From 01f9c622a02ca34afbdab51c23e0cb2bbfd2bb45 Mon Sep 17 00:00:00 2001 From: Nicolas Stalder Date: Sat, 6 Mar 2021 14:23:36 +0100 Subject: [PATCH] Use postcard instead of cbor in ChachaPoly key wrap/unwrap --- Cargo.toml | 3 ++- src/lib.rs | 12 ++++++------ src/mechanisms.rs | 5 +++++ src/mechanisms/chacha8poly1305.rs | 4 ++-- src/mechanisms/hmacsha1.rs | 18 ++---------------- 5 files changed, 17 insertions(+), 25 deletions(-) diff --git a/Cargo.toml b/Cargo.toml index 1814f0591ab..7347b931554 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -15,7 +15,8 @@ embedded-hal = { version = "0.2.3", features = ["unproven"] } generic-array = "0.14.4" heapless = { version = "0.6", features = ["serde"] } nb = "1" -postcard = "0.5.2" +# postcard = "0.5.2" +postcard = { git = "https://github.com/nickray/postcard", branch = "bump-heapless" } rand_core = "0.5" serde = { version = "1.0", default-features = false } zeroize = { version = "1.2", default-features = false, features = ["zeroize_derive"] } diff --git a/src/lib.rs b/src/lib.rs index df35a0bdf65..dc89ea1e270 100644 --- a/src/lib.rs +++ b/src/lib.rs @@ -41,12 +41,12 @@ pub use cbor_smol::{cbor_serialize, cbor_serialize_bytes, cbor_deserialize}; pub use heapless_bytes::{ArrayLength, Bytes, consts}; pub use postcard::{from_bytes as postcard_deserialize, to_slice as postcard_serialize}; -// pub fn postcard_serialize_bytes<'a, 'b, N: ArrayLength, T: serde::Serialize>( -// object: &'a T, -// ) -> postcard::Result> { -// let vec = postcard::to_vec::(object)?; -// Ok(Bytes::::try_from_slice(&vec[..]).unwrap()) -// } +pub fn postcard_serialize_bytes<'a, 'b, N: ArrayLength, T: serde::Serialize>( + object: &'a T, +) -> postcard::Result> { + let vec = postcard::to_vec(object)?; + Ok(Bytes::from(vec)) +} #[cfg(test)] mod tests; diff --git a/src/mechanisms.rs b/src/mechanisms.rs index b2e35d8e3b1..4d94b2eb696 100644 --- a/src/mechanisms.rs +++ b/src/mechanisms.rs @@ -18,7 +18,12 @@ pub struct HmacSha256 {} mod hmacsha256; pub struct HmacSha512 {} +#[cfg(feature = "hmac-sha512")] mod hmacsha512; +#[cfg(not(feature = "hmac-sha512"))] +impl crate::service::GenerateKey for HmacSha512 {} +#[cfg(not(feature = "hmac-sha512"))] +impl crate::service::Sign for HmacSha512 {} pub struct P256 {} pub struct P256Prehashed {} diff --git a/src/mechanisms/chacha8poly1305.rs b/src/mechanisms/chacha8poly1305.rs index 01e2201b65b..9b1858aa9a3 100644 --- a/src/mechanisms/chacha8poly1305.rs +++ b/src/mechanisms/chacha8poly1305.rs @@ -181,7 +181,7 @@ impl WrapKey for super::Chacha8Poly1305 }; let encryption_reply = ::encrypt(keystore, encryption_request)?; - let wrapped_key = crate::cbor_serialize_bytes(&encryption_reply).map_err(|_| Error::CborError)?; + let wrapped_key = crate::postcard_serialize_bytes(&encryption_reply).map_err(|_| Error::CborError)?; Ok(reply::WrapKey { wrapped_key }) } @@ -193,7 +193,7 @@ impl UnwrapKey for super::Chacha8Poly1305 fn unwrap_key(keystore: &mut impl Keystore, request: request::UnwrapKey) -> Result { - let reply::Encrypt { ciphertext, nonce, tag } = crate::cbor_deserialize( + let reply::Encrypt { ciphertext, nonce, tag } = crate::postcard_deserialize( &request.wrapped_key).map_err(|_| Error::CborError)?; let decryption_request = request::Decrypt { diff --git a/src/mechanisms/hmacsha1.rs b/src/mechanisms/hmacsha1.rs index f3ce14d0d27..70b235e9b02 100644 --- a/src/mechanisms/hmacsha1.rs +++ b/src/mechanisms/hmacsha1.rs @@ -1,5 +1,3 @@ -use core::convert::TryInto; - use crate::api::*; // use crate::config::*; use crate::error::Error; @@ -19,18 +17,6 @@ impl Sign for super::HmacSha1 let key_id = request.key.object_id; let shared_secret = keystore.load_key(key::Secrecy::Secret, None, &key_id)?.material; - // let path = keystore.prepare_path_for_key(key::Secrecy::Secret, &key_id)?; - // let (serialized_key, _) = keystore.load_key_unchecked(&path)?; - // let shared_secret = &serialized_key.material; - let l = shared_secret.as_ref().len(); - if (l & 0xf) != 0 { - info_now!("wrong key length, expected multiple of 16, got {}", l); - return Err(Error::WrongKeyKind); - } - // keystore.load_key(&path, key::Kind::SharedSecret32, &mut shared_secret)?; - // keystore.load_key(&path, key::Kind::SymmetricKey16, &mut shared_secret)?; - - // let mut mac = HmacSha1::new_varkey(&shared_secret) let mut mac = HmacSha1::new_varkey(&shared_secret.as_ref()) .expect("HMAC can take key of any size"); @@ -39,8 +25,8 @@ impl Sign for super::HmacSha1 // To get underlying array use `code` method, but be carefull, since // incorrect use of the code material may permit timing attacks which defeat // the security provided by the `MacResult` - let code_bytes: [u8; 32] = result.into_bytes().as_slice().try_into().unwrap(); - let signature = Signature::try_from_slice(&code_bytes).unwrap(); + // let code_bytes: [u8; 32] = result.into_bytes().as_slice().try_into().unwrap(); + let signature = Signature::try_from_slice(&result.into_bytes()).unwrap(); // return signature Ok(reply::Sign { signature })