no message
This commit is contained in:
1 parent
5bdac671f9
commit
0b0803f3f9
1292 files changed
+21890
-30219
No files matched your search
@@ -0,0 +1,72 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import <Foundation/Foundation.h>
|
||||
#import <libsodium-ios/sodium/crypto_box_curve25519xsalsa20poly1305.h>
|
||||
#import "AGKeyPair.h"
|
||||
|
||||
/**
|
||||
* Provide public key authenticated encryption via curve25519xsalsa20poly1305
|
||||
* (see http://nacl.cr.yp.to/box.html)
|
||||
*/
|
||||
@interface AGCryptoBox : NSObject
|
||||
|
||||
@property(readonly, nonatomic, strong) NSData *privateKey;
|
||||
@property(readonly, nonatomic, strong) NSData *publicKey;
|
||||
|
||||
/**
|
||||
* Crypto box default initialization
|
||||
*
|
||||
* @param keyPair containig public and private keys provided.
|
||||
*
|
||||
* @return the AGCryptoBox object.
|
||||
*/
|
||||
- (id)initWithKeyPair:(AGKeyPair *)keyPair;
|
||||
|
||||
/**
|
||||
* Crypto box initialization
|
||||
*
|
||||
* @param publicKey the public encryption key provided.
|
||||
* @param privateKey the private encryption key provided.
|
||||
*
|
||||
* @return the AGCryptoBox object.
|
||||
*/
|
||||
- (id)initWithKey:(NSData *)publicKey privateKey:(NSData *)privateKey;
|
||||
|
||||
/**
|
||||
* Encrypts and authenticates the data object provided given a nonce.
|
||||
*
|
||||
* @param data The data object to encrypt.
|
||||
* @param nonce the cryptographically secure pseudorandom number.
|
||||
* @param error If an error occurs, upon return contains an `NSError` object that describes the problem.
|
||||
*
|
||||
* @return An NSData object that holds the encrypted(cipher) data.
|
||||
*/
|
||||
- (NSData *)encrypt:(NSData *)data nonce:(NSData *)nonce error:(NSError * __autoreleasing *)error;
|
||||
|
||||
/**
|
||||
* Decrypts the data object provided given a nonce.
|
||||
*
|
||||
* @param data The data object(cipher) to decrypt.
|
||||
* @param nonce The cryptographically secure pseudorandom number.
|
||||
* @param error If an error occurs, upon return contains an `NSError` object that describes the problem.
|
||||
*
|
||||
* @return An NSData object that holds the decrypted data.
|
||||
*/
|
||||
- (NSData *)decrypt:(NSData *)data nonce:(NSData *)nonce error:(NSError * __autoreleasing *)error;
|
||||
|
||||
@end
|
||||
@@ -0,0 +1,96 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import "AGCryptoBox.h"
|
||||
#import "AGUtil.h"
|
||||
|
||||
@implementation AGCryptoBox
|
||||
|
||||
- (id)initWithKeyPair:(AGKeyPair *)keyPair {
|
||||
return [self initWithKey:keyPair.publicKey privateKey:keyPair.privateKey];
|
||||
}
|
||||
|
||||
- (id)initWithKey:(NSData *)publicKey privateKey:(NSData *)privateKey {
|
||||
NSParameterAssert(privateKey != nil && [privateKey length] == crypto_box_curve25519xsalsa20poly1305_SECRETKEYBYTES);
|
||||
NSParameterAssert(publicKey != nil && [publicKey length] == crypto_box_curve25519xsalsa20poly1305_PUBLICKEYBYTES);
|
||||
|
||||
self = [super init];
|
||||
|
||||
if (self) {
|
||||
_privateKey = privateKey;
|
||||
_publicKey = publicKey;
|
||||
}
|
||||
return self;
|
||||
}
|
||||
|
||||
- (NSData *)encrypt:(NSData *)data nonce:(NSData *)nonce error:(NSError * __autoreleasing *)error {
|
||||
NSParameterAssert(data != nil);
|
||||
NSParameterAssert(nonce != nil && [nonce length] == crypto_box_curve25519xsalsa20poly1305_NONCEBYTES);
|
||||
|
||||
NSData *msg = [AGUtil prependZeros:crypto_box_curve25519xsalsa20poly1305_ZEROBYTES msg:data];
|
||||
NSMutableData *ct = [[NSMutableData alloc] initWithLength:msg.length];
|
||||
|
||||
int status = crypto_box_curve25519xsalsa20poly1305(
|
||||
[ct mutableBytes],
|
||||
[msg bytes],
|
||||
msg.length,
|
||||
[nonce bytes],
|
||||
[_publicKey bytes],
|
||||
[_privateKey bytes]);
|
||||
|
||||
if (status != 0) {
|
||||
if (error) {
|
||||
NSDictionary *userInfo = @{NSLocalizedDescriptionKey:
|
||||
[NSString stringWithFormat:@"failed to encrypt data provided, NaCl error: %d", status]};
|
||||
*error = [NSError errorWithDomain:AGCryptoErrorDomain code:AGCryptoFailedToEncryptError userInfo:userInfo];
|
||||
}
|
||||
return nil;
|
||||
}
|
||||
|
||||
return [ct subdataWithRange:NSMakeRange(crypto_box_curve25519xsalsa20poly1305_BOXZEROBYTES,
|
||||
ct.length - crypto_box_curve25519xsalsa20poly1305_BOXZEROBYTES)];
|
||||
}
|
||||
|
||||
- (NSData *)decrypt:(NSData *)data nonce:(NSData *)nonce error:(NSError * __autoreleasing *)error {
|
||||
NSParameterAssert(data != nil);
|
||||
NSParameterAssert(nonce != nil && [nonce length] == crypto_box_curve25519xsalsa20poly1305_NONCEBYTES);
|
||||
|
||||
NSData *ct = [AGUtil prependZeros:crypto_box_curve25519xsalsa20poly1305_BOXZEROBYTES msg:data];
|
||||
NSMutableData *message = [[NSMutableData alloc] initWithLength:ct.length];
|
||||
|
||||
int status = crypto_box_curve25519xsalsa20poly1305_open(
|
||||
[message mutableBytes],
|
||||
[ct bytes],
|
||||
message.length,
|
||||
[nonce bytes],
|
||||
[_publicKey bytes],
|
||||
[_privateKey bytes]);
|
||||
|
||||
if (status != 0) {
|
||||
if (error) {
|
||||
NSDictionary *userInfo = @{NSLocalizedDescriptionKey:
|
||||
[NSString stringWithFormat:@"failed to decrypt data provided, NaCl error: %d", status]};
|
||||
*error = [NSError errorWithDomain:AGCryptoErrorDomain code:AGCryptoFailedToDecryptError userInfo:userInfo];
|
||||
}
|
||||
return nil;
|
||||
}
|
||||
|
||||
return [message subdataWithRange:NSMakeRange(crypto_box_curve25519xsalsa20poly1305_ZEROBYTES,
|
||||
message.length - crypto_box_curve25519xsalsa20poly1305_ZEROBYTES)];
|
||||
}
|
||||
|
||||
@end
|
||||
+43
@@ -0,0 +1,43 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import <Foundation/Foundation.h>
|
||||
|
||||
/**
|
||||
* Class that create a message digest using SHA2 hash function
|
||||
* (see http://csrc.nist.gov/publications/fips/fips180-4/fips-180-4.pdf)
|
||||
*/
|
||||
@interface AGHash : NSObject
|
||||
|
||||
/**
|
||||
* Initialize with the Hash function provided.
|
||||
*
|
||||
* @param algorithm The length of hash function e.g. CC_SHA512_DIGEST_LENGTH or CC_SHA256_DIGEST_LENGTH
|
||||
*
|
||||
* @return The AGHash object.
|
||||
*/
|
||||
- (id)init:(char)algorithm;
|
||||
|
||||
/**
|
||||
* Create a message digest based on the string provided.
|
||||
*
|
||||
* @param str The raw text.
|
||||
*
|
||||
* @return an NSData object containing the message digest.
|
||||
*/
|
||||
- (NSData *)digest:(NSString *)str;
|
||||
@end
|
||||
+57
@@ -0,0 +1,57 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import <CommonCrypto/CommonDigest.h>
|
||||
#import "AGHash.h"
|
||||
|
||||
|
||||
@implementation AGHash {
|
||||
unsigned char _algorithm;
|
||||
}
|
||||
|
||||
- (id)init:(char)algorithm {
|
||||
self = [super init];
|
||||
if (self) {
|
||||
_algorithm = algorithm;
|
||||
}
|
||||
|
||||
return self;
|
||||
}
|
||||
|
||||
- (id)init {
|
||||
self = [super init];
|
||||
if (self) {
|
||||
_algorithm = CC_SHA256_DIGEST_LENGTH;
|
||||
}
|
||||
|
||||
return self;
|
||||
}
|
||||
|
||||
- (NSData *)digest:(NSString *)str {
|
||||
NSData *dataIn = [str dataUsingEncoding:NSUTF8StringEncoding];
|
||||
NSMutableData *hash = [NSMutableData dataWithLength:_algorithm];
|
||||
|
||||
if (_algorithm == CC_SHA512_DIGEST_LENGTH ) {
|
||||
CC_SHA512(dataIn.bytes, (CC_LONG)dataIn.length, hash.mutableBytes);
|
||||
} else {
|
||||
CC_SHA256(dataIn.bytes, (CC_LONG)dataIn.length, hash.mutableBytes);
|
||||
}
|
||||
|
||||
return hash;
|
||||
}
|
||||
|
||||
@end
|
||||
+30
@@ -0,0 +1,30 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import <Foundation/Foundation.h>
|
||||
#import <libsodium-ios/sodium/crypto_box_curve25519xsalsa20poly1305.h>
|
||||
|
||||
/**
|
||||
* Represents a pair of cryptographic keys (a public and a private key) used for asymmetric encryption
|
||||
*/
|
||||
@interface AGKeyPair : NSObject
|
||||
|
||||
@property(readonly, nonatomic, strong) NSData *privateKey;
|
||||
@property(readonly, nonatomic, strong) NSData *publicKey;
|
||||
|
||||
- (id)initWithPrivateKey:(NSData *)privateKey publicKey:(NSData *)publicKey;
|
||||
@end
|
||||
+42
@@ -0,0 +1,42 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import "AGKeyPair.h"
|
||||
|
||||
@implementation AGKeyPair
|
||||
|
||||
- (id)initWithPrivateKey:(NSData *)privateKey publicKey:(NSData *)publicKey {
|
||||
self = [super init];
|
||||
|
||||
if (self) {
|
||||
_publicKey = publicKey;
|
||||
_privateKey = privateKey;
|
||||
}
|
||||
|
||||
return self;
|
||||
}
|
||||
|
||||
- (id)init {
|
||||
NSMutableData *publicKey = [NSMutableData dataWithLength:crypto_box_curve25519xsalsa20poly1305_PUBLICKEYBYTES];
|
||||
NSMutableData *privateKey = [NSMutableData dataWithLength:crypto_box_curve25519xsalsa20poly1305_SECRETKEYBYTES];
|
||||
|
||||
//Generate the keypair
|
||||
crypto_box_curve25519xsalsa20poly1305_keypair([publicKey mutableBytes], [privateKey mutableBytes]);
|
||||
|
||||
return [self initWithPrivateKey:privateKey publicKey:publicKey];
|
||||
}
|
||||
@end
|
||||
+72
@@ -0,0 +1,72 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import <Foundation/Foundation.h>
|
||||
|
||||
// constants used by PBKDF2 algorithm.
|
||||
extern const NSUInteger AGPBKDF2Iterations;
|
||||
extern const NSUInteger AGPBKDF2MinimumIterations;
|
||||
extern const NSUInteger AGPBKDF2DerivedKeyLength;
|
||||
extern const NSUInteger AGPBKDF2MinimumSaltLength;
|
||||
|
||||
/**
|
||||
* Class that derives a key from a text password/passphrase using
|
||||
* the PBKDF2 algorithm provided by CommonCrypto.
|
||||
* (see http://en.wikipedia.org/wiki/PBKDF2)
|
||||
*/
|
||||
@interface AGPBKDF2 : NSObject
|
||||
|
||||
/**
|
||||
* Derive a key from text password/passphrase.
|
||||
*
|
||||
* @param password The password/passphrase to use for key derivation.
|
||||
*
|
||||
* @return an NSData object containing the derived key.
|
||||
*/
|
||||
- (NSData *)deriveKey:(NSString *)password;
|
||||
|
||||
/**
|
||||
* Derive a key from text password/passphrase.
|
||||
*
|
||||
* @param password The password/passphrase to use for key derivation.
|
||||
* @param salt A randomly chosen value used used during key derivation.
|
||||
*
|
||||
* @return an NSData object containing the derived key.
|
||||
*/
|
||||
- (NSData *)deriveKey:(NSString *)password salt:(NSData *)salt;
|
||||
|
||||
/**
|
||||
* Derive a key from text password/passphrase.
|
||||
*
|
||||
* @param password The password/passphrase to use for key derivation.
|
||||
* @param salt A randomly chosen value used used during key derivation.
|
||||
* @param iterations The number of iterations against the cryptographic hash.
|
||||
*
|
||||
* @return an NSData object containing the derived key.
|
||||
*/
|
||||
- (NSData *)deriveKey:(NSString *)password salt:(NSData *)salt iterations:(NSUInteger)iterations;
|
||||
|
||||
- (BOOL)validate:(NSString *)password encryptedPassword:(NSData *)encryptedPassword salt:(NSData *)salt;
|
||||
|
||||
/**
|
||||
* Returns the salt used for the key derivation
|
||||
*
|
||||
* @return an NSData object containing the salt
|
||||
*/
|
||||
- (NSData *)salt;
|
||||
|
||||
@end
|
||||
+76
@@ -0,0 +1,76 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import "AGPBKDF2.h"
|
||||
#import "AGRandomGenerator.h"
|
||||
|
||||
#import <CommonCrypto/CommonCryptor.h>
|
||||
#import <CommonCrypto/CommonKeyDerivation.h>
|
||||
|
||||
const NSUInteger AGPBKDF2Iterations = 20000;
|
||||
const NSUInteger AGPBKDF2MinimumIterations = 10000;
|
||||
const NSUInteger AGPBKDF2DerivedKeyLength = 32;
|
||||
const NSUInteger AGPBKDF2MinimumSaltLength = 16;
|
||||
|
||||
@implementation AGPBKDF2 {
|
||||
NSData *_salt;
|
||||
}
|
||||
|
||||
- (NSData *)deriveKey:(NSString *)password {
|
||||
return [self deriveKey:password salt:[AGRandomGenerator randomBytes]];
|
||||
}
|
||||
|
||||
- (NSData *)deriveKey:(NSString *)password salt:(NSData *)salt {
|
||||
return [self deriveKey:password salt:salt iterations:AGPBKDF2Iterations];
|
||||
}
|
||||
|
||||
- (NSData *)deriveKey:(NSString *)password salt:(NSData *)salt iterations:(NSUInteger)iterations {
|
||||
NSParameterAssert(password != nil);
|
||||
NSParameterAssert(salt != nil && [salt length] >= AGPBKDF2MinimumSaltLength);
|
||||
NSParameterAssert(iterations >= AGPBKDF2MinimumIterations);
|
||||
|
||||
_salt = salt;
|
||||
|
||||
NSMutableData *key = [NSMutableData dataWithLength:AGPBKDF2DerivedKeyLength];
|
||||
|
||||
int result = CCKeyDerivationPBKDF(kCCPBKDF2,
|
||||
[password UTF8String],
|
||||
[password length],
|
||||
[salt bytes],
|
||||
[salt length],
|
||||
kCCPRFHmacAlgSHA1,
|
||||
(uint)iterations,
|
||||
[key mutableBytes],
|
||||
AGPBKDF2DerivedKeyLength);
|
||||
if (result == kCCParamError) {
|
||||
return nil;
|
||||
}
|
||||
|
||||
return key;
|
||||
}
|
||||
|
||||
- (BOOL)validate:(NSString *)password encryptedPassword:(NSData *)encryptedPassword salt:(NSData *)salt {
|
||||
NSData *attempt = [self deriveKey:password salt:salt];
|
||||
|
||||
return [encryptedPassword isEqual:attempt];
|
||||
}
|
||||
|
||||
- (NSData *)salt {
|
||||
return _salt;
|
||||
}
|
||||
|
||||
@end
|
||||
@@ -0,0 +1,41 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import <Foundation/Foundation.h>
|
||||
|
||||
/**
|
||||
* Utility class for random generation of cryptographically secure random numbers.
|
||||
*/
|
||||
@interface AGRandomGenerator : NSObject
|
||||
|
||||
/**
|
||||
* Generate secure random numbers with default size of 16 bytes.
|
||||
*
|
||||
* @return an NSData object filled with random bytes.
|
||||
*/
|
||||
+ (NSData *)randomBytes;
|
||||
|
||||
/**
|
||||
* Generate secure random numbers with length bytes.
|
||||
*
|
||||
* @param length The length of the random bytes to generate.
|
||||
*
|
||||
* @return an NSData object filled with random bytes.
|
||||
*/
|
||||
+ (NSData *)randomBytes:(size_t)length;
|
||||
|
||||
@end
|
||||
@@ -0,0 +1,34 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import "AGRandomGenerator.h"
|
||||
|
||||
@implementation AGRandomGenerator
|
||||
|
||||
+ (NSData *)randomBytes {
|
||||
return [self randomBytes:16];
|
||||
}
|
||||
|
||||
+ (NSData *)randomBytes:(size_t)length {
|
||||
NSMutableData *data = [NSMutableData dataWithLength:length];
|
||||
|
||||
int res = SecRandomCopyBytes(kSecRandomDefault, length, [data mutableBytes]);
|
||||
|
||||
return (res == noErr? data: nil);
|
||||
}
|
||||
|
||||
@end
|
||||
@@ -0,0 +1,58 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import <Foundation/Foundation.h>
|
||||
#import <libsodium-ios/sodium/crypto_secretbox_xsalsa20poly1305.h>
|
||||
|
||||
/**
|
||||
* Provide symmetric key authenticated encryption via xsalsa20poly1305
|
||||
* (see http://nacl.cr.yp.to/secretbox.html)
|
||||
*/
|
||||
@interface AGSecretBox : NSObject
|
||||
|
||||
/**
|
||||
* Secret box default initialization
|
||||
*
|
||||
* @param key the private encryption key provided.
|
||||
*
|
||||
* @return the AGSecretBox object.
|
||||
*/
|
||||
- (id)initWithKey:(NSData *)key;
|
||||
|
||||
/**
|
||||
* Encrypts and authenticates the data object provided given a nonce.
|
||||
*
|
||||
* @param data The data object to encrypt.
|
||||
* @param nonce the cryptographically secure pseudorandom number.
|
||||
* @param error If an error occurs, upon return contains an `NSError` object that describes the problem.
|
||||
*
|
||||
* @return An NSData object that holds the encrypted(cipher) data.
|
||||
*/
|
||||
- (NSData *)encrypt:(NSData *)data nonce:(NSData *)nonce error:(NSError * __autoreleasing *)error;
|
||||
|
||||
/**
|
||||
* Decrypts the data object provided given a nonce.
|
||||
*
|
||||
* @param data The data object(cipher) to decrypt.
|
||||
* @param nonce The cryptographically secure pseudorandom number.
|
||||
* @param error If an error occurs, upon return contains an `NSError` object that describes the problem.
|
||||
*
|
||||
* @return An NSData object that holds the decrypted data.
|
||||
*/
|
||||
- (NSData *)decrypt:(NSData *)data nonce:(NSData *)nonce error:(NSError * __autoreleasing *)error;
|
||||
|
||||
@end
|
||||
@@ -0,0 +1,92 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import "AGSecretBox.h"
|
||||
#import "AGUtil.h"
|
||||
|
||||
@implementation AGSecretBox {
|
||||
NSData *_key;
|
||||
}
|
||||
|
||||
- (id)initWithKey:(NSData *)key {
|
||||
NSParameterAssert(key != nil && [key length] == crypto_secretbox_xsalsa20poly1305_KEYBYTES);
|
||||
|
||||
self = [super init];
|
||||
if (self) {
|
||||
_key = key;
|
||||
}
|
||||
|
||||
return self;
|
||||
}
|
||||
|
||||
- (NSData *)encrypt:(NSData *)data nonce:(NSData *)nonce error:(NSError * __autoreleasing *)error {
|
||||
NSParameterAssert(data != nil);
|
||||
NSParameterAssert(nonce != nil && [nonce length] == crypto_secretbox_xsalsa20poly1305_NONCEBYTES);
|
||||
|
||||
NSData *msg = [AGUtil prependZeros:crypto_secretbox_xsalsa20poly1305_ZEROBYTES msg:data];
|
||||
NSMutableData *ct = [[NSMutableData alloc] initWithLength:msg.length];
|
||||
|
||||
int status = crypto_secretbox_xsalsa20poly1305(
|
||||
[ct mutableBytes],
|
||||
[msg bytes],
|
||||
msg.length,
|
||||
[nonce bytes],
|
||||
[_key bytes]);
|
||||
|
||||
|
||||
if (status != 0) {
|
||||
if (error) {
|
||||
NSDictionary *userInfo = @{NSLocalizedDescriptionKey:
|
||||
[NSString stringWithFormat:@"failed to encrypt data provided, NaCl error: %d", status]};
|
||||
*error = [NSError errorWithDomain:AGCryptoErrorDomain code:AGCryptoFailedToEncryptError userInfo:userInfo];
|
||||
}
|
||||
return nil;
|
||||
}
|
||||
|
||||
return [ct subdataWithRange:NSMakeRange(crypto_secretbox_xsalsa20poly1305_BOXZEROBYTES,
|
||||
ct.length - crypto_secretbox_xsalsa20poly1305_BOXZEROBYTES)];
|
||||
}
|
||||
|
||||
- (NSData *)decrypt:(NSData *)data nonce:(NSData *)nonce error:(NSError * __autoreleasing *)error {
|
||||
NSParameterAssert(data != nil);
|
||||
NSParameterAssert(nonce != nil && [nonce length] == crypto_secretbox_xsalsa20poly1305_NONCEBYTES);
|
||||
|
||||
|
||||
NSData *ct = [AGUtil prependZeros:crypto_secretbox_xsalsa20poly1305_BOXZEROBYTES msg:data];
|
||||
NSMutableData *message = [[NSMutableData alloc] initWithLength:ct.length];
|
||||
|
||||
int status = crypto_secretbox_xsalsa20poly1305_open(
|
||||
[message mutableBytes],
|
||||
[ct bytes],
|
||||
message.length,
|
||||
[nonce bytes],
|
||||
[_key bytes]);
|
||||
|
||||
if (status != 0) {
|
||||
if (error) {
|
||||
NSDictionary *userInfo = @{NSLocalizedDescriptionKey:
|
||||
[NSString stringWithFormat:@"failed to decrypt data provided, NaCl error: %d", status]};
|
||||
*error = [NSError errorWithDomain:AGCryptoErrorDomain code:AGCryptoFailedToDecryptError userInfo:userInfo];
|
||||
}
|
||||
return nil;
|
||||
}
|
||||
|
||||
return [message subdataWithRange:NSMakeRange(crypto_secretbox_xsalsa20poly1305_ZEROBYTES,
|
||||
message.length - crypto_secretbox_xsalsa20poly1305_ZEROBYTES)];
|
||||
}
|
||||
|
||||
@end
|
||||
@@ -0,0 +1,40 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import <Foundation/Foundation.h>
|
||||
#import <libsodium-ios/sodium/crypto_sign_ed25519.h>
|
||||
#import <libsodium-ios/sodium/randombytes.h>
|
||||
|
||||
/**
|
||||
* Create digital signatures
|
||||
* (see http://ed25519.cr.yp.to)
|
||||
*/
|
||||
@interface AGSigningKey : NSObject
|
||||
|
||||
@property(readonly, nonatomic, strong) NSData *secretKey;
|
||||
@property(readonly, nonatomic, strong) NSData *publicKey;
|
||||
|
||||
/**
|
||||
* Digitally sign a message to prevent against tampering and forgery.
|
||||
*
|
||||
* @param message The message to be signed.
|
||||
*
|
||||
* @return An NSData object that holds the signed message.
|
||||
*/
|
||||
- (NSData *)sign:(NSData *)message;
|
||||
|
||||
@end
|
||||
@@ -0,0 +1,64 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import "AGSigningKey.h"
|
||||
#import "AGUtil.h"
|
||||
|
||||
@implementation AGSigningKey {
|
||||
NSMutableData *_secretKey;
|
||||
NSMutableData *_publicKey;
|
||||
}
|
||||
|
||||
- (id)init {
|
||||
self = [super init];
|
||||
|
||||
if (self) {
|
||||
NSMutableData *seed = [NSMutableData dataWithLength:crypto_sign_ed25519_SECRETKEYBYTES];
|
||||
randombytes([seed mutableBytes], [seed length]);
|
||||
|
||||
_publicKey = [NSMutableData dataWithLength:crypto_sign_ed25519_PUBLICKEYBYTES];
|
||||
_secretKey = [NSMutableData dataWithLength:crypto_sign_ed25519_SECRETKEYBYTES];
|
||||
|
||||
// Generate the keypair
|
||||
int status = crypto_sign_ed25519_seed_keypair([_publicKey mutableBytes],
|
||||
[_secretKey mutableBytes],
|
||||
[seed mutableBytes]);
|
||||
// should not happen
|
||||
NSAssert(status == 0, @"Failed to generate a key pair", status);
|
||||
}
|
||||
|
||||
return self;
|
||||
}
|
||||
|
||||
- (NSData *)sign:(NSData *)message {
|
||||
NSParameterAssert(message != nil);
|
||||
|
||||
NSMutableData *signature = [AGUtil prependZeros:crypto_sign_ed25519_BYTES msg:message];
|
||||
|
||||
unsigned long long bufferLen;
|
||||
// sign the message
|
||||
int status = crypto_sign_ed25519([signature mutableBytes], &bufferLen,
|
||||
[message bytes],
|
||||
[message length],
|
||||
[_secretKey bytes]);
|
||||
|
||||
NSAssert(status == 0, @"unable to sign message", status);
|
||||
|
||||
return [signature subdataWithRange:NSMakeRange(0, crypto_sign_ed25519_BYTES)];
|
||||
}
|
||||
|
||||
@end
|
||||
+61
@@ -0,0 +1,61 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import <Foundation/Foundation.h>
|
||||
#import <libsodium-ios/sodium/crypto_box_curve25519xsalsa20poly1305.h>
|
||||
|
||||
typedef NS_ENUM(NSInteger, AGCryptoErrorCodes) {
|
||||
AGCryptoFailedToEncryptError = -101,
|
||||
AGCryptoFailedToDecryptError = -102
|
||||
};
|
||||
|
||||
extern NSString * const AGCryptoErrorDomain;
|
||||
|
||||
/**
|
||||
* Utility class for cryptographic operations
|
||||
*/
|
||||
@interface AGUtil : NSObject
|
||||
|
||||
/**
|
||||
* Append zeros to the message provided.
|
||||
*
|
||||
* @param n Number of zeros.
|
||||
* @param message The provided message.
|
||||
*
|
||||
* @return An NSData object that holds the result.
|
||||
*/
|
||||
+ (NSMutableData *)prependZeros:(NSUInteger)n msg:(NSData *)message;
|
||||
|
||||
/**
|
||||
* Convert the provided data to hex.
|
||||
*
|
||||
* @param data The NSData to be converted to hex representation.
|
||||
*
|
||||
* @return An NSString object with the result of the conversion.
|
||||
*/
|
||||
+ (NSString *)hexString:(NSData *)data;
|
||||
|
||||
/**
|
||||
* Convert the provided hex string to bytes.
|
||||
*
|
||||
* @param data The hex string to be converted.
|
||||
*
|
||||
* @return An NSData object with the result of the conversion.
|
||||
*/
|
||||
+ (NSData *)hexStringToBytes:(NSString *)data;
|
||||
|
||||
@end
|
||||
+56
@@ -0,0 +1,56 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import "AGUtil.h"
|
||||
|
||||
NSString * const AGCryptoErrorDomain = @"AGCryptoErrorDomain";
|
||||
|
||||
@implementation AGUtil
|
||||
|
||||
+ (NSMutableData *)prependZeros:(NSUInteger)n msg:(NSData *)message {
|
||||
NSMutableData *data = [NSMutableData dataWithLength:n+message.length];
|
||||
|
||||
[data replaceBytesInRange:NSMakeRange(n, message.length) withBytes:[message bytes]];
|
||||
|
||||
return data;
|
||||
}
|
||||
|
||||
+ (NSString *)hexString:(NSData *)data {
|
||||
NSMutableString *stringBuffer = [NSMutableString stringWithCapacity:([data length] * 2)];
|
||||
const unsigned char *dataBuffer = [data bytes];
|
||||
|
||||
for (int i = 0; i < [data length]; ++i) {
|
||||
[stringBuffer appendFormat:@"%02X", dataBuffer[i]];
|
||||
}
|
||||
return stringBuffer;
|
||||
}
|
||||
|
||||
+ (NSData *)hexStringToBytes:(NSString *)hex {
|
||||
NSMutableData *buffer = [NSMutableData data];
|
||||
unsigned int intValue;
|
||||
|
||||
for (int i = 0; i + 2 <= [hex length]; i += 2) {
|
||||
NSRange range = NSMakeRange(i, 2);
|
||||
NSString * hexString = [hex substringWithRange:range];
|
||||
NSScanner * scanner = [NSScanner scannerWithString:hexString];
|
||||
[scanner scanHexInt:&intValue];
|
||||
[buffer appendBytes:&intValue length:1];
|
||||
}
|
||||
return buffer;
|
||||
}
|
||||
|
||||
@end
|
||||
@@ -0,0 +1,45 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import <Foundation/Foundation.h>
|
||||
|
||||
/**
|
||||
* Verify digital signatures
|
||||
* (see http://ed25519.cr.yp.to)
|
||||
*/
|
||||
@interface AGVerifyKey : NSObject
|
||||
|
||||
/**
|
||||
* Initialize with the public key provided.
|
||||
*
|
||||
* @param key The Public key.
|
||||
|
||||
* @return the AGVerifyKey object.
|
||||
*/
|
||||
- (id)initWithKey:(NSData *)key;
|
||||
|
||||
/**
|
||||
* Verify the integrity of the message with the signature provided.
|
||||
*
|
||||
* @param message The message to be verified.
|
||||
* @param signature The provided signature.
|
||||
*
|
||||
* @return the result of the verification process.
|
||||
*/
|
||||
- (BOOL)verify:(NSData *)message signature:(NSData *)signature;
|
||||
|
||||
@end
|
||||
@@ -0,0 +1,63 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#import "AGVerifyKey.h"
|
||||
#import "AGUtil.h"
|
||||
#import <libsodium-ios/sodium/crypto_sign_ed25519.h>
|
||||
|
||||
|
||||
@implementation AGVerifyKey {
|
||||
NSData *_key;
|
||||
}
|
||||
|
||||
- (id)initWithKey:(NSData *)key {
|
||||
NSParameterAssert(key != nil && [key length] == crypto_sign_ed25519_PUBLICKEYBYTES);
|
||||
|
||||
self = [super init];
|
||||
if (self) {
|
||||
_key = key;
|
||||
}
|
||||
|
||||
return self;
|
||||
}
|
||||
|
||||
- (BOOL)verify:(NSData *)message signature:(NSData *)signature {
|
||||
NSParameterAssert(message != nil);
|
||||
NSParameterAssert(signature != nil && [signature length] == crypto_sign_ed25519_BYTES);
|
||||
|
||||
NSMutableData *signAndMsg = [NSMutableData data];
|
||||
[signAndMsg appendData:signature];
|
||||
[signAndMsg appendData:message];
|
||||
|
||||
unsigned long long bufferLen;
|
||||
NSMutableData *newBuffer = [[NSMutableData alloc] initWithLength:signAndMsg.length];
|
||||
|
||||
int status = crypto_sign_ed25519_open([newBuffer mutableBytes],
|
||||
&bufferLen,
|
||||
[signAndMsg bytes],
|
||||
signAndMsg.length,
|
||||
[_key bytes]);
|
||||
|
||||
if( status != 0 ) {
|
||||
NSLog(@"Invalid signature %i", status);
|
||||
return NO;
|
||||
}
|
||||
|
||||
return YES;
|
||||
}
|
||||
|
||||
@end
|
||||
@@ -0,0 +1,32 @@
|
||||
/*
|
||||
* JBoss, Home of Professional Open Source.
|
||||
* Copyright Red Hat, Inc., and individual contributors
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#ifndef _AEROGEARCRYPTO_
|
||||
#define _AEROGEARCRYPTO_
|
||||
|
||||
// imports
|
||||
#import "AGPBKDF2.h"
|
||||
#import "AGRandomGenerator.h"
|
||||
#import "AGSecretBox.h"
|
||||
#import "AGCryptoBox.h"
|
||||
#import "AGHash.h"
|
||||
#import "AGSigningKey.h"
|
||||
#import "AGVerifyKey.h"
|
||||
#import "AGKeyPair.h"
|
||||
#import "AGUtil.h"
|
||||
|
||||
#endif /* _AEROGEARCRYPTO_ */
|
||||
Reference in new issue
Block a user