canmove, Confirmed users
725
edits
(→Deriving encryption and HMAC keys from the Sync Key: added missing value for HMAC_INPUT) |
|||
| Line 42: | Line 42: | ||
First we base32-decode the syncKey from 26 characters to 16 bytes (128 bits). The base32 alphabet is the one specified in [http://tools.ietf.org/html/rfc4648 RFC 4648] except with '''l''' replaced by '''8''' and '''o''' replaced by '''9''': | First we base32-decode the syncKey from 26 characters to 16 bytes (128 bits). The base32 alphabet is the one specified in [http://tools.ietf.org/html/rfc4648 RFC 4648] except with '''l''' replaced by '''8''' and '''o''' replaced by '''9''': | ||
prk = decodeKeyBase32(syncKey) | |||
The resulting key is then expanded to an encryption and HMAC key using the algorithm described in [http://tools.ietf.org/html/rfc5869 RFC 5869] | The resulting key is then expanded to an encryption key T(1) and HMAC key T(2) using the algorithm described in [http://tools.ietf.org/html/rfc5869 RFC 5869] | ||
info = "Sync-AES_256_CBC-HMAC256" + username | |||
T(1) = HMAC-SHA256(prk, "" + info + 0x01) | |||
T(2) = HMAC-SHA256(prk, T(1) + info + 0x02) | |||
==== Upgrading existing Sync Keys to the new AES key ==== | ==== Upgrading existing Sync Keys to the new AES key ==== | ||