2016-09-21 18:37:04 +00:00
|
|
|
/*
|
|
|
|
* Copyright (c) Pavol Rusnak, SatoshiLabs
|
|
|
|
*
|
|
|
|
* Licensed under TREZOR License
|
|
|
|
* see LICENSE file for details
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include "py/objstr.h"
|
|
|
|
|
2017-12-12 19:31:03 +00:00
|
|
|
#include "aes/aes.h"
|
2018-01-18 14:26:22 +00:00
|
|
|
#include "memzero.h"
|
2016-09-21 18:37:04 +00:00
|
|
|
|
2017-06-14 15:40:50 +00:00
|
|
|
/// class AES:
|
|
|
|
/// '''
|
|
|
|
/// AES context.
|
|
|
|
/// '''
|
2016-09-21 18:37:04 +00:00
|
|
|
typedef struct _mp_obj_AES_t {
|
|
|
|
mp_obj_base_t base;
|
|
|
|
union {
|
|
|
|
aes_encrypt_ctx encrypt_ctx;
|
|
|
|
aes_decrypt_ctx decrypt_ctx;
|
|
|
|
} ctx;
|
|
|
|
mp_int_t mode;
|
|
|
|
uint8_t iv[AES_BLOCK_SIZE];
|
|
|
|
uint8_t ctr[AES_BLOCK_SIZE];
|
|
|
|
} mp_obj_AES_t;
|
|
|
|
|
2016-09-24 11:11:06 +00:00
|
|
|
enum {
|
|
|
|
ECB = 0x00,
|
|
|
|
CBC = 0x01,
|
|
|
|
CFB = 0x02,
|
|
|
|
OFB = 0x03,
|
|
|
|
CTR = 0x04,
|
|
|
|
Encrypt = 0x40,
|
|
|
|
Decrypt = 0x80,
|
|
|
|
};
|
|
|
|
|
|
|
|
#define AESModeMask 0x3F
|
|
|
|
#define AESDirMask 0xC0
|
|
|
|
|
2017-06-14 17:27:13 +00:00
|
|
|
/// def __init__(self, mode: int, key: bytes, iv: bytes = None) -> None:
|
2017-06-14 15:40:50 +00:00
|
|
|
/// '''
|
|
|
|
/// Initialize AES context.
|
|
|
|
/// '''
|
2017-06-14 16:47:38 +00:00
|
|
|
STATIC mp_obj_t mod_trezorcrypto_AES_make_new(const mp_obj_type_t *type, size_t n_args, size_t n_kw, const mp_obj_t *args) {
|
2016-09-21 18:37:04 +00:00
|
|
|
mp_arg_check_num(n_args, n_kw, 2, 3, false);
|
|
|
|
mp_obj_AES_t *o = m_new_obj(mp_obj_AES_t);
|
|
|
|
o->base.type = type;
|
|
|
|
o->mode = mp_obj_get_int(args[0]);
|
2016-09-24 11:11:06 +00:00
|
|
|
if ((o->mode & AESModeMask) > 0x04) {
|
2016-10-07 10:09:05 +00:00
|
|
|
mp_raise_ValueError("Invalid AES mode");
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
|
|
|
mp_buffer_info_t key;
|
|
|
|
mp_get_buffer_raise(args[1], &key, MP_BUFFER_READ);
|
|
|
|
if (key.len != 16 && key.len != 24 && key.len != 32) {
|
2016-10-07 10:09:05 +00:00
|
|
|
mp_raise_ValueError("Invalid length of key (has to be 128, 192 or 256 bits)");
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
|
|
|
if (n_args > 2) {
|
|
|
|
mp_buffer_info_t iv;
|
|
|
|
mp_get_buffer_raise(args[2], &iv, MP_BUFFER_READ);
|
|
|
|
if (iv.len != AES_BLOCK_SIZE) {
|
2016-10-07 10:09:05 +00:00
|
|
|
mp_raise_ValueError("Invalid length of initialization vector (has to be 128 bits)");
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
|
|
|
memcpy(o->iv, iv.buf, AES_BLOCK_SIZE);
|
|
|
|
} else {
|
|
|
|
memset(o->iv, 0, AES_BLOCK_SIZE);
|
|
|
|
}
|
|
|
|
memset(o->ctr, 0, AES_BLOCK_SIZE);
|
|
|
|
switch (key.len) {
|
|
|
|
case 16:
|
2016-09-24 11:11:06 +00:00
|
|
|
if (o->mode == (ECB | Decrypt) || o->mode == (CBC | Decrypt)) {
|
2016-09-21 18:37:04 +00:00
|
|
|
aes_decrypt_key128(key.buf, &(o->ctx.decrypt_ctx));
|
2016-09-22 10:57:51 +00:00
|
|
|
} else {
|
|
|
|
aes_encrypt_key128(key.buf, &(o->ctx.encrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 24:
|
2016-09-24 11:11:06 +00:00
|
|
|
if (o->mode == (ECB | Decrypt) || o->mode == (CBC | Decrypt)) {
|
2016-09-21 18:37:04 +00:00
|
|
|
aes_decrypt_key192(key.buf, &(o->ctx.decrypt_ctx));
|
2016-09-22 10:57:51 +00:00
|
|
|
} else {
|
|
|
|
aes_encrypt_key192(key.buf, &(o->ctx.encrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 32:
|
2016-09-24 11:11:06 +00:00
|
|
|
if (o->mode == (ECB | Decrypt) || o->mode == (CBC |Decrypt)) {
|
2016-09-21 18:37:04 +00:00
|
|
|
aes_decrypt_key256(key.buf, &(o->ctx.decrypt_ctx));
|
2016-09-22 10:57:51 +00:00
|
|
|
} else {
|
|
|
|
aes_encrypt_key256(key.buf, &(o->ctx.encrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
return MP_OBJ_FROM_PTR(o);
|
|
|
|
}
|
|
|
|
|
2017-06-14 15:40:50 +00:00
|
|
|
/// def update(self, data: bytes) -> bytes:
|
2016-09-23 15:25:34 +00:00
|
|
|
/// '''
|
2017-06-14 15:40:50 +00:00
|
|
|
/// Update AES context with data.
|
2016-09-23 15:25:34 +00:00
|
|
|
/// '''
|
2017-06-14 16:47:38 +00:00
|
|
|
STATIC mp_obj_t mod_trezorcrypto_AES_update(mp_obj_t self, mp_obj_t data) {
|
2016-09-21 18:37:04 +00:00
|
|
|
mp_buffer_info_t buf;
|
|
|
|
mp_get_buffer_raise(data, &buf, MP_BUFFER_READ);
|
2016-10-04 16:53:32 +00:00
|
|
|
if (buf.len == 0) {
|
2018-01-03 20:53:58 +00:00
|
|
|
return mp_const_empty_bytes;
|
2016-10-04 16:53:32 +00:00
|
|
|
}
|
2018-01-05 12:13:20 +00:00
|
|
|
vstr_t vstr;
|
|
|
|
vstr_init_len(&vstr, buf.len);
|
2016-10-04 16:53:32 +00:00
|
|
|
mp_obj_AES_t *o = MP_OBJ_TO_PTR(self);
|
2016-09-24 11:11:06 +00:00
|
|
|
switch (o->mode & AESModeMask) {
|
|
|
|
case ECB:
|
2016-09-21 18:37:04 +00:00
|
|
|
if (buf.len & (AES_BLOCK_SIZE - 1)) {
|
2016-10-07 10:09:05 +00:00
|
|
|
mp_raise_ValueError("Invalid data length");
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
2016-09-24 11:11:06 +00:00
|
|
|
if ((o->mode & AESDirMask) == Encrypt) {
|
2018-01-05 12:13:20 +00:00
|
|
|
aes_ecb_encrypt(buf.buf, (uint8_t *)vstr.buf, buf.len, &(o->ctx.encrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
} else {
|
2018-01-05 12:13:20 +00:00
|
|
|
aes_ecb_decrypt(buf.buf, (uint8_t *)vstr.buf, buf.len, &(o->ctx.decrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
|
|
|
break;
|
2016-09-24 11:11:06 +00:00
|
|
|
case CBC:
|
2016-09-21 18:37:04 +00:00
|
|
|
if (buf.len & (AES_BLOCK_SIZE - 1)) {
|
2016-10-07 10:09:05 +00:00
|
|
|
mp_raise_ValueError("Invalid data length");
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
2016-09-24 11:11:06 +00:00
|
|
|
if ((o->mode & AESDirMask) == Encrypt) {
|
2018-01-05 12:13:20 +00:00
|
|
|
aes_cbc_encrypt(buf.buf, (uint8_t *)vstr.buf, buf.len, o->iv, &(o->ctx.encrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
} else {
|
2018-01-05 12:13:20 +00:00
|
|
|
aes_cbc_decrypt(buf.buf, (uint8_t *)vstr.buf, buf.len, o->iv, &(o->ctx.decrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
|
|
|
break;
|
2016-09-24 11:11:06 +00:00
|
|
|
case CFB:
|
|
|
|
if ((o->mode & AESDirMask) == Encrypt) {
|
2018-01-05 12:13:20 +00:00
|
|
|
aes_cfb_encrypt(buf.buf, (uint8_t *)vstr.buf, buf.len, o->iv, &(o->ctx.encrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
} else {
|
2018-01-05 12:13:20 +00:00
|
|
|
aes_cfb_decrypt(buf.buf, (uint8_t *)vstr.buf, buf.len, o->iv, &(o->ctx.encrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
|
|
|
break;
|
2016-09-24 11:11:06 +00:00
|
|
|
case OFB: // (encrypt == decrypt)
|
2018-01-05 12:13:20 +00:00
|
|
|
aes_ofb_crypt(buf.buf, (uint8_t *)vstr.buf, buf.len, o->iv, &(o->ctx.encrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
break;
|
2016-09-24 11:11:06 +00:00
|
|
|
case CTR: // (encrypt == decrypt)
|
2018-01-05 12:13:20 +00:00
|
|
|
aes_ctr_crypt(buf.buf, (uint8_t *)vstr.buf, buf.len, o->ctr, aes_ctr_cbuf_inc, &(o->ctx.encrypt_ctx));
|
2016-09-21 18:37:04 +00:00
|
|
|
break;
|
|
|
|
}
|
2018-01-07 12:56:18 +00:00
|
|
|
return mp_obj_new_str_from_vstr(&mp_type_bytes, &vstr);
|
2016-09-21 18:37:04 +00:00
|
|
|
}
|
2017-06-14 16:47:38 +00:00
|
|
|
STATIC MP_DEFINE_CONST_FUN_OBJ_2(mod_trezorcrypto_AES_update_obj, mod_trezorcrypto_AES_update);
|
2016-09-21 18:37:04 +00:00
|
|
|
|
2017-06-14 16:47:38 +00:00
|
|
|
STATIC mp_obj_t mod_trezorcrypto_AES___del__(mp_obj_t self) {
|
2016-09-21 18:37:04 +00:00
|
|
|
mp_obj_AES_t *o = MP_OBJ_TO_PTR(self);
|
2018-01-18 14:26:22 +00:00
|
|
|
memzero(&(o->ctx), sizeof(aes_encrypt_ctx));
|
|
|
|
memzero(o->iv, AES_BLOCK_SIZE);
|
2016-09-21 18:37:04 +00:00
|
|
|
return mp_const_none;
|
|
|
|
}
|
2017-06-14 16:47:38 +00:00
|
|
|
STATIC MP_DEFINE_CONST_FUN_OBJ_1(mod_trezorcrypto_AES___del___obj, mod_trezorcrypto_AES___del__);
|
2016-09-21 18:37:04 +00:00
|
|
|
|
2017-06-14 16:47:38 +00:00
|
|
|
STATIC const mp_rom_map_elem_t mod_trezorcrypto_AES_locals_dict_table[] = {
|
|
|
|
{ MP_ROM_QSTR(MP_QSTR_update), MP_ROM_PTR(&mod_trezorcrypto_AES_update_obj) },
|
|
|
|
{ MP_ROM_QSTR(MP_QSTR___del__), MP_ROM_PTR(&mod_trezorcrypto_AES___del___obj) },
|
2016-09-24 11:11:06 +00:00
|
|
|
{ MP_ROM_QSTR(MP_QSTR_ECB), MP_OBJ_NEW_SMALL_INT(ECB) },
|
|
|
|
{ MP_ROM_QSTR(MP_QSTR_CBC), MP_OBJ_NEW_SMALL_INT(CBC) },
|
|
|
|
{ MP_ROM_QSTR(MP_QSTR_CFB), MP_OBJ_NEW_SMALL_INT(CFB) },
|
|
|
|
{ MP_ROM_QSTR(MP_QSTR_OFB), MP_OBJ_NEW_SMALL_INT(OFB) },
|
|
|
|
{ MP_ROM_QSTR(MP_QSTR_CTR), MP_OBJ_NEW_SMALL_INT(CTR) },
|
|
|
|
{ MP_ROM_QSTR(MP_QSTR_Encrypt), MP_OBJ_NEW_SMALL_INT(Encrypt) },
|
|
|
|
{ MP_ROM_QSTR(MP_QSTR_Decrypt), MP_OBJ_NEW_SMALL_INT(Decrypt) },
|
2016-09-21 18:37:04 +00:00
|
|
|
};
|
2017-06-14 16:47:38 +00:00
|
|
|
STATIC MP_DEFINE_CONST_DICT(mod_trezorcrypto_AES_locals_dict, mod_trezorcrypto_AES_locals_dict_table);
|
2016-09-21 18:37:04 +00:00
|
|
|
|
2017-06-14 16:47:38 +00:00
|
|
|
STATIC const mp_obj_type_t mod_trezorcrypto_AES_type = {
|
2016-09-21 18:37:04 +00:00
|
|
|
{ &mp_type_type },
|
|
|
|
.name = MP_QSTR_AES,
|
2017-06-14 16:47:38 +00:00
|
|
|
.make_new = mod_trezorcrypto_AES_make_new,
|
|
|
|
.locals_dict = (void*)&mod_trezorcrypto_AES_locals_dict,
|
2016-09-21 18:37:04 +00:00
|
|
|
};
|