lokinet/llarp/encrypted_frame.cpp

148 lines
3.3 KiB
C++
Raw Normal View History

2018-06-11 13:44:49 +00:00
#include <llarp/crypto.hpp>
2018-06-10 14:05:48 +00:00
#include <llarp/encrypted_frame.hpp>
2018-06-11 13:25:10 +00:00
#include "logger.hpp"
2018-06-10 14:05:48 +00:00
2018-06-14 20:13:07 +00:00
#define OverheadSize (PUBKEYSIZE + TUNNONCESIZE + SHORTHASHSIZE)
2018-06-10 14:05:48 +00:00
namespace llarp
{
2018-06-11 13:25:10 +00:00
Encrypted::Encrypted(const byte_t* buf, size_t sz)
2018-06-10 14:05:48 +00:00
{
2018-06-11 13:25:10 +00:00
size = sz;
data = new byte_t[sz];
if(buf)
memcpy(data, buf, sz);
m_Buffer.base = data;
m_Buffer.cur = data;
m_Buffer.sz = size;
2018-06-10 14:05:48 +00:00
}
2018-06-11 13:25:10 +00:00
Encrypted::Encrypted(size_t sz) : Encrypted(nullptr, sz)
2018-06-10 14:05:48 +00:00
{
}
2018-06-11 13:25:10 +00:00
Encrypted::~Encrypted()
2018-06-10 14:05:48 +00:00
{
2018-06-11 13:25:10 +00:00
if(data)
delete[] data;
2018-06-10 14:05:48 +00:00
}
2018-06-11 13:44:49 +00:00
bool
EncryptedFrame::EncryptInPlace(byte_t* ourSecretKey, byte_t* otherPubkey,
llarp_crypto* crypto)
{
// format of frame is
// <32 bytes keyed hash of following data>
// <32 bytes nonce>
// <32 bytes pubkey>
// <N bytes encrypted payload>
//
byte_t* hash = data;
byte_t* nonce = hash + SHORTHASHSIZE;
byte_t* pubkey = nonce + TUNNONCESIZE;
byte_t* body = pubkey + PUBKEYSIZE;
2018-06-11 13:44:49 +00:00
SharedSecret shared;
2018-06-11 13:44:49 +00:00
auto DH = crypto->dh_client;
auto Encrypt = crypto->xchacha20;
auto MDS = crypto->hmac;
llarp_buffer_t buf;
buf.base = body;
buf.cur = buf.base;
buf.sz = size - OverheadSize;
// set our pubkey
memcpy(pubkey, llarp::seckey_topublic(ourSecretKey), PUBKEYSIZE);
2018-06-11 13:44:49 +00:00
// randomize nonce
crypto->randbytes(nonce, TUNNONCESIZE);
2018-06-11 13:44:49 +00:00
// derive shared key
if(!DH(shared, otherPubkey, nonce, ourSecretKey))
{
llarp::Error("DH failed");
return false;
}
// encrypt body
if(!Encrypt(buf, shared, nonce))
{
llarp::Error("encrypt failed");
return false;
}
// generate message auth
buf.base = nonce;
buf.cur = buf.base;
buf.sz = size - SHORTHASHSIZE;
2018-06-11 13:44:49 +00:00
if(!MDS(hash, buf, shared))
{
llarp::Error("Failed to generate messgae auth");
return false;
}
return true;
}
2018-06-10 14:05:48 +00:00
bool
2018-06-11 13:25:10 +00:00
EncryptedFrame::DecryptInPlace(byte_t* ourSecretKey, llarp_crypto* crypto)
2018-06-10 14:05:48 +00:00
{
2018-06-11 13:25:10 +00:00
if(size <= OverheadSize)
{
llarp::Warn("encrypted frame too small, ", size, " <= ", OverheadSize);
return false;
}
// format of frame is
// <32 bytes keyed hash of following data>
// <32 bytes nonce>
// <32 bytes pubkey>
// <N bytes encrypted payload>
//
byte_t* hash = data;
byte_t* nonce = hash + SHORTHASHSIZE;
byte_t* otherPubkey = nonce + TUNNONCESIZE;
byte_t* body = otherPubkey + PUBKEYSIZE;
2018-06-11 13:25:10 +00:00
// use dh_server becuase we are not the creator of this message
auto DH = crypto->dh_server;
auto Decrypt = crypto->xchacha20;
2018-06-11 13:44:49 +00:00
auto MDS = crypto->hmac;
2018-06-11 13:25:10 +00:00
llarp_buffer_t buf;
2018-06-11 13:44:49 +00:00
buf.base = nonce;
2018-06-11 13:25:10 +00:00
buf.cur = buf.base;
buf.sz = size - SHORTHASHSIZE;
2018-06-11 13:25:10 +00:00
SharedSecret shared;
ShortHash digest;
2018-06-11 13:25:10 +00:00
if(!DH(shared, otherPubkey, nonce, ourSecretKey))
{
llarp::Error("DH failed");
return false;
}
2018-06-11 13:44:49 +00:00
if(!MDS(digest, buf, shared))
2018-06-11 13:25:10 +00:00
{
llarp::Error("Digest failed");
return false;
}
if(memcmp(digest, hash, digest.size()))
2018-06-11 13:25:10 +00:00
{
llarp::Error("message authentication failed");
return false;
}
2018-06-11 13:44:49 +00:00
buf.base = body;
buf.cur = body;
buf.sz = size - OverheadSize;
2018-06-11 13:25:10 +00:00
if(!Decrypt(buf, shared, nonce))
{
llarp::Error("decrypt failed");
return false;
}
return true;
2018-06-10 14:05:48 +00:00
}
}