mirror of
https://github.com/Atmosphere-NX/Atmosphere
synced 2024-12-21 20:01:16 +00:00
crypto: implement CmacGenerator
This commit is contained in:
parent
3a5f70dceb
commit
9f8d17b9e6
4 changed files with 241 additions and 0 deletions
|
@ -30,6 +30,7 @@
|
|||
#include <vapours/crypto/crypto_aes_ctr_encryptor_decryptor.hpp>
|
||||
#include <vapours/crypto/crypto_aes_xts_encryptor_decryptor.hpp>
|
||||
#include <vapours/crypto/crypto_aes_gcm_encryptor.hpp>
|
||||
#include <vapours/crypto/crypto_aes_128_cmac_generator.hpp>
|
||||
#include <vapours/crypto/crypto_rsa_pkcs1_sha256_verifier.hpp>
|
||||
#include <vapours/crypto/crypto_rsa_pss_sha256_verifier.hpp>
|
||||
#include <vapours/crypto/crypto_rsa_oaep_sha256_decoder.hpp>
|
||||
|
|
|
@ -0,0 +1,61 @@
|
|||
/*
|
||||
* Copyright (c) Atmosphère-NX
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms and conditions of the GNU General Public License,
|
||||
* version 2, as published by the Free Software Foundation.
|
||||
*
|
||||
* This program is distributed in the hope it will be useful, but WITHOUT
|
||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
||||
* more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
|
||||
#pragma once
|
||||
#include <vapours/common.hpp>
|
||||
#include <vapours/assert.hpp>
|
||||
#include <vapours/util.hpp>
|
||||
#include <vapours/crypto/crypto_aes_encryptor.hpp>
|
||||
#include <vapours/crypto/crypto_cmac_generator.hpp>
|
||||
|
||||
namespace ams::crypto {
|
||||
|
||||
class Aes128CmacGenerator {
|
||||
NON_COPYABLE(Aes128CmacGenerator);
|
||||
NON_MOVEABLE(Aes128CmacGenerator);
|
||||
public:
|
||||
static constexpr size_t MacSize = AesEncryptor128::BlockSize;
|
||||
private:
|
||||
AesEncryptor128 m_aes;
|
||||
CmacGenerator<AesEncryptor128> m_cmac_generator;
|
||||
public:
|
||||
Aes128CmacGenerator() { /* ... */ }
|
||||
|
||||
void Initialize(const void *key, size_t key_size) {
|
||||
AMS_ASSERT(key_size == AesEncryptor128::KeySize);
|
||||
|
||||
m_aes.Initialize(key, key_size);
|
||||
m_cmac_generator.Initialize(std::addressof(m_aes));
|
||||
}
|
||||
|
||||
void Update(const void *data, size_t size) {
|
||||
m_cmac_generator.Update(data, size);
|
||||
}
|
||||
|
||||
void GetMac(void *dst, size_t size) {
|
||||
m_cmac_generator.GetMac(dst, size);
|
||||
}
|
||||
};
|
||||
|
||||
ALWAYS_INLINE void GenerateAes128Cmac(void *dst, size_t dst_size, const void *data, size_t data_size, const void *key, size_t key_size) {
|
||||
Aes128CmacGenerator cmac_generator;
|
||||
|
||||
cmac_generator.Initialize(key, key_size);
|
||||
cmac_generator.Update(data, data_size);
|
||||
cmac_generator.GetMac(dst, dst_size);
|
||||
}
|
||||
|
||||
}
|
|
@ -0,0 +1,51 @@
|
|||
/*
|
||||
* Copyright (c) Atmosphère-NX
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms and conditions of the GNU General Public License,
|
||||
* version 2, as published by the Free Software Foundation.
|
||||
*
|
||||
* This program is distributed in the hope it will be useful, but WITHOUT
|
||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
||||
* more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
|
||||
#pragma once
|
||||
#include <vapours/common.hpp>
|
||||
#include <vapours/assert.hpp>
|
||||
#include <vapours/util.hpp>
|
||||
#include <vapours/crypto/impl/crypto_cmac_impl.hpp>
|
||||
|
||||
namespace ams::crypto {
|
||||
|
||||
template<typename BlockCipher>
|
||||
class CmacGenerator {
|
||||
NON_COPYABLE(CmacGenerator);
|
||||
NON_MOVEABLE(CmacGenerator);
|
||||
private:
|
||||
using Impl = impl::CmacImpl<BlockCipher>;
|
||||
public:
|
||||
static constexpr size_t MacSize = BlockCipher::BlockSize;
|
||||
private:
|
||||
Impl m_impl;
|
||||
public:
|
||||
CmacGenerator() { /* ... */ }
|
||||
|
||||
void Initialize(const BlockCipher *cipher) {
|
||||
return m_impl.Initialize(cipher);
|
||||
}
|
||||
|
||||
void Update(const void *data, size_t size) {
|
||||
return m_impl.Update(data, size);
|
||||
}
|
||||
|
||||
void GetMac(void *dst, size_t dst_size) {
|
||||
return m_impl.GetMac(dst, dst_size);
|
||||
}
|
||||
};
|
||||
|
||||
}
|
|
@ -0,0 +1,128 @@
|
|||
/*
|
||||
* Copyright (c) Atmosphère-NX
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms and conditions of the GNU General Public License,
|
||||
* version 2, as published by the Free Software Foundation.
|
||||
*
|
||||
* This program is distributed in the hope it will be useful, but WITHOUT
|
||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
||||
* more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
|
||||
#pragma once
|
||||
#include <vapours/common.hpp>
|
||||
#include <vapours/assert.hpp>
|
||||
#include <vapours/util.hpp>
|
||||
#include <vapours/crypto/impl/crypto_hash_function.hpp>
|
||||
#include <vapours/crypto/impl/crypto_cbc_mac_impl.hpp>
|
||||
#include <vapours/crypto/crypto_memory_clear.hpp>
|
||||
|
||||
namespace ams::crypto::impl {
|
||||
|
||||
template<typename BlockCipher>
|
||||
class CmacImpl {
|
||||
NON_COPYABLE(CmacImpl);
|
||||
NON_MOVEABLE(CmacImpl);
|
||||
public:
|
||||
static constexpr size_t BlockSize = BlockCipher::BlockSize;
|
||||
static constexpr size_t MacSize = BlockSize;
|
||||
static_assert(BlockSize == 0x10); /* TODO: Should this be supported? */
|
||||
private:
|
||||
enum State {
|
||||
State_None = 0,
|
||||
State_Initialized = 1,
|
||||
State_Done = 2,
|
||||
};
|
||||
private:
|
||||
CbcMacImpl m_cbc_mac_impl;
|
||||
u8 m_sub_key[BlockSize];
|
||||
State m_state;
|
||||
public:
|
||||
CmacImpl() : m_state(State_None) { /* ... */ }
|
||||
~CmacImpl() {
|
||||
/* Clear everything. */
|
||||
ClearMemory(this, sizeof(*this));
|
||||
}
|
||||
|
||||
void Initialize(const BlockCipher *cipher);
|
||||
void Update(const void *data, size_t data_size);
|
||||
void GetMac(void *dst, size_t dst_size);
|
||||
private:
|
||||
static void MultiplyOneOverGF128(u8 *data) {
|
||||
/* Determine the carry bit. */
|
||||
const u8 carry = data[0] & 0x80;
|
||||
|
||||
/* Shift all bytes by one bit. */
|
||||
for (size_t i = 0; i < BlockSize - 1; ++i) {
|
||||
data[i] = (data[i] << 1) | (data[i + 1] >> 7);
|
||||
}
|
||||
data[BlockSize - 1] <<= 1;
|
||||
|
||||
/* Adjust based on carry. */
|
||||
if (carry) {
|
||||
data[BlockSize - 1] ^= 0x87;
|
||||
}
|
||||
}
|
||||
};
|
||||
|
||||
template<typename BlockCipher>
|
||||
inline void CmacImpl<BlockCipher>::Initialize(const BlockCipher *cipher) {
|
||||
/* Clear the key storage. */
|
||||
std::memset(m_sub_key, 0, sizeof(m_sub_key));
|
||||
|
||||
/* Set the key storage. */
|
||||
cipher->EncryptBlock(m_sub_key, BlockSize, m_sub_key, BlockSize);
|
||||
MultiplyOneOverGF128(m_sub_key);
|
||||
|
||||
/* Initialize the cbc-mac impl. */
|
||||
m_cbc_mac_impl.Initialize(cipher);
|
||||
|
||||
/* Mark initialized. */
|
||||
m_state = State_Initialized;
|
||||
}
|
||||
|
||||
template<typename BlockCipher>
|
||||
inline void CmacImpl<BlockCipher>::Update(const void *data, size_t data_size) {
|
||||
AMS_ASSERT(m_state == State_Initialized);
|
||||
|
||||
m_cbc_mac_impl.template Update<BlockCipher>(data, data_size);
|
||||
}
|
||||
|
||||
template<typename BlockCipher>
|
||||
inline void CmacImpl<BlockCipher>::GetMac(void *dst, size_t dst_size) {
|
||||
AMS_ASSERT(m_state == State_Initialized || m_state == State_Done);
|
||||
AMS_ASSERT(dst_size >= MacSize);
|
||||
AMS_UNUSED(dst_size);
|
||||
|
||||
/* If we're not already finalized, get the final mac. */
|
||||
if (m_state == State_Initialized) {
|
||||
/* Process padding as needed. */
|
||||
if (m_cbc_mac_impl.GetBufferedDataSize() != BlockSize) {
|
||||
/* Determine the remaining size. */
|
||||
const size_t remaining = BlockSize - m_cbc_mac_impl.GetBufferedDataSize();
|
||||
|
||||
/* Update with padding. */
|
||||
static constexpr u8 s_padding[BlockSize] = { 0x80, /* ... */ };
|
||||
m_cbc_mac_impl.template Update<BlockCipher>(s_padding, remaining);
|
||||
|
||||
/* Update our subkey. */
|
||||
MultiplyOneOverGF128(m_sub_key);
|
||||
}
|
||||
|
||||
/* Mask the subkey. */
|
||||
m_cbc_mac_impl.MaskBufferedData(m_sub_key, BlockSize);
|
||||
|
||||
/* Set our state as done. */
|
||||
m_state = State_Done;
|
||||
}
|
||||
|
||||
/* Get the mac. */
|
||||
m_cbc_mac_impl.GetMac(dst, dst_size);
|
||||
}
|
||||
|
||||
}
|
Loading…
Reference in a new issue