@cryptotaxi247 / kubo / commits / 9d05b3523

crypto/key: stretcher refactor

Juan Batiz-Benet committed Dec 11, 2014 at 01:52 UTC 9d05b35231875ca2ead870c824fd286b9065b586
2 files changed +30 -26
crypto/key.go
+18 -21
@@ -134,9 +134,15 @@ func GenerateEKeyPair(curveName string) ([]byte, GenSharedKey, error) {
134 return pubKey, done, nil
135 }
136
137 +type StretchedKeys struct {
138 + IV []byte
139 + MacKey []byte
140 + CipherKey []byte
141 +}
142 +
143 // Generates a set of keys for each party by stretching the shared key.
144 // (myIV, theirIV, myCipherKey, theirCipherKey, myMACKey, theirMACKey)
139 -func KeyStretcher(cmp int, cipherType string, hashType string, secret []byte) ([]byte, []byte, []byte, []byte, []byte, []byte) {
145 +func KeyStretcher(cipherType string, hashType string, secret []byte) (StretchedKeys, StretchedKeys) {
146 var cipherKeySize int
147 var ivSize int
148 switch cipherType {
@@ -198,31 +204,22 @@ func KeyStretcher(cmp int, cipherType string, hashType string, secret []byte) ([
204 a = m.Sum(nil)
205 }
206
201 - myResult := make([]byte, ivSize+cipherKeySize+hmacKeySize)
202 - theirResult := make([]byte, ivSize+cipherKeySize+hmacKeySize)
203 -
207 half := len(result) / 2
208 + r1 := result[:half]
209 + r2 := result[half:]
210
206 - if cmp == 1 {
207 - copy(myResult, result[:half])
208 - copy(theirResult, result[half:])
209 - } else if cmp == -1 {
210 - copy(myResult, result[half:])
211 - copy(theirResult, result[:half])
212 - } else { // Shouldn't happen, but oh well.
213 - copy(myResult, result[half:])
214 - copy(theirResult, result[half:])
215 - }
211 + var k1 StretchedKeys
212 + var k2 StretchedKeys
213
217 - myIV := myResult[0:ivSize]
218 - myCKey := myResult[ivSize : ivSize+cipherKeySize]
219 - myMKey := myResult[ivSize+cipherKeySize:]
214 + k1.IV = r1[0:ivSize]
215 + k1.CipherKey = r1[ivSize : ivSize+cipherKeySize]
216 + k1.MacKey = r1[ivSize+cipherKeySize:]
217
221 - theirIV := theirResult[0:ivSize]
222 - theirCKey := theirResult[ivSize : ivSize+cipherKeySize]
223 - theirMKey := theirResult[ivSize+cipherKeySize:]
218 + k2.IV = r2[0:ivSize]
219 + k2.CipherKey = r2[ivSize : ivSize+cipherKeySize]
220 + k2.MacKey = r2[ivSize+cipherKeySize:]
221
225 - return myIV, theirIV, myCKey, theirCKey, myMKey, theirMKey
222 + return k1, k2
223 }
224
225 // UnmarshalPublicKey converts a protobuf serialized public key into its
crypto/spipe/handshake.go
+12 -5
@@ -183,12 +183,19 @@ func (s *SecurePipe) handshake() error {
183 return err
184 }
185
186 + k1, k2 := ci.KeyStretcher(cipherType, hashType, secret)
187 cmp := bytes.Compare(myPubKey, proposeResp.GetPubkey())
187 -
188 - mIV, tIV, mCKey, tCKey, mMKey, tMKey := ci.KeyStretcher(cmp, cipherType, hashType, secret)
189 -
190 - go s.handleSecureIn(hashType, cipherType, tIV, tCKey, tMKey)
191 - go s.handleSecureOut(hashType, cipherType, mIV, mCKey, mMKey)
188 + switch cmp {
189 + case 1:
190 + case -1:
191 + k1, k2 = k2, k1 // swap
192 + case 0: // really shouldnt kappen.
193 + copy(k2.IV, k1.IV)
194 + copy(k2.MacKey, k1.MacKey)
195 + copy(k2.CipherKey, k1.CipherKey)
196 + }
197 + go s.handleSecureIn(hashType, cipherType, k2.IV, k2.CipherKey, k2.MacKey)
198 + go s.handleSecureOut(hashType, cipherType, k1.IV, k1.CipherKey, k1.MacKey)
199
200 finished := []byte("Finished")
201