Services/Sync/SimplifiedCrypto: Difference between revisions

(→‎Deriving encryption and HMAC keys from the Sync Key: added missing value for HMAC_INPUT)
Line 42: Line 42:
First we base32-decode the syncKey from 26 characters to 16 bytes (128 bits). The base32 alphabet is the one specified in [http://tools.ietf.org/html/rfc4648 RFC 4648] except with '''l''' replaced by '''8''' and '''o''' replaced by '''9''':
First we base32-decode the syncKey from 26 characters to 16 bytes (128 bits). The base32 alphabet is the one specified in [http://tools.ietf.org/html/rfc4648 RFC 4648] except with '''l''' replaced by '''8''' and '''o''' replaced by '''9''':


       let m = Utils.decodeKeyBase32(syncKey);
       prk = decodeKeyBase32(syncKey)


The resulting key is then expanded to an encryption and HMAC key using the algorithm described in [http://tools.ietf.org/html/rfc5869 RFC 5869]
The resulting key is then expanded to an encryption key T(1) and HMAC key T(2) using the algorithm described in [http://tools.ietf.org/html/rfc5869 RFC 5869]
     
      // Our extra input to SHA256-HMAC in generateEntry
      // This includes the full crypto spec; change this when our algo changes.
      HMAC_INPUT: "Sync-AES_256_CBC-HMAC256",
      // Reuse the hasher.
      let h = Utils.makeHMACHasher();
     
      // First key.
      let u = this.username;
      let k1 = Utils.makeHMACKey("" + HMAC_INPUT + u + "\x01");
      let enc = Utils.sha256HMACBytes(m, k1, h);
     
      // Second key: depends on the output of the first run.
      let k2 = Utils.makeHMACKey(enc + HMAC_INPUT + u + "\x02");
      let hmac = Utils.sha256HMACBytes(m, k2, h);


enc and hmac are the 256 bit encryption and HMAC keys, respectively.
      info = "Sync-AES_256_CBC-HMAC256" + username
      T(1) = HMAC-SHA256(prk, "" + info + 0x01)
      T(2) = HMAC-SHA256(prk, T(1) + info + 0x02)


==== Upgrading existing Sync Keys to the new AES key ====
==== Upgrading existing Sync Keys to the new AES key ====
canmove, Confirmed users
725

edits