clientsession 0.4.1 → 0.9.3.0
raw patch · 13 files changed
Files
- ChangeLog.md +13/−0
- LICENSE +17/−22
- README.md +6/−0
- Web/ClientSession.hs +0/−145
- bench.hs +19/−0
- bin/generate.hs +9/−0
- c/aestable.c +0/−400
- c/helper.c +0/−166
- clientsession.cabal +50/−28
- runtests.hs +0/−58
- src/System/LookupEnv.hs +6/−0
- src/Web/ClientSession.hs +361/−0
- tests/runtests.hs +103/−0
+ ChangeLog.md view
@@ -0,0 +1,13 @@+# ChangeLog for clientsession++## 0.9.3.0++* Migrate to crypton from cryptonite.++## 0.9.2.0++* Migrate crypto-aes and cprng-aes to cryptonite. [#36](https://github.com/yesodweb/clientsession/pull/36)++## 0.9.1.2++* Clarify that we're using MIT license
LICENSE view
@@ -1,25 +1,20 @@-The following license covers this documentation, and the source code, except-where otherwise indicated.--Copyright 2008, Michael Snoyman. All rights reserved.--Redistribution and use in source and binary forms, with or without-modification, are permitted provided that the following conditions are met:+Copyright (c) 2008 Michael Snoyman, http://www.yesodweb.com/ -* Redistributions of source code must retain the above copyright notice, this- list of conditions and the following disclaimer.+Permission is hereby granted, free of charge, to any person obtaining+a copy of this software and associated documentation files (the+"Software"), to deal in the Software without restriction, including+without limitation the rights to use, copy, modify, merge, publish,+distribute, sublicense, and/or sell copies of the Software, and to+permit persons to whom the Software is furnished to do so, subject to+the following conditions: -* Redistributions in binary form must reproduce the above copyright notice,- this list of conditions and the following disclaimer in the documentation- and/or other materials provided with the distribution.+The above copyright notice and this permission notice shall be+included in all copies or substantial portions of the Software. -THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS "AS IS" AND ANY EXPRESS OR-IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF-MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO-EVENT SHALL THE COPYRIGHT HOLDERS BE LIABLE FOR ANY DIRECT, INDIRECT,-INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT-NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA,-OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF-LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE-OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF-ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,+EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF+MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND+NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE+LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION+OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION+WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+ README.md view
@@ -0,0 +1,6 @@+## clientsession++Securely store session data in a client-side cookie.++Achieves security through AES-CTR encryption and Skein-MAC-512-256+authentication. Uses Base64 encoding to avoid any issues with characters.
− Web/ClientSession.hs
@@ -1,145 +0,0 @@-{-# LANGUAGE FlexibleContexts #-}-{-# LANGUAGE ForeignFunctionInterface #-}-{-# LANGUAGE TemplateHaskell #-}---------------------------------------------------------------- Module : Web.ClientSession--- Copyright : Michael Snoyman--- License : BSD3------ Maintainer : Michael Snoyman <michael@snoyman.com>--- Stability : Stable--- Portability : portable------ Stores session data in a client cookie.--------------------------------------------------------------module Web.ClientSession- ( -- * Automatic key generation- Key- , getKey- , embedKey- , defaultKeyFile- , getDefaultKey- , embedDefaultKey- -- * Actual encryption/decryption- , encrypt- , decrypt- ) where--import System.Directory-import qualified Data.ByteString as S-import qualified Data.ByteString.Char8 as B--import System.Random--import Data.ByteString.Unsafe--import Foreign.C-import Foreign.Ptr-import Foreign.Marshal.Alloc-import Foreign.Storable-import System.IO.Unsafe-import Language.Haskell.TH--type Key = S.ByteString---- | The default key file.-defaultKeyFile :: String-defaultKeyFile = "client_session_key.aes"---- | Simply calls 'getKey' 'defaultKeyFile'.-getDefaultKey :: IO Key-getDefaultKey = getKey defaultKeyFile---- | Simply calls 'embedKey' 'defaultKeyFile'.-embedDefaultKey :: Q Exp-embedDefaultKey = embedKey defaultKeyFile---- | Get a key from the given text file.------ If the file does not exist a random key will be generated and stored in that--- file.-getKey :: FilePath -- ^ File name where key is stored.- -> IO Key -- ^ The actual key.-getKey keyFile = do- exists <- doesFileExist keyFile- if exists- then do- key <- S.readFile keyFile- if S.length key < minKeyLength- then newKey- else return key- else newKey- where- newKey = do- key' <- randomKey- S.writeFile keyFile key'- return key'---- | Embed a key from the given text file into haskell source.------ Eliminates overhead of reading key file with each request.-embedKey :: FilePath -> Q Exp-embedKey keyFile = do- k <- runIO $ getKey keyFile- let cs = B.unpack k- [| B.pack |] `appE` (litE $ stringL cs)--minKeyLength :: Int-minKeyLength = 16--randomKey :: IO Key-randomKey = do- g <- newStdGen- let (nums, _) =- foldr- (\_ (n, g') -> let (n', g'') = next g' in (n' : n, g''))- ([], g)- [1..minKeyLength]- return $ S.pack $ map fromIntegral nums--encrypt :: S.ByteString -- ^ key- -> S.ByteString -- ^ data- -> S.ByteString-encrypt keyBS dataBS = unsafePerformIO $- unsafeUseAsCString keyBS $ \keyPtr ->- unsafeUseAsCStringLen dataBS $ \(dataPtr, dataLen) -> do- let keyPtr' = castPtr keyPtr- dataPtr' = castPtr dataPtr- dataLen' = fromIntegral dataLen- allocaBytes 4 $ \lenp -> do- newPtr <- c_encrypt dataLen' dataPtr' keyPtr' lenp- let newPtr' = castPtr newPtr- len <- peek lenp- let len' = fromIntegral len- unsafePackCStringFinalizer newPtr' len' $ free newPtr'--decrypt :: S.ByteString -- ^ key- -> S.ByteString -- ^ data- -> Maybe S.ByteString-decrypt keyBS dataBS = unsafePerformIO $- unsafeUseAsCString keyBS $ \keyPtr ->- unsafeUseAsCStringLen dataBS $ \(dataPtr, dataLen) -> do- let keyPtr' = castPtr keyPtr- dataPtr' = castPtr dataPtr- dataLen' = fromIntegral dataLen- allocaBytes 4 $ \lenp -> do- newPtr <- c_decrypt dataLen' dataPtr' keyPtr' lenp- if newPtr == nullPtr- then return Nothing- else do- let newPtr' = castPtr newPtr- len <- peek lenp- let len' = fromIntegral len- bs <- unsafePackCStringFinalizer newPtr' len'- $ free newPtr'- return $ Just bs--foreign import ccall unsafe "encrypt"- c_encrypt :: CUInt -> Ptr CUChar -> Ptr CUChar -> Ptr CUInt- -> IO (Ptr CChar)--foreign import ccall unsafe "decrypt"- c_decrypt :: CUInt -> Ptr CChar -> Ptr CUChar -> Ptr CUInt- -> IO (Ptr CUChar)
+ bench.hs view
@@ -0,0 +1,19 @@+import qualified Data.ByteString as B+import Web.ClientSession+import Data.Maybe+import Data.Serialize++import Criterion.Main+import Text.Printf++Right key = initKey (B.replicate 96 0xFE)+Just iv = mkIV (B.replicate 16 0xB0)++main :: IO ()+main =+ defaultMain+ [ bgroup "encrypt then decrypt"+ [ bench (printf "Message length = %d bytes" len) $+ whnf (fromJust . decrypt key . encrypt key iv) (B.replicate len 0xAA)+ | len <- [0, 50, 100, 400, 2000, 80000]]+ ]
+ bin/generate.hs view
@@ -0,0 +1,9 @@+module Main where++import Data.Maybe (fromMaybe, listToMaybe)+import Control.Monad (void)+import System.Environment (getArgs)+import Web.ClientSession (randomKeyEnv)++main :: IO ()+main = void $ randomKeyEnv . fromMaybe "SESSION_KEY" . listToMaybe =<< getArgs
− c/aestable.c
@@ -1,400 +0,0 @@-// advanced encryption standard -// author: karl malbrain, malbrain@yahoo.com -/* -This work, including the source code, documentation -and related data, is placed into the public domain. - -The orginal author is Karl Malbrain. - -THIS SOFTWARE IS PROVIDED AS-IS WITHOUT WARRANTY -OF ANY KIND, NOT EVEN THE IMPLIED WARRANTY OF -MERCHANTABILITY. THE AUTHOR OF THIS SOFTWARE, -ASSUMES _NO_ RESPONSIBILITY FOR ANY CONSEQUENCE -RESULTING FROM THE USE, MODIFICATION, OR -REDISTRIBUTION OF THIS SOFTWARE. -*/ - -typedef unsigned char uchar; -#include <string.h> -#include <memory.h> - -// AES only supports Nb=4 -#define Nb 4 // number of columns in the state & expanded key - -#define Nk 4 // number of columns in a key -#define Nr 10 // number of rounds in encryption - -uchar Sbox[256] = { // forward s-box -0x63, 0x7c, 0x77, 0x7b, 0xf2, 0x6b, 0x6f, 0xc5, 0x30, 0x01, 0x67, 0x2b, 0xfe, 0xd7, 0xab, 0x76, -0xca, 0x82, 0xc9, 0x7d, 0xfa, 0x59, 0x47, 0xf0, 0xad, 0xd4, 0xa2, 0xaf, 0x9c, 0xa4, 0x72, 0xc0, -0xb7, 0xfd, 0x93, 0x26, 0x36, 0x3f, 0xf7, 0xcc, 0x34, 0xa5, 0xe5, 0xf1, 0x71, 0xd8, 0x31, 0x15, -0x04, 0xc7, 0x23, 0xc3, 0x18, 0x96, 0x05, 0x9a, 0x07, 0x12, 0x80, 0xe2, 0xeb, 0x27, 0xb2, 0x75, -0x09, 0x83, 0x2c, 0x1a, 0x1b, 0x6e, 0x5a, 0xa0, 0x52, 0x3b, 0xd6, 0xb3, 0x29, 0xe3, 0x2f, 0x84, -0x53, 0xd1, 0x00, 0xed, 0x20, 0xfc, 0xb1, 0x5b, 0x6a, 0xcb, 0xbe, 0x39, 0x4a, 0x4c, 0x58, 0xcf, -0xd0, 0xef, 0xaa, 0xfb, 0x43, 0x4d, 0x33, 0x85, 0x45, 0xf9, 0x02, 0x7f, 0x50, 0x3c, 0x9f, 0xa8, -0x51, 0xa3, 0x40, 0x8f, 0x92, 0x9d, 0x38, 0xf5, 0xbc, 0xb6, 0xda, 0x21, 0x10, 0xff, 0xf3, 0xd2, -0xcd, 0x0c, 0x13, 0xec, 0x5f, 0x97, 0x44, 0x17, 0xc4, 0xa7, 0x7e, 0x3d, 0x64, 0x5d, 0x19, 0x73, -0x60, 0x81, 0x4f, 0xdc, 0x22, 0x2a, 0x90, 0x88, 0x46, 0xee, 0xb8, 0x14, 0xde, 0x5e, 0x0b, 0xdb, -0xe0, 0x32, 0x3a, 0x0a, 0x49, 0x06, 0x24, 0x5c, 0xc2, 0xd3, 0xac, 0x62, 0x91, 0x95, 0xe4, 0x79, -0xe7, 0xc8, 0x37, 0x6d, 0x8d, 0xd5, 0x4e, 0xa9, 0x6c, 0x56, 0xf4, 0xea, 0x65, 0x7a, 0xae, 0x08, -0xba, 0x78, 0x25, 0x2e, 0x1c, 0xa6, 0xb4, 0xc6, 0xe8, 0xdd, 0x74, 0x1f, 0x4b, 0xbd, 0x8b, 0x8a, -0x70, 0x3e, 0xb5, 0x66, 0x48, 0x03, 0xf6, 0x0e, 0x61, 0x35, 0x57, 0xb9, 0x86, 0xc1, 0x1d, 0x9e, -0xe1, 0xf8, 0x98, 0x11, 0x69, 0xd9, 0x8e, 0x94, 0x9b, 0x1e, 0x87, 0xe9, 0xce, 0x55, 0x28, 0xdf, -0x8c, 0xa1, 0x89, 0x0d, 0xbf, 0xe6, 0x42, 0x68, 0x41, 0x99, 0x2d, 0x0f, 0xb0, 0x54, 0xbb, 0x16}; - -uchar InvSbox[256] = { // inverse s-box -0x52, 0x09, 0x6a, 0xd5, 0x30, 0x36, 0xa5, 0x38, 0xbf, 0x40, 0xa3, 0x9e, 0x81, 0xf3, 0xd7, 0xfb, -0x7c, 0xe3, 0x39, 0x82, 0x9b, 0x2f, 0xff, 0x87, 0x34, 0x8e, 0x43, 0x44, 0xc4, 0xde, 0xe9, 0xcb, -0x54, 0x7b, 0x94, 0x32, 0xa6, 0xc2, 0x23, 0x3d, 0xee, 0x4c, 0x95, 0x0b, 0x42, 0xfa, 0xc3, 0x4e, -0x08, 0x2e, 0xa1, 0x66, 0x28, 0xd9, 0x24, 0xb2, 0x76, 0x5b, 0xa2, 0x49, 0x6d, 0x8b, 0xd1, 0x25, -0x72, 0xf8, 0xf6, 0x64, 0x86, 0x68, 0x98, 0x16, 0xd4, 0xa4, 0x5c, 0xcc, 0x5d, 0x65, 0xb6, 0x92, -0x6c, 0x70, 0x48, 0x50, 0xfd, 0xed, 0xb9, 0xda, 0x5e, 0x15, 0x46, 0x57, 0xa7, 0x8d, 0x9d, 0x84, -0x90, 0xd8, 0xab, 0x00, 0x8c, 0xbc, 0xd3, 0x0a, 0xf7, 0xe4, 0x58, 0x05, 0xb8, 0xb3, 0x45, 0x06, -0xd0, 0x2c, 0x1e, 0x8f, 0xca, 0x3f, 0x0f, 0x02, 0xc1, 0xaf, 0xbd, 0x03, 0x01, 0x13, 0x8a, 0x6b, -0x3a, 0x91, 0x11, 0x41, 0x4f, 0x67, 0xdc, 0xea, 0x97, 0xf2, 0xcf, 0xce, 0xf0, 0xb4, 0xe6, 0x73, -0x96, 0xac, 0x74, 0x22, 0xe7, 0xad, 0x35, 0x85, 0xe2, 0xf9, 0x37, 0xe8, 0x1c, 0x75, 0xdf, 0x6e, -0x47, 0xf1, 0x1a, 0x71, 0x1d, 0x29, 0xc5, 0x89, 0x6f, 0xb7, 0x62, 0x0e, 0xaa, 0x18, 0xbe, 0x1b, -0xfc, 0x56, 0x3e, 0x4b, 0xc6, 0xd2, 0x79, 0x20, 0x9a, 0xdb, 0xc0, 0xfe, 0x78, 0xcd, 0x5a, 0xf4, -0x1f, 0xdd, 0xa8, 0x33, 0x88, 0x07, 0xc7, 0x31, 0xb1, 0x12, 0x10, 0x59, 0x27, 0x80, 0xec, 0x5f, -0x60, 0x51, 0x7f, 0xa9, 0x19, 0xb5, 0x4a, 0x0d, 0x2d, 0xe5, 0x7a, 0x9f, 0x93, 0xc9, 0x9c, 0xef, -0xa0, 0xe0, 0x3b, 0x4d, 0xae, 0x2a, 0xf5, 0xb0, 0xc8, 0xeb, 0xbb, 0x3c, 0x83, 0x53, 0x99, 0x61, -0x17, 0x2b, 0x04, 0x7e, 0xba, 0x77, 0xd6, 0x26, 0xe1, 0x69, 0x14, 0x63, 0x55, 0x21, 0x0c, 0x7d}; - -// combined Xtimes2[Sbox[]] -uchar Xtime2Sbox[256] = { -0xc6, 0xf8, 0xee, 0xf6, 0xff, 0xd6, 0xde, 0x91, 0x60, 0x02, 0xce, 0x56, 0xe7, 0xb5, 0x4d, 0xec, -0x8f, 0x1f, 0x89, 0xfa, 0xef, 0xb2, 0x8e, 0xfb, 0x41, 0xb3, 0x5f, 0x45, 0x23, 0x53, 0xe4, 0x9b, -0x75, 0xe1, 0x3d, 0x4c, 0x6c, 0x7e, 0xf5, 0x83, 0x68, 0x51, 0xd1, 0xf9, 0xe2, 0xab, 0x62, 0x2a, -0x08, 0x95, 0x46, 0x9d, 0x30, 0x37, 0x0a, 0x2f, 0x0e, 0x24, 0x1b, 0xdf, 0xcd, 0x4e, 0x7f, 0xea, -0x12, 0x1d, 0x58, 0x34, 0x36, 0xdc, 0xb4, 0x5b, 0xa4, 0x76, 0xb7, 0x7d, 0x52, 0xdd, 0x5e, 0x13, -0xa6, 0xb9, 0x00, 0xc1, 0x40, 0xe3, 0x79, 0xb6, 0xd4, 0x8d, 0x67, 0x72, 0x94, 0x98, 0xb0, 0x85, -0xbb, 0xc5, 0x4f, 0xed, 0x86, 0x9a, 0x66, 0x11, 0x8a, 0xe9, 0x04, 0xfe, 0xa0, 0x78, 0x25, 0x4b, -0xa2, 0x5d, 0x80, 0x05, 0x3f, 0x21, 0x70, 0xf1, 0x63, 0x77, 0xaf, 0x42, 0x20, 0xe5, 0xfd, 0xbf, -0x81, 0x18, 0x26, 0xc3, 0xbe, 0x35, 0x88, 0x2e, 0x93, 0x55, 0xfc, 0x7a, 0xc8, 0xba, 0x32, 0xe6, -0xc0, 0x19, 0x9e, 0xa3, 0x44, 0x54, 0x3b, 0x0b, 0x8c, 0xc7, 0x6b, 0x28, 0xa7, 0xbc, 0x16, 0xad, -0xdb, 0x64, 0x74, 0x14, 0x92, 0x0c, 0x48, 0xb8, 0x9f, 0xbd, 0x43, 0xc4, 0x39, 0x31, 0xd3, 0xf2, -0xd5, 0x8b, 0x6e, 0xda, 0x01, 0xb1, 0x9c, 0x49, 0xd8, 0xac, 0xf3, 0xcf, 0xca, 0xf4, 0x47, 0x10, -0x6f, 0xf0, 0x4a, 0x5c, 0x38, 0x57, 0x73, 0x97, 0xcb, 0xa1, 0xe8, 0x3e, 0x96, 0x61, 0x0d, 0x0f, -0xe0, 0x7c, 0x71, 0xcc, 0x90, 0x06, 0xf7, 0x1c, 0xc2, 0x6a, 0xae, 0x69, 0x17, 0x99, 0x3a, 0x27, -0xd9, 0xeb, 0x2b, 0x22, 0xd2, 0xa9, 0x07, 0x33, 0x2d, 0x3c, 0x15, 0xc9, 0x87, 0xaa, 0x50, 0xa5, -0x03, 0x59, 0x09, 0x1a, 0x65, 0xd7, 0x84, 0xd0, 0x82, 0x29, 0x5a, 0x1e, 0x7b, 0xa8, 0x6d, 0x2c -}; - -// combined Xtimes3[Sbox[]] -uchar Xtime3Sbox[256] = { -0xa5, 0x84, 0x99, 0x8d, 0x0d, 0xbd, 0xb1, 0x54, 0x50, 0x03, 0xa9, 0x7d, 0x19, 0x62, 0xe6, 0x9a, -0x45, 0x9d, 0x40, 0x87, 0x15, 0xeb, 0xc9, 0x0b, 0xec, 0x67, 0xfd, 0xea, 0xbf, 0xf7, 0x96, 0x5b, -0xc2, 0x1c, 0xae, 0x6a, 0x5a, 0x41, 0x02, 0x4f, 0x5c, 0xf4, 0x34, 0x08, 0x93, 0x73, 0x53, 0x3f, -0x0c, 0x52, 0x65, 0x5e, 0x28, 0xa1, 0x0f, 0xb5, 0x09, 0x36, 0x9b, 0x3d, 0x26, 0x69, 0xcd, 0x9f, -0x1b, 0x9e, 0x74, 0x2e, 0x2d, 0xb2, 0xee, 0xfb, 0xf6, 0x4d, 0x61, 0xce, 0x7b, 0x3e, 0x71, 0x97, -0xf5, 0x68, 0x00, 0x2c, 0x60, 0x1f, 0xc8, 0xed, 0xbe, 0x46, 0xd9, 0x4b, 0xde, 0xd4, 0xe8, 0x4a, -0x6b, 0x2a, 0xe5, 0x16, 0xc5, 0xd7, 0x55, 0x94, 0xcf, 0x10, 0x06, 0x81, 0xf0, 0x44, 0xba, 0xe3, -0xf3, 0xfe, 0xc0, 0x8a, 0xad, 0xbc, 0x48, 0x04, 0xdf, 0xc1, 0x75, 0x63, 0x30, 0x1a, 0x0e, 0x6d, -0x4c, 0x14, 0x35, 0x2f, 0xe1, 0xa2, 0xcc, 0x39, 0x57, 0xf2, 0x82, 0x47, 0xac, 0xe7, 0x2b, 0x95, -0xa0, 0x98, 0xd1, 0x7f, 0x66, 0x7e, 0xab, 0x83, 0xca, 0x29, 0xd3, 0x3c, 0x79, 0xe2, 0x1d, 0x76, -0x3b, 0x56, 0x4e, 0x1e, 0xdb, 0x0a, 0x6c, 0xe4, 0x5d, 0x6e, 0xef, 0xa6, 0xa8, 0xa4, 0x37, 0x8b, -0x32, 0x43, 0x59, 0xb7, 0x8c, 0x64, 0xd2, 0xe0, 0xb4, 0xfa, 0x07, 0x25, 0xaf, 0x8e, 0xe9, 0x18, -0xd5, 0x88, 0x6f, 0x72, 0x24, 0xf1, 0xc7, 0x51, 0x23, 0x7c, 0x9c, 0x21, 0xdd, 0xdc, 0x86, 0x85, -0x90, 0x42, 0xc4, 0xaa, 0xd8, 0x05, 0x01, 0x12, 0xa3, 0x5f, 0xf9, 0xd0, 0x91, 0x58, 0x27, 0xb9, -0x38, 0x13, 0xb3, 0x33, 0xbb, 0x70, 0x89, 0xa7, 0xb6, 0x22, 0x92, 0x20, 0x49, 0xff, 0x78, 0x7a, -0x8f, 0xf8, 0x80, 0x17, 0xda, 0x31, 0xc6, 0xb8, 0xc3, 0xb0, 0x77, 0x11, 0xcb, 0xfc, 0xd6, 0x3a -}; - -// modular multiplication tables -// based on: - -// Xtime2[x] = (x & 0x80 ? 0x1b : 0) ^ (x + x) -// Xtime3[x] = x^Xtime2[x]; - -uchar Xtime2[256] = { -0x00, 0x02, 0x04, 0x06, 0x08, 0x0a, 0x0c, 0x0e, 0x10, 0x12, 0x14, 0x16, 0x18, 0x1a, 0x1c, 0x1e, -0x20, 0x22, 0x24, 0x26, 0x28, 0x2a, 0x2c, 0x2e, 0x30, 0x32, 0x34, 0x36, 0x38, 0x3a, 0x3c, 0x3e, -0x40, 0x42, 0x44, 0x46, 0x48, 0x4a, 0x4c, 0x4e, 0x50, 0x52, 0x54, 0x56, 0x58, 0x5a, 0x5c, 0x5e, -0x60, 0x62, 0x64, 0x66, 0x68, 0x6a, 0x6c, 0x6e, 0x70, 0x72, 0x74, 0x76, 0x78, 0x7a, 0x7c, 0x7e, -0x80, 0x82, 0x84, 0x86, 0x88, 0x8a, 0x8c, 0x8e, 0x90, 0x92, 0x94, 0x96, 0x98, 0x9a, 0x9c, 0x9e, -0xa0, 0xa2, 0xa4, 0xa6, 0xa8, 0xaa, 0xac, 0xae, 0xb0, 0xb2, 0xb4, 0xb6, 0xb8, 0xba, 0xbc, 0xbe, -0xc0, 0xc2, 0xc4, 0xc6, 0xc8, 0xca, 0xcc, 0xce, 0xd0, 0xd2, 0xd4, 0xd6, 0xd8, 0xda, 0xdc, 0xde, -0xe0, 0xe2, 0xe4, 0xe6, 0xe8, 0xea, 0xec, 0xee, 0xf0, 0xf2, 0xf4, 0xf6, 0xf8, 0xfa, 0xfc, 0xfe, -0x1b, 0x19, 0x1f, 0x1d, 0x13, 0x11, 0x17, 0x15, 0x0b, 0x09, 0x0f, 0x0d, 0x03, 0x01, 0x07, 0x05, -0x3b, 0x39, 0x3f, 0x3d, 0x33, 0x31, 0x37, 0x35, 0x2b, 0x29, 0x2f, 0x2d, 0x23, 0x21, 0x27, 0x25, -0x5b, 0x59, 0x5f, 0x5d, 0x53, 0x51, 0x57, 0x55, 0x4b, 0x49, 0x4f, 0x4d, 0x43, 0x41, 0x47, 0x45, -0x7b, 0x79, 0x7f, 0x7d, 0x73, 0x71, 0x77, 0x75, 0x6b, 0x69, 0x6f, 0x6d, 0x63, 0x61, 0x67, 0x65, -0x9b, 0x99, 0x9f, 0x9d, 0x93, 0x91, 0x97, 0x95, 0x8b, 0x89, 0x8f, 0x8d, 0x83, 0x81, 0x87, 0x85, -0xbb, 0xb9, 0xbf, 0xbd, 0xb3, 0xb1, 0xb7, 0xb5, 0xab, 0xa9, 0xaf, 0xad, 0xa3, 0xa1, 0xa7, 0xa5, -0xdb, 0xd9, 0xdf, 0xdd, 0xd3, 0xd1, 0xd7, 0xd5, 0xcb, 0xc9, 0xcf, 0xcd, 0xc3, 0xc1, 0xc7, 0xc5, -0xfb, 0xf9, 0xff, 0xfd, 0xf3, 0xf1, 0xf7, 0xf5, 0xeb, 0xe9, 0xef, 0xed, 0xe3, 0xe1, 0xe7, 0xe5}; - -uchar Xtime9[256] = { -0x00, 0x09, 0x12, 0x1b, 0x24, 0x2d, 0x36, 0x3f, 0x48, 0x41, 0x5a, 0x53, 0x6c, 0x65, 0x7e, 0x77, -0x90, 0x99, 0x82, 0x8b, 0xb4, 0xbd, 0xa6, 0xaf, 0xd8, 0xd1, 0xca, 0xc3, 0xfc, 0xf5, 0xee, 0xe7, -0x3b, 0x32, 0x29, 0x20, 0x1f, 0x16, 0x0d, 0x04, 0x73, 0x7a, 0x61, 0x68, 0x57, 0x5e, 0x45, 0x4c, -0xab, 0xa2, 0xb9, 0xb0, 0x8f, 0x86, 0x9d, 0x94, 0xe3, 0xea, 0xf1, 0xf8, 0xc7, 0xce, 0xd5, 0xdc, -0x76, 0x7f, 0x64, 0x6d, 0x52, 0x5b, 0x40, 0x49, 0x3e, 0x37, 0x2c, 0x25, 0x1a, 0x13, 0x08, 0x01, -0xe6, 0xef, 0xf4, 0xfd, 0xc2, 0xcb, 0xd0, 0xd9, 0xae, 0xa7, 0xbc, 0xb5, 0x8a, 0x83, 0x98, 0x91, -0x4d, 0x44, 0x5f, 0x56, 0x69, 0x60, 0x7b, 0x72, 0x05, 0x0c, 0x17, 0x1e, 0x21, 0x28, 0x33, 0x3a, -0xdd, 0xd4, 0xcf, 0xc6, 0xf9, 0xf0, 0xeb, 0xe2, 0x95, 0x9c, 0x87, 0x8e, 0xb1, 0xb8, 0xa3, 0xaa, -0xec, 0xe5, 0xfe, 0xf7, 0xc8, 0xc1, 0xda, 0xd3, 0xa4, 0xad, 0xb6, 0xbf, 0x80, 0x89, 0x92, 0x9b, -0x7c, 0x75, 0x6e, 0x67, 0x58, 0x51, 0x4a, 0x43, 0x34, 0x3d, 0x26, 0x2f, 0x10, 0x19, 0x02, 0x0b, -0xd7, 0xde, 0xc5, 0xcc, 0xf3, 0xfa, 0xe1, 0xe8, 0x9f, 0x96, 0x8d, 0x84, 0xbb, 0xb2, 0xa9, 0xa0, -0x47, 0x4e, 0x55, 0x5c, 0x63, 0x6a, 0x71, 0x78, 0x0f, 0x06, 0x1d, 0x14, 0x2b, 0x22, 0x39, 0x30, -0x9a, 0x93, 0x88, 0x81, 0xbe, 0xb7, 0xac, 0xa5, 0xd2, 0xdb, 0xc0, 0xc9, 0xf6, 0xff, 0xe4, 0xed, -0x0a, 0x03, 0x18, 0x11, 0x2e, 0x27, 0x3c, 0x35, 0x42, 0x4b, 0x50, 0x59, 0x66, 0x6f, 0x74, 0x7d, -0xa1, 0xa8, 0xb3, 0xba, 0x85, 0x8c, 0x97, 0x9e, 0xe9, 0xe0, 0xfb, 0xf2, 0xcd, 0xc4, 0xdf, 0xd6, -0x31, 0x38, 0x23, 0x2a, 0x15, 0x1c, 0x07, 0x0e, 0x79, 0x70, 0x6b, 0x62, 0x5d, 0x54, 0x4f, 0x46}; - -uchar XtimeB[256] = { -0x00, 0x0b, 0x16, 0x1d, 0x2c, 0x27, 0x3a, 0x31, 0x58, 0x53, 0x4e, 0x45, 0x74, 0x7f, 0x62, 0x69, -0xb0, 0xbb, 0xa6, 0xad, 0x9c, 0x97, 0x8a, 0x81, 0xe8, 0xe3, 0xfe, 0xf5, 0xc4, 0xcf, 0xd2, 0xd9, -0x7b, 0x70, 0x6d, 0x66, 0x57, 0x5c, 0x41, 0x4a, 0x23, 0x28, 0x35, 0x3e, 0x0f, 0x04, 0x19, 0x12, -0xcb, 0xc0, 0xdd, 0xd6, 0xe7, 0xec, 0xf1, 0xfa, 0x93, 0x98, 0x85, 0x8e, 0xbf, 0xb4, 0xa9, 0xa2, -0xf6, 0xfd, 0xe0, 0xeb, 0xda, 0xd1, 0xcc, 0xc7, 0xae, 0xa5, 0xb8, 0xb3, 0x82, 0x89, 0x94, 0x9f, -0x46, 0x4d, 0x50, 0x5b, 0x6a, 0x61, 0x7c, 0x77, 0x1e, 0x15, 0x08, 0x03, 0x32, 0x39, 0x24, 0x2f, -0x8d, 0x86, 0x9b, 0x90, 0xa1, 0xaa, 0xb7, 0xbc, 0xd5, 0xde, 0xc3, 0xc8, 0xf9, 0xf2, 0xef, 0xe4, -0x3d, 0x36, 0x2b, 0x20, 0x11, 0x1a, 0x07, 0x0c, 0x65, 0x6e, 0x73, 0x78, 0x49, 0x42, 0x5f, 0x54, -0xf7, 0xfc, 0xe1, 0xea, 0xdb, 0xd0, 0xcd, 0xc6, 0xaf, 0xa4, 0xb9, 0xb2, 0x83, 0x88, 0x95, 0x9e, -0x47, 0x4c, 0x51, 0x5a, 0x6b, 0x60, 0x7d, 0x76, 0x1f, 0x14, 0x09, 0x02, 0x33, 0x38, 0x25, 0x2e, -0x8c, 0x87, 0x9a, 0x91, 0xa0, 0xab, 0xb6, 0xbd, 0xd4, 0xdf, 0xc2, 0xc9, 0xf8, 0xf3, 0xee, 0xe5, -0x3c, 0x37, 0x2a, 0x21, 0x10, 0x1b, 0x06, 0x0d, 0x64, 0x6f, 0x72, 0x79, 0x48, 0x43, 0x5e, 0x55, -0x01, 0x0a, 0x17, 0x1c, 0x2d, 0x26, 0x3b, 0x30, 0x59, 0x52, 0x4f, 0x44, 0x75, 0x7e, 0x63, 0x68, -0xb1, 0xba, 0xa7, 0xac, 0x9d, 0x96, 0x8b, 0x80, 0xe9, 0xe2, 0xff, 0xf4, 0xc5, 0xce, 0xd3, 0xd8, -0x7a, 0x71, 0x6c, 0x67, 0x56, 0x5d, 0x40, 0x4b, 0x22, 0x29, 0x34, 0x3f, 0x0e, 0x05, 0x18, 0x13, -0xca, 0xc1, 0xdc, 0xd7, 0xe6, 0xed, 0xf0, 0xfb, 0x92, 0x99, 0x84, 0x8f, 0xbe, 0xb5, 0xa8, 0xa3}; - -uchar XtimeD[256] = { -0x00, 0x0d, 0x1a, 0x17, 0x34, 0x39, 0x2e, 0x23, 0x68, 0x65, 0x72, 0x7f, 0x5c, 0x51, 0x46, 0x4b, -0xd0, 0xdd, 0xca, 0xc7, 0xe4, 0xe9, 0xfe, 0xf3, 0xb8, 0xb5, 0xa2, 0xaf, 0x8c, 0x81, 0x96, 0x9b, -0xbb, 0xb6, 0xa1, 0xac, 0x8f, 0x82, 0x95, 0x98, 0xd3, 0xde, 0xc9, 0xc4, 0xe7, 0xea, 0xfd, 0xf0, -0x6b, 0x66, 0x71, 0x7c, 0x5f, 0x52, 0x45, 0x48, 0x03, 0x0e, 0x19, 0x14, 0x37, 0x3a, 0x2d, 0x20, -0x6d, 0x60, 0x77, 0x7a, 0x59, 0x54, 0x43, 0x4e, 0x05, 0x08, 0x1f, 0x12, 0x31, 0x3c, 0x2b, 0x26, -0xbd, 0xb0, 0xa7, 0xaa, 0x89, 0x84, 0x93, 0x9e, 0xd5, 0xd8, 0xcf, 0xc2, 0xe1, 0xec, 0xfb, 0xf6, -0xd6, 0xdb, 0xcc, 0xc1, 0xe2, 0xef, 0xf8, 0xf5, 0xbe, 0xb3, 0xa4, 0xa9, 0x8a, 0x87, 0x90, 0x9d, -0x06, 0x0b, 0x1c, 0x11, 0x32, 0x3f, 0x28, 0x25, 0x6e, 0x63, 0x74, 0x79, 0x5a, 0x57, 0x40, 0x4d, -0xda, 0xd7, 0xc0, 0xcd, 0xee, 0xe3, 0xf4, 0xf9, 0xb2, 0xbf, 0xa8, 0xa5, 0x86, 0x8b, 0x9c, 0x91, -0x0a, 0x07, 0x10, 0x1d, 0x3e, 0x33, 0x24, 0x29, 0x62, 0x6f, 0x78, 0x75, 0x56, 0x5b, 0x4c, 0x41, -0x61, 0x6c, 0x7b, 0x76, 0x55, 0x58, 0x4f, 0x42, 0x09, 0x04, 0x13, 0x1e, 0x3d, 0x30, 0x27, 0x2a, -0xb1, 0xbc, 0xab, 0xa6, 0x85, 0x88, 0x9f, 0x92, 0xd9, 0xd4, 0xc3, 0xce, 0xed, 0xe0, 0xf7, 0xfa, -0xb7, 0xba, 0xad, 0xa0, 0x83, 0x8e, 0x99, 0x94, 0xdf, 0xd2, 0xc5, 0xc8, 0xeb, 0xe6, 0xf1, 0xfc, -0x67, 0x6a, 0x7d, 0x70, 0x53, 0x5e, 0x49, 0x44, 0x0f, 0x02, 0x15, 0x18, 0x3b, 0x36, 0x21, 0x2c, -0x0c, 0x01, 0x16, 0x1b, 0x38, 0x35, 0x22, 0x2f, 0x64, 0x69, 0x7e, 0x73, 0x50, 0x5d, 0x4a, 0x47, -0xdc, 0xd1, 0xc6, 0xcb, 0xe8, 0xe5, 0xf2, 0xff, 0xb4, 0xb9, 0xae, 0xa3, 0x80, 0x8d, 0x9a, 0x97}; - -uchar XtimeE[256] = { -0x00, 0x0e, 0x1c, 0x12, 0x38, 0x36, 0x24, 0x2a, 0x70, 0x7e, 0x6c, 0x62, 0x48, 0x46, 0x54, 0x5a, -0xe0, 0xee, 0xfc, 0xf2, 0xd8, 0xd6, 0xc4, 0xca, 0x90, 0x9e, 0x8c, 0x82, 0xa8, 0xa6, 0xb4, 0xba, -0xdb, 0xd5, 0xc7, 0xc9, 0xe3, 0xed, 0xff, 0xf1, 0xab, 0xa5, 0xb7, 0xb9, 0x93, 0x9d, 0x8f, 0x81, -0x3b, 0x35, 0x27, 0x29, 0x03, 0x0d, 0x1f, 0x11, 0x4b, 0x45, 0x57, 0x59, 0x73, 0x7d, 0x6f, 0x61, -0xad, 0xa3, 0xb1, 0xbf, 0x95, 0x9b, 0x89, 0x87, 0xdd, 0xd3, 0xc1, 0xcf, 0xe5, 0xeb, 0xf9, 0xf7, -0x4d, 0x43, 0x51, 0x5f, 0x75, 0x7b, 0x69, 0x67, 0x3d, 0x33, 0x21, 0x2f, 0x05, 0x0b, 0x19, 0x17, -0x76, 0x78, 0x6a, 0x64, 0x4e, 0x40, 0x52, 0x5c, 0x06, 0x08, 0x1a, 0x14, 0x3e, 0x30, 0x22, 0x2c, -0x96, 0x98, 0x8a, 0x84, 0xae, 0xa0, 0xb2, 0xbc, 0xe6, 0xe8, 0xfa, 0xf4, 0xde, 0xd0, 0xc2, 0xcc, -0x41, 0x4f, 0x5d, 0x53, 0x79, 0x77, 0x65, 0x6b, 0x31, 0x3f, 0x2d, 0x23, 0x09, 0x07, 0x15, 0x1b, -0xa1, 0xaf, 0xbd, 0xb3, 0x99, 0x97, 0x85, 0x8b, 0xd1, 0xdf, 0xcd, 0xc3, 0xe9, 0xe7, 0xf5, 0xfb, -0x9a, 0x94, 0x86, 0x88, 0xa2, 0xac, 0xbe, 0xb0, 0xea, 0xe4, 0xf6, 0xf8, 0xd2, 0xdc, 0xce, 0xc0, -0x7a, 0x74, 0x66, 0x68, 0x42, 0x4c, 0x5e, 0x50, 0x0a, 0x04, 0x16, 0x18, 0x32, 0x3c, 0x2e, 0x20, -0xec, 0xe2, 0xf0, 0xfe, 0xd4, 0xda, 0xc8, 0xc6, 0x9c, 0x92, 0x80, 0x8e, 0xa4, 0xaa, 0xb8, 0xb6, -0x0c, 0x02, 0x10, 0x1e, 0x34, 0x3a, 0x28, 0x26, 0x7c, 0x72, 0x60, 0x6e, 0x44, 0x4a, 0x58, 0x56, -0x37, 0x39, 0x2b, 0x25, 0x0f, 0x01, 0x13, 0x1d, 0x47, 0x49, 0x5b, 0x55, 0x7f, 0x71, 0x63, 0x6d, -0xd7, 0xd9, 0xcb, 0xc5, 0xef, 0xe1, 0xf3, 0xfd, 0xa7, 0xa9, 0xbb, 0xb5, 0x9f, 0x91, 0x83, 0x8d}; - -// exchanges columns in each of 4 rows -// row0 - unchanged, row1- shifted left 1, -// row2 - shifted left 2 and row3 - shifted left 3 -void ShiftRows (uchar *state) -{ -uchar tmp; - - // just substitute row 0 - state[0] = Sbox[state[0]], state[4] = Sbox[state[4]]; - state[8] = Sbox[state[8]], state[12] = Sbox[state[12]]; - - // rotate row 1 - tmp = Sbox[state[1]], state[1] = Sbox[state[5]]; - state[5] = Sbox[state[9]], state[9] = Sbox[state[13]], state[13] = tmp; - - // rotate row 2 - tmp = Sbox[state[2]], state[2] = Sbox[state[10]], state[10] = tmp; - tmp = Sbox[state[6]], state[6] = Sbox[state[14]], state[14] = tmp; - - // rotate row 3 - tmp = Sbox[state[15]], state[15] = Sbox[state[11]]; - state[11] = Sbox[state[7]], state[7] = Sbox[state[3]], state[3] = tmp; -} - -// restores columns in each of 4 rows -// row0 - unchanged, row1- shifted right 1, -// row2 - shifted right 2 and row3 - shifted right 3 -void InvShiftRows (uchar *state) -{ -uchar tmp; - - // restore row 0 - state[0] = InvSbox[state[0]], state[4] = InvSbox[state[4]]; - state[8] = InvSbox[state[8]], state[12] = InvSbox[state[12]]; - - // restore row 1 - tmp = InvSbox[state[13]], state[13] = InvSbox[state[9]]; - state[9] = InvSbox[state[5]], state[5] = InvSbox[state[1]], state[1] = tmp; - - // restore row 2 - tmp = InvSbox[state[2]], state[2] = InvSbox[state[10]], state[10] = tmp; - tmp = InvSbox[state[6]], state[6] = InvSbox[state[14]], state[14] = tmp; - - // restore row 3 - tmp = InvSbox[state[3]], state[3] = InvSbox[state[7]]; - state[7] = InvSbox[state[11]], state[11] = InvSbox[state[15]], state[15] = tmp; -} - -// recombine and mix each row in a column -void MixSubColumns (uchar *state) -{ -uchar tmp[4 * Nb]; - - // mixing column 0 - tmp[0] = Xtime2Sbox[state[0]] ^ Xtime3Sbox[state[5]] ^ Sbox[state[10]] ^ Sbox[state[15]]; - tmp[1] = Sbox[state[0]] ^ Xtime2Sbox[state[5]] ^ Xtime3Sbox[state[10]] ^ Sbox[state[15]]; - tmp[2] = Sbox[state[0]] ^ Sbox[state[5]] ^ Xtime2Sbox[state[10]] ^ Xtime3Sbox[state[15]]; - tmp[3] = Xtime3Sbox[state[0]] ^ Sbox[state[5]] ^ Sbox[state[10]] ^ Xtime2Sbox[state[15]]; - - // mixing column 1 - tmp[4] = Xtime2Sbox[state[4]] ^ Xtime3Sbox[state[9]] ^ Sbox[state[14]] ^ Sbox[state[3]]; - tmp[5] = Sbox[state[4]] ^ Xtime2Sbox[state[9]] ^ Xtime3Sbox[state[14]] ^ Sbox[state[3]]; - tmp[6] = Sbox[state[4]] ^ Sbox[state[9]] ^ Xtime2Sbox[state[14]] ^ Xtime3Sbox[state[3]]; - tmp[7] = Xtime3Sbox[state[4]] ^ Sbox[state[9]] ^ Sbox[state[14]] ^ Xtime2Sbox[state[3]]; - - // mixing column 2 - tmp[8] = Xtime2Sbox[state[8]] ^ Xtime3Sbox[state[13]] ^ Sbox[state[2]] ^ Sbox[state[7]]; - tmp[9] = Sbox[state[8]] ^ Xtime2Sbox[state[13]] ^ Xtime3Sbox[state[2]] ^ Sbox[state[7]]; - tmp[10] = Sbox[state[8]] ^ Sbox[state[13]] ^ Xtime2Sbox[state[2]] ^ Xtime3Sbox[state[7]]; - tmp[11] = Xtime3Sbox[state[8]] ^ Sbox[state[13]] ^ Sbox[state[2]] ^ Xtime2Sbox[state[7]]; - - // mixing column 3 - tmp[12] = Xtime2Sbox[state[12]] ^ Xtime3Sbox[state[1]] ^ Sbox[state[6]] ^ Sbox[state[11]]; - tmp[13] = Sbox[state[12]] ^ Xtime2Sbox[state[1]] ^ Xtime3Sbox[state[6]] ^ Sbox[state[11]]; - tmp[14] = Sbox[state[12]] ^ Sbox[state[1]] ^ Xtime2Sbox[state[6]] ^ Xtime3Sbox[state[11]]; - tmp[15] = Xtime3Sbox[state[12]] ^ Sbox[state[1]] ^ Sbox[state[6]] ^ Xtime2Sbox[state[11]]; - - memcpy (state, tmp, sizeof(tmp)); -} - -// restore and un-mix each row in a column -void InvMixSubColumns (uchar *state) -{ -uchar tmp[4 * Nb]; -int i; - - // restore column 0 - tmp[0] = XtimeE[state[0]] ^ XtimeB[state[1]] ^ XtimeD[state[2]] ^ Xtime9[state[3]]; - tmp[5] = Xtime9[state[0]] ^ XtimeE[state[1]] ^ XtimeB[state[2]] ^ XtimeD[state[3]]; - tmp[10] = XtimeD[state[0]] ^ Xtime9[state[1]] ^ XtimeE[state[2]] ^ XtimeB[state[3]]; - tmp[15] = XtimeB[state[0]] ^ XtimeD[state[1]] ^ Xtime9[state[2]] ^ XtimeE[state[3]]; - - // restore column 1 - tmp[4] = XtimeE[state[4]] ^ XtimeB[state[5]] ^ XtimeD[state[6]] ^ Xtime9[state[7]]; - tmp[9] = Xtime9[state[4]] ^ XtimeE[state[5]] ^ XtimeB[state[6]] ^ XtimeD[state[7]]; - tmp[14] = XtimeD[state[4]] ^ Xtime9[state[5]] ^ XtimeE[state[6]] ^ XtimeB[state[7]]; - tmp[3] = XtimeB[state[4]] ^ XtimeD[state[5]] ^ Xtime9[state[6]] ^ XtimeE[state[7]]; - - // restore column 2 - tmp[8] = XtimeE[state[8]] ^ XtimeB[state[9]] ^ XtimeD[state[10]] ^ Xtime9[state[11]]; - tmp[13] = Xtime9[state[8]] ^ XtimeE[state[9]] ^ XtimeB[state[10]] ^ XtimeD[state[11]]; - tmp[2] = XtimeD[state[8]] ^ Xtime9[state[9]] ^ XtimeE[state[10]] ^ XtimeB[state[11]]; - tmp[7] = XtimeB[state[8]] ^ XtimeD[state[9]] ^ Xtime9[state[10]] ^ XtimeE[state[11]]; - - // restore column 3 - tmp[12] = XtimeE[state[12]] ^ XtimeB[state[13]] ^ XtimeD[state[14]] ^ Xtime9[state[15]]; - tmp[1] = Xtime9[state[12]] ^ XtimeE[state[13]] ^ XtimeB[state[14]] ^ XtimeD[state[15]]; - tmp[6] = XtimeD[state[12]] ^ Xtime9[state[13]] ^ XtimeE[state[14]] ^ XtimeB[state[15]]; - tmp[11] = XtimeB[state[12]] ^ XtimeD[state[13]] ^ Xtime9[state[14]] ^ XtimeE[state[15]]; - - for( i=0; i < 4 * Nb; i++ ) - state[i] = InvSbox[tmp[i]]; -} - -// encrypt/decrypt columns of the key -// n.b. you can replace this with -// byte-wise xor if you wish. - -void AddRoundKey (unsigned *state, unsigned *key) -{ -int idx; - - for( idx = 0; idx < 4; idx++ ) - state[idx] ^= key[idx]; -} - -uchar Rcon[11] = { -0x00, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36}; - -// produce Nb bytes for each round -void ExpandKey (uchar *key, uchar *expkey) -{ -uchar tmp0, tmp1, tmp2, tmp3, tmp4; -unsigned idx; - - memcpy (expkey, key, Nk * 4); - - for( idx = Nk; idx < Nb * (Nr + 1); idx++ ) { - tmp0 = expkey[4*idx - 4]; - tmp1 = expkey[4*idx - 3]; - tmp2 = expkey[4*idx - 2]; - tmp3 = expkey[4*idx - 1]; - if( !(idx % Nk) ) { - tmp4 = tmp3; - tmp3 = Sbox[tmp0]; - tmp0 = Sbox[tmp1] ^ Rcon[idx/Nk]; - tmp1 = Sbox[tmp2]; - tmp2 = Sbox[tmp4]; - } else if( Nk > 6 && idx % Nk == 4 ) { - tmp0 = Sbox[tmp0]; - tmp1 = Sbox[tmp1]; - tmp2 = Sbox[tmp2]; - tmp3 = Sbox[tmp3]; - } - - expkey[4*idx+0] = expkey[4*idx - 4*Nk + 0] ^ tmp0; - expkey[4*idx+1] = expkey[4*idx - 4*Nk + 1] ^ tmp1; - expkey[4*idx+2] = expkey[4*idx - 4*Nk + 2] ^ tmp2; - expkey[4*idx+3] = expkey[4*idx - 4*Nk + 3] ^ tmp3; - } -} - -// encrypt one 128 bit block -void Encrypt (uchar *in, uchar *expkey, uchar *out) -{ -uchar state[Nb * 4]; -unsigned round; - - memcpy (state, in, Nb * 4); - AddRoundKey ((unsigned *)state, (unsigned *)expkey); - - for( round = 1; round < Nr + 1; round++ ) { - if( round < Nr ) - MixSubColumns (state); - else - ShiftRows (state); - - AddRoundKey ((unsigned *)state, (unsigned *)expkey + round * Nb); - } - - memcpy (out, state, sizeof(state)); -} - -void Decrypt (uchar *in, uchar *expkey, uchar *out) -{ -uchar state[Nb * 4]; -unsigned round; - - memcpy (state, in, sizeof(state)); - - AddRoundKey ((unsigned *)state, (unsigned *)expkey + Nr * Nb); - InvShiftRows(state); - - for( round = Nr; round--; ) - { - AddRoundKey ((unsigned *)state, (unsigned *)expkey + round * Nb); - if( round ) - InvMixSubColumns (state); - } - - memcpy (out, state, sizeof(state)); -}
− c/helper.c
@@ -1,166 +0,0 @@-#include <stdlib.h>-#include <stdint.h>-#include <string.h>--typedef unsigned char uchar;-typedef unsigned int uint;-#define Nb 4 // number of columns in the state & expanded key-#define Nr 10 // number of rounds in encryption--void ExpandKey(uchar *key, uchar *expkey);-void Encrypt (uchar *in, uchar *expkey, uchar *out);-void Decrypt (uchar *in, uchar *expkey, uchar *out);--void get_hash(uint *out, uchar *in, uint len)-{- uint32_t hash = 0;-- for (; len--; ++in) {- hash = (hash >> 1) + ((hash & 1) << 31);- hash += *in;- }-- *out = hash;-}--/* http://base64.sourceforge.net/b64.c. LICENCE: Copyright (c) 2001- * Bob Trower, Trantor Standard Systems Inc. */--static const char cb64[]="ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";--void base64_enc(char *out, uchar *in, uint len)-{- while (len) {- uchar buffin[3];- buffin[0] = *(in++);- if (--len) {- buffin[1] = *(in++);- if (--len) {- buffin[2] = *(in++);- --len;- } else {- buffin[2] = 0;- }- } else {- buffin[1] = 0;- buffin[2] = 0;- }-- *(out++) = cb64[buffin[0] >> 2];- *(out++) = cb64[ (buffin[0] & 0x03) << 4- | (buffin[1] & 0xf0) >> 4];- *(out++) = cb64[ (buffin[1] & 0x0f) << 2- | (buffin[2] & 0xc0) >> 6];- *(out++) = cb64[buffin[2] & 0x3f];- }-}--int parse_char(uchar *out, char in)-{- if ('A' <= in && in <= 'Z') {- *out = in - 'A';- } else if ('a' <= in && in <= 'z') {- *out = in - 'a' + 26;- } else if ('0' <= in && in <= '9') {- *out = in - '0' + 52;- } else if (in == '+') {- *out = 62;- } else if (in == '/') {- *out = 63;- } else {- return 0;- }- return 1;-}--int base64_dec(uchar *out, char *in, uint len)-{- for (; len; in += 4, out += 3, len -= 4) {- uchar tmp[4];- int i = 0;- for (i = 0; i < 4; ++i) {- if (! parse_char(tmp + i, in[i])) return 0;- }- out[0] = tmp[0] << 2 | tmp[1] >> 4;- out[1] = tmp[1] << 4 | tmp[2] >> 2;- out[2] = ((tmp[2] << 6) & 0xc0) | tmp[3];- }- return 1;-}--char * encrypt(uint32_t len, uchar *in, uchar *key, uint *outlen)-{- uchar expkey[4 * Nb * (Nr + 1)];- uchar *out;- uint i;- uint totlen, encoded_len;- uchar *tmp;- uchar buff[16];-- /* 4 bytes for the hash, 4 bytes for the length, then the string.- * Need to align to 16 bytes.- */- totlen = len + 8;- totlen += (- totlen) % 16;- tmp = alloca(totlen);- bzero(tmp, totlen);- get_hash((uint*) tmp, in, len);- memcpy(tmp + 4, &len, 4);- memcpy(tmp + 8, in, len);-- ExpandKey(key, expkey);- for (i = 0; i < totlen; i += 16) {- Encrypt(tmp + i, expkey, buff);-- memcpy(tmp + i, buff, 16);- }-- encoded_len = ((totlen + 2) / 3) * 4;- out = malloc(encoded_len + 1);- out[encoded_len] = 0;- base64_enc(out, tmp, totlen);-- *outlen = encoded_len;- return out;-}--uchar * decrypt(uint len, char *in, uchar *key, uint *out_len)-{- uchar expkey[4 * Nb * (Nr + 1)];- uchar *out;- uint i;- uchar buff[16];- uint outlen;- uint hash, orig_hash;- uint32_t orig_len;-- if (! len % 4) return 0;- outlen = len / 4 * 3;- out = alloca(outlen + (- outlen) % 16);-- if (! base64_dec(out, in, len)) {- return 0;- }-- ExpandKey(key, expkey);-- for (i = 0; i < outlen; i += 16) {- Decrypt(out + i, expkey, buff);- memcpy(out + i, buff, 16);- }-- orig_hash = *((uint*) out);- orig_len = *((uint32_t*) (out + 4));- if (orig_len > outlen) return 0;- get_hash(&hash, out + 8, orig_len);- if (orig_hash != hash) {- return 0;- }-- uchar *realout = malloc(orig_len + 1);- realout[orig_len] = 0;- memcpy(realout, out + 8, orig_len);-- *out_len = orig_len;- return realout;-}
clientsession.cabal view
@@ -1,47 +1,69 @@ name: clientsession-version: 0.4.1-license: BSD3+version: 0.9.3.0+license: MIT license-file: LICENSE-author: Michael Snoyman <michael@snoyman.com>+author: Michael Snoyman <michael@snoyman.com>, Felipe Lessa <felipe.lessa@gmail.com> maintainer: Michael Snoyman <michael@snoyman.com>-synopsis: Store session data in a cookie.-description: Achieves security through AES encryption and MD5 hashing.- Uses base64 encoding to avoid any issues with characters.+synopsis: Securely store session data in a client-side cookie.+description: Achieves security through AES-CTR encryption and+ Skein-MAC-512-256 authentication. Uses Base64+ encoding to avoid any issues with characters. category: Web stability: stable-cabal-version: >= 1.6+cabal-version: >= 1.10 build-type: Simple-homepage: http://github.com/snoyberg/clientsession/tree/master+homepage: http://github.com/yesodweb/clientsession/tree/master+extra-source-files: tests/runtests.hs bench.hs ChangeLog.md README.md -flag buildtests+flag test description: Build the executable to run unit tests default: False +executable clientsession-generate+ default-language: Haskell2010+ main-is: generate.hs+ build-depends: base+ , clientsession+ ghc-options: -Wall+ hs-source-dirs: bin+ library- build-depends: base >=4 && <5,- bytestring >= 0.9 && < 0.10,- directory >= 1 && < 1.2,- random >= 1.0.0.2 && < 1.1,- template-haskell+ default-language: Haskell2010+ build-depends: base >= 4.8 && < 5+ -- https://github.com/yesodweb/clientsession/commit/1221230770feff60f77ff676d52fc464cb77b2d9#r122087962+ -- Data.Bifunctor entered base in 4.8+ , bytestring >= 0.9+ , cereal >= 0.3+ , directory >= 1+ , tagged >= 0.1+ , crypto-api >= 0.8+ , skein == 1.0.*+ , base64-bytestring >= 0.1.1.1+ , entropy >= 0.2.1+ , crypton >= 1.0+ , setenv exposed-modules: Web.ClientSession+ other-modules: System.LookupEnv ghc-options: -Wall- c-sources: c/aestable.c c/helper.c+ hs-source-dirs: src -executable runtests- if flag(buildtests)- Buildable: True- cpp-options: -DTEST- build-depends: test-framework,- test-framework-quickcheck2,- test-framework-hunit,- QuickCheck >= 2 && < 3,- HUnit- else- Buildable: False+test-suite runtests+ default-language: Haskell2010+ type: exitcode-stdio-1.0+ build-depends: base+ , bytestring >= 0.9+ , hspec >= 1.3+ , QuickCheck >= 2+ , HUnit+ , transformers+ , containers+ , cereal+ -- finally, our own package+ , clientsession ghc-options: -Wall+ hs-source-dirs: tests main-is: runtests.hs- c-sources: c/aestable.c c/helper.c source-repository head type: git- location: git://github.com/snoyberg/clientsession.git+ location: https://github.com/yesodweb/clientsession.git
− runtests.hs
@@ -1,58 +0,0 @@-{-# LANGUAGE FlexibleInstances #-}-{-# LANGUAGE MultiParamTypeClasses #-}-{-# OPTIONS_GHC -fno-warn-orphans #-}-import Test.Framework (defaultMain)-import Test.QuickCheck-import Test.Framework.Providers.QuickCheck2-import Test.Framework.Providers.HUnit-import Test.HUnit--import qualified Data.ByteString as S-import qualified Data.ByteString.Char8 as S8--import Web.ClientSession-import System.IO.Unsafe-import Data.Word--main :: IO ()-main = defaultMain- [ testProperty "encrypt/decrypt success" propEncDec- , testProperty "encrypt/decrypt failure" propEncDecFailure- , testProperty "AES encrypt/decrypt success" propAES- , testProperty "AES encryption changes bs" propAESChanges- , testCase "specific values" caseSpecific- ]--propEncDec :: S.ByteString -> Bool-propEncDec bs = unsafePerformIO $ do- key <- getDefaultKey- let s = encrypt key bs- let bs' = decrypt key s- return $ Just bs == bs'--propEncDecFailure :: S.ByteString -> Bool-propEncDecFailure bs = unsafePerformIO $ do- key <- getDefaultKey- let s = encrypt key bs- let bs' = decrypt key $ (S.head s + 1) `S.cons` S.drop 1 s- return $ Just bs /= bs'--propAES :: S.ByteString -> S.ByteString -> Bool-propAES key bs = decrypt key (encrypt key bs) == Just bs--propAESChanges :: S.ByteString -> S.ByteString -> Bool-propAESChanges key bs = encrypt key bs /= bs--caseSpecific :: Assertion-caseSpecific = do- let s = S8.pack $ show [("lo\ENQ\143XAq","\DC2\207\226\DC1;.z56|\203\222"),("\USnu#\139\ETXB\201 ","l"),("\RS\b,zM2U\184\191F)\EOT\220S\NUL","O\\\GSd\247\246\n\EOT\SYN\182U2G"),("\219\NAK\217\CAN\252","ym\STX\188\232?\\\145"),("\239k","\vRZP\a\DC2F>"),("\FS\180P &\RS\174zSL\\?@","p\170\237vZ|\GS>\SYNk\176n\r"),("","\199D\DC3\200m)"),("6\152tVhB\246)9","\ENQdfU\SUB"),("I\ACK\181\NUL","\129\&6s\130q\US)oR1\197\FSp\US\SYN0"),("\183\200<\250","\211 \131g4\207N\155"),("\248O6k\CANK\135\234.","`\205!+&Z&9\DLE\244\214HP\SI\161"),("\"I'\ACK\149 \CAN\197","\141N\201\SO\204\\o.\128\148")]- key <- getDefaultKey- Just s @=? decrypt key (encrypt key s)- let s' = S.concat $ replicate 500 s- Just s' @=? decrypt key (encrypt key s')--instance Arbitrary S.ByteString where- arbitrary = S.pack `fmap` arbitrary--instance Arbitrary Word8 where- arbitrary = arbitraryBoundedIntegral
+ src/System/LookupEnv.hs view
@@ -0,0 +1,6 @@+module System.LookupEnv (lookupEnv) where++import System.Environment (getEnvironment)++lookupEnv :: String -> IO (Maybe String)+lookupEnv envVar = fmap (lookup envVar) $ getEnvironment
+ src/Web/ClientSession.hs view
@@ -0,0 +1,361 @@+{-# LANGUAGE FlexibleContexts #-}+{-# LANGUAGE ForeignFunctionInterface #-}+{-# LANGUAGE NamedFieldPuns #-}+{-# LANGUAGE TemplateHaskell #-}+{-# LANGUAGE CPP #-}+{-# LANGUAGE PackageImports #-}+---------------------------------------------------------+--+-- |+--+-- Module : Web.ClientSession+-- Copyright : Michael Snoyman+-- License : BSD3+--+-- Maintainer : Michael Snoyman <michael@snoyman.com>+-- Stability : Stable+-- Portability : portable+--+-- Stores session data in a client cookie. In order to do so,+-- we:+--+-- * Encrypt the cookie data using AES in CTR mode. This allows+-- you to store sensitive information on the client side without+-- worrying about eavesdropping.+--+-- * Authenticate the encrypted cookie data using+-- Skein-MAC-512-256. Besides detecting potential errors in+-- storage or transmission of the cookies (integrity), the MAC+-- also avoids malicious modifications of the cookie data by+-- assuring you that the cookie data really was generated by this+-- server (authenticity).+--+-- * Encode everything using Base64. Thus we avoid problems with+-- non-printable characters by giving the browser a simple+-- string.+--+-- Simple usage of the library involves just calling+-- 'getDefaultKey' on the startup of your server, 'encryptIO'+-- when serializing cookies and 'decrypt' when parsing then back.+--+---------------------------------------------------------+module Web.ClientSession+ ( -- * Automatic key generation+ Key+ , IV+ , randomIV+ , mkIV+ , getKey+ , getKeyEnv+ , defaultKeyFile+ , getDefaultKey+ , initKey+ , randomKey+ , randomKeyEnv+ -- * Actual encryption/decryption+ , encrypt+ , encryptIO+ , decrypt+ ) where++-- from base+import Control.Applicative ((<$>))+import Control.Concurrent (forkIO)+import Control.Monad (guard, when)+import Data.Bifunctor (first)+import Data.Function (on)++#if MIN_VERSION_base(4,7,0)+import System.Environment (lookupEnv, setEnv)+#elif MIN_VERSION_base(4,6,0)+import System.Environment (lookupEnv)+import System.SetEnv (setEnv)+#else+import System.LookupEnv (lookupEnv)+import System.SetEnv (setEnv)+#endif++import System.IO.Unsafe (unsafePerformIO)+import qualified Data.IORef as I++-- from directory+import System.Directory (doesFileExist)++-- from bytestring+import qualified Data.ByteString as S+import qualified Data.ByteString.Char8 as C+import qualified Data.ByteString.Base64 as B++-- from cereal+import Data.Serialize (encode, Serialize (put, get), getBytes, putByteString)++-- from tagged+import Data.Tagged (Tagged, untag)++-- from crypto-api+import Crypto.Classes (constTimeEq)++-- from crypton+import qualified Crypto.Cipher.AES as A+import Crypto.Cipher.Types(Cipher(..),BlockCipher(..),makeIV)+import Crypto.Error (eitherCryptoError)+import "crypton" Crypto.Random (ChaChaDRG,drgNew,randomBytesGenerate)++-- from skein+import Crypto.Skein (skeinMAC', Skein_512_256)++-- from entropy+import System.Entropy (getEntropy)+++-- | The keys used to store the cookies. We have an AES key used+-- to encrypt the cookie and a Skein-MAC-512-256 key used verify+-- the authencity and integrity of the cookie. The AES key must+-- have exactly 32 bytes (256 bits) while Skein-MAC-512-256 must+-- have 64 bytes (512 bits).+--+-- See also 'getDefaultKey' and 'initKey'.+data Key = Key { aesKey ::+ !A.AES256+ -- ^ AES key with 32 bytes.+ , macKey :: !(S.ByteString -> Skein_512_256)+ -- ^ Skein-MAC key. Instead of storing the key+ -- data, we store a partially applied function+ -- for calculating the MAC (see 'skeinMAC'').+ , keyRaw :: !S.ByteString+ }++instance Eq Key where+ Key _ _ r1 == Key _ _ r2 = r1 == r2++instance Serialize Key where+ put = putByteString . keyRaw+ get = either error id . initKey <$> getBytes 96++-- | Dummy 'Show' instance.+instance Show Key where+ show _ = "<Web.ClientSession.Key>"++-- | The initialization vector used by AES. Must be exactly 16+-- bytes long.+newtype IV = IV S.ByteString++unsafeMkIV :: S.ByteString -> IV+unsafeMkIV bs = (IV bs)++unIV :: IV -> S.ByteString+unIV (IV bs) = bs++instance Eq IV where+ (==) = (==) `on` unIV+ (/=) = (/=) `on` unIV++instance Ord IV where+ compare = compare `on` unIV+ (<=) = (<=) `on` unIV+ (<) = (<) `on` unIV+ (>=) = (>=) `on` unIV+ (>) = (>) `on` unIV++instance Show IV where+ show = show . unIV++instance Serialize IV where+ put = put . unIV+ get = unsafeMkIV <$> get++-- | Construct an initialization vector from a 'S.ByteString'.+-- Fails if there isn't exactly 16 bytes.+mkIV :: S.ByteString -> Maybe IV+mkIV bs | S.length bs == 16 = Just (unsafeMkIV bs)+ | otherwise = Nothing++-- | Randomly construct a fresh initialization vector. You+-- /MUST NOT/ reuse initialization vectors.+randomIV :: IO IV+randomIV = chaChaRNG++-- | The default key file.+defaultKeyFile :: FilePath+defaultKeyFile = "client_session_key.aes"++-- | Simply calls 'getKey' 'defaultKeyFile'.+getDefaultKey :: IO Key+getDefaultKey = getKey defaultKeyFile++-- | Get a key from the given text file.+--+-- If the file does not exist or is corrupted a random key will+-- be generated and stored in that file.+getKey :: FilePath -- ^ File name where key is stored.+ -> IO Key -- ^ The actual key.+getKey keyFile = do+ exists <- doesFileExist keyFile+ if exists+ then S.readFile keyFile >>= either (const newKey) return . initKey+ else newKey+ where+ newKey = do+ (bs, key') <- randomKey+ S.writeFile keyFile bs+ return key'++-- | Get the key from the named environment variable+--+-- Assumes the value is a Base64-encoded string. If the variable is not set, a+-- random key will be generated, set in the environment, and the Base64-encoded+-- version printed on @/dev/stdout@.+getKeyEnv :: String -- ^ Name of the environment variable+ -> IO Key -- ^ The actual key.+getKeyEnv envVar = do+ mvalue <- lookupEnv envVar+ case mvalue of+ Just value -> either (const newKey) return $ initKey =<< decode value+ Nothing -> newKey+ where+ decode = B.decode . C.pack+ newKey = randomKeyEnv envVar++-- | Generate a random 'Key'. Besides the 'Key', the+-- 'ByteString' passed to 'initKey' is returned so that it can be+-- saved for later use.+randomKey :: IO (S.ByteString, Key)+randomKey = do+ bs <- getEntropy 96+ case initKey bs of+ Left e -> error $ "Web.ClientSession.randomKey: never here, " ++ e+ Right key -> return (bs, key)++-- | Generate a random 'Key', set a Base64-encoded version of it in the given+-- environment variable, then return it. Also prints the generated string to+-- @/dev/stdout@.+randomKeyEnv :: String -> IO Key+randomKeyEnv envVar = do+ (bs, key) <- randomKey+ let encoded = C.unpack $ B.encode bs+ setEnv envVar encoded+ putStrLn $ envVar ++ "=" ++ encoded+ return key++-- | Initializes a 'Key' from a random 'S.ByteString'. Fails if+-- there isn't exactly 96 bytes (256 bits for AES and 512 bits+-- for Skein-MAC-512-512).+--+-- Note that the input string is assumed to be uniformly chosen+-- from the set of all 96-byte strings. In other words, each+-- byte should be chosen from the set of all byte values (0-255)+-- with the same probability.+--+-- In particular, this function does not do any kind of key+-- stretching. You should never feed it a password, for example.+--+-- It's /highly/ recommended to feed @initKey@ only with values+-- generated by 'randomKey', unless you really know what you're+-- doing.+initKey :: S.ByteString -> Either String Key+initKey bs | S.length bs /= 96 = Left $ "Web.ClientSession.initKey: length of " +++ show (S.length bs) ++ " /= 96."+initKey bs = do+ let (preMacKey, preAesKey) = S.splitAt 64 bs+ aesKey <- first show $ eitherCryptoError (cipherInit preAesKey)+ Right $ Key { aesKey+ , macKey = skeinMAC' preMacKey+ , keyRaw = bs+ }++-- | Same as 'encrypt', however randomly generates the+-- initialization vector for you.+encryptIO :: Key -> S.ByteString -> IO S.ByteString+encryptIO key x = do+ iv <- randomIV+ return $ encrypt key iv x++-- | Encrypt (AES-CTR), authenticate (Skein-MAC-512-256) and+-- encode (Base64) the given cookie data. The returned byte+-- string is ready to be used in a response header.+encrypt :: Key -- ^ Key of the server.+ -> IV -- ^ New, random initialization vector (see 'randomIV').+ -> S.ByteString -- ^ Serialized cookie data.+ -> S.ByteString -- ^ Encoded cookie data to be given to+ -- the client browser.+encrypt key (IV b) x = case makeIV b of+ Nothing -> error "Web.ClientSession.encrypt: Failed to makeIV"+ Just iv -> B.encode final+ where+ encrypted = ctrCombine (aesKey key) iv x+ toBeAuthed = b `S.append` encrypted+ auth = macKey key toBeAuthed+ final = encode auth `S.append` toBeAuthed++-- | Decode (Base64), verify the integrity and authenticity+-- (Skein-MAC-512-256) and decrypt (AES-CTR) the given encoded+-- cookie data. Returns the original serialized cookie data.+-- Fails if the data is corrupted.+decrypt :: Key -- ^ Key of the server.+ -> S.ByteString -- ^ Encoded cookie data given by the browser.+ -> Maybe S.ByteString -- ^ Serialized cookie data.+decrypt key dataBS64 = do+ dataBS <- either (const Nothing) Just $ B.decode dataBS64+ guard (S.length dataBS >= 48) -- 16 bytes of IV + 32 bytes of Skein-MAC-512-256+ let (auth, toBeAuthed) = S.splitAt 32 dataBS+ auth' = macKey key toBeAuthed+ guard (encode auth' `constTimeEq` auth)+ let (iv, encrypted) = S.splitAt 16 toBeAuthed+ iv' <- makeIV iv+ return $! ctrCombine (aesKey key) iv' encrypted+++-- [from when the code used cprng-aes.AESRNG]+-- Significantly more efficient random IV generation. Initial+-- benchmarks placed it at 6.06 us versus 1.69 ms for+-- Crypto.Modes.getIVIO, since it does not require /dev/urandom+-- I/O for every call.++-- [now with crypton.ChaChaDRG]+-- I haven't run any benchmark; this conversion is a case of “code+-- that doesn't crash trumps performance.”++data ChaChaState =+ CCSt {-# UNPACK #-} !ChaChaDRG -- Our CPRNG using ChaCha+ {-# UNPACK #-} !Int -- How many IVs were generated with this+ -- CPRNG. Used to control reseeding.++-- | Construct initial state of the CPRNG.+chaChaSeed :: IO ChaChaState+chaChaSeed = do+ drg <- drgNew+ return $! CCSt drg 0++-- | Reseed the CPRNG with new entropy from the system pool.+chaChaReseed :: IO ()+chaChaReseed = do+ drg' <- drgNew+ I.writeIORef chaChaRef $ CCSt drg' 0++-- | 'IORef' that keeps the current state of the CPRNG. Yep,+-- global state. Used in thread-safe was only, though.+chaChaRef :: I.IORef ChaChaState+chaChaRef = unsafePerformIO $ chaChaSeed >>= I.newIORef+{-# NOINLINE chaChaRef #-}++-- | Construct a new 16-byte IV using our CPRNG. Forks another+-- thread to reseed the CPRNG should its usage count reach a+-- hardcoded threshold.+chaChaRNG :: IO IV+chaChaRNG = do+ (bs, count) <-+ I.atomicModifyIORef chaChaRef $ \(CCSt drg count) ->+ let (bs', drg') = randomBytesGenerate 16 drg+ in (CCSt drg' (succ count), (bs', count))+ when (count == threshold) $ void $ forkIO chaChaReseed+ return $! unsafeMkIV bs+ where+ void f = f >> return ()++-- | How many IVs should be generated before reseeding the CPRNG.+-- This number depends basically on how paranoid you are. We+-- think 100.000 is a good compromise: larger numbers give only a+-- small performance advantage, while it still is a small number+-- since we only generate 1.5 MiB of random data between reseeds.+threshold :: Int+threshold = 100000
+ tests/runtests.hs view
@@ -0,0 +1,103 @@+{-# LANGUAGE FlexibleInstances #-}+{-# LANGUAGE MultiParamTypeClasses #-}+{-# OPTIONS_GHC -fno-warn-orphans #-}+import Test.HUnit (assertBool)+import Test.Hspec+import Test.QuickCheck+import Control.Monad (replicateM)++import qualified Data.ByteString as S+import qualified Data.ByteString.Char8 as S8++import Web.ClientSession+import System.IO.Unsafe++import qualified Data.Set as Set+import Control.Monad.Trans.State.Strict (evalStateT, get, put)+import Control.Monad.Trans.Class (lift)+import Control.Monad (replicateM_)++import Data.Serialize (encode, decode)++main :: IO ()+main = hspec $ describe "client session" $ do+ it "encrypt/decrypt success" $ property propEncDec+ it "encrypt/decrypt success (environment key)" $ property propEncDecEnv+ it "encrypt/decrypt failure" $ property propEncDecFailure+ it "AES encrypt/decrypt success" $ property propAES+ it "AES encryption changes bs" $ property propAESChanges+ it "specific values" caseSpecific+ it "randomIV is really random" caseRandomIV+ it "serialize instance" $ property propSerialize++propEncDec :: S.ByteString -> Bool+propEncDec bs = unsafePerformIO $ do+ key <- getDefaultKey+ s <- encryptIO key bs+ let bs' = decrypt key s+ return $ Just bs == bs'++propEncDecEnv :: S.ByteString -> Bool+propEncDecEnv bs = unsafePerformIO $ do+ key <- getKeyEnv "SESSION_KEY"+ s <- encryptIO key bs+ let bs' = decrypt key s+ return $ Just bs == bs'++propEncDecFailure :: S.ByteString -> Bool+propEncDecFailure bs = unsafePerformIO $ do+ key <- getDefaultKey+ s <- encryptIO key bs+ let bs' = decrypt key $ (S.head s + 1) `S.cons` S.drop 1 s+ return $ Just bs /= bs'++propAES :: MyKey -> MyIV -> S.ByteString -> Bool+propAES (MyKey key) (MyIV iv) bs = decrypt key (encrypt key iv bs) == Just bs++propAESChanges :: MyKey -> MyIV -> S.ByteString -> Bool+propAESChanges (MyKey key) (MyIV iv) bs = encrypt key iv bs /= bs++caseSpecific :: Expectation+caseSpecific = do+ let s = S8.pack $ show [("lo\ENQ\143XAq","\DC2\207\226\DC1;.z56|\203\222"),("\USnu#\139\ETXB\201 ","l"),("\RS\b,zM2U\184\191F)\EOT\220S\NUL","O\\\GSd\247\246\n\EOT\SYN\182U2G"),("\219\NAK\217\CAN\252","ym\STX\188\232?\\\145"),("\239k","\vRZP\a\DC2F>"),("\FS\180P &\RS\174zSL\\?@","p\170\237vZ|\GS>\SYNk\176n\r"),("","\199D\DC3\200m)"),("6\152tVhB\246)9","\ENQdfU\SUB"),("I\ACK\181\NUL","\129\&6s\130q\US)oR1\197\FSp\US\SYN0"),("\183\200<\250","\211 \131g4\207N\155"),("\248O6k\CANK\135\234.","`\205!+&Z&9\DLE\244\214HP\SI\161"),("\"I'\ACK\149 \CAN\197","\141N\201\SO\204\\o.\128\148")]+ key <- getDefaultKey+ iv <- randomIV+ decrypt key (encrypt key iv s) `shouldBe` Just s+ let s' = S.concat $ replicate 500 s+ decrypt key (encrypt key iv s') `shouldBe` Just s'++caseRandomIV :: Expectation+caseRandomIV = do+ evalStateT (replicateM_ 10000 go) Set.empty+ where+ go = do+ val <- lift randomIV+ set <- get+ lift $ assertBool "No duplicated keys" (not $ val `Set.member` set)+ put $ Set.insert val set++propSerialize :: MyKey -> Bool+propSerialize (MyKey key) = Right key == decode (encode key)++instance Arbitrary S.ByteString where+ arbitrary = S.pack `fmap` arbitrary++newtype MyKey = MyKey Key++instance Arbitrary MyKey where+ arbitrary = do+ ws <- replicateM 96 arbitrary+ either error (return . MyKey) $ initKey $ S.pack ws++instance Show MyKey where+ show (MyKey key) = "MyKey:" ++ show (encode key)++newtype MyIV = MyIV IV++instance Arbitrary MyIV where+ arbitrary = do+ ws <- replicateM 16 arbitrary+ maybe (error "Invalid IV") (return . MyIV) $ mkIV $ S.pack ws++instance Show MyIV where+ show _ = "<Iv>"