Files
MicrOBU/obu-firmware/external/vanetza-idf/vanetza/security/pqc/hybrid_certificate.hpp
T
Ashin Walpola d107534eb2 Keep vanetza-idf in obu-firmware, so a plain clone builds the firmware
obu-firmware builds against the vanetza-idf C-ITS library, which until now
came from the colleague's microbu-esp32c5 tree beside the repository and was
not tracked here, so a clone of this repository could not build the firmware
it ships. The library alone is now part of obu-firmware, as
obu-firmware/external/vanetza-idf: their external/vanetza-idf at commit
cf4b99f, unchanged (9775 files; see its PROVENANCE.md). CMake takes it from
there by default; -DVANETZA_IDF_DIR still points the build elsewhere.

The rest of the colleague's tree (their own VAM firmware, PKI tooling,
station-link Python tools, the V2X2MAP bridge) stays out of this repository
and gitignored; nothing is pushed to their repository. NOTES.md, docs/06,
TODO.md and the pcap verifier's usage line point at the new location.
2026-09-24 10:56:05 +02:00

82 lines
2.5 KiB
C++

#pragma once
#include <vanetza/common/byte_buffer.hpp>
#include <vanetza/security/hash_algorithm.hpp>
#include <vanetza/security/pqc/fndsa512.hpp>
#include <boost/optional/optional.hpp>
namespace vanetza
{
namespace security
{
class Backend;
struct PrivateKey;
namespace v3
{
class Certificate;
class CertificateView;
} // namespace v3
namespace pqc
{
/** The two nested certificate signatures used by the experimental profile. */
enum class SignatureLayer
{
Alternative,
Primary,
};
/** Shape of the optional alternative material carried by a certificate. */
enum class MaterialState
{
None,
Authority,
EndEntity,
Inconsistent,
};
boost::optional<PublicKey> get_alternative_public_key(const v3::CertificateView&);
boost::optional<Signature> get_alternative_signature(const v3::CertificateView&);
MaterialState alternative_material_state(const v3::CertificateView&);
void set_alternative_public_key(v3::Certificate&, const PublicKey&);
void set_alternative_signature(v3::Certificate&, const Signature&);
void clear_alternative_public_key(v3::Certificate&);
void clear_alternative_signature(v3::Certificate&);
/**
* Calculate the certificate signature hash.
*
* The construction follows the IEEE 1609.2 certificate signature input:
* H(H(COER(toBeSigned)) || H(COER(canonical issuer certificate))). For a
* self-signed certificate the issuer input is empty. The alternative layer
* omits altSignatureValue from toBeSigned; the primary layer includes it.
*/
ByteBuffer calculate_certificate_hash(
::vanetza::security::Backend&, HashAlgorithm, const v3::CertificateView& subject,
const v3::CertificateView* issuer, SignatureLayer);
/** Sign or verify the outer, classical certificate signature. */
void sign_primary_certificate(
v3::Certificate&, const v3::CertificateView* issuer,
::vanetza::security::Backend&, const ::vanetza::security::PrivateKey& issuer_key);
bool verify_primary_certificate(
const v3::CertificateView&, const v3::CertificateView* issuer,
::vanetza::security::Backend&);
/** Sign or verify the inner FN-DSA-512 certificate signature. */
void sign_alternative_certificate(
v3::Certificate&, const v3::CertificateView* issuer,
::vanetza::security::Backend& hash_backend, Backend&,
const PrivateKey& issuer_key);
bool verify_alternative_certificate(
const v3::CertificateView&, const v3::CertificateView* issuer,
::vanetza::security::Backend&, Backend&);
} // namespace pqc
} // namespace security
} // namespace vanetza