You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
123 lines
4.6 KiB
123 lines
4.6 KiB
// secure_channel.h |
|
#ifndef SECURE_CHANNEL_H |
|
#define SECURE_CHANNEL_H |
|
|
|
#ifdef __cplusplus |
|
extern "C" { |
|
#endif |
|
|
|
|
|
#include <stdint.h> |
|
#include <stddef.h> |
|
|
|
// Размеры ключей |
|
#define SC_PRIVKEY_SIZE 32 |
|
#define SC_PUBKEY_SIZE 32 |
|
#define SC_HASH_SIZE 32 |
|
#define SC_NONCE_SIZE 13 // CCM requires exactly 13 bytes |
|
#define SC_SHARED_SECRET_SIZE SC_HASH_SIZE |
|
#define SC_SESSION_KEY_SIZE 16 |
|
#define SC_TAG_SIZE 16 |
|
#define SC_CRC32_SIZE 4 |
|
|
|
// Обфускация pubkey при передаче (salt + double SHA256 XOR) |
|
#define SC_PUBKEY_ENC_SALT_SIZE 8 |
|
#define SC_PUBKEY_ENC_SIZE (SC_PUBKEY_SIZE + SC_PUBKEY_ENC_SALT_SIZE) |
|
|
|
// Коды возврата |
|
#define SC_OK 0 |
|
#define SC_ERR_INVALID_ARG -1 |
|
#define SC_ERR_CRYPTO -2 |
|
#define SC_ERR_NOT_INITIALIZED -3 |
|
#define SC_ERR_AUTH_FAILED -4 |
|
#define SC_ERR_CRC_FAILED -5 |
|
|
|
#define SC_PEER_PUBKEY_BIN 0 |
|
#define SC_PEER_PUBKEY_HEX 1 |
|
|
|
// Типы |
|
typedef int sc_status_t; |
|
typedef struct secure_channel sc_context_t; |
|
|
|
struct SC_MYKEYS { |
|
/* Локальные ключи */ |
|
uint8_t private_key[SC_PRIVKEY_SIZE]; |
|
uint8_t public_key[SC_PUBKEY_SIZE]; |
|
}; |
|
|
|
// Контекст защищенного канала |
|
struct secure_channel { |
|
struct SC_MYKEYS* pk; |
|
/* Ключ пира (после key exchange) */ |
|
uint8_t peer_public_key[SC_PUBKEY_SIZE]; |
|
uint8_t session_key[SC_SESSION_KEY_SIZE]; /* Derived session key */ |
|
|
|
uint8_t initialized; |
|
uint8_t peer_key_set; |
|
uint8_t session_ready; |
|
uint64_t tx_counter; |
|
uint64_t rx_counter; |
|
}; |
|
|
|
// Функции инициализации |
|
sc_status_t sc_init_ctx(sc_context_t *ctx, struct SC_MYKEYS *mykeys); |
|
sc_status_t sc_generate_keypair(struct SC_MYKEYS *keys); |
|
sc_status_t sc_init_local_keys(struct SC_MYKEYS *mykeys, const char *public_key, const char *private_key); |
|
sc_status_t sc_set_peer_public_key(sc_context_t *ctx, const uint8_t *peer_public_key, int mode);// mode: 0-bin 1-hex key format |
|
sc_status_t sc_compute_public_key_from_private(const uint8_t *private_key, uint8_t *public_key); |
|
|
|
// Криптографические операции |
|
sc_status_t sc_encrypt(sc_context_t *ctx, const uint8_t *plaintext, size_t plaintext_len, uint8_t *ciphertext, size_t *ciphertext_len); |
|
sc_status_t sc_decrypt(sc_context_t *ctx, const uint8_t *ciphertext, size_t ciphertext_len, uint8_t *plaintext, size_t *plaintext_len); |
|
|
|
// SHA256-based transcode: XOR data with SHA256(key) |
|
sc_status_t sc_sha_transcode(const uint8_t *key, size_t key_len, uint8_t *data, size_t data_len); |
|
|
|
// Obfuscate pubkey при передаче: XOR с SHA256(salt+peer_pubkey) || SHA256(peer_pubkey+salt) |
|
sc_status_t sc_obfuscate_pubkey(const uint8_t *salt, const uint8_t *peer_pubkey, const uint8_t *pubkey, uint8_t *output); |
|
|
|
// --- Streaming cipher (AES-128-CTR, confidentiality only) --- |
|
|
|
#define SC_STREAM_NONCE_SIZE 12 |
|
|
|
struct sc_stream_state { |
|
void *ectx; // EVP_CIPHER_CTX* |
|
uint8_t initialized; |
|
}; |
|
|
|
sc_status_t sc_stream_init(sc_context_t *ctx, struct sc_stream_state *state, uint32_t stream_id); |
|
sc_status_t sc_stream_xor(struct sc_stream_state *state, uint8_t *data, size_t data_len); |
|
void sc_stream_cleanup(struct sc_stream_state *state); |
|
|
|
// --- Streaming Ed25519 signature --- |
|
// SHA-512 инкрементально (EVP_DigestUpdate) + Ed25519 подпись хеша (one-shot EVP_DigestSign). |
|
// Память O(1), не зависит от размера данных. |
|
|
|
#define SC_SIGN_SIZE 64 // Ed25519 signature size |
|
|
|
struct sc_stream_sign_state { |
|
void *md_ctx; // EVP_MD_CTX* — SHA-512 аккумулятор |
|
void *pkey; // EVP_PKEY* — Ed25519 ключ |
|
uint8_t initialized; |
|
uint8_t is_sign; // 1=sign, 0=verify |
|
}; |
|
|
|
sc_status_t sc_stream_sign_init(sc_context_t *ctx, struct sc_stream_sign_state *state); |
|
sc_status_t sc_stream_sign_verify_init(struct sc_stream_sign_state *state, const uint8_t *ed25519_pubkey); |
|
sc_status_t sc_stream_sign_update(struct sc_stream_sign_state *state, const uint8_t *data, size_t len); |
|
sc_status_t sc_stream_sign_final(struct sc_stream_sign_state *state, uint8_t *sig_out, size_t *sig_len); |
|
sc_status_t sc_stream_sign_verify(struct sc_stream_sign_state *state, const uint8_t *sig, size_t sig_len); |
|
void sc_stream_sign_cleanup(struct sc_stream_sign_state *state); |
|
|
|
sc_status_t sc_ed25519_sign(const uint8_t privkey[32], const uint8_t* msg, size_t msg_len, uint8_t sig_out[64]); |
|
sc_status_t sc_ed25519_verify(const uint8_t pubkey[32], const uint8_t* msg, size_t msg_len, const uint8_t sig[64]); |
|
|
|
sc_status_t sc_derive_ed25519_pubkey(const uint8_t *x25519_privkey, uint8_t *ed25519_pubkey_out); |
|
|
|
uint64_t sc_derive_node_id_from_pubkey(const uint8_t *public_key); |
|
|
|
|
|
#ifdef __cplusplus |
|
} |
|
#endif |
|
#endif // SECURE_CHANNEL_H
|
|
|