crypto/key: stretcher refactor
Juan Batiz-Benet committed
Dec 11, 2014 at 01:52 UTC
9d05b35231875ca2ead870c824fd286b9065b586
2 files changed
+30
-26
crypto/key.go
+18
-21
@@ -134,9 +134,15 @@ func GenerateEKeyPair(curveName string) ([]byte, GenSharedKey, error) {
134
return pubKey, done, nil
135
}
136
137
+type StretchedKeys struct {
138
+ IV []byte
139
+ MacKey []byte
140
+ CipherKey []byte
141
+}
142
+
143
// Generates a set of keys for each party by stretching the shared key.
144
// (myIV, theirIV, myCipherKey, theirCipherKey, myMACKey, theirMACKey)
139
-func KeyStretcher(cmp int, cipherType string, hashType string, secret []byte) ([]byte, []byte, []byte, []byte, []byte, []byte) {
145
+func KeyStretcher(cipherType string, hashType string, secret []byte) (StretchedKeys, StretchedKeys) {
146
var cipherKeySize int
147
var ivSize int
148
switch cipherType {
@@ -198,31 +204,22 @@ func KeyStretcher(cmp int, cipherType string, hashType string, secret []byte) ([
204
a = m.Sum(nil)
205
}
206
201
- myResult := make([]byte, ivSize+cipherKeySize+hmacKeySize)
202
- theirResult := make([]byte, ivSize+cipherKeySize+hmacKeySize)
203
-
207
half := len(result) / 2
208
+ r1 := result[:half]
209
+ r2 := result[half:]
210
206
- if cmp == 1 {
207
- copy(myResult, result[:half])
208
- copy(theirResult, result[half:])
209
- } else if cmp == -1 {
210
- copy(myResult, result[half:])
211
- copy(theirResult, result[:half])
212
- } else { // Shouldn't happen, but oh well.
213
- copy(myResult, result[half:])
214
- copy(theirResult, result[half:])
215
- }
211
+ var k1 StretchedKeys
212
+ var k2 StretchedKeys
213
217
- myIV := myResult[0:ivSize]
218
- myCKey := myResult[ivSize : ivSize+cipherKeySize]
219
- myMKey := myResult[ivSize+cipherKeySize:]
214
+ k1.IV = r1[0:ivSize]
215
+ k1.CipherKey = r1[ivSize : ivSize+cipherKeySize]
216
+ k1.MacKey = r1[ivSize+cipherKeySize:]
217
221
- theirIV := theirResult[0:ivSize]
222
- theirCKey := theirResult[ivSize : ivSize+cipherKeySize]
223
- theirMKey := theirResult[ivSize+cipherKeySize:]
218
+ k2.IV = r2[0:ivSize]
219
+ k2.CipherKey = r2[ivSize : ivSize+cipherKeySize]
220
+ k2.MacKey = r2[ivSize+cipherKeySize:]
221
225
- return myIV, theirIV, myCKey, theirCKey, myMKey, theirMKey
222
+ return k1, k2
223
}
224
225
// UnmarshalPublicKey converts a protobuf serialized public key into its
crypto/spipe/handshake.go
+12
-5
@@ -183,12 +183,19 @@ func (s *SecurePipe) handshake() error {
183
return err
184
}
185
186
+ k1, k2 := ci.KeyStretcher(cipherType, hashType, secret)
187
cmp := bytes.Compare(myPubKey, proposeResp.GetPubkey())
187
-
188
- mIV, tIV, mCKey, tCKey, mMKey, tMKey := ci.KeyStretcher(cmp, cipherType, hashType, secret)
189
-
190
- go s.handleSecureIn(hashType, cipherType, tIV, tCKey, tMKey)
191
- go s.handleSecureOut(hashType, cipherType, mIV, mCKey, mMKey)
188
+ switch cmp {
189
+ case 1:
190
+ case -1:
191
+ k1, k2 = k2, k1 // swap
192
+ case 0: // really shouldnt kappen.
193
+ copy(k2.IV, k1.IV)
194
+ copy(k2.MacKey, k1.MacKey)
195
+ copy(k2.CipherKey, k1.CipherKey)
196
+ }
197
+ go s.handleSecureIn(hashType, cipherType, k2.IV, k2.CipherKey, k2.MacKey)
198
+ go s.handleSecureOut(hashType, cipherType, k1.IV, k1.CipherKey, k1.MacKey)
199
200
finished := []byte("Finished")
201