Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 1 | /* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil -*- */ |
| 2 | /* |
| 3 | * Copyright (c) 2013, Regents of the University of California |
| 4 | * Yingdi Yu |
| 5 | * |
| 6 | * BSD license, See the LICENSE file for more information |
| 7 | * |
| 8 | * Author: Yingdi Yu <yingdi@cs.ucla.edu> |
| 9 | */ |
| 10 | |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 11 | #include "sec-policy-chrono-chat-panel.h" |
Yingdi Yu | f8f572d | 2014-01-13 11:19:47 -0800 | [diff] [blame] | 12 | #include <ndn-cpp/security/verifier.hpp> |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 13 | #include <ndn-cpp/security/signature-sha256-with-rsa.hpp> |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 14 | // #include <boost/bind.hpp> |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 15 | |
| 16 | #include "logging.h" |
| 17 | |
| 18 | using namespace std; |
| 19 | using namespace ndn; |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 20 | using namespace ndn::ptr_lib; |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 21 | |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 22 | INIT_LOGGER("SecPolicyChronoChatPanel"); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 23 | |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 24 | SecPolicyChronoChatPanel::SecPolicyChronoChatPanel(const int & stepLimit) |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 25 | : m_stepLimit(stepLimit) |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 26 | , m_certificateCache() |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 27 | { |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 28 | m_localPrefixRegex = make_shared<Regex>("^<local><ndn><prefix><><>$"); |
Yingdi Yu | 9b34b1f | 2013-11-01 17:37:51 -0700 | [diff] [blame] | 29 | |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 30 | m_invitationDataSigningRule = make_shared<SecRuleIdentity>("^<ndn><broadcast><chronos><invitation>([^<chatroom>]*)<chatroom>", |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 31 | "^([^<KEY>]*)<KEY>(<>*)<><ID-CERT><>$", |
| 32 | "==", "\\1", "\\1\\2", true); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 33 | |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 34 | m_dskRule = make_shared<SecRuleIdentity>("^([^<KEY>]*)<KEY><dsk-.*><ID-CERT><>$", |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 35 | "^([^<KEY>]*)<KEY>(<>*)<ksk-.*><ID-CERT>$", |
| 36 | "==", "\\1", "\\1\\2", true); |
Yingdi Yu | b2e747d | 2013-11-05 23:06:43 -0800 | [diff] [blame] | 37 | |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 38 | m_endorseeRule = make_shared<SecRuleIdentity>("^([^<DNS>]*)<DNS><>*<ENDORSEE><>$", |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 39 | "^([^<KEY>]*)<KEY>(<>*)<ksk-.*><ID-CERT>$", |
| 40 | "==", "\\1", "\\1\\2", true); |
Yingdi Yu | b2e747d | 2013-11-05 23:06:43 -0800 | [diff] [blame] | 41 | |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 42 | m_kskRegex = make_shared<Regex>("^([^<KEY>]*)<KEY>(<>*<ksk-.*>)<ID-CERT><>$", "\\1\\2"); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 43 | |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 44 | m_keyNameRegex = make_shared<Regex>("^([^<KEY>]*)<KEY>(<>*<ksk-.*>)<ID-CERT>$", "\\1\\2"); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 45 | |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 46 | m_signingCertificateRegex = make_shared<Regex>("^<ndn><broadcast><chronos><invitation>([^<chatroom>]*)<chatroom>", "\\1"); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 47 | } |
| 48 | |
| 49 | bool |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 50 | SecPolicyChronoChatPanel::skipVerifyAndTrust (const Data & data) |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 51 | { |
| 52 | if(m_localPrefixRegex->match(data.getName())) |
| 53 | return true; |
| 54 | |
| 55 | return false; |
| 56 | } |
| 57 | |
| 58 | bool |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 59 | SecPolicyChronoChatPanel::requireVerify (const Data & data) |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 60 | { |
| 61 | // if(m_invitationDataRule->matchDataName(data)) |
| 62 | // return true; |
Yingdi Yu | 9b34b1f | 2013-11-01 17:37:51 -0700 | [diff] [blame] | 63 | if(m_kskRegex->match(data.getName())) |
| 64 | return true; |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 65 | if(m_dskRule->matchDataName(data)) |
| 66 | return true; |
| 67 | |
Yingdi Yu | b2e747d | 2013-11-05 23:06:43 -0800 | [diff] [blame] | 68 | if(m_endorseeRule->matchDataName(data)) |
| 69 | return true; |
| 70 | |
| 71 | |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 72 | return false; |
| 73 | } |
| 74 | |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 75 | shared_ptr<ValidationRequest> |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 76 | SecPolicyChronoChatPanel::checkVerificationPolicy(const shared_ptr<Data>& data, |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 77 | int stepCount, |
| 78 | const OnVerified& onVerified, |
| 79 | const OnVerifyFailed& onVerifyFailed) |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 80 | { |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 81 | if(m_stepLimit == stepCount) |
| 82 | { |
Yingdi Yu | e35bdb8 | 2013-11-07 11:32:40 -0800 | [diff] [blame] | 83 | _LOG_ERROR("Reach the maximum steps of verification!"); |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 84 | onVerifyFailed(data); |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 85 | return shared_ptr<ValidationRequest>(); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 86 | } |
| 87 | |
Yingdi Yu | f8f572d | 2014-01-13 11:19:47 -0800 | [diff] [blame] | 88 | try{ |
| 89 | SignatureSha256WithRsa sig(data->getSignature()); |
| 90 | const Name & keyLocatorName = sig.getKeyLocator().getName(); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 91 | |
Yingdi Yu | f8f572d | 2014-01-13 11:19:47 -0800 | [diff] [blame] | 92 | if(m_kskRegex->match(data->getName())) |
| 93 | { |
| 94 | Name keyName = m_kskRegex->expand(); |
| 95 | map<Name, PublicKey>::iterator it = m_trustAnchors.find(keyName); |
| 96 | if(m_trustAnchors.end() != it) |
| 97 | { |
| 98 | // _LOG_DEBUG("found key!"); |
| 99 | IdentityCertificate identityCertificate(*data); |
| 100 | if(it->second == identityCertificate.getPublicKeyInfo()) |
| 101 | onVerified(data); |
| 102 | else |
| 103 | onVerifyFailed(data); |
| 104 | } |
| 105 | else |
| 106 | onVerifyFailed(data); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 107 | |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 108 | return shared_ptr<ValidationRequest>(); |
Yingdi Yu | f8f572d | 2014-01-13 11:19:47 -0800 | [diff] [blame] | 109 | } |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 110 | |
Yingdi Yu | f8f572d | 2014-01-13 11:19:47 -0800 | [diff] [blame] | 111 | if(m_dskRule->satisfy(*data)) |
| 112 | { |
| 113 | m_keyNameRegex->match(keyLocatorName); |
| 114 | Name keyName = m_keyNameRegex->expand(); |
| 115 | |
| 116 | if(m_trustAnchors.end() != m_trustAnchors.find(keyName)) |
| 117 | if(Verifier::verifySignature(*data, sig, m_trustAnchors[keyName])) |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 118 | onVerified(data); |
Yingdi Yu | 9b34b1f | 2013-11-01 17:37:51 -0700 | [diff] [blame] | 119 | else |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 120 | onVerifyFailed(data); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 121 | else |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 122 | onVerifyFailed(data); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 123 | |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 124 | return shared_ptr<ValidationRequest>(); |
Yingdi Yu | f8f572d | 2014-01-13 11:19:47 -0800 | [diff] [blame] | 125 | } |
Yingdi Yu | b2e747d | 2013-11-05 23:06:43 -0800 | [diff] [blame] | 126 | |
Yingdi Yu | f8f572d | 2014-01-13 11:19:47 -0800 | [diff] [blame] | 127 | if(m_endorseeRule->satisfy(*data)) |
| 128 | { |
| 129 | m_keyNameRegex->match(keyLocatorName); |
| 130 | Name keyName = m_keyNameRegex->expand(); |
| 131 | if(m_trustAnchors.end() != m_trustAnchors.find(keyName)) |
| 132 | if(Verifier::verifySignature(*data, sig, m_trustAnchors[keyName])) |
| 133 | onVerified(data); |
| 134 | else |
| 135 | onVerifyFailed(data); |
Yingdi Yu | b2e747d | 2013-11-05 23:06:43 -0800 | [diff] [blame] | 136 | else |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 137 | onVerifyFailed(data); |
Yingdi Yu | b2e747d | 2013-11-05 23:06:43 -0800 | [diff] [blame] | 138 | |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 139 | return shared_ptr<ValidationRequest>(); |
Yingdi Yu | f8f572d | 2014-01-13 11:19:47 -0800 | [diff] [blame] | 140 | } |
| 141 | }catch(SignatureSha256WithRsa::Error &e){ |
| 142 | _LOG_DEBUG("checkVerificationPolicy: " << e.what()); |
| 143 | onVerifyFailed(data); |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 144 | return shared_ptr<ValidationRequest>(); |
Yingdi Yu | f8f572d | 2014-01-13 11:19:47 -0800 | [diff] [blame] | 145 | }catch(KeyLocator::Error &e){ |
| 146 | _LOG_DEBUG("checkVerificationPolicy: " << e.what()); |
| 147 | onVerifyFailed(data); |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 148 | return shared_ptr<ValidationRequest>(); |
Yingdi Yu | f8f572d | 2014-01-13 11:19:47 -0800 | [diff] [blame] | 149 | } |
Yingdi Yu | b2e747d | 2013-11-05 23:06:43 -0800 | [diff] [blame] | 150 | |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 151 | _LOG_DEBUG("Unverified!"); |
| 152 | |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 153 | onVerifyFailed(data); |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 154 | return shared_ptr<ValidationRequest>(); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 155 | } |
| 156 | |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 157 | bool |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 158 | SecPolicyChronoChatPanel::checkSigningPolicy(const Name & dataName, const Name & certificateName) |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 159 | { |
| 160 | return m_invitationDataSigningRule->satisfy(dataName, certificateName); |
| 161 | } |
| 162 | |
| 163 | Name |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 164 | SecPolicyChronoChatPanel::inferSigningIdentity(const Name & dataName) |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 165 | { |
| 166 | if(m_signingCertificateRegex->match(dataName)) |
| 167 | return m_signingCertificateRegex->expand(); |
| 168 | else |
| 169 | return Name(); |
| 170 | } |
| 171 | |
| 172 | void |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 173 | SecPolicyChronoChatPanel::addTrustAnchor(const EndorseCertificate& selfEndorseCertificate) |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 174 | { |
Yingdi Yu | 6eabbd7 | 2013-12-27 08:44:12 +0800 | [diff] [blame] | 175 | _LOG_DEBUG("Add Anchor: " << selfEndorseCertificate.getPublicKeyName().toUri()); |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 176 | m_trustAnchors.insert(pair <Name, PublicKey > (selfEndorseCertificate.getPublicKeyName(), selfEndorseCertificate.getPublicKeyInfo())); |
Yingdi Yu | 7989eb2 | 2013-10-31 17:38:22 -0700 | [diff] [blame] | 177 | } |
Yingdi Yu | af305d7 | 2013-11-10 11:54:02 -0800 | [diff] [blame] | 178 | |
Yingdi Yu | 7223269 | 2013-11-12 17:50:21 -0800 | [diff] [blame] | 179 | void |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 180 | SecPolicyChronoChatPanel::removeTrustAnchor(const Name& keyName) |
Yingdi Yu | 7223269 | 2013-11-12 17:50:21 -0800 | [diff] [blame] | 181 | { |
| 182 | m_trustAnchors.erase(keyName); |
| 183 | } |
| 184 | |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 185 | shared_ptr<PublicKey> |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 186 | SecPolicyChronoChatPanel::getTrustedKey(const Name& inviterCertName) |
Yingdi Yu | af305d7 | 2013-11-10 11:54:02 -0800 | [diff] [blame] | 187 | { |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 188 | Name keyLocatorName = inviterCertName.getPrefix(-1); |
Yingdi Yu | 6eabbd7 | 2013-12-27 08:44:12 +0800 | [diff] [blame] | 189 | _LOG_DEBUG("inviter cert name: " << inviterCertName.toUri()); |
Yingdi Yu | af305d7 | 2013-11-10 11:54:02 -0800 | [diff] [blame] | 190 | m_keyNameRegex->match(keyLocatorName); |
| 191 | Name keyName = m_keyNameRegex->expand(); |
| 192 | |
| 193 | if(m_trustAnchors.end() != m_trustAnchors.find(keyName)) |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 194 | return make_shared<PublicKey>(m_trustAnchors[keyName]); |
Yingdi Yu | 93adb1a | 2014-01-16 10:30:26 -0800 | [diff] [blame] | 195 | return shared_ptr<PublicKey>(); |
Yingdi Yu | 76dd800 | 2013-12-24 11:16:32 +0800 | [diff] [blame] | 196 | } |