45#ifndef PQCEE_SAFEQUARD_API_H
46#define PQCEE_SAFEQUARD_API_H
56#define SAFEQUARD_LOG_LEVEL_ERROR 1
61#define SAFEQUARD_LOG_LEVEL_WARN 2
66#define SAFEQUARD_LOG_LEVEL_INFO 3
71#define SAFEQUARD_LOG_LEVEL_DEBUG 4
79#define SAFEQUARD_LOG_MESSAGE_CAPACITY 64
84#define ML_DSA_65_SEED_SIZE 32
89#define ML_DSA_65_PUBLIC_KEY_SIZE 1952
94#define ML_DSA_65_SIGNATURE_SIZE 3309
99#define ML_KEM_768_SEED_SIZE 64
104#define ML_KEM_768_ENCAP_KEY_SIZE 1184
109#define ML_KEM_768_DECAP_KEY_SIZE 2400
114#define ML_KEM_768_CIPHERTEXT_SIZE 1088
119#define ML_KEM_SHARED_SECRET_SIZE 32
124#define ML_KEM_SHARED_SECRET_IV_SIZE 16
129#define SHA_512_BLOCK_SIZE 128
134#define SHA_512_DIGEST_SIZE 64
139#define SAFEQUARD_SUCCESS 0
144#define SAFEQUARD_ERROR_INVALID_LOG_LEVEL -1
149#define SAFEQUARD_ERROR_GENERIC -1000
154#define SAFEQUARD_ERROR_NOT_SUPPORTED -1001
159#define SAFEQUARD_ERROR_NOT_PERMITTED -1002
164#define SAFEQUARD_ERROR_BUFFER_TOO_SMALL -1003
169#define SAFEQUARD_ERROR_ALREADY_EXISTS -1004
174#define SAFEQUARD_ERROR_DOES_NOT_EXIST -1005
179#define SAFEQUARD_ERROR_BAD_STATE -1006
184#define SAFEQUARD_ERROR_INVALID_ARGUMENT -1007
189#define SAFEQUARD_ERROR_INSUFFICIENT_MEMORY -1008
194#define SAFEQUARD_ERROR_INSUFFICIENT_STORAGE -1009
199#define SAFEQUARD_ERROR_COMMUNICATION_FAILURE -1010
204#define SAFEQUARD_ERROR_STORAGE_FAILURE -1011
209#define SAFEQUARD_ERROR_DATA_CORRUPT -1012
214#define SAFEQUARD_ERROR_DATA_INVALID -1013
219#define SAFEQUARD_ERROR_HARDWARE_FAILURE -1014
224#define SAFEQUARD_ERROR_CORRUPTION_DETECTED -1015
229#define SAFEQUARD_ERROR_INSUFFICIENT_ENTROPY -1016
234#define SAFEQUARD_ERROR_INVALID_SIGNATURE -1017
239#define SAFEQUARD_ERROR_INVALID_PADDING -1018
244#define SAFEQUARD_ERROR_INSUFFICIENT_DATA -1019
249#define SAFEQUARD_ERROR_INVALID_HANDLE -1020
254#define SAFEQUARD_ERROR_BACKEND -1099
260#define SAFEQUARD_ERROR_MALFORMED_DER -1100
265#define SAFEQUARD_ERROR_TRAILING_DATA -1101
272#define SAFEQUARD_ERROR_UNSUPPORTED_ALGORITHM -1102
278#define SAFEQUARD_ERROR_INVALID_PUBLIC_KEY -1103
285#define SAFEQUARD_ERROR_ROOT_NOT_SELF_ISSUED -1105
294#define SAFEQUARD_ERROR_INVALID_ROOT_SIGNATURE -1106
300#define SAFEQUARD_ERROR_INVALID_TIME -1107
305#define SAFEQUARD_ERROR_TIME_SOURCE_UNAVAILABLE -1108
311#define SAFEQUARD_ERROR_CERTIFICATE_NOT_YET_VALID -1109
317#define SAFEQUARD_ERROR_CERTIFICATE_EXPIRED -1110
323#define SAFEQUARD_ERROR_ISSUER_MISMATCH -1111
331#define SAFEQUARD_ERROR_CERTIFICATE_MUST_BE_V3 -1112
337#define SAFEQUARD_ERROR_DUPLICATE_EXTENSION -1113
346#define SAFEQUARD_ERROR_UNKNOWN_CRITICAL_EXTENSION -1114
352#define SAFEQUARD_ERROR_MISSING_BASIC_CONSTRAINTS -1115
357#define SAFEQUARD_ERROR_BASIC_CONSTRAINTS_NOT_CRITICAL -1116
363#define SAFEQUARD_ERROR_EXPECTED_CA -1117
368#define SAFEQUARD_ERROR_LEAF_IS_CA -1118
373#define SAFEQUARD_ERROR_MISSING_KEY_USAGE -1119
378#define SAFEQUARD_ERROR_KEY_USAGE_NOT_CRITICAL -1120
384#define SAFEQUARD_ERROR_INVALID_CA_KEY_USAGE -1121
393#define SAFEQUARD_ERROR_INVALID_LEAF_KEY_USAGE -1122
399#define SAFEQUARD_ERROR_MISSING_EXTENDED_KEY_USAGE -1123
405#define SAFEQUARD_ERROR_EXTENDED_KEY_USAGE_NOT_CRITICAL -1124
411#define SAFEQUARD_ERROR_INVALID_CODE_SIGNING_USAGE -1125
417#define SAFEQUARD_ERROR_PATH_LENGTH_EXCEEDED -1126
423#define SAFEQUARD_ERROR_TOO_MANY_INTERMEDIATES -1127
429#define SAFEQUARD_ERROR_INVALID_PKCS8 -1128
438#define SAFEQUARD_ERROR_PKCS8_DECRYPTION_FAILED -1129
444#define SAFEQUARD_ERROR_INVALID_PRIVATE_KEY_ALGORITHM -1130
452#define SAFEQUARD_ERROR_SEED_NOT_AVAILABLE -1131
458#define SAFEQUARD_ERROR_INVALID_SEED_ENCODING -1132
507 size_t signature_size);
529 size_t public_key_size,
532 const uint8_t *signature,
533 size_t signature_size);
563 const uint8_t *trusted_cert,
564 size_t trusted_cert_size,
565 const uint8_t *leaf_cert,
566 size_t leaf_cert_size,
595 const uint8_t *signature,
596 size_t signature_size);
629 size_t encap_key_size,
649 const uint8_t *encap_key,
650 size_t encap_key_size,
652 size_t ciphertext_size,
653 uint8_t *encrypted_message,
654 size_t encrypted_message_size);
676 const uint8_t *encrypted_message,
677 size_t encrypted_message_size,
678 const uint8_t *ciphertext,
679 size_t ciphertext_size,
681 size_t message_size);
740 const uint8_t *chunk,
void safequard_panic_wrap(void)
Panic the current thread.
int safequard_mlkem768_init(uint8_t *context, size_t context_size, uint8_t *encap_key, size_t encap_key_size, size_t *out)
Generate a new ML-KEM-768 keypair for encrypting and decrypting messages.
int safequard_sha512_update(uint8_t *context, size_t context_size, const uint8_t *chunk, size_t chunk_size)
Update a SHA-512 context for streaming hashing operations.
int safequard_mlkem768_finalise(uint8_t *context, size_t context_size)
Finalise the decryption process.
int safequard_mldsa65_sign(const uint8_t *seed, size_t seed_size, const uint8_t *data, size_t data_size, uint8_t *signature, size_t signature_size)
Sign an ML-DSA-65 message.
int safequard_sha512(const uint8_t *message, size_t message_size, uint8_t *hash, size_t hash_size)
Compute a SHA-512 digest of a message.
int safequard_init(uint32_t max_log_level)
Initialise the safequard_api library.
int safequard_mlkem768_decrypt(const uint8_t *context, size_t context_size, const uint8_t *encrypted_message, size_t encrypted_message_size, const uint8_t *ciphertext, size_t ciphertext_size, uint8_t *message, size_t message_size)
Decrypt an ML-KEM-768 encrypted message.
int safequard_sha512_init(uint8_t *context, size_t context_size, size_t *out)
Generate a new SHA-512 context for streaming hash operations.
int safequard_mlkem768_encrypt(const uint8_t *message, size_t message_size, const uint8_t *encap_key, size_t encap_key_size, uint8_t *ciphertext, size_t ciphertext_size, uint8_t *encrypted_message, size_t encrypted_message_size)
Encrypt a message using an encapsulation key.
int safequard_fv_import_key(uint8_t *context, size_t context_size, const uint8_t *trusted_cert, size_t trusted_cert_size, const uint8_t *leaf_cert, size_t leaf_cert_size, size_t *out)
Import an ML-DSA-65 public key to prepare for verification.
int safequard_sha512_finalise(uint8_t *context, size_t context_size, uint8_t *hash, size_t hash_size)
Finalise a SHA-512 operation and receive the hash.
void safequard_log_message(uint32_t level, const char *message, size_t message_length)
Log a message.
int safequard_fv_verify(const uint8_t *context, size_t context_size, const uint8_t *data, size_t data_size, const uint8_t *signature, size_t signature_size)
Verify an ML-DSA-65-signed data using a certificate trust chain.
int64_t get_current_time(void)
Get the current unix time.
int safequard_mldsa65_verify(const uint8_t *public_key, size_t public_key_size, const uint8_t *data, size_t data_size, const uint8_t *signature, size_t signature_size)
Verify an ML-DSA-65-signed data.