| OLD | NEW |
| 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #ifndef NET_QUIC_CRYPTO_CRYPTO_PROTOCOL_H_ | 5 #ifndef NET_QUIC_CRYPTO_CRYPTO_PROTOCOL_H_ |
| 6 #define NET_QUIC_CRYPTO_CRYPTO_PROTOCOL_H_ | 6 #define NET_QUIC_CRYPTO_CRYPTO_PROTOCOL_H_ |
| 7 | 7 |
| 8 #include <map> | 8 #include <map> |
| 9 #include <string> | 9 #include <string> |
| 10 #include <vector> | 10 #include <vector> |
| 11 | 11 |
| 12 #include "base/basictypes.h" | 12 #include "base/basictypes.h" |
| 13 #include "base/logging.h" | 13 #include "base/logging.h" |
| 14 #include "net/base/net_export.h" | 14 #include "net/base/net_export.h" |
| 15 #include "net/quic/quic_protocol.h" |
| 15 #include "net/quic/quic_time.h" | 16 #include "net/quic/quic_time.h" |
| 16 | 17 |
| 17 namespace net { | 18 namespace net { |
| 18 | 19 |
| 20 // CryptoTag is the type of a tag in the wire protocol. |
| 19 typedef uint32 CryptoTag; | 21 typedef uint32 CryptoTag; |
| 22 typedef std::string ServerConfigID; |
| 20 typedef std::map<CryptoTag, std::string> CryptoTagValueMap; | 23 typedef std::map<CryptoTag, std::string> CryptoTagValueMap; |
| 21 typedef std::vector<CryptoTag> CryptoTagVector; | 24 typedef std::vector<CryptoTag> CryptoTagVector; |
| 22 // An intermediate format of a handshake message that's convenient for a | 25 // An intermediate format of a handshake message that's convenient for a |
| 23 // CryptoFramer to serialize from or parse into. | 26 // CryptoFramer to serialize from or parse into. |
| 24 struct NET_EXPORT_PRIVATE CryptoHandshakeMessage { | 27 struct NET_EXPORT_PRIVATE CryptoHandshakeMessage { |
| 25 CryptoHandshakeMessage(); | 28 CryptoHandshakeMessage(); |
| 26 ~CryptoHandshakeMessage(); | 29 ~CryptoHandshakeMessage(); |
| 30 |
| 31 // SetValue sets an element with the given tag to the raw, memory contents of |
| 32 // |v|. |
| 33 template<class T> void SetValue(CryptoTag tag, const T& v) { |
| 34 tag_value_map[tag] = std::string(reinterpret_cast<const char*>(&v), |
| 35 sizeof(v)); |
| 36 } |
| 37 |
| 38 // SetVector sets an element with the given tag to the raw contents of an |
| 39 // array of elements in |v|. |
| 40 template<class T> void SetVector(CryptoTag tag, const std::vector<T>& v) { |
| 41 if (v.empty()) { |
| 42 tag_value_map[tag] = std::string(); |
| 43 } else { |
| 44 tag_value_map[tag] = std::string(reinterpret_cast<const char*>(&v[0]), |
| 45 v.size() * sizeof(T)); |
| 46 } |
| 47 } |
| 48 |
| 49 // SetTaglist sets an element with the given tag to contain a list of tags, |
| 50 // passed as varargs. The argument list must be terminated with a 0 element. |
| 51 void SetTaglist(CryptoTag tag, ...); |
| 52 |
| 53 // GetTaglist finds an element with the given tag containing zero or more |
| 54 // tags. If such a tag doesn't exist, it returns false. Otherwise it sets |
| 55 // |out_tags| and |out_len| to point to the array of tags and returns true. |
| 56 // The array points into the CryptoHandshakeMessage and is valid only for as |
| 57 // long as the CryptoHandshakeMessage exists and is not modified. |
| 58 QuicErrorCode GetTaglist(CryptoTag tag, const CryptoTag** out_tags, |
| 59 size_t* out_len) const; |
| 60 |
| 61 bool GetString(CryptoTag tag, std::string* out) const; |
| 62 QuicErrorCode GetUint32(CryptoTag tag, uint32* out) const; |
| 63 |
| 27 CryptoTag tag; | 64 CryptoTag tag; |
| 28 CryptoTagValueMap tag_value_map; | 65 CryptoTagValueMap tag_value_map; |
| 29 }; | 66 }; |
| 30 | 67 |
| 31 // Crypto tags are written to the wire with a big-endian | 68 // Crypto tags are written to the wire with a big-endian |
| 32 // representation of the name of the tag. For example | 69 // representation of the name of the tag. For example |
| 33 // the client hello tag (CHLO) will be written as the | 70 // the client hello tag (CHLO) will be written as the |
| 34 // following 4 bytes: 'C' 'H' 'L' 'O'. Since it is | 71 // following 4 bytes: 'C' 'H' 'L' 'O'. Since it is |
| 35 // stored in memory as a little endian uint32, we need | 72 // stored in memory as a little endian uint32, we need |
| 36 // to reverse the order of the bytes. | 73 // to reverse the order of the bytes. |
| 37 #define MAKE_TAG(a, b, c, d) (d << 24) + (c << 16) + (b << 8) + a | 74 #define MAKE_TAG(a, b, c, d) (d << 24) + (c << 16) + (b << 8) + a |
| 38 | 75 |
| 39 const CryptoTag kCHLO = MAKE_TAG('C', 'H', 'L', 'O'); // Client hello | 76 const CryptoTag kCHLO = MAKE_TAG('C', 'H', 'L', 'O'); // Client hello |
| 40 const CryptoTag kSHLO = MAKE_TAG('S', 'H', 'L', 'O'); // Server hello | 77 const CryptoTag kSHLO = MAKE_TAG('S', 'H', 'L', 'O'); // Server hello |
| 78 const CryptoTag kSCFG = MAKE_TAG('S', 'H', 'L', 'O'); // Server config |
| 41 | 79 |
| 42 // Key exchange methods | 80 // Key exchange methods |
| 43 const CryptoTag kP256 = MAKE_TAG('P', '2', '5', '6'); // ECDH, Curve P-256 | 81 const CryptoTag kP256 = MAKE_TAG('P', '2', '5', '6'); // ECDH, Curve P-256 |
| 44 const CryptoTag kC255 = MAKE_TAG('C', '2', '5', '5'); // ECDH, Curve25519 | 82 const CryptoTag kC255 = MAKE_TAG('C', '2', '5', '5'); // ECDH, Curve25519 |
| 45 | 83 |
| 46 // AEAD algorithms | 84 // AEAD algorithms |
| 47 const CryptoTag kNULL = MAKE_TAG('N', 'U', 'L', 'L'); // null algorithm | 85 const CryptoTag kNULL = MAKE_TAG('N', 'U', 'L', 'L'); // null algorithm |
| 48 const CryptoTag kAESH = MAKE_TAG('A', 'E', 'S', 'H'); // AES128 + SHA256 | 86 const CryptoTag kAESH = MAKE_TAG('A', 'E', 'S', 'H'); // AES128 + SHA256 |
| 49 const CryptoTag kAESG = MAKE_TAG('A', 'E', 'S', 'G'); // AES128 + GCM | 87 const CryptoTag kAESG = MAKE_TAG('A', 'E', 'S', 'G'); // AES128 + GCM |
| 50 | 88 |
| 51 // Congestion control feedback types | 89 // Congestion control feedback types |
| 52 const CryptoTag kQBIC = MAKE_TAG('Q', 'B', 'I', 'C'); // TCP cubic | 90 const CryptoTag kQBIC = MAKE_TAG('Q', 'B', 'I', 'C'); // TCP cubic |
| 53 const CryptoTag kINAR = MAKE_TAG('I', 'N', 'A', 'R'); // Inter arrival | 91 const CryptoTag kINAR = MAKE_TAG('I', 'N', 'A', 'R'); // Inter arrival |
| 54 | 92 |
| 55 // Client hello tags | 93 // Client hello tags |
| 56 const CryptoTag kVERS = MAKE_TAG('V', 'E', 'R', 'S'); // Version | 94 const CryptoTag kVERS = MAKE_TAG('V', 'E', 'R', 'S'); // Version |
| 57 const CryptoTag kNONC = MAKE_TAG('N', 'O', 'N', 'C'); // The connection nonce | 95 const CryptoTag kNONC = MAKE_TAG('N', 'O', 'N', 'C'); // The connection nonce |
| 58 const CryptoTag kSSID = MAKE_TAG('S', 'S', 'I', 'D'); // Session ID | 96 const CryptoTag kSSID = MAKE_TAG('S', 'S', 'I', 'D'); // Session ID |
| 59 const CryptoTag kKEXS = MAKE_TAG('K', 'E', 'X', 'S'); // Key exchange methods | 97 const CryptoTag kKEXS = MAKE_TAG('K', 'E', 'X', 'S'); // Key exchange methods |
| 60 const CryptoTag kAEAD = MAKE_TAG('A', 'E', 'A', 'D'); // Authenticated | 98 const CryptoTag kAEAD = MAKE_TAG('A', 'E', 'A', 'D'); // Authenticated |
| 61 // encryption algorithms | 99 // encryption algorithms |
| 62 const CryptoTag kCGST = MAKE_TAG('C', 'G', 'S', 'T'); // Congestion control | 100 const CryptoTag kCGST = MAKE_TAG('C', 'G', 'S', 'T'); // Congestion control |
| 63 // feedback types | 101 // feedback types |
| 64 const CryptoTag kICSL = MAKE_TAG('I', 'C', 'S', 'L'); // Idle connection state | 102 const CryptoTag kICSL = MAKE_TAG('I', 'C', 'S', 'L'); // Idle connection state |
| 65 // lifetime | 103 // lifetime |
| 66 const CryptoTag kKATO = MAKE_TAG('K', 'A', 'T', 'O'); // Keepalive timeout | 104 const CryptoTag kKATO = MAKE_TAG('K', 'A', 'T', 'O'); // Keepalive timeout |
| 67 const CryptoTag kSNI = MAKE_TAG('S', 'N', 'I', '\0'); // Server name | 105 const CryptoTag kSNI = MAKE_TAG('S', 'N', 'I', '\0'); // Server name |
| 68 // indication | 106 // indication |
| 69 const CryptoTag kPUBS = MAKE_TAG('P', 'U', 'B', 'S'); // Public key values | 107 const CryptoTag kPUBS = MAKE_TAG('P', 'U', 'B', 'S'); // Public key values |
| 108 const CryptoTag kSCID = MAKE_TAG('S', 'C', 'I', 'D'); // Server config id |
| 70 | 109 |
| 71 const size_t kMaxEntries = 16; // Max number of entries in a message. | 110 const size_t kMaxEntries = 16; // Max number of entries in a message. |
| 72 | 111 |
| 73 const size_t kNonceSize = 32; // Size in bytes of the connection nonce. | 112 const size_t kNonceSize = 32; // Size in bytes of the connection nonce. |
| 74 | 113 |
| 75 // Crypto configuration settings. | |
| 76 struct NET_EXPORT_PRIVATE QuicCryptoConfig { | |
| 77 // Initializes the members to 0 or empty values. | |
| 78 QuicCryptoConfig(); | |
| 79 ~QuicCryptoConfig(); | |
| 80 | |
| 81 // Sets the members to client-side or server-side default values. | |
| 82 void SetClientDefaults(); | |
| 83 void SetServerDefaults(); | |
| 84 | |
| 85 // Protocol version | |
| 86 uint16 version; | |
| 87 // Key exchange methods | |
| 88 CryptoTagVector key_exchange; | |
| 89 // Authenticated encryption with associated data (AEAD) algorithms | |
| 90 CryptoTagVector aead; | |
| 91 // Congestion control feedback types | |
| 92 CryptoTagVector congestion_control; | |
| 93 // Idle connection state lifetime | |
| 94 QuicTime::Delta idle_connection_state_lifetime; | |
| 95 // Keepalive timeout, or 0 to turn off keepalive probes | |
| 96 QuicTime::Delta keepalive_timeout; | |
| 97 }; | |
| 98 | |
| 99 // Parameters negotiated by the crypto handshake. | |
| 100 struct NET_EXPORT_PRIVATE QuicCryptoNegotiatedParams { | |
| 101 // Initializes the members to 0 or empty values. | |
| 102 QuicCryptoNegotiatedParams(); | |
| 103 ~QuicCryptoNegotiatedParams(); | |
| 104 | |
| 105 // Sets the members to the values that would be negotiated from the default | |
| 106 // client-side and server-side configuration settings. | |
| 107 void SetDefaults(); | |
| 108 | |
| 109 uint16 version; | |
| 110 CryptoTag key_exchange; | |
| 111 CryptoTag aead; | |
| 112 CryptoTag congestion_control; | |
| 113 QuicTime::Delta idle_connection_state_lifetime; | |
| 114 }; | |
| 115 | |
| 116 } // namespace net | 114 } // namespace net |
| 117 | 115 |
| 118 #endif // NET_QUIC_CRYPTO_CRYPTO_PROTOCOL_H_ | 116 #endif // NET_QUIC_CRYPTO_CRYPTO_PROTOCOL_H_ |
| OLD | NEW |