mirror of
https://github.com/Atmosphere-NX/Atmosphere.git
synced 2024-11-22 11:56:40 +00:00
crypto: implement CmacGenerator
This commit is contained in:
parent
3a5f70dceb
commit
9f8d17b9e6
4 changed files with 241 additions and 0 deletions
|
@ -30,6 +30,7 @@
|
||||||
#include <vapours/crypto/crypto_aes_ctr_encryptor_decryptor.hpp>
|
#include <vapours/crypto/crypto_aes_ctr_encryptor_decryptor.hpp>
|
||||||
#include <vapours/crypto/crypto_aes_xts_encryptor_decryptor.hpp>
|
#include <vapours/crypto/crypto_aes_xts_encryptor_decryptor.hpp>
|
||||||
#include <vapours/crypto/crypto_aes_gcm_encryptor.hpp>
|
#include <vapours/crypto/crypto_aes_gcm_encryptor.hpp>
|
||||||
|
#include <vapours/crypto/crypto_aes_128_cmac_generator.hpp>
|
||||||
#include <vapours/crypto/crypto_rsa_pkcs1_sha256_verifier.hpp>
|
#include <vapours/crypto/crypto_rsa_pkcs1_sha256_verifier.hpp>
|
||||||
#include <vapours/crypto/crypto_rsa_pss_sha256_verifier.hpp>
|
#include <vapours/crypto/crypto_rsa_pss_sha256_verifier.hpp>
|
||||||
#include <vapours/crypto/crypto_rsa_oaep_sha256_decoder.hpp>
|
#include <vapours/crypto/crypto_rsa_oaep_sha256_decoder.hpp>
|
||||||
|
|
|
@ -0,0 +1,61 @@
|
||||||
|
/*
|
||||||
|
* Copyright (c) Atmosphère-NX
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or modify it
|
||||||
|
* under the terms and conditions of the GNU General Public License,
|
||||||
|
* version 2, as published by the Free Software Foundation.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope it will be useful, but WITHOUT
|
||||||
|
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||||
|
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
||||||
|
* more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#pragma once
|
||||||
|
#include <vapours/common.hpp>
|
||||||
|
#include <vapours/assert.hpp>
|
||||||
|
#include <vapours/util.hpp>
|
||||||
|
#include <vapours/crypto/crypto_aes_encryptor.hpp>
|
||||||
|
#include <vapours/crypto/crypto_cmac_generator.hpp>
|
||||||
|
|
||||||
|
namespace ams::crypto {
|
||||||
|
|
||||||
|
class Aes128CmacGenerator {
|
||||||
|
NON_COPYABLE(Aes128CmacGenerator);
|
||||||
|
NON_MOVEABLE(Aes128CmacGenerator);
|
||||||
|
public:
|
||||||
|
static constexpr size_t MacSize = AesEncryptor128::BlockSize;
|
||||||
|
private:
|
||||||
|
AesEncryptor128 m_aes;
|
||||||
|
CmacGenerator<AesEncryptor128> m_cmac_generator;
|
||||||
|
public:
|
||||||
|
Aes128CmacGenerator() { /* ... */ }
|
||||||
|
|
||||||
|
void Initialize(const void *key, size_t key_size) {
|
||||||
|
AMS_ASSERT(key_size == AesEncryptor128::KeySize);
|
||||||
|
|
||||||
|
m_aes.Initialize(key, key_size);
|
||||||
|
m_cmac_generator.Initialize(std::addressof(m_aes));
|
||||||
|
}
|
||||||
|
|
||||||
|
void Update(const void *data, size_t size) {
|
||||||
|
m_cmac_generator.Update(data, size);
|
||||||
|
}
|
||||||
|
|
||||||
|
void GetMac(void *dst, size_t size) {
|
||||||
|
m_cmac_generator.GetMac(dst, size);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
ALWAYS_INLINE void GenerateAes128Cmac(void *dst, size_t dst_size, const void *data, size_t data_size, const void *key, size_t key_size) {
|
||||||
|
Aes128CmacGenerator cmac_generator;
|
||||||
|
|
||||||
|
cmac_generator.Initialize(key, key_size);
|
||||||
|
cmac_generator.Update(data, data_size);
|
||||||
|
cmac_generator.GetMac(dst, dst_size);
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
|
@ -0,0 +1,51 @@
|
||||||
|
/*
|
||||||
|
* Copyright (c) Atmosphère-NX
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or modify it
|
||||||
|
* under the terms and conditions of the GNU General Public License,
|
||||||
|
* version 2, as published by the Free Software Foundation.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope it will be useful, but WITHOUT
|
||||||
|
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||||
|
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
||||||
|
* more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#pragma once
|
||||||
|
#include <vapours/common.hpp>
|
||||||
|
#include <vapours/assert.hpp>
|
||||||
|
#include <vapours/util.hpp>
|
||||||
|
#include <vapours/crypto/impl/crypto_cmac_impl.hpp>
|
||||||
|
|
||||||
|
namespace ams::crypto {
|
||||||
|
|
||||||
|
template<typename BlockCipher>
|
||||||
|
class CmacGenerator {
|
||||||
|
NON_COPYABLE(CmacGenerator);
|
||||||
|
NON_MOVEABLE(CmacGenerator);
|
||||||
|
private:
|
||||||
|
using Impl = impl::CmacImpl<BlockCipher>;
|
||||||
|
public:
|
||||||
|
static constexpr size_t MacSize = BlockCipher::BlockSize;
|
||||||
|
private:
|
||||||
|
Impl m_impl;
|
||||||
|
public:
|
||||||
|
CmacGenerator() { /* ... */ }
|
||||||
|
|
||||||
|
void Initialize(const BlockCipher *cipher) {
|
||||||
|
return m_impl.Initialize(cipher);
|
||||||
|
}
|
||||||
|
|
||||||
|
void Update(const void *data, size_t size) {
|
||||||
|
return m_impl.Update(data, size);
|
||||||
|
}
|
||||||
|
|
||||||
|
void GetMac(void *dst, size_t dst_size) {
|
||||||
|
return m_impl.GetMac(dst, dst_size);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
}
|
|
@ -0,0 +1,128 @@
|
||||||
|
/*
|
||||||
|
* Copyright (c) Atmosphère-NX
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or modify it
|
||||||
|
* under the terms and conditions of the GNU General Public License,
|
||||||
|
* version 2, as published by the Free Software Foundation.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope it will be useful, but WITHOUT
|
||||||
|
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||||
|
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
||||||
|
* more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License
|
||||||
|
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#pragma once
|
||||||
|
#include <vapours/common.hpp>
|
||||||
|
#include <vapours/assert.hpp>
|
||||||
|
#include <vapours/util.hpp>
|
||||||
|
#include <vapours/crypto/impl/crypto_hash_function.hpp>
|
||||||
|
#include <vapours/crypto/impl/crypto_cbc_mac_impl.hpp>
|
||||||
|
#include <vapours/crypto/crypto_memory_clear.hpp>
|
||||||
|
|
||||||
|
namespace ams::crypto::impl {
|
||||||
|
|
||||||
|
template<typename BlockCipher>
|
||||||
|
class CmacImpl {
|
||||||
|
NON_COPYABLE(CmacImpl);
|
||||||
|
NON_MOVEABLE(CmacImpl);
|
||||||
|
public:
|
||||||
|
static constexpr size_t BlockSize = BlockCipher::BlockSize;
|
||||||
|
static constexpr size_t MacSize = BlockSize;
|
||||||
|
static_assert(BlockSize == 0x10); /* TODO: Should this be supported? */
|
||||||
|
private:
|
||||||
|
enum State {
|
||||||
|
State_None = 0,
|
||||||
|
State_Initialized = 1,
|
||||||
|
State_Done = 2,
|
||||||
|
};
|
||||||
|
private:
|
||||||
|
CbcMacImpl m_cbc_mac_impl;
|
||||||
|
u8 m_sub_key[BlockSize];
|
||||||
|
State m_state;
|
||||||
|
public:
|
||||||
|
CmacImpl() : m_state(State_None) { /* ... */ }
|
||||||
|
~CmacImpl() {
|
||||||
|
/* Clear everything. */
|
||||||
|
ClearMemory(this, sizeof(*this));
|
||||||
|
}
|
||||||
|
|
||||||
|
void Initialize(const BlockCipher *cipher);
|
||||||
|
void Update(const void *data, size_t data_size);
|
||||||
|
void GetMac(void *dst, size_t dst_size);
|
||||||
|
private:
|
||||||
|
static void MultiplyOneOverGF128(u8 *data) {
|
||||||
|
/* Determine the carry bit. */
|
||||||
|
const u8 carry = data[0] & 0x80;
|
||||||
|
|
||||||
|
/* Shift all bytes by one bit. */
|
||||||
|
for (size_t i = 0; i < BlockSize - 1; ++i) {
|
||||||
|
data[i] = (data[i] << 1) | (data[i + 1] >> 7);
|
||||||
|
}
|
||||||
|
data[BlockSize - 1] <<= 1;
|
||||||
|
|
||||||
|
/* Adjust based on carry. */
|
||||||
|
if (carry) {
|
||||||
|
data[BlockSize - 1] ^= 0x87;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
template<typename BlockCipher>
|
||||||
|
inline void CmacImpl<BlockCipher>::Initialize(const BlockCipher *cipher) {
|
||||||
|
/* Clear the key storage. */
|
||||||
|
std::memset(m_sub_key, 0, sizeof(m_sub_key));
|
||||||
|
|
||||||
|
/* Set the key storage. */
|
||||||
|
cipher->EncryptBlock(m_sub_key, BlockSize, m_sub_key, BlockSize);
|
||||||
|
MultiplyOneOverGF128(m_sub_key);
|
||||||
|
|
||||||
|
/* Initialize the cbc-mac impl. */
|
||||||
|
m_cbc_mac_impl.Initialize(cipher);
|
||||||
|
|
||||||
|
/* Mark initialized. */
|
||||||
|
m_state = State_Initialized;
|
||||||
|
}
|
||||||
|
|
||||||
|
template<typename BlockCipher>
|
||||||
|
inline void CmacImpl<BlockCipher>::Update(const void *data, size_t data_size) {
|
||||||
|
AMS_ASSERT(m_state == State_Initialized);
|
||||||
|
|
||||||
|
m_cbc_mac_impl.template Update<BlockCipher>(data, data_size);
|
||||||
|
}
|
||||||
|
|
||||||
|
template<typename BlockCipher>
|
||||||
|
inline void CmacImpl<BlockCipher>::GetMac(void *dst, size_t dst_size) {
|
||||||
|
AMS_ASSERT(m_state == State_Initialized || m_state == State_Done);
|
||||||
|
AMS_ASSERT(dst_size >= MacSize);
|
||||||
|
AMS_UNUSED(dst_size);
|
||||||
|
|
||||||
|
/* If we're not already finalized, get the final mac. */
|
||||||
|
if (m_state == State_Initialized) {
|
||||||
|
/* Process padding as needed. */
|
||||||
|
if (m_cbc_mac_impl.GetBufferedDataSize() != BlockSize) {
|
||||||
|
/* Determine the remaining size. */
|
||||||
|
const size_t remaining = BlockSize - m_cbc_mac_impl.GetBufferedDataSize();
|
||||||
|
|
||||||
|
/* Update with padding. */
|
||||||
|
static constexpr u8 s_padding[BlockSize] = { 0x80, /* ... */ };
|
||||||
|
m_cbc_mac_impl.template Update<BlockCipher>(s_padding, remaining);
|
||||||
|
|
||||||
|
/* Update our subkey. */
|
||||||
|
MultiplyOneOverGF128(m_sub_key);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Mask the subkey. */
|
||||||
|
m_cbc_mac_impl.MaskBufferedData(m_sub_key, BlockSize);
|
||||||
|
|
||||||
|
/* Set our state as done. */
|
||||||
|
m_state = State_Done;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Get the mac. */
|
||||||
|
m_cbc_mac_impl.GetMac(dst, dst_size);
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
Loading…
Reference in a new issue