Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 1 | /* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */ |
Davide Pesavento | 8aad372 | 2017-09-16 20:57:28 -0400 | [diff] [blame] | 2 | /* |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 3 | * Copyright (c) 2013-2022 Regents of the University of California. |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 4 | * |
| 5 | * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions). |
| 6 | * |
| 7 | * ndn-cxx library is free software: you can redistribute it and/or modify it under the |
| 8 | * terms of the GNU Lesser General Public License as published by the Free Software |
| 9 | * Foundation, either version 3 of the License, or (at your option) any later version. |
| 10 | * |
| 11 | * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY |
| 12 | * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A |
| 13 | * PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details. |
| 14 | * |
| 15 | * You should have received copies of the GNU General Public License and GNU Lesser |
| 16 | * General Public License along with ndn-cxx, e.g., in COPYING.md file. If not, see |
| 17 | * <http://www.gnu.org/licenses/>. |
| 18 | * |
| 19 | * See AUTHORS.md for complete list of ndn-cxx authors and contributors. |
| 20 | */ |
| 21 | |
Davide Pesavento | 7e78064 | 2018-11-24 15:51:34 -0500 | [diff] [blame] | 22 | #include "ndn-cxx/security/verification-helpers.hpp" |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 23 | |
Davide Pesavento | 7e78064 | 2018-11-24 15:51:34 -0500 | [diff] [blame] | 24 | #include "ndn-cxx/data.hpp" |
Davide Pesavento | 7e78064 | 2018-11-24 15:51:34 -0500 | [diff] [blame] | 25 | #include "ndn-cxx/encoding/buffer-stream.hpp" |
Alexander Afanasyev | 09236c2 | 2020-06-03 13:42:38 -0400 | [diff] [blame] | 26 | #include "ndn-cxx/interest.hpp" |
| 27 | #include "ndn-cxx/security/certificate.hpp" |
Junxiao Shi | 24c5a00 | 2018-12-12 04:47:15 +0000 | [diff] [blame] | 28 | #include "ndn-cxx/security/impl/openssl.hpp" |
Davide Pesavento | 7e78064 | 2018-11-24 15:51:34 -0500 | [diff] [blame] | 29 | #include "ndn-cxx/security/pib/key.hpp" |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 30 | #include "ndn-cxx/security/tpm/tpm.hpp" |
Davide Pesavento | 7e78064 | 2018-11-24 15:51:34 -0500 | [diff] [blame] | 31 | #include "ndn-cxx/security/transform/bool-sink.hpp" |
| 32 | #include "ndn-cxx/security/transform/buffer-source.hpp" |
| 33 | #include "ndn-cxx/security/transform/digest-filter.hpp" |
| 34 | #include "ndn-cxx/security/transform/public-key.hpp" |
| 35 | #include "ndn-cxx/security/transform/stream-sink.hpp" |
| 36 | #include "ndn-cxx/security/transform/verifier-filter.hpp" |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 37 | |
| 38 | namespace ndn { |
| 39 | namespace security { |
| 40 | |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 41 | namespace { |
| 42 | |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 43 | class ParseResult |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 44 | { |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 45 | public: |
| 46 | ParseResult() = default; |
| 47 | |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 48 | ParseResult(SignatureInfo info, InputBuffers bufs, span<const uint8_t> sig) |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 49 | : info(std::move(info)) |
| 50 | , bufs(std::move(bufs)) |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 51 | , sig(sig) |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 52 | { |
| 53 | } |
| 54 | |
| 55 | public: |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 56 | SignatureInfo info; |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 57 | InputBuffers bufs; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 58 | span<const uint8_t> sig; |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 59 | }; |
| 60 | |
| 61 | } // namespace |
| 62 | |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 63 | bool |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 64 | verifySignature(const InputBuffers& blobs, span<const uint8_t> sig, const transform::PublicKey& key) |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 65 | { |
| 66 | bool result = false; |
| 67 | try { |
| 68 | using namespace transform; |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 69 | bufferSource(blobs) >> verifierFilter(DigestAlgorithm::SHA256, key, sig) |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 70 | >> boolSink(result); |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 71 | } |
| 72 | catch (const transform::Error&) { |
| 73 | return false; |
| 74 | } |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 75 | |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 76 | return result; |
| 77 | } |
| 78 | |
| 79 | bool |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 80 | verifySignature(const InputBuffers& blobs, span<const uint8_t> sig, span<const uint8_t> key) |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 81 | { |
Davide Pesavento | 77d9e81 | 2019-06-03 22:05:54 -0400 | [diff] [blame] | 82 | transform::PublicKey pKey; |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 83 | try { |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 84 | pKey.loadPkcs8(key); |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 85 | } |
| 86 | catch (const transform::Error&) { |
| 87 | return false; |
| 88 | } |
| 89 | |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 90 | return verifySignature(blobs, sig, pKey); |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 91 | } |
| 92 | |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 93 | static ParseResult |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 94 | parse(const Data& data) |
| 95 | { |
| 96 | try { |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 97 | return ParseResult(data.getSignatureInfo(), |
| 98 | data.extractSignedRanges(), |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 99 | {data.getSignatureValue().value(), data.getSignatureValue().value_size()}); |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 100 | } |
| 101 | catch (const tlv::Error&) { |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 102 | return ParseResult(); |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 103 | } |
| 104 | } |
| 105 | |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 106 | static ParseResult |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 107 | parse(const Interest& interest) |
| 108 | { |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 109 | try { |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 110 | interest.wireEncode(); |
| 111 | |
| 112 | if (interest.getSignatureInfo() && interest.getSignatureValue().isValid()) { |
| 113 | // Verify using v0.3 Signed Interest semantics |
| 114 | Block sigValue = interest.getSignatureValue(); |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 115 | return ParseResult(*interest.getSignatureInfo(), |
| 116 | interest.extractSignedRanges(), |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 117 | {sigValue.value(), sigValue.value_size()}); |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 118 | } |
| 119 | else { |
| 120 | // Verify using older Signed Interest semantics |
| 121 | const Name& interestName = interest.getName(); |
| 122 | if (interestName.size() < signed_interest::MIN_SIZE) { |
| 123 | return ParseResult(); |
| 124 | } |
| 125 | |
| 126 | const Block& nameBlock = interestName.wireEncode(); |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 127 | SignatureInfo info(interestName[signed_interest::POS_SIG_INFO].blockFromValue()); |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 128 | Block sigValue(interestName[signed_interest::POS_SIG_VALUE].blockFromValue()); |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 129 | return ParseResult(info, |
| 130 | {{nameBlock.value(), |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 131 | nameBlock.value_size() - interestName[signed_interest::POS_SIG_VALUE].size()}}, |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 132 | {sigValue.value(), |
| 133 | sigValue.value_size()}); |
Eric Newberry | b74bbda | 2020-06-18 19:33:58 -0700 | [diff] [blame] | 134 | } |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 135 | } |
| 136 | catch (const tlv::Error&) { |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 137 | return ParseResult(); |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 138 | } |
| 139 | } |
| 140 | |
| 141 | static bool |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 142 | verifySignature(const ParseResult& params, const transform::PublicKey& key) |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 143 | { |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 144 | return !params.bufs.empty() && verifySignature(params.bufs, params.sig, key); |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 145 | } |
| 146 | |
| 147 | static bool |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 148 | verifySignature(const ParseResult& params, span<const uint8_t> key) |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 149 | { |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 150 | return !params.bufs.empty() && verifySignature(params.bufs, params.sig, key); |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 151 | } |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 152 | |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 153 | static bool |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 154 | verifySignature(const ParseResult& params, const tpm::Tpm& tpm, const Name& keyName, |
| 155 | DigestAlgorithm digestAlgorithm) |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 156 | { |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 157 | return !params.bufs.empty() && bool(tpm.verify(params.bufs, params.sig, keyName, digestAlgorithm)); |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 158 | } |
| 159 | |
| 160 | static bool |
| 161 | verifyDigest(const ParseResult& params, DigestAlgorithm algorithm) |
| 162 | { |
| 163 | if (params.bufs.empty()) { |
| 164 | return false; |
| 165 | } |
| 166 | |
| 167 | OBufferStream os; |
| 168 | try { |
| 169 | using namespace transform; |
| 170 | bufferSource(params.bufs) >> digestFilter(algorithm) >> streamSink(os); |
| 171 | } |
| 172 | catch (const transform::Error&) { |
| 173 | return false; |
| 174 | } |
| 175 | auto result = os.buf(); |
| 176 | |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 177 | if (result->size() != params.sig.size()) { |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 178 | return false; |
| 179 | } |
| 180 | |
| 181 | // constant-time buffer comparison to mitigate timing attacks |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 182 | return CRYPTO_memcmp(result->data(), params.sig.data(), params.sig.size()) == 0; |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 183 | } |
| 184 | |
| 185 | bool |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 186 | verifySignature(const Data& data, span<const uint8_t> key) |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 187 | { |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 188 | return verifySignature(parse(data), key); |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 189 | } |
| 190 | |
| 191 | bool |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 192 | verifySignature(const Interest& interest, span<const uint8_t> key) |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 193 | { |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 194 | return verifySignature(parse(interest), key); |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 195 | } |
| 196 | |
| 197 | bool |
Davide Pesavento | 77d9e81 | 2019-06-03 22:05:54 -0400 | [diff] [blame] | 198 | verifySignature(const Data& data, const transform::PublicKey& key) |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 199 | { |
| 200 | return verifySignature(parse(data), key); |
| 201 | } |
| 202 | |
| 203 | bool |
Davide Pesavento | 77d9e81 | 2019-06-03 22:05:54 -0400 | [diff] [blame] | 204 | verifySignature(const Interest& interest, const transform::PublicKey& key) |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 205 | { |
| 206 | return verifySignature(parse(interest), key); |
| 207 | } |
| 208 | |
| 209 | bool |
| 210 | verifySignature(const Data& data, const pib::Key& key) |
| 211 | { |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 212 | return verifySignature(parse(data), key.getPublicKey()); |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 213 | } |
| 214 | |
| 215 | bool |
| 216 | verifySignature(const Interest& interest, const pib::Key& key) |
| 217 | { |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 218 | return verifySignature(parse(interest), key.getPublicKey()); |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 219 | } |
| 220 | |
| 221 | bool |
Davide Pesavento | f2cae61 | 2021-03-24 18:47:05 -0400 | [diff] [blame] | 222 | verifySignature(const Data& data, const optional<Certificate>& cert) |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 223 | { |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 224 | auto parsed = parse(data); |
| 225 | if (cert) { |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 226 | return verifySignature(parsed, {cert->getContent().value(), cert->getContent().value_size()}); |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 227 | } |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 228 | else if (parsed.info.getSignatureType() == tlv::SignatureTypeValue::DigestSha256) { |
| 229 | return verifyDigest(parsed, DigestAlgorithm::SHA256); |
| 230 | } |
| 231 | // Add any other self-verifying signatures here (if any) |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 232 | else { |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 233 | return false; |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 234 | } |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 235 | } |
| 236 | |
| 237 | bool |
Davide Pesavento | f2cae61 | 2021-03-24 18:47:05 -0400 | [diff] [blame] | 238 | verifySignature(const Interest& interest, const optional<Certificate>& cert) |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 239 | { |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 240 | auto parsed = parse(interest); |
| 241 | if (cert) { |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 242 | return verifySignature(parsed, {cert->getContent().value(), cert->getContent().value_size()}); |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 243 | } |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 244 | else if (parsed.info.getSignatureType() == tlv::SignatureTypeValue::DigestSha256) { |
| 245 | return verifyDigest(parsed, DigestAlgorithm::SHA256); |
| 246 | } |
| 247 | // Add any other self-verifying signatures here (if any) |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 248 | else { |
Davide Pesavento | 809f754 | 2021-03-24 18:53:05 -0400 | [diff] [blame] | 249 | return false; |
Justin Labry | aef53b6 | 2021-03-10 06:07:27 +0000 | [diff] [blame] | 250 | } |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 251 | } |
| 252 | |
laqinfan | bc997e5 | 2019-06-25 22:11:09 -0500 | [diff] [blame] | 253 | bool |
| 254 | verifySignature(const Data& data, const tpm::Tpm& tpm, |
| 255 | const Name& keyName, DigestAlgorithm digestAlgorithm) |
| 256 | { |
| 257 | return verifySignature(parse(data), tpm, keyName, digestAlgorithm); |
| 258 | } |
| 259 | |
| 260 | bool |
| 261 | verifySignature(const Interest& interest, const tpm::Tpm& tpm, |
| 262 | const Name& keyName, DigestAlgorithm digestAlgorithm) |
| 263 | { |
| 264 | return verifySignature(parse(interest), tpm, keyName, digestAlgorithm); |
| 265 | } |
| 266 | |
Alexander Afanasyev | 574aa86 | 2017-01-10 19:53:28 -0800 | [diff] [blame] | 267 | } // namespace security |
| 268 | } // namespace ndn |