2018-06-11 13:44:49 +00:00
|
|
|
#include <llarp/crypto.hpp>
|
2018-06-10 14:05:48 +00:00
|
|
|
#include <llarp/encrypted_frame.hpp>
|
2018-06-11 13:25:10 +00:00
|
|
|
#include "logger.hpp"
|
2018-06-18 22:03:50 +00:00
|
|
|
#include "mem.hpp"
|
2018-06-10 14:05:48 +00:00
|
|
|
|
|
|
|
namespace llarp
|
|
|
|
{
|
2018-06-22 00:25:30 +00:00
|
|
|
Encrypted::Encrypted()
|
|
|
|
{
|
|
|
|
UpdateBuffer();
|
|
|
|
}
|
|
|
|
|
2018-06-21 12:55:02 +00:00
|
|
|
Encrypted::Encrypted(const byte_t* buf, size_t sz) : _sz(sz)
|
2018-06-10 14:05:48 +00:00
|
|
|
{
|
2018-06-21 12:55:02 +00:00
|
|
|
_data = new byte_t[sz];
|
2018-06-11 13:25:10 +00:00
|
|
|
if(buf)
|
2018-06-19 17:11:24 +00:00
|
|
|
memcpy(data(), buf, sz);
|
2018-06-18 22:03:50 +00:00
|
|
|
else
|
2018-06-19 17:11:24 +00:00
|
|
|
llarp::Zero(data(), sz);
|
2018-06-21 12:55:02 +00:00
|
|
|
UpdateBuffer();
|
|
|
|
}
|
|
|
|
Encrypted::~Encrypted()
|
|
|
|
{
|
|
|
|
if(_data)
|
|
|
|
delete[] _data;
|
2018-06-10 14:05:48 +00:00
|
|
|
}
|
|
|
|
|
2018-06-11 13:25:10 +00:00
|
|
|
Encrypted::Encrypted(size_t sz) : Encrypted(nullptr, sz)
|
2018-06-10 14:05:48 +00:00
|
|
|
{
|
|
|
|
}
|
|
|
|
|
2018-06-11 13:44:49 +00:00
|
|
|
bool
|
|
|
|
EncryptedFrame::EncryptInPlace(byte_t* ourSecretKey, byte_t* otherPubkey,
|
|
|
|
llarp_crypto* crypto)
|
|
|
|
{
|
|
|
|
// format of frame is
|
|
|
|
// <32 bytes keyed hash of following data>
|
|
|
|
// <32 bytes nonce>
|
|
|
|
// <32 bytes pubkey>
|
|
|
|
// <N bytes encrypted payload>
|
|
|
|
//
|
2018-06-19 17:11:24 +00:00
|
|
|
byte_t* hash = data();
|
2018-06-12 11:57:14 +00:00
|
|
|
byte_t* nonce = hash + SHORTHASHSIZE;
|
|
|
|
byte_t* pubkey = nonce + TUNNONCESIZE;
|
|
|
|
byte_t* body = pubkey + PUBKEYSIZE;
|
2018-06-11 13:44:49 +00:00
|
|
|
|
2018-06-12 11:57:14 +00:00
|
|
|
SharedSecret shared;
|
2018-06-11 13:44:49 +00:00
|
|
|
|
|
|
|
auto DH = crypto->dh_client;
|
|
|
|
auto Encrypt = crypto->xchacha20;
|
|
|
|
auto MDS = crypto->hmac;
|
|
|
|
|
|
|
|
llarp_buffer_t buf;
|
|
|
|
buf.base = body;
|
|
|
|
buf.cur = buf.base;
|
2018-06-19 17:11:24 +00:00
|
|
|
buf.sz = size() - EncryptedFrame::OverheadSize;
|
2018-06-11 13:44:49 +00:00
|
|
|
|
|
|
|
// set our pubkey
|
2018-06-12 11:57:14 +00:00
|
|
|
memcpy(pubkey, llarp::seckey_topublic(ourSecretKey), PUBKEYSIZE);
|
2018-06-11 13:44:49 +00:00
|
|
|
// randomize nonce
|
2018-06-12 11:57:14 +00:00
|
|
|
crypto->randbytes(nonce, TUNNONCESIZE);
|
2018-06-11 13:44:49 +00:00
|
|
|
|
|
|
|
// derive shared key
|
2018-06-20 12:34:48 +00:00
|
|
|
if(!DH(shared, otherPubkey, ourSecretKey, nonce))
|
2018-06-11 13:44:49 +00:00
|
|
|
{
|
|
|
|
llarp::Error("DH failed");
|
|
|
|
return false;
|
|
|
|
}
|
2018-06-20 12:34:48 +00:00
|
|
|
|
2018-06-11 13:44:49 +00:00
|
|
|
// encrypt body
|
|
|
|
if(!Encrypt(buf, shared, nonce))
|
|
|
|
{
|
|
|
|
llarp::Error("encrypt failed");
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
// generate message auth
|
|
|
|
buf.base = nonce;
|
|
|
|
buf.cur = buf.base;
|
2018-06-19 17:11:24 +00:00
|
|
|
buf.sz = size() - SHORTHASHSIZE;
|
2018-06-11 13:44:49 +00:00
|
|
|
|
|
|
|
if(!MDS(hash, buf, shared))
|
|
|
|
{
|
|
|
|
llarp::Error("Failed to generate messgae auth");
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2018-06-10 14:05:48 +00:00
|
|
|
bool
|
2018-06-11 13:25:10 +00:00
|
|
|
EncryptedFrame::DecryptInPlace(byte_t* ourSecretKey, llarp_crypto* crypto)
|
2018-06-10 14:05:48 +00:00
|
|
|
{
|
2018-06-19 17:11:24 +00:00
|
|
|
if(size() <= size_t(EncryptedFrame::OverheadSize))
|
2018-06-11 13:25:10 +00:00
|
|
|
{
|
2018-06-19 17:11:24 +00:00
|
|
|
llarp::Warn("encrypted frame too small, ", size(),
|
2018-06-18 22:03:50 +00:00
|
|
|
" <= ", size_t(EncryptedFrame::OverheadSize));
|
2018-06-11 13:25:10 +00:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
// format of frame is
|
|
|
|
// <32 bytes keyed hash of following data>
|
|
|
|
// <32 bytes nonce>
|
|
|
|
// <32 bytes pubkey>
|
|
|
|
// <N bytes encrypted payload>
|
|
|
|
//
|
2018-06-19 17:11:24 +00:00
|
|
|
byte_t* hash = data();
|
2018-06-12 11:57:14 +00:00
|
|
|
byte_t* nonce = hash + SHORTHASHSIZE;
|
|
|
|
byte_t* otherPubkey = nonce + TUNNONCESIZE;
|
|
|
|
byte_t* body = otherPubkey + PUBKEYSIZE;
|
2018-06-11 13:25:10 +00:00
|
|
|
|
|
|
|
// use dh_server becuase we are not the creator of this message
|
|
|
|
auto DH = crypto->dh_server;
|
|
|
|
auto Decrypt = crypto->xchacha20;
|
2018-06-11 13:44:49 +00:00
|
|
|
auto MDS = crypto->hmac;
|
2018-06-11 13:25:10 +00:00
|
|
|
|
|
|
|
llarp_buffer_t buf;
|
2018-06-11 13:44:49 +00:00
|
|
|
buf.base = nonce;
|
2018-06-11 13:25:10 +00:00
|
|
|
buf.cur = buf.base;
|
2018-06-19 17:11:24 +00:00
|
|
|
buf.sz = size() - SHORTHASHSIZE;
|
2018-06-11 13:25:10 +00:00
|
|
|
|
2018-06-12 11:57:14 +00:00
|
|
|
SharedSecret shared;
|
|
|
|
ShortHash digest;
|
2018-06-11 13:25:10 +00:00
|
|
|
|
2018-06-20 12:34:48 +00:00
|
|
|
if(!DH(shared, otherPubkey, ourSecretKey, nonce))
|
2018-06-11 13:25:10 +00:00
|
|
|
{
|
|
|
|
llarp::Error("DH failed");
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2018-06-11 13:44:49 +00:00
|
|
|
if(!MDS(digest, buf, shared))
|
2018-06-11 13:25:10 +00:00
|
|
|
{
|
|
|
|
llarp::Error("Digest failed");
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2018-06-12 11:57:14 +00:00
|
|
|
if(memcmp(digest, hash, digest.size()))
|
2018-06-11 13:25:10 +00:00
|
|
|
{
|
|
|
|
llarp::Error("message authentication failed");
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2018-06-11 13:44:49 +00:00
|
|
|
buf.base = body;
|
|
|
|
buf.cur = body;
|
2018-06-19 17:11:24 +00:00
|
|
|
buf.sz = size() - EncryptedFrame::OverheadSize;
|
2018-06-11 13:44:49 +00:00
|
|
|
|
2018-06-11 13:25:10 +00:00
|
|
|
if(!Decrypt(buf, shared, nonce))
|
|
|
|
{
|
|
|
|
llarp::Error("decrypt failed");
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
return true;
|
2018-06-10 14:05:48 +00:00
|
|
|
}
|
2018-06-18 22:03:50 +00:00
|
|
|
} // namespace llarp
|