OLD | NEW |
1 // Copyright (c) 2013 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2013 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #ifndef NET_QUIC_CRYPTO_CRYPTO_SECRET_BOXER_H_ | 5 #ifndef NET_QUIC_CRYPTO_CRYPTO_SECRET_BOXER_H_ |
6 #define NET_QUIC_CRYPTO_CRYPTO_SECRET_BOXER_H_ | 6 #define NET_QUIC_CRYPTO_CRYPTO_SECRET_BOXER_H_ |
7 | 7 |
8 #include <stddef.h> | 8 #include <stddef.h> |
9 | 9 |
10 #include <string> | 10 #include <string> |
(...skipping 12 matching lines...) Expand all Loading... |
23 // then, later, can authenticate+decrypt the resulting boxes. This object is | 23 // then, later, can authenticate+decrypt the resulting boxes. This object is |
24 // thread-safe. | 24 // thread-safe. |
25 class NET_EXPORT_PRIVATE CryptoSecretBoxer { | 25 class NET_EXPORT_PRIVATE CryptoSecretBoxer { |
26 public: | 26 public: |
27 CryptoSecretBoxer(); | 27 CryptoSecretBoxer(); |
28 ~CryptoSecretBoxer(); | 28 ~CryptoSecretBoxer(); |
29 | 29 |
30 // GetKeySize returns the number of bytes in a key. | 30 // GetKeySize returns the number of bytes in a key. |
31 static size_t GetKeySize(); | 31 static size_t GetKeySize(); |
32 | 32 |
33 // SetKeys sets a std::list of encryption keys. The first key in the std::list | 33 // used by |Box|, but all supplied keys will be tried by |Unbox|, to handle |
34 // will be used by |Box|, but all supplied keys will be tried by |Unbox|, to | 34 // key skew across the fleet. This must be called before |Box| or |Unbox|. |
35 // handle key skew across the fleet. This must be called before |Box| or | 35 // Keys must be |GetKeySize()| bytes long. |
36 // |Unbox|. Keys must be |GetKeySize()| bytes long. | |
37 void SetKeys(const std::vector<std::string>& keys); | 36 void SetKeys(const std::vector<std::string>& keys); |
38 | 37 |
39 // Box encrypts |plaintext| using a random nonce generated from |rand| and | 38 // Box encrypts |plaintext| using a random nonce generated from |rand| and |
40 // returns the resulting ciphertext. Since an authenticator and nonce are | 39 // returns the resulting ciphertext. Since an authenticator and nonce are |
41 // included, the result will be slightly larger than |plaintext|. The first | 40 // included, the result will be slightly larger than |plaintext|. The first |
42 // key in the std::vector supplied to |SetKeys| will be used. | 41 // key in the std::vector supplied to |SetKeys| will be used. |
43 std::string Box(QuicRandom* rand, base::StringPiece plaintext) const; | 42 std::string Box(QuicRandom* rand, base::StringPiece plaintext) const; |
44 | 43 |
45 // Unbox takes the result of a previous call to |Box| in |ciphertext| and | 44 // Unbox takes the result of a previous call to |Box| in |ciphertext| and |
46 // authenticates+decrypts it. If |ciphertext| cannot be decrypted with any of | 45 // authenticates+decrypts it. If |ciphertext| cannot be decrypted with any of |
47 // the supplied keys, the function returns false. Otherwise, |out_storage| is | 46 // the supplied keys, the function returns false. Otherwise, |out_storage| is |
48 // used to store the result and |out| is set to point into |out_storage| and | 47 // used to store the result and |out| is set to point into |out_storage| and |
49 // contains the original plaintext. | 48 // contains the original plaintext. |
50 bool Unbox(base::StringPiece ciphertext, | 49 bool Unbox(base::StringPiece ciphertext, |
51 std::string* out_storage, | 50 std::string* out_storage, |
52 base::StringPiece* out) const; | 51 base::StringPiece* out) const; |
53 | 52 |
54 private: | 53 private: |
55 mutable base::Lock lock_; | 54 mutable base::Lock lock_; |
56 // GUARDED_BY(lock_). | 55 // GUARDED_BY(lock_).mutable Mutex lock_; |
57 std::vector<std::string> keys_; | 56 std::vector<std::string> keys_; |
58 | 57 |
59 DISALLOW_COPY_AND_ASSIGN(CryptoSecretBoxer); | 58 DISALLOW_COPY_AND_ASSIGN(CryptoSecretBoxer); |
60 }; | 59 }; |
61 | 60 |
62 } // namespace net | 61 } // namespace net |
63 | 62 |
64 #endif // NET_QUIC_CRYPTO_CRYPTO_SECRET_BOXER_H_ | 63 #endif // NET_QUIC_CRYPTO_CRYPTO_SECRET_BOXER_H_ |
OLD | NEW |