2020-05-22 16:18:41 +03:00
|
|
|
/*
|
|
|
|
* Copyright (c) 2013-2020, The PurpleI2P Project
|
|
|
|
*
|
|
|
|
* This file is part of Purple i2pd project and licensed under BSD3
|
|
|
|
*
|
|
|
|
* See full license text in LICENSE file at top of project tree
|
|
|
|
*/
|
|
|
|
|
2020-01-15 15:13:43 -05:00
|
|
|
#ifndef ECIES_X25519_AEAD_RATCHET_SESSION_H__
|
|
|
|
#define ECIES_X25519_AEAD_RATCHET_SESSION_H__
|
|
|
|
|
2020-01-16 19:33:00 -05:00
|
|
|
#include <string.h>
|
2020-01-15 15:13:43 -05:00
|
|
|
#include <inttypes.h>
|
|
|
|
#include <functional>
|
2020-01-21 14:40:23 -05:00
|
|
|
#include <memory>
|
2020-01-17 11:21:41 -05:00
|
|
|
#include <vector>
|
2020-03-26 19:03:38 -04:00
|
|
|
#include <list>
|
2020-04-16 21:30:18 -04:00
|
|
|
#include <unordered_map>
|
2020-01-15 15:13:43 -05:00
|
|
|
#include "Identity.h"
|
2020-01-16 16:34:13 -05:00
|
|
|
#include "Crypto.h"
|
2020-01-16 14:59:19 -05:00
|
|
|
#include "Garlic.h"
|
2020-04-16 21:30:18 -04:00
|
|
|
#include "Tag.h"
|
2020-01-15 15:13:43 -05:00
|
|
|
|
|
|
|
namespace i2p
|
|
|
|
{
|
|
|
|
namespace garlic
|
|
|
|
{
|
2020-05-23 15:58:11 -04:00
|
|
|
const int ECIESX25519_RESTART_TIMEOUT = 120; // number of second since session creation we can restart session after
|
2020-04-30 21:27:35 -04:00
|
|
|
const int ECIESX25519_EXPIRATION_TIMEOUT = 480; // in seconds
|
2020-07-15 16:20:35 -04:00
|
|
|
const int ECIESX25519_INACTIVITY_TIMEOUT = 90; // number of seconds we receive nothing and should restart if we can
|
|
|
|
const int ECIESX25519_SEND_INACTIVITY_TIMEOUT = 5000; // number of milliseconds we can send empty(pyaload only) packet after
|
2020-04-30 21:27:35 -04:00
|
|
|
const int ECIESX25519_INCOMING_TAGS_EXPIRATION_TIMEOUT = 600; // in seconds
|
|
|
|
const int ECIESX25519_PREVIOUS_TAGSET_EXPIRATION_TIMEOUT = 180; // 180
|
2020-05-05 13:01:23 -04:00
|
|
|
const int ECIESX25519_TAGSET_MAX_NUM_TAGS = 4096; // number of tags we request new tagset after
|
2020-04-30 21:27:35 -04:00
|
|
|
const int ECIESX25519_MIN_NUM_GENERATED_TAGS = 24;
|
|
|
|
const int ECIESX25519_MAX_NUM_GENERATED_TAGS = 160;
|
|
|
|
const int ECIESX25519_NSR_NUM_GENERATED_TAGS = 12;
|
2020-03-01 13:25:50 +03:00
|
|
|
|
|
|
|
const size_t ECIESX25519_OPTIMAL_PAYLOAD_SIZE = 1912; // 1912 = 1956 /* to fit 2 tunnel messages */
|
2020-05-18 16:42:06 -04:00
|
|
|
// - 16 /* I2NP header */ - 16 /* poly hash */ - 8 /* tag */ - 4 /* garlic length */
|
2020-03-01 13:25:50 +03:00
|
|
|
|
2020-04-24 15:46:02 -04:00
|
|
|
class ECIESX25519AEADRatchetSession;
|
2020-09-15 19:39:18 -04:00
|
|
|
class RatchetTagSet: public std::enable_shared_from_this<RatchetTagSet>
|
2020-03-01 13:25:50 +03:00
|
|
|
{
|
|
|
|
public:
|
|
|
|
|
|
|
|
RatchetTagSet (std::shared_ptr<ECIESX25519AEADRatchetSession> session): m_Session (session) {};
|
|
|
|
|
|
|
|
void DHInitialize (const uint8_t * rootKey, const uint8_t * k);
|
|
|
|
void NextSessionTagRatchet ();
|
|
|
|
uint64_t GetNextSessionTag ();
|
2020-04-24 21:36:08 -04:00
|
|
|
const uint8_t * GetNextRootKey () const { return m_NextRootKey; };
|
2020-03-01 13:25:50 +03:00
|
|
|
int GetNextIndex () const { return m_NextIndex; };
|
2020-03-07 18:46:40 -05:00
|
|
|
void GetSymmKey (int index, uint8_t * key);
|
2020-09-08 07:46:55 -04:00
|
|
|
void DeleteSymmKey (int index);
|
2020-04-24 15:46:02 -04:00
|
|
|
|
|
|
|
std::shared_ptr<ECIESX25519AEADRatchetSession> GetSession () { return m_Session.lock (); };
|
2020-04-24 21:36:08 -04:00
|
|
|
int GetTagSetID () const { return m_TagSetID; };
|
|
|
|
void SetTagSetID (int tagsetID) { m_TagSetID = tagsetID; };
|
2020-09-08 07:46:55 -04:00
|
|
|
void SetTrimBehind (int index) { if (index > m_TrimBehindIndex) m_TrimBehindIndex = index; };
|
2020-04-30 21:27:35 -04:00
|
|
|
|
|
|
|
void Expire ();
|
|
|
|
bool IsExpired (uint64_t ts) const { return m_ExpirationTimestamp && ts > m_ExpirationTimestamp; };
|
2020-09-15 19:39:18 -04:00
|
|
|
virtual bool IsIndexExpired (int index) const { return m_Session.expired () || index < m_TrimBehindIndex; };
|
|
|
|
|
|
|
|
virtual bool HandleNextMessage (uint8_t * buf, size_t len, int index);
|
2020-09-07 18:45:05 -04:00
|
|
|
|
2020-02-08 21:51:02 -05:00
|
|
|
private:
|
2020-03-01 13:25:50 +03:00
|
|
|
|
|
|
|
union
|
|
|
|
{
|
|
|
|
uint64_t ll[8];
|
|
|
|
uint8_t buf[64];
|
|
|
|
|
|
|
|
const uint8_t * GetSessTagCK () const { return buf; }; // sessTag_chainKey = keydata[0:31]
|
|
|
|
const uint8_t * GetSessTagConstant () const { return buf + 32; }; // SESSTAG_CONSTANT = keydata[32:63]
|
|
|
|
uint64_t GetTag () const { return ll[4]; }; // tag = keydata[32:39]
|
|
|
|
|
|
|
|
} m_KeyData;
|
|
|
|
uint8_t m_SessTagConstant[32], m_SymmKeyCK[32], m_CurrentSymmKeyCK[64], m_NextRootKey[32];
|
2020-09-07 18:45:05 -04:00
|
|
|
int m_NextIndex, m_NextSymmKeyIndex, m_TrimBehindIndex = 0;
|
2020-03-01 13:25:50 +03:00
|
|
|
std::unordered_map<int, i2p::data::Tag<32> > m_ItermediateSymmKeys;
|
|
|
|
std::weak_ptr<ECIESX25519AEADRatchetSession> m_Session;
|
|
|
|
int m_TagSetID = 0;
|
|
|
|
uint64_t m_ExpirationTimestamp = 0;
|
|
|
|
};
|
|
|
|
|
2020-06-04 18:19:38 -04:00
|
|
|
class NSRatchetTagSet: public RatchetTagSet
|
|
|
|
{
|
|
|
|
public:
|
|
|
|
|
|
|
|
NSRatchetTagSet (std::shared_ptr<ECIESX25519AEADRatchetSession> session):
|
|
|
|
RatchetTagSet (session), m_DummySession (session) {};
|
|
|
|
|
|
|
|
private:
|
|
|
|
|
|
|
|
std::shared_ptr<ECIESX25519AEADRatchetSession> m_DummySession; // we need a strong pointer for NS
|
|
|
|
};
|
2020-09-15 19:39:18 -04:00
|
|
|
|
|
|
|
class DatabaseLookupTagSet: public RatchetTagSet
|
|
|
|
{
|
|
|
|
public:
|
|
|
|
|
|
|
|
DatabaseLookupTagSet (GarlicDestination * destination, const uint8_t * key);
|
|
|
|
|
|
|
|
bool IsIndexExpired (int index) const { return false; };
|
|
|
|
bool HandleNextMessage (uint8_t * buf, size_t len, int index);
|
|
|
|
|
|
|
|
private:
|
|
|
|
|
|
|
|
GarlicDestination * m_Destination;
|
|
|
|
uint8_t m_Key[32];
|
|
|
|
};
|
2020-06-04 18:19:38 -04:00
|
|
|
|
2020-03-01 13:25:50 +03:00
|
|
|
enum ECIESx25519BlockType
|
2020-01-15 15:13:43 -05:00
|
|
|
{
|
2020-03-01 13:25:50 +03:00
|
|
|
eECIESx25519BlkDateTime = 0,
|
|
|
|
eECIESx25519BlkSessionID = 1,
|
2020-01-15 15:13:43 -05:00
|
|
|
eECIESx25519BlkTermination = 4,
|
2020-03-01 13:25:50 +03:00
|
|
|
eECIESx25519BlkOptions = 5,
|
|
|
|
eECIESx25519BlkNextKey = 7,
|
|
|
|
eECIESx25519BlkAck = 8,
|
|
|
|
eECIESx25519BlkAckRequest = 9,
|
|
|
|
eECIESx25519BlkGalicClove = 11,
|
|
|
|
eECIESx25519BlkPadding = 254
|
|
|
|
};
|
2020-01-15 15:13:43 -05:00
|
|
|
|
2020-04-24 21:36:08 -04:00
|
|
|
const uint8_t ECIESX25519_NEXT_KEY_KEY_PRESENT_FLAG = 0x01;
|
|
|
|
const uint8_t ECIESX25519_NEXT_KEY_REVERSE_KEY_FLAG = 0x02;
|
|
|
|
const uint8_t ECIESX25519_NEXT_KEY_REQUEST_REVERSE_KEY_FLAG = 0x04;
|
2020-03-01 13:25:50 +03:00
|
|
|
|
|
|
|
class ECIESX25519AEADRatchetSession: public GarlicRoutingSession, public std::enable_shared_from_this<ECIESX25519AEADRatchetSession>
|
|
|
|
{
|
|
|
|
enum SessionState
|
|
|
|
{
|
|
|
|
eSessionStateNew = 0,
|
|
|
|
eSessionStateNewSessionReceived,
|
2020-02-03 16:21:07 -05:00
|
|
|
eSessionStateNewSessionSent,
|
2020-04-02 21:48:39 -04:00
|
|
|
eSessionStateNewSessionReplySent,
|
2020-03-01 13:25:50 +03:00
|
|
|
eSessionStateEstablished
|
|
|
|
};
|
2020-01-17 11:21:41 -05:00
|
|
|
|
2020-04-25 21:09:03 -04:00
|
|
|
struct DHRatchet
|
|
|
|
{
|
|
|
|
int keyID = 0;
|
2020-06-30 13:00:41 -04:00
|
|
|
std::shared_ptr<i2p::crypto::X25519Keys> key;
|
2020-04-25 21:09:03 -04:00
|
|
|
uint8_t remote[32]; // last remote public key
|
2020-04-26 19:27:31 -04:00
|
|
|
bool newKey = true;
|
2020-03-01 13:25:50 +03:00
|
|
|
};
|
2020-01-15 15:13:43 -05:00
|
|
|
|
2020-03-01 13:25:50 +03:00
|
|
|
public:
|
|
|
|
|
|
|
|
ECIESX25519AEADRatchetSession (GarlicDestination * owner, bool attachLeaseSet);
|
|
|
|
~ECIESX25519AEADRatchetSession ();
|
2020-01-15 15:13:43 -05:00
|
|
|
|
2020-05-12 18:30:04 -04:00
|
|
|
bool HandleNextMessage (uint8_t * buf, size_t len, std::shared_ptr<RatchetTagSet> receiveTagset, int index = 0);
|
2020-03-01 13:25:50 +03:00
|
|
|
std::shared_ptr<I2NPMessage> WrapSingleMessage (std::shared_ptr<const I2NPMessage> msg);
|
|
|
|
|
|
|
|
const uint8_t * GetRemoteStaticKey () const { return m_RemoteStaticKey; }
|
2020-01-16 19:33:00 -05:00
|
|
|
void SetRemoteStaticKey (const uint8_t * key) { memcpy (m_RemoteStaticKey, key, 32); }
|
2020-01-15 15:13:43 -05:00
|
|
|
|
2020-01-30 11:48:32 -05:00
|
|
|
void SetDestination (const i2p::data::IdentHash& dest) // TODO:
|
|
|
|
{
|
|
|
|
if (!m_Destination) m_Destination.reset (new i2p::data::IdentHash (dest));
|
|
|
|
}
|
2020-03-01 13:25:50 +03:00
|
|
|
|
2020-03-14 16:35:34 -04:00
|
|
|
bool CheckExpired (uint64_t ts); // true is expired
|
2020-05-23 10:20:22 -04:00
|
|
|
bool CanBeRestarted (uint64_t ts) const { return ts > m_SessionCreatedTimestamp + ECIESX25519_RESTART_TIMEOUT; }
|
2020-05-23 15:58:11 -04:00
|
|
|
bool IsInactive (uint64_t ts) const { return ts > m_LastActivityTimestamp + ECIESX25519_INACTIVITY_TIMEOUT && CanBeRestarted (ts); }
|
|
|
|
|
2020-05-02 11:13:40 -04:00
|
|
|
bool IsRatchets () const { return true; };
|
2020-10-27 08:32:38 -04:00
|
|
|
bool IsReadyToSend () const { return m_State != eSessionStateNewSessionSent; };
|
2020-07-15 16:20:35 -04:00
|
|
|
uint64_t GetLastActivityTimestamp () const { return m_LastActivityTimestamp; };
|
2020-03-01 13:25:50 +03:00
|
|
|
|
|
|
|
private:
|
2020-01-15 15:13:43 -05:00
|
|
|
|
2020-01-22 21:42:30 -05:00
|
|
|
void ResetKeys ();
|
2020-03-01 13:25:50 +03:00
|
|
|
void MixHash (const uint8_t * buf, size_t len);
|
2020-02-05 15:48:51 -05:00
|
|
|
void CreateNonce (uint64_t seqn, uint8_t * nonce);
|
2020-03-01 13:25:50 +03:00
|
|
|
bool GenerateEphemeralKeysAndEncode (uint8_t * buf); // buf is 32 bytes
|
2020-04-24 15:46:02 -04:00
|
|
|
std::shared_ptr<RatchetTagSet> CreateNewSessionTagset ();
|
2020-01-15 15:13:43 -05:00
|
|
|
|
2020-02-03 16:21:07 -05:00
|
|
|
bool HandleNewIncomingSession (const uint8_t * buf, size_t len);
|
2020-03-01 13:25:50 +03:00
|
|
|
bool HandleNewOutgoingSessionReply (uint8_t * buf, size_t len);
|
2020-05-12 18:30:04 -04:00
|
|
|
bool HandleExistingSessionMessage (uint8_t * buf, size_t len, std::shared_ptr<RatchetTagSet> receiveTagset, int index);
|
2020-03-01 13:25:50 +03:00
|
|
|
void HandlePayload (const uint8_t * buf, size_t len, const std::shared_ptr<RatchetTagSet>& receiveTagset, int index);
|
2020-04-24 21:36:08 -04:00
|
|
|
void HandleNextKey (const uint8_t * buf, size_t len, const std::shared_ptr<RatchetTagSet>& receiveTagset);
|
2020-03-01 13:25:50 +03:00
|
|
|
|
|
|
|
bool NewOutgoingSessionMessage (const uint8_t * payload, size_t len, uint8_t * out, size_t outLen);
|
|
|
|
bool NewSessionReplyMessage (const uint8_t * payload, size_t len, uint8_t * out, size_t outLen);
|
2020-04-02 21:48:39 -04:00
|
|
|
bool NextNewSessionReplyMessage (const uint8_t * payload, size_t len, uint8_t * out, size_t outLen);
|
2020-02-05 15:48:51 -05:00
|
|
|
bool NewExistingSessionMessage (const uint8_t * payload, size_t len, uint8_t * out, size_t outLen);
|
2020-03-01 13:25:50 +03:00
|
|
|
|
|
|
|
std::vector<uint8_t> CreatePayload (std::shared_ptr<const I2NPMessage> msg, bool first);
|
2020-07-29 17:47:46 -04:00
|
|
|
size_t CreateGarlicClove (std::shared_ptr<const I2NPMessage> msg, uint8_t * buf, size_t len);
|
2020-05-13 18:09:26 -04:00
|
|
|
size_t CreateLeaseSetClove (std::shared_ptr<const i2p::data::LocalLeaseSet> ls, uint64_t ts, uint8_t * buf, size_t len);
|
2020-03-01 13:25:50 +03:00
|
|
|
|
2020-04-24 21:36:08 -04:00
|
|
|
void GenerateMoreReceiveTags (std::shared_ptr<RatchetTagSet> receiveTagset, int numTags);
|
2020-04-26 19:27:31 -04:00
|
|
|
void NewNextSendRatchet ();
|
2020-01-15 15:13:43 -05:00
|
|
|
|
2020-03-01 13:25:50 +03:00
|
|
|
private:
|
|
|
|
|
|
|
|
uint8_t m_H[32], m_CK[64] /* [chainkey, key] */, m_RemoteStaticKey[32];
|
2020-04-02 21:48:39 -04:00
|
|
|
uint8_t m_Aepk[32]; // Alice's ephemeral keys, for incoming only
|
2020-04-28 18:23:13 -04:00
|
|
|
uint8_t m_NSREncodedKey[32], m_NSRH[32], m_NSRKey[32]; // new session reply, for incoming only
|
2020-06-30 13:00:41 -04:00
|
|
|
std::shared_ptr<i2p::crypto::X25519Keys> m_EphemeralKeys;
|
2020-03-01 13:25:50 +03:00
|
|
|
SessionState m_State = eSessionStateNew;
|
2020-07-15 16:20:35 -04:00
|
|
|
uint64_t m_SessionCreatedTimestamp = 0, m_LastActivityTimestamp = 0, // incoming
|
|
|
|
m_LastSentTimestamp = 0; // in milliseconds
|
2020-06-04 18:19:38 -04:00
|
|
|
std::shared_ptr<RatchetTagSet> m_SendTagset, m_NSRSendTagset;
|
2020-03-01 13:25:50 +03:00
|
|
|
std::unique_ptr<i2p::data::IdentHash> m_Destination;// TODO: might not need it
|
2020-03-31 17:35:51 -04:00
|
|
|
std::list<std::pair<uint16_t, int> > m_AckRequests; // (tagsetid, index)
|
2020-04-26 19:27:31 -04:00
|
|
|
bool m_SendReverseKey = false, m_SendForwardKey = false;
|
|
|
|
std::unique_ptr<DHRatchet> m_NextReceiveRatchet, m_NextSendRatchet;
|
2020-06-13 21:24:16 -04:00
|
|
|
uint8_t m_PaddingSizes[32], m_NextPaddingSize;
|
|
|
|
|
2020-04-29 20:50:31 -04:00
|
|
|
public:
|
|
|
|
|
|
|
|
// for HTTP only
|
|
|
|
int GetState () const { return (int)m_State; }
|
|
|
|
i2p::data::IdentHash GetDestination () const
|
|
|
|
{
|
|
|
|
return m_Destination ? *m_Destination : i2p::data::IdentHash ();
|
2020-03-01 13:25:50 +03:00
|
|
|
}
|
|
|
|
};
|
2020-04-07 11:40:18 -04:00
|
|
|
|
|
|
|
std::shared_ptr<I2NPMessage> WrapECIESX25519AEADRatchetMessage (std::shared_ptr<const I2NPMessage> msg, const uint8_t * key, uint64_t tag);
|
2020-01-15 15:13:43 -05:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
#endif
|