You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 

149 lines
6.0 KiB

/*
* dm_crypto.c — криптография прямого чата (DM)
*/
#include "dm_crypto.h"
#include "../../lib/debug_config.h"
#define OPENSSL_API_COMPAT 0x10100000L
#include <openssl/evp.h>
#include <openssl/sha.h>
#include <string.h>
#include <stdio.h>
#define DM_ID "dm_crypto"
/* Медиа использует тот же ключ target, но отдельное пространство nonce. */
void dm_build_media_nonce(uint64_t author, const uint8_t media_id[16], uint64_t part, uint8_t nonce[DM_NONCE_SIZE]) {
SHA256_CTX ctx;
uint8_t hash[32];
SHA256_Init(&ctx);
SHA256_Update(&ctx, "utun_dm_media", 13);
SHA256_Update(&ctx, &author, sizeof(author));
SHA256_Update(&ctx, media_id, 16);
SHA256_Update(&ctx, &part, sizeof(part));
SHA256_Final(hash, &ctx);
memcpy(nonce, hash, DM_NONCE_SIZE);
}
uint64_t dm_derive_conv_id(uint64_t a, uint64_t b) {
uint64_t lo = a < b ? a : b;
uint64_t hi = a < b ? b : a;
SHA256_CTX ctx;
uint8_t hash[32];
SHA256_Init(&ctx);
SHA256_Update(&ctx, "utun_dm_v1", 9);
SHA256_Update(&ctx, &lo, 8);
SHA256_Update(&ctx, &hi, 8);
SHA256_Final(hash, &ctx);
uint64_t id;
memcpy(&id, hash, 8);
id &= 0x7FFFFFFFFFFFFFFFULL;
if (id == 0) id = 1;
return id;
}
int dm_derive_content_key(const uint8_t my_priv[32], const uint8_t peer_pub[32],
uint8_t out[DM_CONTENT_KEY_SIZE]) {
if (!my_priv || !peer_pub || !out) return -1;
EVP_PKEY* my_pkey = EVP_PKEY_new_raw_private_key(EVP_PKEY_X25519, NULL, my_priv, 32);
if (!my_pkey) { DEBUG_ERROR(DEBUG_CATEGORY_DM, "%s: EVP_PKEY_new_raw_private_key failed", DM_ID); return -1; }
EVP_PKEY* peer_pkey = EVP_PKEY_new_raw_public_key(EVP_PKEY_X25519, NULL, peer_pub, 32);
if (!peer_pkey) { EVP_PKEY_free(my_pkey); DEBUG_ERROR(DEBUG_CATEGORY_DM, "%s: EVP_PKEY_new_raw_public_key failed", DM_ID); return -1; }
EVP_PKEY_CTX* dctx = EVP_PKEY_CTX_new(my_pkey, NULL);
uint8_t shared[32];
size_t shared_len = sizeof(shared);
int rc = -1;
if (!dctx) goto out;
if (EVP_PKEY_derive_init(dctx) <= 0) goto out;
if (EVP_PKEY_derive_set_peer(dctx, peer_pkey) <= 0) goto out;
if (EVP_PKEY_derive(dctx, shared, &shared_len) <= 0 || shared_len != sizeof(shared)) goto out;
SHA256_CTX sctx;
SHA256_Init(&sctx);
SHA256_Update(&sctx, shared, sizeof(shared));
SHA256_Update(&sctx, "utun_dm_content", 15);
SHA256_Final(out, &sctx);
rc = 0;
out:
if (dctx) EVP_PKEY_CTX_free(dctx);
EVP_PKEY_free(my_pkey);
EVP_PKEY_free(peer_pkey);
if (rc != 0) DEBUG_ERROR(DEBUG_CATEGORY_DM, "%s: X25519 derive failed", DM_ID);
return rc;
}
void dm_build_nonce(uint64_t conv_id, uint64_t author, uint64_t seq, uint8_t nonce[DM_NONCE_SIZE]) {
SHA256_CTX ctx;
uint8_t hash[32];
SHA256_Init(&ctx);
SHA256_Update(&ctx, &conv_id, 8);
SHA256_Update(&ctx, &author, 8);
SHA256_Update(&ctx, &seq, 8);
SHA256_Final(hash, &ctx);
memcpy(nonce, hash, DM_NONCE_SIZE);
}
static int dm_ccm_crypt(const uint8_t key[DM_CONTENT_KEY_SIZE], const uint8_t nonce[DM_NONCE_SIZE],
const uint8_t* in, size_t in_len, uint8_t* out, size_t* out_len,
int encrypt, const uint8_t* tag_in) {
if (!key || !nonce || (!in && in_len) || !out || !out_len ||
(encrypt ? in_len > DM_CCM_PLAIN_MAX : in_len < DM_TAG_SIZE || in_len - DM_TAG_SIZE > DM_CCM_PLAIN_MAX)) {
DEBUG_ERROR(DEBUG_CATEGORY_DM, "%s: invalid CCM arguments encrypt=%d bytes=%zu", DM_ID, encrypt, in_len);
return -1;
}
*out_len = 0;
static const uint8_t empty = 0;
if (!in) in = &empty;
EVP_CIPHER_CTX* ectx = EVP_CIPHER_CTX_new();
if (!ectx) { DEBUG_ERROR(DEBUG_CATEGORY_DM, "%s: CCM context allocation failed", DM_ID); return -1; }
const EVP_CIPHER* cipher = EVP_aes_256_ccm();
int rc = -1;
if (encrypt) {
if (EVP_EncryptInit_ex(ectx, cipher, NULL, NULL, NULL) != 1
|| EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_IVLEN, DM_NONCE_SIZE, NULL) != 1
|| EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_TAG, DM_TAG_SIZE, NULL) != 1
|| EVP_EncryptInit_ex(ectx, NULL, NULL, key, nonce) != 1) goto done;
int outl;
if (EVP_EncryptUpdate(ectx, NULL, &outl, NULL, (int)in_len) != 1) goto done;
if (EVP_EncryptUpdate(ectx, out, &outl, in, (int)in_len) != 1 || outl != (int)in_len) goto done;
int tmpl;
if (EVP_EncryptFinal_ex(ectx, out + outl, &tmpl) != 1) goto done;
if (EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_GET_TAG, DM_TAG_SIZE, out + in_len) != 1) goto done;
*out_len = in_len + DM_TAG_SIZE;
} else {
if (in_len < DM_TAG_SIZE) goto done;
size_t body = in_len - DM_TAG_SIZE;
if (EVP_DecryptInit_ex(ectx, cipher, NULL, NULL, NULL) != 1
|| EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_IVLEN, DM_NONCE_SIZE, NULL) != 1
|| EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_TAG, DM_TAG_SIZE, (void*)(tag_in ? tag_in : in + body)) != 1
|| EVP_DecryptInit_ex(ectx, NULL, NULL, key, nonce) != 1) goto done;
int outl;
if (EVP_DecryptUpdate(ectx, NULL, &outl, NULL, (int)body) != 1) goto done;
if (EVP_DecryptUpdate(ectx, out, &outl, in, (int)body) != 1 || outl != (int)body) goto done;
*out_len = body;
}
rc = 0;
done:
EVP_CIPHER_CTX_free(ectx);
if (rc) DEBUG_ERROR(DEBUG_CATEGORY_DM, "%s: CCM %s failed bytes=%zu", DM_ID, encrypt ? "encrypt" : "decrypt", in_len);
return rc;
}
int dm_encrypt(const uint8_t key[DM_CONTENT_KEY_SIZE], const uint8_t nonce[DM_NONCE_SIZE],
const uint8_t* plain, size_t plain_len, uint8_t* out, size_t* out_len) {
return dm_ccm_crypt(key, nonce, plain, plain_len, out, out_len, 1, NULL);
}
int dm_decrypt(const uint8_t key[DM_CONTENT_KEY_SIZE], const uint8_t nonce[DM_NONCE_SIZE],
const uint8_t* ct, size_t ct_len, uint8_t* out, size_t* out_len) {
return dm_ccm_crypt(key, nonce, ct, ct_len, out, out_len, 0, NULL);
}