security: Add BlockCipher in transformation

Change-Id: I2c09509acd69e7f9270ef8c9b6e5e16ede2a8042
Refs: #3009
diff --git a/src/security/security-common.cpp b/src/security/security-common.cpp
index 0f8714d..0ea60cb 100644
--- a/src/security/security-common.cpp
+++ b/src/security/security-common.cpp
@@ -105,6 +105,23 @@
 }
 
 std::ostream&
+operator<<(std::ostream& os, CipherOperator op)
+{
+  switch (op) {
+  case CipherOperator::DECRYPT:
+    os << "DECRYPT";
+    break;
+  case CipherOperator::ENCRYPT:
+    os << "ENCRYPT";
+    break;
+  default:
+    os << static_cast<int>(op);
+    break;
+  };
+  return os;
+}
+
+std::ostream&
 operator<<(std::ostream& os, AclType aclType)
 {
   switch (aclType) {
diff --git a/src/security/security-common.hpp b/src/security/security-common.hpp
index 15a82bf..8594581 100644
--- a/src/security/security-common.hpp
+++ b/src/security/security-common.hpp
@@ -73,6 +73,14 @@
 std::ostream&
 operator<<(std::ostream& os, BlockCipherAlgorithm algorithm);
 
+enum class CipherOperator {
+  DECRYPT = 0,
+  ENCRYPT = 1
+};
+
+std::ostream&
+operator<<(std::ostream& os, CipherOperator op);
+
 enum class AclType {
   NONE,
   PUBLIC,
diff --git a/src/security/transform.hpp b/src/security/transform.hpp
index 7c5776d..2d2ef2e 100644
--- a/src/security/transform.hpp
+++ b/src/security/transform.hpp
@@ -35,5 +35,6 @@
 #include "transform/base64-decode.hpp"
 #include "transform/digest-filter.hpp"
 #include "transform/hmac-filter.hpp"
+#include "transform/block-cipher.hpp"
 
 #endif // NDN_CXX_SECURITY_TRANSFORM_HPP
diff --git a/src/security/transform/block-cipher.cpp b/src/security/transform/block-cipher.cpp
new file mode 100644
index 0000000..b53ec4f
--- /dev/null
+++ b/src/security/transform/block-cipher.cpp
@@ -0,0 +1,166 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2013-2016 Regents of the University of California.
+ *
+ * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
+ *
+ * ndn-cxx library is free software: you can redistribute it and/or modify it under the
+ * terms of the GNU Lesser General Public License as published by the Free Software
+ * Foundation, either version 3 of the License, or (at your option) any later version.
+ *
+ * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
+ * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
+ * PARTICULAR PURPOSE.  See the GNU Lesser General Public License for more details.
+ *
+ * You should have received copies of the GNU General Public License and GNU Lesser
+ * General Public License along with ndn-cxx, e.g., in COPYING.md file.  If not, see
+ * <http://www.gnu.org/licenses/>.
+ *
+ * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
+ */
+
+#include "block-cipher.hpp"
+#include "../detail/openssl.hpp"
+
+#include <boost/lexical_cast.hpp>
+
+namespace ndn {
+namespace security {
+namespace transform {
+
+class BlockCipher::Impl
+{
+public:
+  Impl()
+    : m_cipher(BIO_new(BIO_f_cipher()))
+    , m_sink(BIO_new(BIO_s_mem()))
+  {
+    BIO_push(m_cipher, m_sink);
+  }
+
+  ~Impl()
+  {
+    BIO_free_all(m_sink);
+  }
+
+public:
+  BIO* m_cipher;
+  BIO* m_sink; // BIO_f_cipher alone does not work without a sink
+};
+
+BlockCipher::BlockCipher(BlockCipherAlgorithm algo, CipherOperator op,
+                         const uint8_t* key, size_t keyLen,
+                         const uint8_t* iv, size_t ivLen)
+  : m_impl(new Impl)
+{
+  switch (algo) {
+  case BlockCipherAlgorithm::AES_CBC:
+    initializeAesCbc(key, keyLen, iv, ivLen, op);
+    break;
+  default:
+    BOOST_THROW_EXCEPTION(Error(getIndex(), "Cipher algorithm " +
+                                boost::lexical_cast<std::string>(algo) + " is not supported"));
+  }
+}
+
+void
+BlockCipher::preTransform()
+{
+  fillOutputBuffer();
+}
+
+size_t
+BlockCipher::convert(const uint8_t* data, size_t dataLen)
+{
+  if (dataLen == 0)
+    return 0;
+
+  int wLen = BIO_write(m_impl->m_cipher, data, dataLen);
+
+  if (wLen <= 0) { // fail to write data
+    if (!BIO_should_retry(m_impl->m_cipher)) {
+      // we haven't written everything but some error happens, and we cannot retry
+      BOOST_THROW_EXCEPTION(Error(getIndex(), "Failed to accept more input"));
+    }
+    return 0;
+  }
+  else { // update number of bytes written
+    fillOutputBuffer();
+    return wLen;
+  }
+}
+
+void
+BlockCipher::finalize()
+{
+  if (BIO_flush(m_impl->m_cipher) != 1)
+    BOOST_THROW_EXCEPTION(Error(getIndex(), "Failed to flush"));
+
+  while (!isConverterEmpty()) {
+    fillOutputBuffer();
+    while (!isOutputBufferEmpty()) {
+      flushOutputBuffer();
+    }
+  }
+}
+
+void
+BlockCipher::fillOutputBuffer()
+{
+  int nRead = BIO_pending(m_impl->m_sink);
+  if (nRead <= 0)
+    return;
+
+  // there is something to read from BIO
+  auto buffer = make_unique<OBuffer>(nRead);
+  int rLen = BIO_read(m_impl->m_sink, &(*buffer)[0], nRead);
+  if (rLen < 0)
+    return;
+
+  if (rLen < nRead)
+    buffer->erase(buffer->begin() + rLen, buffer->end());
+  setOutputBuffer(std::move(buffer));
+}
+
+bool
+BlockCipher::isConverterEmpty() const
+{
+  return (BIO_pending(m_impl->m_sink) <= 0);
+}
+
+void
+BlockCipher::initializeAesCbc(const uint8_t* key, size_t keyLen,
+                              const uint8_t* iv, size_t ivLen,
+                              CipherOperator op)
+{
+  if (keyLen != ivLen)
+    BOOST_THROW_EXCEPTION(Error(getIndex(), "Key length must be the same as IV length"));
+
+  const EVP_CIPHER* cipherType = nullptr;
+  switch (keyLen) {
+  case 16:
+    cipherType = EVP_aes_128_cbc();
+    break;
+  case 24:
+    cipherType = EVP_aes_192_cbc();
+    break;
+  case 32:
+    cipherType = EVP_aes_256_cbc();
+    break;
+  default:
+    BOOST_THROW_EXCEPTION(Error(getIndex(), "Key length is not supported"));
+  }
+  BIO_set_cipher(m_impl->m_cipher, cipherType, key, iv, static_cast<int>(op));
+}
+
+unique_ptr<Transform>
+blockCipher(BlockCipherAlgorithm algo, CipherOperator op,
+            const uint8_t* key, size_t keyLen,
+            const uint8_t* iv, size_t ivLen)
+{
+  return make_unique<BlockCipher>(algo, op, key, keyLen, iv, ivLen);
+}
+
+} // namespace transform
+} // namespace security
+} // namespace ndn
diff --git a/src/security/transform/block-cipher.hpp b/src/security/transform/block-cipher.hpp
new file mode 100644
index 0000000..dd67858
--- /dev/null
+++ b/src/security/transform/block-cipher.hpp
@@ -0,0 +1,109 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2013-2016 Regents of the University of California.
+ *
+ * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
+ *
+ * ndn-cxx library is free software: you can redistribute it and/or modify it under the
+ * terms of the GNU Lesser General Public License as published by the Free Software
+ * Foundation, either version 3 of the License, or (at your option) any later version.
+ *
+ * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
+ * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
+ * PARTICULAR PURPOSE.  See the GNU Lesser General Public License for more details.
+ *
+ * You should have received copies of the GNU General Public License and GNU Lesser
+ * General Public License along with ndn-cxx, e.g., in COPYING.md file.  If not, see
+ * <http://www.gnu.org/licenses/>.
+ *
+ * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
+ */
+
+#ifndef NDN_CXX_SECURITY_TRANSFORM_BLOCK_CIPHER_HPP
+#define NDN_CXX_SECURITY_TRANSFORM_BLOCK_CIPHER_HPP
+
+#include "transform-base.hpp"
+#include "../security-common.hpp"
+
+namespace ndn {
+namespace security {
+namespace transform {
+
+/**
+ * @brief The module to encrypt data using block cipher.
+ *
+ * The padding scheme of the block cipher is set to the default padding scheme of OpenSSl,
+ * which is PKCS padding.
+ */
+class BlockCipher : public Transform
+{
+public:
+  /**
+   * @brief Create a block cipher
+   *
+   * @param algo   The block cipher algorithm (e.g., EncryptMode::AES_CBC).
+   * @param op     The operation that the cipher needs to perform, e.g., CipherOperator::ENCRYPT or CipherOperator::DECRYPT
+   * @param key    The pointer to the key.
+   * @param keyLen The size of the key.
+   * @param iv     The pointer to the initial vector.
+   * @param ivLen  The length of the initial vector.
+   */
+  BlockCipher(BlockCipherAlgorithm algo, CipherOperator op,
+              const uint8_t* key, size_t keyLen,
+              const uint8_t* iv, size_t ivLen);
+
+private:
+  /**
+   * @brief Read partial transformation result (if exists) from BIO
+   */
+  virtual void
+  preTransform() final;
+
+  /**
+   * @brief Write @p data into the cipher
+   *
+   * @return number of bytes that are actually accepted
+   */
+  virtual size_t
+  convert(const uint8_t* data, size_t dataLen) final;
+
+  /**
+   * @brief Finalize the encryption
+   */
+  virtual void
+  finalize() final;
+
+  /**
+   * @brief Fill output buffer with the encryption result from BIO.
+   */
+  void
+  fillOutputBuffer();
+
+  /**
+   * @return true if the cipher does not have partial result.
+   */
+  bool
+  isConverterEmpty() const;
+
+private:
+
+  void
+  initializeAesCbc(const uint8_t* key, size_t keyLen,
+                   const uint8_t* iv, size_t ivLen,
+                   CipherOperator op);
+
+private:
+  class Impl;
+  unique_ptr<Impl> m_impl;
+};
+
+unique_ptr<Transform>
+blockCipher(BlockCipherAlgorithm algo, CipherOperator op,
+            const uint8_t* key, size_t keyLen,
+            const uint8_t* iv, size_t ivLen);
+
+} // namespace transform
+} // namespace security
+} // namespace ndn
+
+#endif // NDN_CXX_SECURITY_TRANSFORM_BLOCK_CIPHER_HPP
diff --git a/tests/unit-tests/security/transform.t.cpp b/tests/unit-tests/security/transform.t.cpp
index c60cdef..b89753a 100644
--- a/tests/unit-tests/security/transform.t.cpp
+++ b/tests/unit-tests/security/transform.t.cpp
@@ -64,6 +64,9 @@
 
   transform::HmacFilter* hmacFilter = nullptr;
   BOOST_CHECK(hmacFilter == nullptr);
+
+  transform::BlockCipher* blockCipher = nullptr;
+  BOOST_CHECK(blockCipher == nullptr);
 }
 
 BOOST_AUTO_TEST_SUITE_END() // TestTransform
diff --git a/tests/unit-tests/security/transform/block-cipher.t.cpp b/tests/unit-tests/security/transform/block-cipher.t.cpp
new file mode 100644
index 0000000..82f5d39
--- /dev/null
+++ b/tests/unit-tests/security/transform/block-cipher.t.cpp
@@ -0,0 +1,108 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2013-2016 Regents of the University of California.
+ *
+ * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
+ *
+ * ndn-cxx library is free software: you can redistribute it and/or modify it under the
+ * terms of the GNU Lesser General Public License as published by the Free Software
+ * Foundation, either version 3 of the License, or (at your option) any later version.
+ *
+ * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
+ * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
+ * PARTICULAR PURPOSE.  See the GNU Lesser General Public License for more details.
+ *
+ * You should have received copies of the GNU General Public License and GNU Lesser
+ * General Public License along with ndn-cxx, e.g., in COPYING.md file.  If not, see
+ * <http://www.gnu.org/licenses/>.
+ *
+ * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
+ */
+
+#include "security/transform/block-cipher.hpp"
+#include "security/transform/buffer-source.hpp"
+#include "security/transform/stream-sink.hpp"
+#include "encoding/buffer-stream.hpp"
+#include <iostream>
+
+#include "boost-test.hpp"
+
+namespace ndn {
+namespace security {
+namespace transform {
+namespace tests {
+
+BOOST_AUTO_TEST_SUITE(Security)
+BOOST_AUTO_TEST_SUITE(Transform)
+BOOST_AUTO_TEST_SUITE(TestBlockCipher)
+
+BOOST_AUTO_TEST_CASE(AesCbc)
+{
+  uint8_t key[] = {
+    0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
+    0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f
+  };
+
+  uint8_t plainText[] = {
+    0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
+    0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
+    0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
+    0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f
+  };
+
+  uint8_t iv[] = {
+    0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
+    0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07
+  };
+
+  /*
+   * Cipher text can be generated using:
+   *
+   * {
+   *   using namespace CryptoPP;
+   *   CBC_Mode<AES>::Encryption aes(key, sizeof(key), iv);
+   *   StringSource(plainText, sizeof(plainText), true,
+   *                new StreamTransformationFilter(aes,
+   *                                               new HexEncoder(new FileSink(std::cerr), false)));
+   * }
+   */
+  uint8_t cipherText[] = {
+    0x07, 0x4d, 0x32, 0x68, 0xc3, 0x40, 0x64, 0x43,
+    0x1e, 0x66, 0x4c, 0x25, 0x66, 0x42, 0x0f, 0x59,
+    0x0a, 0x51, 0x19, 0x07, 0x67, 0x5c, 0x0e, 0xfa,
+    0xa6, 0x8c, 0xbb, 0xaf, 0xfd, 0xea, 0x47, 0xd4,
+    0xc7, 0x2c, 0x12, 0x34, 0x79, 0xde, 0xec, 0xc8,
+    0x75, 0x33, 0x8f, 0x6b, 0xd6, 0x55, 0xf3, 0xfa
+  };
+
+  // encrypt
+  OBufferStream os;
+  bufferSource(plainText, sizeof(plainText)) >>
+    blockCipher(BlockCipherAlgorithm::AES_CBC,
+                CipherOperator::ENCRYPT,
+                key, sizeof(key), iv, sizeof(iv)) >> streamSink(os);
+
+  ConstBufferPtr buf = os.buf();
+  BOOST_CHECK_EQUAL_COLLECTIONS(cipherText, cipherText + sizeof(cipherText),
+                                buf->begin(), buf->end());
+
+  // decrypt
+  OBufferStream os2;
+  bufferSource(cipherText, sizeof(cipherText)) >>
+    blockCipher(BlockCipherAlgorithm::AES_CBC,
+                CipherOperator::DECRYPT,
+                key, sizeof(key), iv, sizeof(iv)) >> streamSink(os2);
+
+  ConstBufferPtr buf2 = os2.buf();
+  BOOST_CHECK_EQUAL_COLLECTIONS(plainText, plainText + sizeof(plainText),
+                                buf2->begin(), buf2->end());
+}
+
+BOOST_AUTO_TEST_SUITE_END() // TestBlockCipher
+BOOST_AUTO_TEST_SUITE_END() // Transform
+BOOST_AUTO_TEST_SUITE_END() // Security
+
+} // namespace tests
+} // namespace transform
+} // namespace security
+} // namespace ndn