Files
MicrOBU/microbu-esp32c5/external/vanetza-idf/vanetza/security/pqc/hybrid_certificate.hpp
T
Ashin Walpola 0e9525162d Keep the colleague's microbu-esp32c5 tree in this repository
obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but
that tree was gitignored, so a clone of this repository could not build the
firmware it ships. It is now committed here as ordinary files in its own
folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP
bridge's signature verification (--trust) used on the bench. Nothing is
fetched from or pushed to the colleague's repository; this repository and
its remotes carry everything. The folder's own .gitignore keeps build output,
downloaded components and private key material out, as it did there; the
committed file set is identical to that repository's tracked files.

The ESP32-C5 is still flashed from obu-firmware/, which only takes
vanetza-idf from microbu-esp32c5/, so the two stay separate folders.
FLASHING.md says how to take a newer version of the colleague's tree (copy
it over the folder, rebuild, test, commit).
2026-09-23 17:46:40 +02:00

82 lines
2.5 KiB
C++

#pragma once
#include <vanetza/common/byte_buffer.hpp>
#include <vanetza/security/hash_algorithm.hpp>
#include <vanetza/security/pqc/fndsa512.hpp>
#include <boost/optional/optional.hpp>
namespace vanetza
{
namespace security
{
class Backend;
struct PrivateKey;
namespace v3
{
class Certificate;
class CertificateView;
} // namespace v3
namespace pqc
{
/** The two nested certificate signatures used by the experimental profile. */
enum class SignatureLayer
{
Alternative,
Primary,
};
/** Shape of the optional alternative material carried by a certificate. */
enum class MaterialState
{
None,
Authority,
EndEntity,
Inconsistent,
};
boost::optional<PublicKey> get_alternative_public_key(const v3::CertificateView&);
boost::optional<Signature> get_alternative_signature(const v3::CertificateView&);
MaterialState alternative_material_state(const v3::CertificateView&);
void set_alternative_public_key(v3::Certificate&, const PublicKey&);
void set_alternative_signature(v3::Certificate&, const Signature&);
void clear_alternative_public_key(v3::Certificate&);
void clear_alternative_signature(v3::Certificate&);
/**
* Calculate the certificate signature hash.
*
* The construction follows the IEEE 1609.2 certificate signature input:
* H(H(COER(toBeSigned)) || H(COER(canonical issuer certificate))). For a
* self-signed certificate the issuer input is empty. The alternative layer
* omits altSignatureValue from toBeSigned; the primary layer includes it.
*/
ByteBuffer calculate_certificate_hash(
::vanetza::security::Backend&, HashAlgorithm, const v3::CertificateView& subject,
const v3::CertificateView* issuer, SignatureLayer);
/** Sign or verify the outer, classical certificate signature. */
void sign_primary_certificate(
v3::Certificate&, const v3::CertificateView* issuer,
::vanetza::security::Backend&, const ::vanetza::security::PrivateKey& issuer_key);
bool verify_primary_certificate(
const v3::CertificateView&, const v3::CertificateView* issuer,
::vanetza::security::Backend&);
/** Sign or verify the inner FN-DSA-512 certificate signature. */
void sign_alternative_certificate(
v3::Certificate&, const v3::CertificateView* issuer,
::vanetza::security::Backend& hash_backend, Backend&,
const PrivateKey& issuer_key);
bool verify_alternative_certificate(
const v3::CertificateView&, const v3::CertificateView* issuer,
::vanetza::security::Backend&, Backend&);
} // namespace pqc
} // namespace security
} // namespace vanetza