blob: af094a7e76f176051111f1c05b5327cb5a0d6ca4 [file] [log] [blame]
Yingdi Yu0b82a4e2013-10-18 11:29:25 -07001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil -*- */
2/*
3 * Copyright (c) 2013, Regents of the University of California
4 * Yingdi Yu
5 *
6 * BSD license, See the LICENSE file for more information
7 *
8 * Author: Yingdi Yu <yingdi@cs.ucla.edu>
9 */
10
11#include "contact-manager.h"
12
Yingdi Yuaa8d7692013-10-18 17:05:02 -070013#ifndef Q_MOC_RUN
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070014#include <ndn.cxx/wrapper/wrapper.h>
15#include <ndn.cxx/security/keychain.h>
16#include <ndn.cxx/security/identity/basic-identity-storage.h>
17#include <ndn.cxx/security/identity/osx-privatekey-storage.h>
18#include <ndn.cxx/security/policy/simple-policy-manager.h>
19#include <ndn.cxx/security/policy/identity-policy-rule.h>
20#include <ndn.cxx/security/cache/ttl-certificate-cache.h>
21#include <ndn.cxx/security/encryption/basic-encryption-manager.h>
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070022#include <fstream>
Yingdi Yu590fa5d2013-10-18 18:35:09 -070023#include "logging.h"
Yingdi Yuaa8d7692013-10-18 17:05:02 -070024#endif
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070025
26using namespace ndn;
27using namespace ndn::security;
28
Yingdi Yu590fa5d2013-10-18 18:35:09 -070029INIT_LOGGER("ContactManager");
30
Yingdi Yuaa8d7692013-10-18 17:05:02 -070031ContactManager::ContactManager(Ptr<ContactStorage> contactStorage,
Yingdi Yu590fa5d2013-10-18 18:35:09 -070032 Ptr<DnsStorage> dnsStorage,
33 QObject* parent)
34 : QObject(parent)
35 , m_contactStorage(contactStorage)
Yingdi Yuaa8d7692013-10-18 17:05:02 -070036 , m_dnsStorage(dnsStorage)
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070037{
Yingdi Yuaa8d7692013-10-18 17:05:02 -070038 setKeychain();
39
40 m_wrapper = Ptr<Wrapper>(new Wrapper(m_keychain));
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070041}
42
43ContactManager::~ContactManager()
44{
45}
46
Yingdi Yuaa8d7692013-10-18 17:05:02 -070047void
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070048ContactManager::setKeychain()
49{
50 Ptr<OSXPrivatekeyStorage> privateStorage = Ptr<OSXPrivatekeyStorage>::Create();
51 Ptr<IdentityManager> identityManager = Ptr<IdentityManager>(new IdentityManager(Ptr<BasicIdentityStorage>::Create(), privateStorage));
52 Ptr<TTLCertificateCache> certificateCache = Ptr<TTLCertificateCache>(new TTLCertificateCache());
53 Ptr<SimplePolicyManager> policyManager = Ptr<SimplePolicyManager>(new SimplePolicyManager(10, certificateCache));
54 Ptr<EncryptionManager> encryptionManager = Ptr<EncryptionManager>(new BasicEncryptionManager(privateStorage, "/tmp/encryption.db"));
55 Ptr<Keychain> keychain = Ptr<Keychain>(new Keychain(identityManager, policyManager, encryptionManager));
56
Yingdi Yuaa8d7692013-10-18 17:05:02 -070057 policyManager->addVerificationPolicyRule(Ptr<IdentityPolicyRule>(new IdentityPolicyRule("^([^<DNS>]*)<DNS><PROFILE>",
58 "^([^<KEY>]*)<KEY>(<>*)<><ID-CERT>",
59 "==", "\\1", "\\1\\2", true)));
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070060 policyManager->addVerificationPolicyRule(Ptr<IdentityPolicyRule>(new IdentityPolicyRule("^([^<PROFILE-CERT>]*)<PROFILE-CERT>",
61 "^([^<KEY>]*)<KEY>(<>*<KSK-.*>)<ID-CERT>",
Yingdi Yuaa8d7692013-10-18 17:05:02 -070062 "==", "\\1", "\\1\\2", true)));
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070063 policyManager->addVerificationPolicyRule(Ptr<IdentityPolicyRule>(new IdentityPolicyRule("^([^<KEY>]*)<KEY>(<>*)<KSK-.*><ID-CERT>",
64 "^([^<KEY>]*)<KEY><DSK-.*><ID-CERT>",
Yingdi Yuaa8d7692013-10-18 17:05:02 -070065 ">", "\\1\\2", "\\1", true)));
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070066 policyManager->addVerificationPolicyRule(Ptr<IdentityPolicyRule>(new IdentityPolicyRule("^([^<KEY>]*)<KEY><DSK-.*><ID-CERT>",
67 "^([^<KEY>]*)<KEY>(<>*)<KSK-.*><ID-CERT>",
Yingdi Yuaa8d7692013-10-18 17:05:02 -070068 "==", "\\1", "\\1\\2", true)));
69
70 policyManager->addSigningPolicyRule(Ptr<IdentityPolicyRule>(new IdentityPolicyRule("^([^<DNS>]*)<DNS><PROFILE>",
71 "^([^<KEY>]*)<KEY>(<>*)<><ID-CERT>",
72 "==", "\\1", "\\1\\2", true)));
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070073
74 ifstream is ("trust-anchor.data", ios::binary);
75 is.seekg (0, ios::end);
76 ifstream::pos_type size = is.tellg();
77 char * memblock = new char [size];
78 is.seekg (0, ios::beg);
79 is.read (memblock, size);
80 is.close();
81
82 Ptr<Blob> readBlob = Ptr<Blob>(new Blob(memblock, size));
83 Ptr<Data> readData = Data::decodeFromWire (readBlob);
84 Ptr<IdentityCertificate> anchor = Ptr<IdentityCertificate>(new IdentityCertificate(*readData));
85 policyManager->addTrustAnchor(anchor);
86
87 delete memblock;
88
Yingdi Yuaa8d7692013-10-18 17:05:02 -070089 m_keychain = keychain;
Yingdi Yu0b82a4e2013-10-18 11:29:25 -070090}
Yingdi Yuaa8d7692013-10-18 17:05:02 -070091
92
93void
94ContactManager::fetchSelfEndorseCertificate(const ndn::Name& identity)
95{
96 Name interestName = identity;
97 interestName.append("DNS").append("PROFILE");
98
99 Ptr<Interest> interestPtr = Ptr<Interest>(new Interest(interestName));
100 Ptr<Closure> closure = Ptr<Closure> (new Closure(boost::bind(&ContactManager::onDnsSelfEndorseCertificateVerified,
101 this,
102 _1,
103 identity),
104 boost::bind(&ContactManager::onDnsSelfEndorseCertificateTimeout,
105 this,
106 _1,
107 _2,
108 identity,
109 0),
110 boost::bind(&ContactManager::onDnsSelfEndorseCertificateUnverified,
111 this,
112 _1,
113 identity)));
114 m_wrapper->sendInterest(interestPtr, closure);
115}
116
117void
118ContactManager::updateProfileData(const Name& identity)
119{
120 // Get current profile;
121 Ptr<Profile> newProfile = m_contactStorage->getSelfProfile(identity);
122 if(NULL == newProfile)
123 return;
124 Ptr<Blob> newProfileBlob = newProfile->toDerBlob();
125
126 // Check if profile exists
127 Ptr<Blob> profileDataBlob = m_contactStorage->getSelfEndorseCertificate(identity);
128 if(NULL != profileDataBlob)
129 {
130 Ptr<Data> plainData = Data::decodeFromWire(profileDataBlob);
131 EndorseCertificate oldEndorseCertificate(*plainData);
132 // _LOG_DEBUG("Certificate converted!");
133 const Blob& oldProfileBlob = oldEndorseCertificate.getProfileData()->content();
134
135 if(oldProfileBlob == *newProfileBlob)
136 return;
137
138 Ptr<EndorseCertificate> newEndorseCertificate = getSignedSelfEndorseCertificate(identity, *newProfile);
139 // _LOG_DEBUG("Signing DONE!");
140 if(NULL == newEndorseCertificate)
141 return;
Yingdi Yu590fa5d2013-10-18 18:35:09 -0700142 _LOG_DEBUG("About to update");
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700143 m_contactStorage->updateSelfEndorseCertificate(newEndorseCertificate, identity);
144
145 publishSelfEndorseCertificateInDNS(newEndorseCertificate);
146 }
147 else
148 {
149 Ptr<EndorseCertificate> newEndorseCertificate = getSignedSelfEndorseCertificate(identity, *newProfile);
150 // _LOG_DEBUG("Signing DONE!");
151 if(NULL == newEndorseCertificate)
152 return;
Yingdi Yu590fa5d2013-10-18 18:35:09 -0700153 _LOG_DEBUG("About to Insert");
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700154 m_contactStorage->addSelfEndorseCertificate(newEndorseCertificate, identity);
155
156 publishSelfEndorseCertificateInDNS(newEndorseCertificate);
157 }
158}
159
Yingdi Yu79c25a22013-10-21 13:38:38 -0700160vector<Ptr<ContactItem> >
161ContactManager::getContactItemList()
162{
163 vector<Ptr<ContactItem> > result;
164
165 vector<Ptr<ContactItem> > ncList = m_contactStorage->getAllNormalContacts();
166 vector<Ptr<TrustedContact> > tcList = m_contactStorage->getAllTrustedContacts();
167
168 result.insert(result.end(), tcList.begin(), tcList.end());
169 result.insert(result.end(), ncList.begin(), ncList.end());
170
171 return result;
172}
173
Yingdi Yud40226b2013-10-23 14:05:12 -0700174Ptr<ContactItem>
175ContactManager::getContact(const ndn::Name& contactNamespace)
176{
177 Ptr<ContactItem> contactItem = m_contactStorage->getNormalContact(contactNamespace);
178 if(NULL != contactItem)
179 return contactItem;
180
181 contactItem = m_contactStorage->getTrustedContact(contactNamespace);
182 if(NULL != contactItem)
183 return contactItem;
184
185 return NULL;
186}
187
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700188Ptr<EndorseCertificate>
189ContactManager::getSignedSelfEndorseCertificate(const Name& identity,
190 const Profile& profile)
191{
192 Ptr<IdentityManager> identityManager = m_keychain->getIdentityManager();
193 Name certificateName = identityManager->getDefaultCertificateNameByIdentity(identity);
194 if(0 == certificateName.size())
195 return NULL;
196
197 Ptr<ProfileData> profileData = Ptr<ProfileData>(new ProfileData(identity, profile));
198 identityManager->signByCertificate(*profileData, certificateName);
199
200 Ptr<security::IdentityCertificate> dskCert = identityManager->getCertificate(certificateName);
201 Ptr<const signature::Sha256WithRsa> dskCertSig = DynamicCast<const signature::Sha256WithRsa>(dskCert->getSignature());
202 // HACK! KSK certificate should be retrieved from network.
203 Ptr<security::IdentityCertificate> kskCert = identityManager->getCertificate(dskCertSig->getKeyLocator().getKeyName());
204
205 vector<string> endorseList;
206 Profile::const_iterator it = profile.begin();
207 for(; it != profile.end(); it++)
208 endorseList.push_back(it->first);
209
210 Ptr<EndorseCertificate> selfEndorseCertificate = Ptr<EndorseCertificate>(new EndorseCertificate(*kskCert,
211 kskCert->getNotBefore(),
212 kskCert->getNotAfter(),
213 profileData,
214 endorseList));
215 identityManager->signByCertificate(*selfEndorseCertificate, kskCert->getName());
216
217 return selfEndorseCertificate;
218}
219
220
221void
222ContactManager::onDnsSelfEndorseCertificateVerified(Ptr<Data> data, const Name& identity)
223{
Yingdi Yuc29fb982013-10-20 19:43:10 -0700224 Ptr<Blob> dataContentBlob = Ptr<Blob>(new Blob(data->content().buf(), data->content().size()));
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700225
Yingdi Yuc29fb982013-10-20 19:43:10 -0700226 Ptr<Data> plainData = Data::decodeFromWire(dataContentBlob);
227
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700228 Ptr<EndorseCertificate> selfEndorseCertificate = Ptr<EndorseCertificate>(new EndorseCertificate(*plainData));
Yingdi Yuc29fb982013-10-20 19:43:10 -0700229
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700230 const security::Publickey& ksk = selfEndorseCertificate->getPublicKeyInfo();
Yingdi Yuc29fb982013-10-20 19:43:10 -0700231
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700232 if(security::PolicyManager::verifySignature(*plainData, ksk))
Yingdi Yuc29fb982013-10-20 19:43:10 -0700233 {
Yingdi Yu79c25a22013-10-21 13:38:38 -0700234 // Profile profile = selfEndorseCertificate->getProfileData()->getProfile();
235 // Profile::const_iterator it = profile.getEntries().begin();
236 // it++;
237 // _LOG_DEBUG("Entry Size: " << it->first);
238
Yingdi Yuc29fb982013-10-20 19:43:10 -0700239 emit contactFetched (*selfEndorseCertificate);
240 }
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700241 else
Yingdi Yuc29fb982013-10-20 19:43:10 -0700242 {
243 emit contactFetchFailed (identity);
244 }
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700245}
246
247void
248ContactManager::onDnsSelfEndorseCertificateUnverified(Ptr<Data> data, const Name& identity)
249{ emit contactFetchFailed (identity); }
250
251void
252ContactManager::onDnsSelfEndorseCertificateTimeout(Ptr<Closure> closure, Ptr<Interest> interest, const Name& identity, int retry)
253{
254 if(retry > 0)
255 {
256 Ptr<Closure> newClosure = Ptr<Closure>(new Closure(closure->m_dataCallback,
257 boost::bind(&ContactManager::onDnsSelfEndorseCertificateTimeout,
258 this,
259 _1,
260 _2,
261 identity,
262 retry - 1),
263 closure->m_unverifiedCallback,
264 closure->m_stepCount)
265 );
266 m_wrapper->sendInterest(interest, newClosure);
267 }
268 else
269 emit contactFetchFailed(identity);
270}
271
272void
273ContactManager::publishSelfEndorseCertificateInDNS(Ptr<EndorseCertificate> selfEndorseCertificate)
274{
275 Ptr<Data> data = Ptr<Data>::Create();
276
277 Name keyName = selfEndorseCertificate->getPublicKeyName();
278 Name identity = keyName.getSubName(0, keyName.size()-1);
279
280 TimeInterval ti = time::NowUnixTimestamp();
281 ostringstream oss;
282 oss << ti.total_seconds();
283
284 Name dnsName = identity;
285 dnsName.append("DNS").append("PROFILE").append(oss.str());
Yingdi Yuc29fb982013-10-20 19:43:10 -0700286
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700287 data->setName(dnsName);
288 Ptr<Blob> blob = selfEndorseCertificate->encodeToWire();
Yingdi Yuc29fb982013-10-20 19:43:10 -0700289
290 // string encoded;
291 // CryptoPP::StringSource ss(reinterpret_cast<const unsigned char *>(blob->buf()), blob->size(), true,
292 // new CryptoPP::Base64Encoder(new CryptoPP::StringSink(encoded), false));
293
294 // Content content(encoded.c_str(), encoded.size());
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700295 Content content(blob->buf(), blob->size());
296 data->setContent(content);
297
298 m_keychain->signByIdentity(*data, identity);
Yingdi Yu590fa5d2013-10-18 18:35:09 -0700299
300 m_dnsStorage->updateDnsSelfProfileData(*data, identity);
Yingdi Yuaa8d7692013-10-18 17:05:02 -0700301
302 Ptr<Blob> dnsBlob = data->encodeToWire();
303
304 m_wrapper->putToCcnd(*dnsBlob);
305}
306
307
308#if WAF
309#include "contact-manager.moc"
310#include "contact-manager.cpp.moc"
311#endif