Use postcard instead of cbor in ChachaPoly key wrap/unwrap

This commit is contained in:
Nicolas Stalder
2021-03-12 15:42:22 +01:00
committed by Nicolas Stalder
parent 7ae9ffb56a
commit 01f9c622a0
5 changed files with 17 additions and 25 deletions
+2 -1
View File
@@ -15,7 +15,8 @@ embedded-hal = { version = "0.2.3", features = ["unproven"] }
generic-array = "0.14.4"
heapless = { version = "0.6", features = ["serde"] }
nb = "1"
postcard = "0.5.2"
# postcard = "0.5.2"
postcard = { git = "https://github.com/nickray/postcard", branch = "bump-heapless" }
rand_core = "0.5"
serde = { version = "1.0", default-features = false }
zeroize = { version = "1.2", default-features = false, features = ["zeroize_derive"] }
+6 -6
View File
@@ -41,12 +41,12 @@ pub use cbor_smol::{cbor_serialize, cbor_serialize_bytes, cbor_deserialize};
pub use heapless_bytes::{ArrayLength, Bytes, consts};
pub use postcard::{from_bytes as postcard_deserialize, to_slice as postcard_serialize};
// pub fn postcard_serialize_bytes<'a, 'b, N: ArrayLength<u8>, T: serde::Serialize>(
// object: &'a T,
// ) -> postcard::Result<Bytes<N>> {
// let vec = postcard::to_vec::<N>(object)?;
// Ok(Bytes::<N>::try_from_slice(&vec[..]).unwrap())
// }
pub fn postcard_serialize_bytes<'a, 'b, N: ArrayLength<u8>, T: serde::Serialize>(
object: &'a T,
) -> postcard::Result<Bytes<N>> {
let vec = postcard::to_vec(object)?;
Ok(Bytes::from(vec))
}
#[cfg(test)]
mod tests;
+5
View File
@@ -18,7 +18,12 @@ pub struct HmacSha256 {}
mod hmacsha256;
pub struct HmacSha512 {}
#[cfg(feature = "hmac-sha512")]
mod hmacsha512;
#[cfg(not(feature = "hmac-sha512"))]
impl crate::service::GenerateKey for HmacSha512 {}
#[cfg(not(feature = "hmac-sha512"))]
impl crate::service::Sign for HmacSha512 {}
pub struct P256 {}
pub struct P256Prehashed {}
+2 -2
View File
@@ -181,7 +181,7 @@ impl WrapKey for super::Chacha8Poly1305
};
let encryption_reply = <super::Chacha8Poly1305>::encrypt(keystore, encryption_request)?;
let wrapped_key = crate::cbor_serialize_bytes(&encryption_reply).map_err(|_| Error::CborError)?;
let wrapped_key = crate::postcard_serialize_bytes(&encryption_reply).map_err(|_| Error::CborError)?;
Ok(reply::WrapKey { wrapped_key })
}
@@ -193,7 +193,7 @@ impl UnwrapKey for super::Chacha8Poly1305
fn unwrap_key(keystore: &mut impl Keystore, request: request::UnwrapKey)
-> Result<reply::UnwrapKey, Error>
{
let reply::Encrypt { ciphertext, nonce, tag } = crate::cbor_deserialize(
let reply::Encrypt { ciphertext, nonce, tag } = crate::postcard_deserialize(
&request.wrapped_key).map_err(|_| Error::CborError)?;
let decryption_request = request::Decrypt {
+2 -16
View File
@@ -1,5 +1,3 @@
use core::convert::TryInto;
use crate::api::*;
// use crate::config::*;
use crate::error::Error;
@@ -19,18 +17,6 @@ impl Sign for super::HmacSha1
let key_id = request.key.object_id;
let shared_secret = keystore.load_key(key::Secrecy::Secret, None, &key_id)?.material;
// let path = keystore.prepare_path_for_key(key::Secrecy::Secret, &key_id)?;
// let (serialized_key, _) = keystore.load_key_unchecked(&path)?;
// let shared_secret = &serialized_key.material;
let l = shared_secret.as_ref().len();
if (l & 0xf) != 0 {
info_now!("wrong key length, expected multiple of 16, got {}", l);
return Err(Error::WrongKeyKind);
}
// keystore.load_key(&path, key::Kind::SharedSecret32, &mut shared_secret)?;
// keystore.load_key(&path, key::Kind::SymmetricKey16, &mut shared_secret)?;
// let mut mac = HmacSha1::new_varkey(&shared_secret)
let mut mac = HmacSha1::new_varkey(&shared_secret.as_ref())
.expect("HMAC can take key of any size");
@@ -39,8 +25,8 @@ impl Sign for super::HmacSha1
// To get underlying array use `code` method, but be carefull, since
// incorrect use of the code material may permit timing attacks which defeat
// the security provided by the `MacResult`
let code_bytes: [u8; 32] = result.into_bytes().as_slice().try_into().unwrap();
let signature = Signature::try_from_slice(&code_bytes).unwrap();
// let code_bytes: [u8; 32] = result.into_bytes().as_slice().try_into().unwrap();
let signature = Signature::try_from_slice(&result.into_bytes()).unwrap();
// return signature
Ok(reply::Sign { signature })