1
0
mirror of https://github.com/PurpleI2P/i2pd.git synced 2025-01-18 20:59:57 +00:00
i2pd/libi2pd/Crypto.h

407 lines
11 KiB
C
Raw Normal View History

/*
* Copyright (c) 2013-2020, The PurpleI2P Project
*
* This file is part of Purple i2pd project and licensed under BSD3
*
* See full license text in LICENSE file at top of project tree
*/
2015-11-03 09:15:49 -05:00
#ifndef CRYPTO_H__
#define CRYPTO_H__
2014-05-06 12:22:22 -04:00
#include <inttypes.h>
2015-11-03 09:15:49 -05:00
#include <string>
#include <vector>
2016-05-11 16:02:26 -04:00
#include <openssl/bn.h>
#include <openssl/dh.h>
#include <openssl/aes.h>
#include <openssl/dsa.h>
2016-11-09 15:59:01 -05:00
#include <openssl/ecdsa.h>
2016-11-04 10:59:55 -04:00
#include <openssl/rsa.h>
2016-05-11 16:02:26 -04:00
#include <openssl/sha.h>
2016-11-10 12:51:39 -05:00
#include <openssl/evp.h>
2016-05-11 16:02:26 -04:00
#include <openssl/rand.h>
2017-02-17 22:26:24 -05:00
#include <openssl/engine.h>
2018-09-08 16:52:42 -04:00
#include <openssl/opensslv.h>
2015-11-03 09:15:49 -05:00
#include "Base.h"
#include "Tag.h"
#include "CPU.h"
2014-05-06 12:22:22 -04:00
2018-09-08 16:52:42 -04:00
// recognize openssl version and features
#if ((OPENSSL_VERSION_NUMBER < 0x010100000) || defined(LIBRESSL_VERSION_NUMBER)) // 1.0.2 and below or LibreSSL
# define LEGACY_OPENSSL 1
# define X509_getm_notBefore X509_get_notBefore
# define X509_getm_notAfter X509_get_notAfter
2018-09-08 16:52:42 -04:00
#else
# define LEGACY_OPENSSL 0
# if (OPENSSL_VERSION_NUMBER >= 0x010101000) // 1.1.1
# define OPENSSL_HKDF 1
# define OPENSSL_EDDSA 1
# define OPENSSL_X25519 1
# define OPENSSL_SIPHASH 1
2018-09-08 16:52:42 -04:00
# endif
# if !defined OPENSSL_NO_CHACHA && !defined OPENSSL_NO_POLY1305 // some builds might not include them
# define OPENSSL_AEAD_CHACHA20_POLY1305 1
# endif
2018-09-08 16:52:42 -04:00
#endif
2014-05-06 12:22:22 -04:00
namespace i2p
{
namespace crypto
2015-11-03 09:15:49 -05:00
{
bool bn2buf (const BIGNUM * bn, uint8_t * buf, size_t len);
2015-11-03 09:15:49 -05:00
// DSA
2018-01-06 11:48:51 +08:00
DSA * CreateDSA ();
2015-11-03 09:15:49 -05:00
// RSA
const BIGNUM * GetRSAE ();
2015-11-03 09:15:49 -05:00
// DH
class DHKeys
{
public:
2018-01-06 11:48:51 +08:00
2015-11-03 09:15:49 -05:00
DHKeys ();
~DHKeys ();
2016-11-10 21:44:40 -05:00
void GenerateKeys ();
const uint8_t * GetPublicKey () const { return m_PublicKey; };
2015-11-03 09:15:49 -05:00
void Agree (const uint8_t * pub, uint8_t * shared);
2018-01-06 11:48:51 +08:00
2015-11-03 09:15:49 -05:00
private:
DH * m_DH;
uint8_t m_PublicKey[256];
2018-01-06 11:48:51 +08:00
};
2018-09-08 16:52:42 -04:00
// x25519
class X25519Keys
{
public:
X25519Keys ();
2019-06-11 10:40:53 -04:00
X25519Keys (const uint8_t * priv, const uint8_t * pub); // if pub is null, derive from priv
2018-09-08 16:52:42 -04:00
~X25519Keys ();
void GenerateKeys ();
const uint8_t * GetPublicKey () const { return m_PublicKey; };
2018-11-01 10:43:31 -04:00
void GetPrivateKey (uint8_t * priv) const;
void SetPrivateKey (const uint8_t * priv, bool calculatePublic = false);
2021-01-01 15:03:11 -05:00
bool Agree (const uint8_t * pub, uint8_t * shared);
2018-09-08 16:52:42 -04:00
bool IsElligatorIneligible () const { return m_IsElligatorIneligible; }
void SetElligatorIneligible () { m_IsElligatorIneligible = true; }
2018-09-08 16:52:42 -04:00
private:
uint8_t m_PublicKey[32];
2018-09-08 16:52:42 -04:00
#if OPENSSL_X25519
EVP_PKEY_CTX * m_Ctx;
EVP_PKEY * m_Pkey;
#else
2018-09-08 16:52:42 -04:00
BN_CTX * m_Ctx;
2018-09-09 08:38:12 -04:00
uint8_t m_PrivateKey[32];
#endif
bool m_IsElligatorIneligible = false; // true if definitly ineligible
2018-09-08 16:52:42 -04:00
};
2015-11-03 09:15:49 -05:00
// ElGamal
void ElGamalEncrypt (const uint8_t * key, const uint8_t * data, uint8_t * encrypted, BN_CTX * ctx, bool zeroPadding = false);
bool ElGamalDecrypt (const uint8_t * key, const uint8_t * encrypted, uint8_t * data, BN_CTX * ctx, bool zeroPadding = false);
2015-11-03 09:15:49 -05:00
void GenerateElGamalKeyPair (uint8_t * priv, uint8_t * pub);
2017-11-06 13:40:58 -05:00
// ECIES
void ECIESEncrypt (const EC_GROUP * curve, const EC_POINT * key, const uint8_t * data, uint8_t * encrypted, BN_CTX * ctx, bool zeroPadding = false); // 222 bytes data, 514 bytes encrypted with zeropadding, 512 without
bool ECIESDecrypt (const EC_GROUP * curve, const BIGNUM * key, const uint8_t * encrypted, uint8_t * data, BN_CTX * ctx, bool zeroPadding = false);
2017-11-06 13:40:58 -05:00
void GenerateECIESKeyPair (const EC_GROUP * curve, BIGNUM *& priv, EC_POINT *& pub);
2018-01-06 11:48:51 +08:00
2015-11-03 09:15:49 -05:00
// HMAC
2018-01-06 11:48:51 +08:00
typedef i2p::data::Tag<32> MACKey;
2015-11-03 09:15:49 -05:00
void HMACMD5Digest (uint8_t * msg, size_t len, const MACKey& key, uint8_t * digest);
// AES
2018-01-06 11:48:51 +08:00
struct ChipherBlock
2014-05-06 12:22:22 -04:00
{
uint8_t buf[16];
2014-05-09 11:44:39 -04:00
2014-05-09 12:05:04 -04:00
void operator^=(const ChipherBlock& other) // XOR
2014-05-09 11:44:39 -04:00
{
2018-11-27 14:33:31 -05:00
if (!(((size_t)buf | (size_t)other.buf) & 0x03)) // multiple of 4 ?
{
2018-11-27 14:33:31 -05:00
for (int i = 0; i < 4; i++)
reinterpret_cast<uint32_t *>(buf)[i] ^= reinterpret_cast<const uint32_t *>(other.buf)[i];
}
2018-11-25 10:33:48 -05:00
else
{
2018-11-25 10:33:48 -05:00
for (int i = 0; i < 16; i++)
buf[i] ^= other.buf[i];
}
2018-01-06 11:48:51 +08:00
}
2014-05-06 12:22:22 -04:00
};
2014-11-01 14:56:13 -04:00
typedef i2p::data::Tag<32> AESKey;
2018-01-06 11:48:51 +08:00
2014-11-18 12:11:45 -05:00
template<size_t sz>
class AESAlignedBuffer // 16 bytes alignment
{
public:
2018-01-06 11:48:51 +08:00
2014-11-18 12:11:45 -05:00
AESAlignedBuffer ()
{
m_Buf = m_UnalignedBuffer;
2014-11-26 11:04:49 -05:00
uint8_t rem = ((size_t)m_Buf) & 0x0f;
2014-11-18 12:11:45 -05:00
if (rem)
m_Buf += (16 - rem);
}
2018-01-06 11:48:51 +08:00
2014-11-18 12:11:45 -05:00
operator uint8_t * () { return m_Buf; };
operator const uint8_t * () const { return m_Buf; };
2016-11-21 21:13:13 -05:00
ChipherBlock * GetChipherBlock () { return (ChipherBlock *)m_Buf; };
const ChipherBlock * GetChipherBlock () const { return (const ChipherBlock *)m_Buf; };
2018-01-06 11:48:51 +08:00
2014-11-18 12:11:45 -05:00
private:
uint8_t m_UnalignedBuffer[sz + 15]; // up to 15 bytes alignment
uint8_t * m_Buf;
2018-01-06 11:48:51 +08:00
};
2014-11-18 12:11:45 -05:00
#ifdef __AES__
2014-05-07 15:40:24 -04:00
class ECBCryptoAESNI
2018-01-06 11:48:51 +08:00
{
2014-05-08 21:43:08 -04:00
public:
2014-05-12 22:51:59 -04:00
uint8_t * GetKeySchedule () { return m_KeySchedule; };
2014-11-18 12:11:45 -05:00
protected:
2014-11-01 21:53:45 -04:00
void ExpandKey (const AESKey& key);
2018-01-06 11:48:51 +08:00
2014-11-18 12:11:45 -05:00
private:
AESAlignedBuffer<240> m_KeySchedule; // 14 rounds for AES-256, 240 bytes
2018-01-06 11:48:51 +08:00
};
#endif
#ifdef __AES__
class ECBEncryption: public ECBCryptoAESNI
#else
2014-05-08 16:49:00 -04:00
class ECBEncryption
#endif
2014-05-08 16:49:00 -04:00
{
public:
2018-01-06 11:48:51 +08:00
void SetKey (const AESKey& key);
void Encrypt(const ChipherBlock * in, ChipherBlock * out);
2014-05-08 16:49:00 -04:00
private:
AES_KEY m_Key;
2018-01-06 11:48:51 +08:00
};
2014-05-08 16:49:00 -04:00
#ifdef __AES__
class ECBDecryption: public ECBCryptoAESNI
#else
2014-05-08 16:49:00 -04:00
class ECBDecryption
#endif
2014-05-08 16:49:00 -04:00
{
public:
2018-01-06 11:48:51 +08:00
void SetKey (const AESKey& key);
void Decrypt (const ChipherBlock * in, ChipherBlock * out);
2014-05-08 16:49:00 -04:00
private:
2015-11-03 09:15:49 -05:00
AES_KEY m_Key;
2018-01-06 11:48:51 +08:00
};
2014-05-08 16:49:00 -04:00
2014-05-06 12:22:22 -04:00
class CBCEncryption
{
public:
2018-01-06 11:48:51 +08:00
2016-11-21 21:13:13 -05:00
CBCEncryption () { memset ((uint8_t *)m_LastBlock, 0, 16); };
2014-05-06 12:22:22 -04:00
2014-11-01 21:53:45 -04:00
void SetKey (const AESKey& key) { m_ECBEncryption.SetKey (key); }; // 32 bytes
2016-11-21 21:13:13 -05:00
void SetIV (const uint8_t * iv) { memcpy ((uint8_t *)m_LastBlock, iv, 16); }; // 16 bytes
2018-06-13 14:56:51 -04:00
void GetIV (uint8_t * iv) const { memcpy (iv, (const uint8_t *)m_LastBlock, 16); };
2014-05-06 12:22:22 -04:00
void Encrypt (int numBlocks, const ChipherBlock * in, ChipherBlock * out);
void Encrypt (const uint8_t * in, std::size_t len, uint8_t * out);
2014-05-14 14:54:01 -04:00
void Encrypt (const uint8_t * in, uint8_t * out); // one block
2014-05-06 12:22:22 -04:00
ECBEncryption & ECB() { return m_ECBEncryption; }
2014-05-06 12:22:22 -04:00
private:
2016-11-21 21:13:13 -05:00
AESAlignedBuffer<16> m_LastBlock;
2018-01-06 11:48:51 +08:00
2014-05-08 21:43:08 -04:00
ECBEncryption m_ECBEncryption;
2014-05-06 12:22:22 -04:00
};
class CBCDecryption
{
public:
2018-01-06 11:48:51 +08:00
2016-11-21 21:13:13 -05:00
CBCDecryption () { memset ((uint8_t *)m_IV, 0, 16); };
2014-05-06 12:22:22 -04:00
2014-11-01 21:53:45 -04:00
void SetKey (const AESKey& key) { m_ECBDecryption.SetKey (key); }; // 32 bytes
2016-11-21 21:13:13 -05:00
void SetIV (const uint8_t * iv) { memcpy ((uint8_t *)m_IV, iv, 16); }; // 16 bytes
2018-06-13 14:56:51 -04:00
void GetIV (uint8_t * iv) const { memcpy (iv, (const uint8_t *)m_IV, 16); };
2014-05-06 12:22:22 -04:00
void Decrypt (int numBlocks, const ChipherBlock * in, ChipherBlock * out);
void Decrypt (const uint8_t * in, std::size_t len, uint8_t * out);
2014-05-14 14:54:01 -04:00
void Decrypt (const uint8_t * in, uint8_t * out); // one block
2014-05-06 12:22:22 -04:00
ECBDecryption & ECB() { return m_ECBDecryption; }
2014-05-06 12:22:22 -04:00
private:
2016-11-21 21:13:13 -05:00
AESAlignedBuffer<16> m_IV;
2014-05-08 21:43:08 -04:00
ECBDecryption m_ECBDecryption;
2018-01-06 11:48:51 +08:00
};
2014-05-15 11:21:41 -04:00
class TunnelEncryption // with double IV encryption
{
public:
2014-11-01 21:53:45 -04:00
void SetKeys (const AESKey& layerKey, const AESKey& ivKey)
2014-05-15 11:21:41 -04:00
{
m_LayerEncryption.SetKey (layerKey);
m_IVEncryption.SetKey (ivKey);
2018-01-06 11:48:51 +08:00
}
2014-05-15 11:21:41 -04:00
2018-01-06 11:48:51 +08:00
void Encrypt (const uint8_t * in, uint8_t * out); // 1024 bytes (16 IV + 1008 data)
2014-05-15 11:21:41 -04:00
private:
ECBEncryption m_IVEncryption;
CBCEncryption m_LayerEncryption;
};
class TunnelDecryption // with double IV encryption
{
public:
2014-11-01 21:53:45 -04:00
void SetKeys (const AESKey& layerKey, const AESKey& ivKey)
2014-05-15 11:21:41 -04:00
{
m_LayerDecryption.SetKey (layerKey);
m_IVDecryption.SetKey (ivKey);
2018-01-06 11:48:51 +08:00
}
2014-05-15 11:21:41 -04:00
2018-01-06 11:48:51 +08:00
void Decrypt (const uint8_t * in, uint8_t * out); // 1024 bytes (16 IV + 1008 data)
2014-05-15 11:21:41 -04:00
private:
ECBDecryption m_IVDecryption;
CBCDecryption m_LayerDecryption;
2018-01-06 11:48:51 +08:00
};
2018-06-13 11:41:46 -04:00
// AEAD/ChaCha20/Poly1305
bool AEADChaCha20Poly1305 (const uint8_t * msg, size_t msgLen, const uint8_t * ad, size_t adLen, const uint8_t * key, const uint8_t * nonce, uint8_t * buf, size_t len, bool encrypt); // msgLen is len without tag
2018-12-04 12:54:48 -05:00
void AEADChaCha20Poly1305Encrypt (const std::vector<std::pair<uint8_t *, size_t> >& bufs, const uint8_t * key, const uint8_t * nonce, uint8_t * mac); // encrypt multiple buffers with zero ad
2019-03-15 12:25:20 -04:00
// ChaCha20
2019-02-28 13:31:51 -05:00
void ChaCha20 (const uint8_t * msg, size_t msgLen, const uint8_t * key, const uint8_t * nonce, uint8_t * out);
2019-03-15 12:25:20 -04:00
// HKDF
void HKDF (const uint8_t * salt, const uint8_t * key, size_t keyLen, const std::string& info, uint8_t * out, size_t outLen = 64); // salt - 32, out - 32 or 64, info <= 32
2019-03-15 12:25:20 -04:00
2020-10-28 21:53:11 -04:00
// Noise
struct NoiseSymmetricState
{
uint8_t m_H[32] /*h*/, m_CK[64] /*[ck, k]*/;
2020-10-28 21:53:11 -04:00
void MixHash (const uint8_t * buf, size_t len);
void MixKey (const uint8_t * sharedSecret);
};
void InitNoiseNState (NoiseSymmetricState& state, const uint8_t * pub); // Noise_N (tunnels, router)
void InitNoiseXKState (NoiseSymmetricState& state, const uint8_t * pub); // Noise_XK (NTCP2)
void InitNoiseIKState (NoiseSymmetricState& state, const uint8_t * pub); // Noise_IK (ratchets)
2018-06-13 11:41:46 -04:00
// init and terminate
void InitCrypto (bool precomputation, bool aesni, bool avx, bool force);
2015-12-31 16:02:10 -05:00
void TerminateCrypto ();
2018-01-06 11:48:51 +08:00
}
}
2016-10-12 12:31:27 -04:00
2018-09-08 16:52:42 -04:00
// take care about openssl below 1.1.0
#if LEGACY_OPENSSL
2016-10-12 12:31:27 -04:00
// define getters and setters introduced in 1.1.0
2018-01-06 11:48:51 +08:00
inline int DSA_set0_pqg(DSA *d, BIGNUM *p, BIGNUM *q, BIGNUM *g)
{
2017-04-05 17:44:23 -04:00
if (d->p) BN_free (d->p);
if (d->q) BN_free (d->q);
if (d->g) BN_free (d->g);
2018-01-06 11:48:51 +08:00
d->p = p; d->q = q; d->g = g; return 1;
2017-04-05 17:44:23 -04:00
}
2018-01-06 11:48:51 +08:00
inline int DSA_set0_key(DSA *d, BIGNUM *pub_key, BIGNUM *priv_key)
{
2017-04-05 17:44:23 -04:00
if (d->pub_key) BN_free (d->pub_key);
if (d->priv_key) BN_free (d->priv_key);
2018-01-06 11:48:51 +08:00
d->pub_key = pub_key; d->priv_key = priv_key; return 1;
}
inline void DSA_get0_key(const DSA *d, const BIGNUM **pub_key, const BIGNUM **priv_key)
2016-11-04 10:59:55 -04:00
{ *pub_key = d->pub_key; *priv_key = d->priv_key; }
2018-01-06 11:48:51 +08:00
inline int DSA_SIG_set0(DSA_SIG *sig, BIGNUM *r, BIGNUM *s)
{
2017-04-05 18:26:56 -04:00
if (sig->r) BN_free (sig->r);
if (sig->s) BN_free (sig->s);
2018-01-06 11:48:51 +08:00
sig->r = r; sig->s = s; return 1;
2017-04-05 18:26:56 -04:00
}
2018-01-06 11:48:51 +08:00
inline void DSA_SIG_get0(const DSA_SIG *sig, const BIGNUM **pr, const BIGNUM **ps)
2016-11-04 10:59:55 -04:00
{ *pr = sig->r; *ps = sig->s; }
2016-11-09 15:59:01 -05:00
inline int ECDSA_SIG_set0(ECDSA_SIG *sig, BIGNUM *r, BIGNUM *s)
2018-01-06 11:48:51 +08:00
{
2016-11-23 16:30:36 -05:00
if (sig->r) BN_free (sig->r);
if (sig->s) BN_free (sig->s);
2018-01-06 11:48:51 +08:00
sig->r = r; sig->s = s; return 1;
2016-11-23 16:30:36 -05:00
}
2016-11-09 15:59:01 -05:00
inline void ECDSA_SIG_get0(const ECDSA_SIG *sig, const BIGNUM **pr, const BIGNUM **ps)
{ *pr = sig->r; *ps = sig->s; }
2018-01-06 11:48:51 +08:00
inline int RSA_set0_key(RSA *r, BIGNUM *n, BIGNUM *e, BIGNUM *d)
2017-04-05 18:26:56 -04:00
{
if (r->n) BN_free (r->n);
if (r->e) BN_free (r->e);
if (r->d) BN_free (r->d);
2018-01-06 11:48:51 +08:00
r->n = n; r->e = e; r->d = d; return 1;
2017-04-05 18:26:56 -04:00
}
2016-11-04 10:59:55 -04:00
inline void RSA_get0_key(const RSA *r, const BIGNUM **n, const BIGNUM **e, const BIGNUM **d)
{ *n = r->n; *e = r->e; *d = r->d; }
2016-10-12 12:31:27 -04:00
2016-11-08 13:11:38 -05:00
inline int DH_set0_pqg(DH *dh, BIGNUM *p, BIGNUM *q, BIGNUM *g)
2018-01-06 11:48:51 +08:00
{
2017-04-05 18:26:56 -04:00
if (dh->p) BN_free (dh->p);
if (dh->q) BN_free (dh->q);
if (dh->g) BN_free (dh->g);
2018-01-06 11:48:51 +08:00
dh->p = p; dh->q = q; dh->g = g; return 1;
2017-04-05 18:26:56 -04:00
}
2016-11-08 13:11:38 -05:00
inline int DH_set0_key(DH *dh, BIGNUM *pub_key, BIGNUM *priv_key)
2018-01-06 11:48:51 +08:00
{
if (dh->pub_key) BN_free (dh->pub_key);
2016-11-08 13:11:38 -05:00
if (dh->priv_key) BN_free (dh->priv_key);
2018-01-06 11:48:51 +08:00
dh->pub_key = pub_key; dh->priv_key = priv_key; return 1;
2016-11-08 13:11:38 -05:00
}
inline void DH_get0_key(const DH *dh, const BIGNUM **pub_key, const BIGNUM **priv_key)
{ *pub_key = dh->pub_key; *priv_key = dh->priv_key; }
2016-11-10 12:51:39 -05:00
inline RSA *EVP_PKEY_get0_RSA(EVP_PKEY *pkey)
{ return pkey->pkey.rsa; }
2017-01-23 16:22:48 -05:00
2017-02-17 22:26:24 -05:00
inline EVP_MD_CTX *EVP_MD_CTX_new ()
{ return EVP_MD_CTX_create(); }
inline void EVP_MD_CTX_free (EVP_MD_CTX *ctx)
{ EVP_MD_CTX_destroy (ctx); }
2017-01-23 16:22:48 -05:00
// ssl
#define TLS_method TLSv1_method
2016-10-12 12:31:27 -04:00
#endif
2014-05-06 12:22:22 -04:00
#endif