static int eap_fast_update_icmk(struct eap_sm *sm, struct eap_fast_data *data) { u8 isk[32], imck[60]; wpa_printf(MSG_DEBUG, "EAP-FAST: Deriving ICMK[%d] (S-IMCK and CMK)", data->simck_idx + 1); /* * RFC 4851, Section 5.2: * IMCK[j] = T-PRF(S-IMCK[j-1], "Inner Methods Compound Keys", * MSK[j], 60) * S-IMCK[j] = first 40 octets of IMCK[j] * CMK[j] = last 20 octets of IMCK[j] */ if (eap_fast_get_phase2_key(sm, data, isk, sizeof(isk)) < 0) return -1; wpa_hexdump_key(MSG_MSGDUMP, "EAP-FAST: ISK[j]", isk, sizeof(isk)); sha1_t_prf(data->simck, EAP_FAST_SIMCK_LEN, "Inner Methods Compound Keys", isk, sizeof(isk), imck, sizeof(imck)); data->simck_idx++; os_memcpy(data->simck, imck, EAP_FAST_SIMCK_LEN); wpa_hexdump_key(MSG_MSGDUMP, "EAP-FAST: S-IMCK[j]", data->simck, EAP_FAST_SIMCK_LEN); os_memcpy(data->cmk, imck + EAP_FAST_SIMCK_LEN, EAP_FAST_CMK_LEN); wpa_hexdump_key(MSG_MSGDUMP, "EAP-FAST: CMK[j]", data->cmk, EAP_FAST_CMK_LEN); return 0; }
void eap_fast_derive_master_secret(const u8 *pac_key, const u8 *server_random, const u8 *client_random, u8 *master_secret) { #define TLS_RANDOM_LEN 32 #define TLS_MASTER_SECRET_LEN 48 u8 seed[2 * TLS_RANDOM_LEN]; wpa_hexdump(MSG_DEBUG, "EAP-FAST: client_random", client_random, TLS_RANDOM_LEN); wpa_hexdump(MSG_DEBUG, "EAP-FAST: server_random", server_random, TLS_RANDOM_LEN); /* * RFC 4851, Section 5.1: * master_secret = T-PRF(PAC-Key, "PAC to master secret label hash", * server_random + client_random, 48) */ os_memcpy(seed, server_random, TLS_RANDOM_LEN); os_memcpy(seed + TLS_RANDOM_LEN, client_random, TLS_RANDOM_LEN); sha1_t_prf(pac_key, EAP_FAST_PAC_KEY_LEN, "PAC to master secret label hash", seed, sizeof(seed), master_secret, TLS_MASTER_SECRET_LEN); wpa_hexdump_key(MSG_DEBUG, "EAP-FAST: master_secret", master_secret, TLS_MASTER_SECRET_LEN); }
void eap_fast_derive_eap_msk(const u8 *simck, u8 *msk) { /* * RFC 4851, Section 5.4: EAP Master Session Key Generation * MSK = T-PRF(S-IMCK[j], "Session Key Generating Function", 64) */ sha1_t_prf(simck, EAP_FAST_SIMCK_LEN, "Session Key Generating Function", (u8 *) "", 0, msk, EAP_FAST_KEY_LEN); wpa_hexdump_key(MSG_DEBUG, "EAP-FAST: Derived key (MSK)", msk, EAP_FAST_KEY_LEN); }
int eap_fast_derive_eap_emsk(const u8 *simck, u8 *emsk) { /* * RFC 4851, Section 5.4: EAP Master Session Key Genreration * EMSK = T-PRF(S-IMCK[j], * "Extended Session Key Generating Function", 64) */ if (sha1_t_prf(simck, EAP_FAST_SIMCK_LEN, "Extended Session Key Generating Function", (u8 *) "", 0, emsk, EAP_EMSK_LEN) < 0) return -1; wpa_hexdump_key(MSG_DEBUG, "EAP-FAST: Derived key (EMSK)", emsk, EAP_EMSK_LEN); return 0; }
static int test_eap_fast(void) { /* RFC 4851, Appendix B.1 */ const u8 pac_key[] = { 0x0B, 0x97, 0x39, 0x0F, 0x37, 0x51, 0x78, 0x09, 0x81, 0x1E, 0xFD, 0x9C, 0x6E, 0x65, 0x94, 0x2B, 0x63, 0x2C, 0xE9, 0x53, 0x89, 0x38, 0x08, 0xBA, 0x36, 0x0B, 0x03, 0x7C, 0xD1, 0x85, 0xE4, 0x14 }; const u8 seed[] = { 0x3F, 0xFB, 0x11, 0xC4, 0x6C, 0xBF, 0xA5, 0x7A, 0x54, 0x40, 0xDA, 0xE8, 0x22, 0xD3, 0x11, 0xD3, 0xF7, 0x6D, 0xE4, 0x1D, 0xD9, 0x33, 0xE5, 0x93, 0x70, 0x97, 0xEB, 0xA9, 0xB3, 0x66, 0xF4, 0x2A, 0x00, 0x00, 0x00, 0x02, 0x6A, 0x66, 0x43, 0x2A, 0x8D, 0x14, 0x43, 0x2C, 0xEC, 0x58, 0x2D, 0x2F, 0xC7, 0x9C, 0x33, 0x64, 0xBA, 0x04, 0xAD, 0x3A, 0x52, 0x54, 0xD6, 0xA5, 0x79, 0xAD, 0x1E, 0x00 }; const u8 master_secret[] = { 0x4A, 0x1A, 0x51, 0x2C, 0x01, 0x60, 0xBC, 0x02, 0x3C, 0xCF, 0xBC, 0x83, 0x3F, 0x03, 0xBC, 0x64, 0x88, 0xC1, 0x31, 0x2F, 0x0B, 0xA9, 0xA2, 0x77, 0x16, 0xA8, 0xD8, 0xE8, 0xBD, 0xC9, 0xD2, 0x29, 0x38, 0x4B, 0x7A, 0x85, 0xBE, 0x16, 0x4D, 0x27, 0x33, 0xD5, 0x24, 0x79, 0x87, 0xB1, 0xC5, 0xA2 }; const u8 key_block[] = { 0x59, 0x59, 0xBE, 0x8E, 0x41, 0x3A, 0x77, 0x74, 0x8B, 0xB2, 0xE5, 0xD3, 0x60, 0xAC, 0x4D, 0x35, 0xDF, 0xFB, 0xC8, 0x1E, 0x9C, 0x24, 0x9C, 0x8B, 0x0E, 0xC3, 0x1D, 0x72, 0xC8, 0x84, 0x9D, 0x57, 0x48, 0x51, 0x2E, 0x45, 0x97, 0x6C, 0x88, 0x70, 0xBE, 0x5F, 0x01, 0xD3, 0x64, 0xE7, 0x4C, 0xBB, 0x11, 0x24, 0xE3, 0x49, 0xE2, 0x3B, 0xCD, 0xEF, 0x7A, 0xB3, 0x05, 0x39, 0x5D, 0x64, 0x8A, 0x44, 0x11, 0xB6, 0x69, 0x88, 0x34, 0x2E, 0x8E, 0x29, 0xD6, 0x4B, 0x7D, 0x72, 0x17, 0x59, 0x28, 0x05, 0xAF, 0xF9, 0xB7, 0xFF, 0x66, 0x6D, 0xA1, 0x96, 0x8F, 0x0B, 0x5E, 0x06, 0x46, 0x7A, 0x44, 0x84, 0x64, 0xC1, 0xC8, 0x0C, 0x96, 0x44, 0x09, 0x98, 0xFF, 0x92, 0xA8, 0xB4, 0xC6, 0x42, 0x28, 0x71 }; const u8 sks[] = { 0xD6, 0x4B, 0x7D, 0x72, 0x17, 0x59, 0x28, 0x05, 0xAF, 0xF9, 0xB7, 0xFF, 0x66, 0x6D, 0xA1, 0x96, 0x8F, 0x0B, 0x5E, 0x06, 0x46, 0x7A, 0x44, 0x84, 0x64, 0xC1, 0xC8, 0x0C, 0x96, 0x44, 0x09, 0x98, 0xFF, 0x92, 0xA8, 0xB4, 0xC6, 0x42, 0x28, 0x71 }; const u8 isk[] = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 }; const u8 imck[] = { 0x16, 0x15, 0x3C, 0x3F, 0x21, 0x55, 0xEF, 0xD9, 0x7F, 0x34, 0xAE, 0xC8, 0x1A, 0x4E, 0x66, 0x80, 0x4C, 0xC3, 0x76, 0xF2, 0x8A, 0xA9, 0x6F, 0x96, 0xC2, 0x54, 0x5F, 0x8C, 0xAB, 0x65, 0x02, 0xE1, 0x18, 0x40, 0x7B, 0x56, 0xBE, 0xEA, 0xA7, 0xC5, 0x76, 0x5D, 0x8F, 0x0B, 0xC5, 0x07, 0xC6, 0xB9, 0x04, 0xD0, 0x69, 0x56, 0x72, 0x8B, 0x6B, 0xB8, 0x15, 0xEC, 0x57, 0x7B }; const u8 msk[] = { 0x4D, 0x83, 0xA9, 0xBE, 0x6F, 0x8A, 0x74, 0xED, 0x6A, 0x02, 0x66, 0x0A, 0x63, 0x4D, 0x2C, 0x33, 0xC2, 0xDA, 0x60, 0x15, 0xC6, 0x37, 0x04, 0x51, 0x90, 0x38, 0x63, 0xDA, 0x54, 0x3E, 0x14, 0xB9, 0x27, 0x99, 0x18, 0x1E, 0x07, 0xBF, 0x0F, 0x5A, 0x5E, 0x3C, 0x32, 0x93, 0x80, 0x8C, 0x6C, 0x49, 0x67, 0xED, 0x24, 0xFE, 0x45, 0x40, 0xA0, 0x59, 0x5E, 0x37, 0xC2, 0xE9, 0xD0, 0x5D, 0x0A, 0xE3 }; const u8 emsk[] = { 0x3A, 0xD4, 0xAB, 0xDB, 0x76, 0xB2, 0x7F, 0x3B, 0xEA, 0x32, 0x2C, 0x2B, 0x74, 0xF4, 0x28, 0x55, 0xEF, 0x2D, 0xBA, 0x78, 0xC9, 0x57, 0x2F, 0x0D, 0x06, 0xCD, 0x51, 0x7C, 0x20, 0x93, 0x98, 0xA9, 0x76, 0xEA, 0x70, 0x21, 0xD7, 0x0E, 0x25, 0x54, 0x97, 0xED, 0xB2, 0x8A, 0xF6, 0xED, 0xFD, 0x0A, 0x2A, 0xE7, 0xA1, 0x58, 0x90, 0x10, 0x50, 0x44, 0xB3, 0x82, 0x85, 0xDB, 0x06, 0x14, 0xD2, 0xF9 }; /* RFC 4851, Appendix B.2 */ u8 tlv[] = { 0x80, 0x0C, 0x00, 0x38, 0x00, 0x01, 0x01, 0x00, 0xD8, 0x6A, 0x8C, 0x68, 0x3C, 0x32, 0x31, 0xA8, 0x56, 0x63, 0xB6, 0x40, 0x21, 0xFE, 0x21, 0x14, 0x4E, 0xE7, 0x54, 0x20, 0x79, 0x2D, 0x42, 0x62, 0xC9, 0xBF, 0x53, 0x7F, 0x54, 0xFD, 0xAC, 0x58, 0x43, 0x24, 0x6E, 0x30, 0x92, 0x17, 0x6D, 0xCF, 0xE6, 0xE0, 0x69, 0xEB, 0x33, 0x61, 0x6A, 0xCC, 0x05, 0xC5, 0x5B, 0xB7 }; const u8 compound_mac[] = { 0x43, 0x24, 0x6E, 0x30, 0x92, 0x17, 0x6D, 0xCF, 0xE6, 0xE0, 0x69, 0xEB, 0x33, 0x61, 0x6A, 0xCC, 0x05, 0xC5, 0x5B, 0xB7 }; u8 buf[512]; const u8 *simck, *cmk; int errors = 0; printf("EAP-FAST test cases\n"); printf("- T-PRF (SHA1) test case / master_secret\n"); sha1_t_prf(pac_key, sizeof(pac_key), "PAC to master secret label hash", seed, sizeof(seed), buf, sizeof(master_secret)); if (memcmp(master_secret, buf, sizeof(master_secret)) != 0) { printf("T-PRF test - FAILED!\n"); errors++; } printf("- PRF (TLS, SHA1/MD5) test case / key_block\n"); if (tls_prf(master_secret, sizeof(master_secret), "key expansion", seed, sizeof(seed), buf, sizeof(key_block)) || memcmp(key_block, buf, sizeof(key_block)) != 0) { printf("PRF test - FAILED!\n"); errors++; } printf("- T-PRF (SHA1) test case / IMCK\n"); sha1_t_prf(sks, sizeof(sks), "Inner Methods Compound Keys", isk, sizeof(isk), buf, sizeof(imck)); if (memcmp(imck, buf, sizeof(imck)) != 0) { printf("T-PRF test - FAILED!\n"); errors++; } simck = imck; cmk = imck + 40; printf("- T-PRF (SHA1) test case / MSK\n"); sha1_t_prf(simck, 40, "Session Key Generating Function", (u8 *) "", 0, buf, sizeof(msk)); if (memcmp(msk, buf, sizeof(msk)) != 0) { printf("T-PRF test - FAILED!\n"); errors++; } printf("- T-PRF (SHA1) test case / EMSK\n"); sha1_t_prf(simck, 40, "Extended Session Key Generating Function", (u8 *) "", 0, buf, sizeof(msk)); if (memcmp(emsk, buf, sizeof(emsk)) != 0) { printf("T-PRF test - FAILED!\n"); errors++; } printf("- Compound MAC test case\n"); memset(tlv + sizeof(tlv) - 20, 0, 20); hmac_sha1(cmk, 20, tlv, sizeof(tlv), tlv + sizeof(tlv) - 20); if (memcmp(tlv + sizeof(tlv) - 20, compound_mac, sizeof(compound_mac)) != 0) { printf("Compound MAC test - FAILED!\n"); errors++; } return errors; }