCK_AVX2_FN; SHA3_BLOCK_N = sha3_block_n_avx2; } else if (IS_INTEL_BMI1(cpuid_flags) && IS_INTEL_BMI2(cpuid_flags)) { - SHA3_BLOCK = sha3_block_bmi2; + SHA3_BLOCK = SHA3_BLOCK_BMI2_FN; SHA3_BLOCK_N = sha3_block_n_bmi2; } else { @@ -972,6 +1031,15 @@ void BlockSha3(word64* s) } #endif +/* Run the block function on a context's state with the context's scratch. */ +#if defined(SHA3_FUNC_PTR) && defined(WC_SHA3_SCRATCH_W) + #define SHA3_BLOCK_RUN(o) (*sha3_block)((o)->s, (o)->scratch) +#elif defined(SHA3_FUNC_PTR) + #define SHA3_BLOCK_RUN(o) (*sha3_block)((o)->s) +#else + #define SHA3_BLOCK_RUN(o) WC_SHA3_BLOCK(o, (o)->s) +#endif + /* Update the SHA-3 hash state with message data. * * sha3 wc_Sha3 object holding state. @@ -991,7 +1059,7 @@ static int Sha3Update(wc_Sha3* sha3, const byte* data, word32 len, word32 p) #endif #ifdef USE_INTEL_SPEEDUP #ifdef WC_C_DYNAMIC_FALLBACK - void (*sha3_block)(word64 *s) = SHA3_BLOCK; + WC_SHA3_BLOCK_FN sha3_block = SHA3_BLOCK; void (*sha3_block_n)(word64 *s, const byte* data, word32 n, word64 c) = SHA3_BLOCK_N; #endif @@ -1064,11 +1132,7 @@ static int Sha3Update(wc_Sha3* sha3, const byte* data, word32 len, word32 p) total_check += p; #endif #endif - #ifdef SHA3_FUNC_PTR - (*sha3_block)(sha3->s); - #else - BlockSha3(sha3->s); - #endif + SHA3_BLOCK_RUN(sha3); sha3->i = 0; } } @@ -1102,11 +1166,7 @@ static int Sha3Update(wc_Sha3* sha3, const byte* data, word32 len, word32 p) } #endif #endif - #ifdef SHA3_FUNC_PTR - (*sha3_block)(sha3->s); - #else - BlockSha3(sha3->s); - #endif + SHA3_BLOCK_RUN(sha3); len -= p * 8U; data += p * 8U; } @@ -1169,7 +1229,7 @@ static int Sha3Final(wc_Sha3* sha3, byte padChar, byte* hash, word32 p, word32 l word32 check = 0; #endif #if defined(WC_C_DYNAMIC_FALLBACK) && defined(USE_INTEL_SPEEDUP) - void (*sha3_block)(word64 *s) = SHA3_BLOCK; + WC_SHA3_BLOCK_FN sha3_block = SHA3_BLOCK; #endif if ((p < WC_SHA3_512_COUNT) || (p > WC_SHA3_128_COUNT)) @@ -1226,11 +1286,7 @@ static int Sha3Final(wc_Sha3* sha3, byte padChar, byte* hash, word32 p, word32 l #endif for (j = 0; l - j >= rate; j += rate) { - #ifdef SHA3_FUNC_PTR - (*sha3_block)(sha3->s); - #else - BlockSha3(sha3->s); - #endif + SHA3_BLOCK_RUN(sha3); #if defined(BIG_ENDIAN_ORDER) ByteReverseWords64((word64*)(hash + j), sha3->s, rate); #elif defined(WOLFSSL_WIDE_BYTE) @@ -1240,11 +1296,7 @@ static int Sha3Final(wc_Sha3* sha3, byte padChar, byte* hash, word32 p, word32 l #endif } if (j != l) { - #ifdef SHA3_FUNC_PTR - (*sha3_block)(sha3->s); - #else - BlockSha3(sha3->s); - #endif + SHA3_BLOCK_RUN(sha3); #if defined(BIG_ENDIAN_ORDER) ByteReverseWords64(sha3->s, sha3->s, rate); XMEMCPY(hash + j, sha3->s, l - j); @@ -1601,6 +1653,9 @@ static void wc_Sha3Wipe(wc_Sha3* sha3) #else ForceZero(sha3->s, sizeof(sha3->s)); ForceZero(sha3->t, sizeof(sha3->t)); +#ifdef WC_SHA3_SCRATCH_W + ForceZero(sha3->scratch, sizeof(sha3->scratch)); +#endif sha3->i = 0; #endif } @@ -2354,7 +2409,7 @@ int wc_Shake128_Absorb(wc_Shake* shake, const byte* data, word32 len) int wc_Shake128_SqueezeBlocks(wc_Shake* shake, byte* out, word32 blockCnt) { #if defined(WC_C_DYNAMIC_FALLBACK) && defined(USE_INTEL_SPEEDUP) - void (*sha3_block)(word64 *s); + WC_SHA3_BLOCK_FN sha3_block; #endif if ((shake == NULL) || (out == NULL && blockCnt != 0)) { @@ -2379,11 +2434,7 @@ int wc_Shake128_SqueezeBlocks(wc_Shake* shake, byte* out, word32 blockCnt) #endif for (; (blockCnt > 0); blockCnt--) { - #ifdef SHA3_FUNC_PTR - (*sha3_block)(shake->s); - #else - BlockSha3(shake->s); - #endif + SHA3_BLOCK_RUN(shake); #if defined(BIG_ENDIAN_ORDER) ByteReverseWords64((word64*)out, shake->s, WC_SHA3_128_COUNT * 8); #elif defined(WOLFSSL_WIDE_BYTE) @@ -2674,7 +2725,7 @@ int wc_Shake256_Absorb(wc_Shake* shake, const byte* data, word32 len) int wc_Shake256_SqueezeBlocks(wc_Shake* shake, byte* out, word32 blockCnt) { #if defined(WC_C_DYNAMIC_FALLBACK) && defined(USE_INTEL_SPEEDUP) - void (*sha3_block)(word64 *s); + WC_SHA3_BLOCK_FN sha3_block; #endif if ((shake == NULL) || (out == NULL && blockCnt != 0)) { @@ -2699,11 +2750,7 @@ int wc_Shake256_SqueezeBlocks(wc_Shake* shake, byte* out, word32 blockCnt) #endif for (; (blockCnt > 0); blockCnt--) { - #ifdef SHA3_FUNC_PTR - (*sha3_block)(shake->s); - #else - BlockSha3(shake->s); - #endif + SHA3_BLOCK_RUN(shake); #if defined(BIG_ENDIAN_ORDER) ByteReverseWords64((word64*)out, shake->s, WC_SHA3_256_COUNT * 8); #elif defined(WOLFSSL_WIDE_BYTE) diff --git a/wolfcrypt/src/wc_frodokem_mat.c b/wolfcrypt/src/wc_frodokem_mat.c index f80966b0b06..6f6c0ac4bc0 100644 --- a/wolfcrypt/src/wc_frodokem_mat.c +++ b/wolfcrypt/src/wc_frodokem_mat.c @@ -1312,10 +1312,10 @@ static int frodokem_gen_a_row_shake(wc_Shake* shake, word16* row, state8[WC_SHA3_128_COUNT * 8 - 1] = 0x80; for (l = 0; l + inc < 2 * p->n; l += inc) { - BlockSha3(state); + WC_SHA3_BLOCK(shake, state); XMEMCPY(rowBytes + l, state8, WC_SHA3_128_BLOCK_SIZE); } - BlockSha3(state); + WC_SHA3_BLOCK(shake, state); XMEMCPY(rowBytes + l, state8, (word32)(2 * p->n - l)); ret = 0; diff --git a/wolfcrypt/src/wc_mldsa.c b/wolfcrypt/src/wc_mldsa.c index 890dcf3955c..9924c9d9abf 100644 --- a/wolfcrypt/src/wc_mldsa.c +++ b/wolfcrypt/src/wc_mldsa.c @@ -535,7 +535,7 @@ static int mldsa_shake256(wc_Shake* shake256, const byte* data, else #endif { - BlockSha3(state); + WC_SHA3_BLOCK(shake256, state); } if (dataLen >= WC_SHA3_256_COUNT * 8) { #ifndef WC_SHA3_NO_ASM @@ -561,7 +561,7 @@ static int mldsa_shake256(wc_Shake* shake256, const byte* data, xorbuf(state, data, WC_SHA3_256_COUNT * 8); dataLen -= WC_SHA3_256_COUNT * 8; data += WC_SHA3_256_COUNT * 8; - BlockSha3(state); + WC_SHA3_BLOCK(shake256, state); } } } @@ -589,7 +589,7 @@ static int mldsa_shake256(wc_Shake* shake256, const byte* data, else #endif { - BlockSha3(state); + WC_SHA3_BLOCK(shake256, state); } if (hash != (byte*)shake256->s) { XMEMCPY(hash, shake256->s, hashLen); @@ -660,7 +660,7 @@ static int mldsa_hash256(wc_Shake* shake256, const byte* data1, else #endif { - BlockSha3(state); + WC_SHA3_BLOCK(shake256, state); } if (data2Len >= WC_SHA3_256_COUNT * 8) { @@ -686,7 +686,7 @@ static int mldsa_hash256(wc_Shake* shake256, const byte* data1, xorbuf(state, data2, WC_SHA3_256_COUNT * 8); data2Len -= WC_SHA3_256_COUNT * 8; data2 += WC_SHA3_256_COUNT * 8; - BlockSha3(state); + WC_SHA3_BLOCK(shake256, state); } } } @@ -718,7 +718,7 @@ static int mldsa_hash256(wc_Shake* shake256, const byte* data1, else #endif { - BlockSha3(state); + WC_SHA3_BLOCK(shake256, state); } XMEMCPY(hash, shake256->s, hashLen); ret = 0; @@ -1017,7 +1017,7 @@ static int mldsa_squeeze256(wc_Shake* shake256, const byte* in, else #endif { - BlockSha3(state); + WC_SHA3_BLOCK(shake256, state); } XMEMCPY(out, shake256->s, WC_SHA3_256_COUNT * 8); out += WC_SHA3_256_COUNT * 8; @@ -5359,7 +5359,7 @@ static int mldsa_sample_in_ball_ex(int level, wc_Shake* shake256, else #endif { - BlockSha3(state); + WC_SHA3_BLOCK(shake256, state); } /* Restart hash block index. */ diff --git a/wolfcrypt/src/wc_mlkem_poly.c b/wolfcrypt/src/wc_mlkem_poly.c index 616da2c3843..e72f6bb0b99 100644 --- a/wolfcrypt/src/wc_mlkem_poly.c +++ b/wolfcrypt/src/wc_mlkem_poly.c @@ -2829,7 +2829,7 @@ static int mlkem_gen_matrix_k3_avx2(sword16* a, byte* seed, int transposed) else #endif /* !WC_SHA3_NO_ASM */ { - BlockSha3(state); + WC_SHA3_BLOCK_SCR(state, state + 25); } XMEMCPY(rand + i, state, SHA3_128_BYTES); } @@ -2847,7 +2847,7 @@ static int mlkem_gen_matrix_k3_avx2(sword16* a, byte* seed, int transposed) else #endif /* !WC_SHA3_NO_ASM */ { - BlockSha3(state); + WC_SHA3_BLOCK_SCR(state, state + 25); } XMEMCPY(rand, state, SHA3_128_BYTES); ctr0 += mlkem_rej_uniform_ins(a + ctr0, MLKEM_N - ctr0, rand, @@ -2957,7 +2957,7 @@ static int mlkem_gen_matrix_k3_avx512(sword16* a, byte* seed, int transposed) else #endif /* !WC_SHA3_NO_ASM */ { - BlockSha3(state); + WC_SHA3_BLOCK_SCR(state, state + 25); } XMEMCPY(rand + i, state, SHA3_128_BYTES); } @@ -2975,7 +2975,7 @@ static int mlkem_gen_matrix_k3_avx512(sword16* a, byte* seed, int transposed) else #endif /* !WC_SHA3_NO_ASM */ { - BlockSha3(state); + WC_SHA3_BLOCK_SCR(state, state + 25); } XMEMCPY(rand, state, SHA3_128_BYTES); ctr[0] += mlkem_rej_uniform_ins(a + ctr[0], MLKEM_N - ctr[0], rand, @@ -3252,11 +3252,11 @@ static int mlkem_gen_matrix_k2_aarch64(sword16* a, byte* seed, int transposed) state[4] = 0x1f0000 + (1 << 8) + 1; XMEMSET(state + 5, 0, sizeof(*state) * (25 - 5)); state[20] = W64LIT(0x8000000000000000); - BlockSha3(state); + WC_SHA3_BLOCK_SCR(state, state + 25); p = (byte*)state; ctr0 = mlkem_rej_uniform_neon(a, MLKEM_N, p, XOF_BLOCK_SIZE); while (ctr0 < MLKEM_N) { - BlockSha3(state); + WC_SHA3_BLOCK_SCR(state, state + 25); ctr0 += mlkem_rej_uniform_neon(a + ctr0, MLKEM_N - ctr0, p, XOF_BLOCK_SIZE); } @@ -3396,11 +3396,11 @@ static int mlkem_gen_matrix_k4_aarch64(sword16* a, byte* seed, int transposed) state[4] = 0x1f0000 + (3 << 8) + 3; XMEMSET(state + 5, 0, sizeof(*state) * (25 - 5)); state[20] = W64LIT(0x8000000000000000); - BlockSha3(state); + WC_SHA3_BLOCK_SCR(state, state + 25); p = (byte*)state; ctr0 = mlkem_rej_uniform_neon(a, MLKEM_N, p, XOF_BLOCK_SIZE); while (ctr0 < MLKEM_N) { - BlockSha3(state); + WC_SHA3_BLOCK_SCR(state, state + 25); ctr0 += mlkem_rej_uniform_neon(a + ctr0, MLKEM_N - ctr0, p, XOF_BLOCK_SIZE); } @@ -3620,7 +3620,7 @@ static int mlkem_prf(wc_Shake* shake256, byte* out, unsigned int outLen, else #endif /* !WC_SHA3_NO_ASM */ { - BlockSha3(state); + WC_SHA3_BLOCK(shake256, state); } /* Copy the state as output. */ @@ -3666,7 +3666,7 @@ static int mlkem_prf(wc_Shake* shake256, byte* out, unsigned int outLen, */ int mlkem_kdf(const byte* seed, int seedLen, byte* out, int outLen) { - word64 state[25]; + word64 state[WC_SHA3_STATE_W]; word32 len64 = seedLen / 8; readUnalignedWords64(state, seed, len64); @@ -3685,7 +3685,7 @@ int mlkem_kdf(const byte* seed, int seedLen, byte* out, int outLen) else #endif { - BlockSha3(state); + WC_SHA3_BLOCK_ST(state); } XMEMCPY(out, state, outLen); @@ -3712,7 +3712,7 @@ int mlkem_kdf(const byte* seed, int seedLen, byte* out, int outLen) */ int mlkem_kdf(const byte* seed, int seedLen, byte* out, int outLen) { - word64 state[25]; + word64 state[WC_SHA3_STATE_W]; word32 len64 = seedLen / 8; readUnalignedWords64(state, seed, len64); @@ -3720,7 +3720,7 @@ int mlkem_kdf(const byte* seed, int seedLen, byte* out, int outLen) XMEMSET(state + len64 + 1, 0, (25 - len64 - 1) * sizeof(word64)); state[WC_SHA3_256_COUNT - 1] = W64LIT(0x8000000000000000); - BlockSha3(state); + WC_SHA3_BLOCK_ST(state); XMEMCPY(out, state, outLen); /* state holds secret KDF output. */ @@ -4827,7 +4827,7 @@ static int mlkem_get_noise_eta2_avx2(MLKEM_PRF_T* prf, sword16* p, else #endif /* !WC_SHA3_NO_ASM */ { - BlockSha3(state); + WC_SHA3_BLOCK(prf, state); } mlkem_cbd_eta2_ins(p, (byte*)state); @@ -5289,15 +5289,15 @@ static void mlkem_get_noise_eta3_aarch64(byte* rand, byte* seed, byte o) { /* ETA3_RAND_SIZE is larger than the SHAKE-256 rate - two squeezes are * needed, so the state cannot be squeezed in place over the output. */ - word64 state[25]; + word64 state[WC_SHA3_STATE_W]; readUnalignedWords64(state, seed, 4); state[4] = 0x1f00 + o; XMEMSET(state + 5, 0, sizeof(*state) * (25 - 5)); state[16] = W64LIT(0x8000000000000000); - BlockSha3(state); + WC_SHA3_BLOCK_ST(state); XMEMCPY(rand , state, SHA3_256_BYTES); - BlockSha3(state); + WC_SHA3_BLOCK_ST(state); XMEMCPY(rand + SHA3_256_BYTES, state, ETA3_RAND_SIZE - SHA3_256_BYTES); /* state is secret-seeded; caller zeroizes rand. */ @@ -5373,7 +5373,7 @@ static void mlkem_get_noise_eta2_aarch64(word64* rand, byte* seed, byte o) rand[4] = 0x1f00 + o; XMEMSET(rand + 5, 0, sizeof(*rand) * (25 - 5)); rand[16] = W64LIT(0x8000000000000000); - BlockSha3(rand); + WC_SHA3_BLOCK_SCR(rand, rand + 25); } /* Get the noise/error by calculating random bytes and sampling to a binomial diff --git a/wolfcrypt/src/wc_slhdsa.c b/wolfcrypt/src/wc_slhdsa.c index bbb83cebda0..cc3468ad1b0 100644 --- a/wolfcrypt/src/wc_slhdsa.c +++ b/wolfcrypt/src/wc_slhdsa.c @@ -564,7 +564,7 @@ static int slhdsakey_hash_shake_3(wc_Shake* shake, const byte* data1, #endif { /* Process the state using C code. */ - BlockSha3(state); + WC_SHA3_BLOCK(shake, state); } /* Copy hash result, of the required length, from the state into hash. */ XMEMCPY(hash, shake->s, hash_len); @@ -676,7 +676,7 @@ static int slhdsakey_hash_shake_4(wc_Shake* shake, const byte* data1, #endif { /* Process the state using C code. */ - BlockSha3(state); + WC_SHA3_BLOCK(shake, state); } /* Copy hash result, of the required length, from the state into hash. */ XMEMCPY(hash, shake->s, hash_len); diff --git a/wolfssl/wolfcrypt/sha3.h b/wolfssl/wolfcrypt/sha3.h index 1c59e274990..4623ee1dbda 100644 --- a/wolfssl/wolfcrypt/sha3.h +++ b/wolfssl/wolfcrypt/sha3.h @@ -141,6 +141,31 @@ enum { #include "cy_crypto_core.h" #endif +/* Round scratch of the C Keccak block function lives in the context so it is + * wiped once at Free: word64 lanes, or word32 halves for the split variant. */ +#if (defined(WC_SHA3_NO_ASM) || (!defined(WOLFSSL_ARMASM) && \ + !defined(WOLFSSL_RISCV_ASM) && !defined(WOLFSSL_PPC64_ASM) && \ + !defined(WOLFSSL_PPC32_ASM))) && !defined(PSOC6_HASH_SHA3) && \ + !defined(WOLFSSL_XILINX_CRYPT) && !defined(WOLFSSL_AFALG_XILINX_SHA3) + #if defined(WOLFSSL_SHA3_SMALL) + #define WC_SHA3_SCRATCH_W 5 + #elif defined(WC_SHA3_SPLIT64) || \ + (defined(WOLFSSL_WIDE_BYTE) && !defined(BIG_ENDIAN_ORDER)) + #define WC_SHA3_SCRATCH_W 80 + #elif !defined(STM32_HASH_SHA3) || defined(WOLFSSL_SHAKE128) || \ + defined(WOLFSSL_SHAKE256) + #define WC_SHA3_SCRATCH_W 30 + #endif +#endif +#ifdef WC_SHA3_SCRATCH_W + typedef void (*WC_SHA3_BLOCK_FN)(word64* s, void* scratch); + /* Lanes to declare for a bare state that carries its own scratch. */ + #define WC_SHA3_STATE_W (25 + WC_SHA3_SCRATCH_W) +#else + typedef void (*WC_SHA3_BLOCK_FN)(word64* s); + #define WC_SHA3_STATE_W 25 +#endif + /* Sha3 digest */ struct wc_Sha3 { #if defined(PSOC6_HASH_SHA3) @@ -152,6 +177,10 @@ struct wc_Sha3 { word64 s[25]; /* Unprocessed message data. */ byte t[200]; +#ifdef WC_SHA3_SCRATCH_W + /* Round scratch for the C block function, wiped at Free. */ + word64 scratch[WC_SHA3_SCRATCH_W]; +#endif /* Index into unprocessed data to place next message byte. */ word32 i; @@ -164,7 +193,7 @@ struct wc_Sha3 { #endif #ifdef WC_C_DYNAMIC_FALLBACK - void (*sha3_block)(word64 *s); + WC_SHA3_BLOCK_FN sha3_block; void (*sha3_block_n)(word64 *s, const byte* data, word32 n, word64 c); #endif @@ -394,7 +423,19 @@ WOLFSSL_API int wc_Cshake256(const byte* name, word32 nameLen, #endif #endif /* WOLFSSL_KMAC || WOLFSSL_CSHAKE */ -WOLFSSL_LOCAL void BlockSha3(word64 *s); +#ifdef WC_SHA3_SCRATCH_W +WOLFSSL_LOCAL void BlockSha3(word64* s, void* scratch); +/* obj is the wc_Sha3 or wc_Shake whose scratch the block function uses. */ +#define WC_SHA3_BLOCK(obj, s) BlockSha3((s), (obj)->scratch) +#define WC_SHA3_BLOCK_SCR(s, scr) BlockSha3((s), (scr)) +/* st is a word64[WC_SHA3_STATE_W] with the scratch after the state. */ +#define WC_SHA3_BLOCK_ST(st) BlockSha3((st), (st) + 25) +#else +WOLFSSL_LOCAL void BlockSha3(word64* s); +#define WC_SHA3_BLOCK(obj, s) BlockSha3(s) +#define WC_SHA3_BLOCK_SCR(s, scr) do { (void)(scr); BlockSha3(s); } while (0) +#define WC_SHA3_BLOCK_ST(st) BlockSha3(st) +#endif #ifdef WC_SHA3_NO_ASM /* asm speedups disabled */ From 1c3cc39c6018e65344ecd3a1d84441c0478d0eac Mon Sep 17 00:00:00 2001 From: jackctj117 Date: Thu, 1 Oct 2026 14:19:00 -0600 Subject: [PATCH 12/12] ML-KEM: add basemul products into r without staging them mlkem_basemul_mont_add staged each product pair of the secret vector in a stack array before adding it to r. Multiply and add in one step so the products stay in registers (FIPS 203 Section 3.3; ISO/IEC 19790:2012 7.9.7). restrict on r, a and b keeps the loop vectorised. --- wolfcrypt/src/wc_mlkem_poly.c | 130 +++++++++++++++++----------------- 1 file changed, 66 insertions(+), 64 deletions(-) diff --git a/wolfcrypt/src/wc_mlkem_poly.c b/wolfcrypt/src/wc_mlkem_poly.c index e72f6bb0b99..68038303df6 100644 --- a/wolfcrypt/src/wc_mlkem_poly.c +++ b/wolfcrypt/src/wc_mlkem_poly.c @@ -1069,6 +1069,49 @@ static void mlkem_basemul(sword16* r, const sword16* a, const sword16* b, r[1] = MLKEM_MONT_RED(p1); } +/* r never aliases a or b; saying so keeps the accumulate loop vectorised. */ +#if defined(__GNUC__) || defined(__clang__) + #define MLKEM_RESTRICT __restrict__ +#elif defined(_MSC_VER) + #define MLKEM_RESTRICT __restrict +#elif defined(__STDC_VERSION__) && (__STDC_VERSION__ >= 199901L) + #define MLKEM_RESTRICT restrict +#else + #define MLKEM_RESTRICT +#endif + +/* Base case multiply added into r: the products of the secret vector stay in + * registers instead of a stack array (ISO/IEC 19790:2012 7.9.7). */ +static void mlkem_basemul_add(sword16* MLKEM_RESTRICT r, + const sword16* MLKEM_RESTRICT a, const sword16* MLKEM_RESTRICT b, + sword16 zeta) +{ + sword16 r0; + sword16 t; + sword16 a0 = a[0]; + sword16 a1 = a[1]; + sword16 b0 = b[0]; + sword16 b1 = b[1]; + sword32 p1; + sword32 p2; + + /* Step 1 */ + p1 = (sword32)a0 * b0; + p2 = (sword32)a1 * b1; + r0 = MLKEM_MONT_RED(p2); + p2 = (sword32)zeta * r0; + p2 += p1; + t = MLKEM_MONT_RED(p2); + r[0] = (sword16)(r[0] + t); + + /* Step 2 */ + p1 = (sword32)a0 * b1; + p2 = (sword32)a1 * b0; + p1 += p2; + t = MLKEM_MONT_RED(p1); + r[1] = (sword16)(r[1] + t); +} + /* Multiply two polynomials in NTT domain. r = a * b. * * FIPS 203, Algorithm 11: MultiplyNTTs(f_hat, g_hat) @@ -1138,8 +1181,8 @@ static void mlkem_basemul_mont(sword16* r, const sword16* a, const sword16* b) * @param [in] a First polynomial multiplier. * @param [in] b Second polynomial multiplier. */ -static void mlkem_basemul_mont_add(sword16* r, const sword16* a, - const sword16* b) +static void mlkem_basemul_mont_add(sword16* MLKEM_RESTRICT r, + const sword16* MLKEM_RESTRICT a, const sword16* MLKEM_RESTRICT b) { const sword16* zeta = zetas + 64; @@ -1147,78 +1190,37 @@ static void mlkem_basemul_mont_add(sword16* r, const sword16* a, /* Two multiplications per loop. */ unsigned int i; for (i = 0; i < MLKEM_N; i += 4, zeta++) { - sword16 t0[2]; - sword16 t2[2]; - - mlkem_basemul(t0, a + i + 0, b + i + 0, zeta[0]); - mlkem_basemul(t2, a + i + 2, b + i + 2, (sword16)(-zeta[0])); - - r[i + 0] = (sword16)(r[i + 0] + t0[0]); - r[i + 1] = (sword16)(r[i + 1] + t0[1]); - r[i + 2] = (sword16)(r[i + 2] + t2[0]); - r[i + 3] = (sword16)(r[i + 3] + t2[1]); + mlkem_basemul_add(r + i + 0, a + i + 0, b + i + 0, zeta[0]); + mlkem_basemul_add(r + i + 2, a + i + 2, b + i + 2, + (sword16)(-zeta[0])); } #elif defined(WOLFSSL_MLKEM_NO_LARGE_CODE) /* Four multiplications per loop. */ unsigned int i; for (i = 0; i < MLKEM_N; i += 8, zeta += 2) { - sword16 t0[2]; - sword16 t2[2]; - sword16 t4[2]; - sword16 t6[2]; - - mlkem_basemul(t0, a + i + 0, b + i + 0, zeta[0]); - mlkem_basemul(t2, a + i + 2, b + i + 2, (sword16)(-zeta[0])); - mlkem_basemul(t4, a + i + 4, b + i + 4, zeta[1]); - mlkem_basemul(t6, a + i + 6, b + i + 6, (sword16)(-zeta[1])); - - r[i + 0] = (sword16)(r[i + 0] + t0[0]); - r[i + 1] = (sword16)(r[i + 1] + t0[1]); - r[i + 2] = (sword16)(r[i + 2] + t2[0]); - r[i + 3] = (sword16)(r[i + 3] + t2[1]); - r[i + 4] = (sword16)(r[i + 4] + t4[0]); - r[i + 5] = (sword16)(r[i + 5] + t4[1]); - r[i + 6] = (sword16)(r[i + 6] + t6[0]); - r[i + 7] = (sword16)(r[i + 7] + t6[1]); + mlkem_basemul_add(r + i + 0, a + i + 0, b + i + 0, zeta[0]); + mlkem_basemul_add(r + i + 2, a + i + 2, b + i + 2, + (sword16)(-zeta[0])); + mlkem_basemul_add(r + i + 4, a + i + 4, b + i + 4, zeta[1]); + mlkem_basemul_add(r + i + 6, a + i + 6, b + i + 6, + (sword16)(-zeta[1])); } #else /* Eight multiplications per loop. */ unsigned int i; for (i = 0; i < MLKEM_N; i += 16, zeta += 4) { - sword16 t0[2]; - sword16 t2[2]; - sword16 t4[2]; - sword16 t6[2]; - sword16 t8[2]; - sword16 t10[2]; - sword16 t12[2]; - sword16 t14[2]; - - mlkem_basemul(t0, a + i + 0, b + i + 0, zeta[0]); - mlkem_basemul(t2, a + i + 2, b + i + 2, (sword16)(-zeta[0])); - mlkem_basemul(t4, a + i + 4, b + i + 4, zeta[1]); - mlkem_basemul(t6, a + i + 6, b + i + 6, (sword16)(-zeta[1])); - mlkem_basemul(t8, a + i + 8, b + i + 8, zeta[2]); - mlkem_basemul(t10, a + i + 10, b + i + 10, (sword16)(-zeta[2])); - mlkem_basemul(t12, a + i + 12, b + i + 12, zeta[3]); - mlkem_basemul(t14, a + i + 14, b + i + 14, (sword16)(-zeta[3])); - - r[i + 0] = (sword16)(r[i + 0] + t0[0]); - r[i + 1] = (sword16)(r[i + 1] + t0[1]); - r[i + 2] = (sword16)(r[i + 2] + t2[0]); - r[i + 3] = (sword16)(r[i + 3] + t2[1]); - r[i + 4] = (sword16)(r[i + 4] + t4[0]); - r[i + 5] = (sword16)(r[i + 5] + t4[1]); - r[i + 6] = (sword16)(r[i + 6] + t6[0]); - r[i + 7] = (sword16)(r[i + 7] + t6[1]); - r[i + 8] = (sword16)(r[i + 8] + t8[0]); - r[i + 9] = (sword16)(r[i + 9] + t8[1]); - r[i + 10] = (sword16)(r[i + 10] + t10[0]); - r[i + 11] = (sword16)(r[i + 11] + t10[1]); - r[i + 12] = (sword16)(r[i + 12] + t12[0]); - r[i + 13] = (sword16)(r[i + 13] + t12[1]); - r[i + 14] = (sword16)(r[i + 14] + t14[0]); - r[i + 15] = (sword16)(r[i + 15] + t14[1]); + mlkem_basemul_add(r + i + 0, a + i + 0, b + i + 0, zeta[0]); + mlkem_basemul_add(r + i + 2, a + i + 2, b + i + 2, + (sword16)(-zeta[0])); + mlkem_basemul_add(r + i + 4, a + i + 4, b + i + 4, zeta[1]); + mlkem_basemul_add(r + i + 6, a + i + 6, b + i + 6, + (sword16)(-zeta[1])); + mlkem_basemul_add(r + i + 8, a + i + 8, b + i + 8, zeta[2]); + mlkem_basemul_add(r + i + 10, a + i + 10, b + i + 10, + (sword16)(-zeta[2])); + mlkem_basemul_add(r + i + 12, a + i + 12, b + i + 12, zeta[3]); + mlkem_basemul_add(r + i + 14, a + i + 14, b + i + 14, + (sword16)(-zeta[3])); } #endif }