-
Notifications
You must be signed in to change notification settings - Fork 366
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
GH-455: ensure BaseCipher.update() fulfills the contract
The org.apache.sshd.common.cipher.Cipher interface specifies for update(byte[] buffer, int offset, int length) that length bytes are encrypted or decrypted in-place in the given buffer, starting at the given offset. The BaseCipher implementation just called javax.crypto.Cipher.update(). That, however, may buffer blocks and not update all data right away. (For instance, AES pipelined implementations may behave that way.) Buffered blocks may be returned/updated in subsequent update() calls. To ensure that really all bytes given are updated, one needs to call doFinal(), which always returns/updates such buffered blocks. But javax.crypto.Cipher.doFinal() resets the cipher to its initial state. For use in SSH, this is not appropriate: the cipher must be reset not to the initial state but to the final state. This is done for CTR ciphers by adding the number of processed blocks to the initial IV and then using that IV for re-initialization. For CBC ciphers, the re-initialization IV must be the last encrypted block processed. Note that in CTR mode, we cannot check for IV re-use. This is not a problem in practice because in the SSH protocol key exchanges happen long before an IV can wrap around.
- Loading branch information
Showing
12 changed files
with
605 additions
and
13 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
55 changes: 55 additions & 0 deletions
55
sshd-common/src/main/java/org/apache/sshd/common/cipher/BaseCBCCipher.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,55 @@ | ||
/* | ||
* Licensed to the Apache Software Foundation (ASF) under one | ||
* or more contributor license agreements. See the NOTICE file | ||
* distributed with this work for additional information | ||
* regarding copyright ownership. The ASF licenses this file | ||
* to you under the Apache License, Version 2.0 (the | ||
* "License"); you may not use this file except in compliance | ||
* with the License. You may obtain a copy of the License at | ||
* | ||
* http://www.apache.org/licenses/LICENSE-2.0 | ||
* | ||
* Unless required by applicable law or agreed to in writing, | ||
* software distributed under the License is distributed on an | ||
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY | ||
* KIND, either express or implied. See the License for the | ||
* specific language governing permissions and limitations | ||
* under the License. | ||
*/ | ||
|
||
package org.apache.sshd.common.cipher; | ||
|
||
import java.security.spec.AlgorithmParameterSpec; | ||
import java.util.Arrays; | ||
|
||
import javax.crypto.spec.IvParameterSpec; | ||
|
||
public class BaseCBCCipher extends BaseCipher { | ||
|
||
private byte[] lastEncryptedBlock; | ||
|
||
public BaseCBCCipher(int ivsize, int authSize, int kdfSize, String algorithm, int keySize, String transformation, | ||
int blkSize) { | ||
super(ivsize, authSize, kdfSize, algorithm, keySize, transformation, blkSize); | ||
} | ||
|
||
@Override | ||
public void update(byte[] input, int inputOffset, int inputLen) throws Exception { | ||
if (mode == Mode.Decrypt) { | ||
lastEncryptedBlock = Arrays.copyOfRange(input, inputOffset + inputLen - getCipherBlockSize(), | ||
inputOffset + inputLen); | ||
} | ||
super.update(input, inputOffset, inputLen); | ||
} | ||
|
||
@Override | ||
protected AlgorithmParameterSpec determineNewParameters(byte[] processed, int offset, int length) { | ||
// The IV is the last encrypted block | ||
if (mode == Mode.Decrypt) { | ||
byte[] result = lastEncryptedBlock; | ||
lastEncryptedBlock = null; | ||
return new IvParameterSpec(result); | ||
} | ||
return new IvParameterSpec(Arrays.copyOfRange(processed, offset + length - getCipherBlockSize(), offset + length)); | ||
} | ||
} |
78 changes: 78 additions & 0 deletions
78
sshd-common/src/main/java/org/apache/sshd/common/cipher/BaseCTRCipher.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,78 @@ | ||
/* | ||
* Licensed to the Apache Software Foundation (ASF) under one | ||
* or more contributor license agreements. See the NOTICE file | ||
* distributed with this work for additional information | ||
* regarding copyright ownership. The ASF licenses this file | ||
* to you under the Apache License, Version 2.0 (the | ||
* "License"); you may not use this file except in compliance | ||
* with the License. You may obtain a copy of the License at | ||
* | ||
* http://www.apache.org/licenses/LICENSE-2.0 | ||
* | ||
* Unless required by applicable law or agreed to in writing, | ||
* software distributed under the License is distributed on an | ||
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY | ||
* KIND, either express or implied. See the License for the | ||
* specific language governing permissions and limitations | ||
* under the License. | ||
*/ | ||
|
||
package org.apache.sshd.common.cipher; | ||
|
||
import java.security.InvalidAlgorithmParameterException; | ||
import java.security.InvalidKeyException; | ||
import java.security.spec.AlgorithmParameterSpec; | ||
|
||
import javax.crypto.spec.IvParameterSpec; | ||
|
||
import org.apache.sshd.common.util.buffer.ByteArrayBuffer; | ||
|
||
public class BaseCTRCipher extends BaseCipher { | ||
|
||
private long blocksProcessed; | ||
|
||
public BaseCTRCipher(int ivsize, int authSize, int kdfSize, String algorithm, int keySize, String transformation, | ||
int blkSize) { | ||
super(ivsize, authSize, kdfSize, algorithm, keySize, transformation, blkSize); | ||
} | ||
|
||
@Override | ||
public void update(byte[] input, int inputOffset, int inputLen) throws Exception { | ||
blocksProcessed += inputLen / getCipherBlockSize(); | ||
super.update(input, inputOffset, inputLen); | ||
} | ||
|
||
@Override | ||
protected void reInit(byte[] processed, int offset, int length) | ||
throws InvalidKeyException, InvalidAlgorithmParameterException { | ||
super.reInit(processed, offset, length); | ||
blocksProcessed = 0; | ||
} | ||
|
||
@Override | ||
protected AlgorithmParameterSpec determineNewParameters(byte[] processed, int offset, int length) { | ||
byte[] iv = getCipherInstance().getIV().clone(); | ||
// Treat the IV as a counter and add blocksProcessed | ||
ByteArrayBuffer buf = new ByteArrayBuffer(iv, iv.length - Long.BYTES, Long.BYTES); | ||
long unsigned = buf.getLong(); | ||
long highBitBefore = unsigned & ~Long.MAX_VALUE; | ||
unsigned &= Long.MAX_VALUE; // Clear most significant bit | ||
unsigned += blocksProcessed; | ||
long highBitNow = unsigned & ~Long.MAX_VALUE; | ||
unsigned = (unsigned & Long.MAX_VALUE) | (highBitBefore ^ highBitNow); | ||
int carry = (int) ((highBitBefore & highBitNow) >>> (Long.SIZE - 1)); | ||
addCarry(iv, iv.length - Long.BYTES, carry); | ||
buf.wpos(iv.length - Long.BYTES); | ||
buf.putLong(unsigned); | ||
return new IvParameterSpec(iv); | ||
} | ||
|
||
private void addCarry(byte[] iv, int length, int carry) { | ||
int add = carry; | ||
for (int i = length - 1; i >= 0; i--) { | ||
int b = (iv[i] & 0xFF) + add; | ||
iv[i] = (byte) b; | ||
add = b >> Byte.SIZE; | ||
} | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.