15821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// Copyright (c) 2011 The Chromium Authors. All rights reserved. 25821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// Use of this source code is governed by a BSD-style license that can be 35821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)// found in the LICENSE file. 45821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 55821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "crypto/hmac.h" 65821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 75821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include <openssl/hmac.h> 85821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 95821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include <algorithm> 105821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include <vector> 115821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 125821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/logging.h" 135821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/memory/scoped_ptr.h" 145821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "base/stl_util.h" 155821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)#include "crypto/openssl_util.h" 165821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 175821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)namespace crypto { 185821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 195821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)struct HMACPlatformData { 205821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) std::vector<unsigned char> key; 215821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)}; 225821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 235821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)HMAC::HMAC(HashAlgorithm hash_alg) 245821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) : hash_alg_(hash_alg), plat_(new HMACPlatformData()) { 255821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) // Only SHA-1 and SHA-256 hash algorithms are supported now. 265821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) DCHECK(hash_alg_ == SHA1 || hash_alg_ == SHA256); 275821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)} 285821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 292a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles)bool HMAC::Init(const unsigned char* key, size_t key_length) { 305821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) // Init must not be called more than once on the same HMAC object. 315821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) DCHECK(plat_->key.empty()); 325821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 335821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) plat_->key.assign(key, key + key_length); 34a02191e04bc25c4935f804f2c080ae28663d096dBen Murdoch if (key_length == 0) { 35a02191e04bc25c4935f804f2c080ae28663d096dBen Murdoch // Special-case: if the key is empty, use a key with one zero 36a02191e04bc25c4935f804f2c080ae28663d096dBen Murdoch // byte. OpenSSL's HMAC function breaks when passed a NULL key. (It calls 37a02191e04bc25c4935f804f2c080ae28663d096dBen Murdoch // HMAC_Init_ex which treats a NULL key as having already been initialized 38a02191e04bc25c4935f804f2c080ae28663d096dBen Murdoch // with a key previously.) HMAC pads keys with zeros, so this key is 39a02191e04bc25c4935f804f2c080ae28663d096dBen Murdoch // equivalent. 40a02191e04bc25c4935f804f2c080ae28663d096dBen Murdoch plat_->key.push_back(0); 41a02191e04bc25c4935f804f2c080ae28663d096dBen Murdoch } 425821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) return true; 435821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)} 445821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 455821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)HMAC::~HMAC() { 465821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) // Zero out key copy. 475821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) plat_->key.assign(plat_->key.size(), 0); 485821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) STLClearObject(&plat_->key); 495821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)} 505821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 515821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)bool HMAC::Sign(const base::StringPiece& data, 525821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) unsigned char* digest, 532a99a7e74a7f215066514fe81d2bfa6639d9edddTorne (Richard Coles) size_t digest_length) const { 545821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) DCHECK(!plat_->key.empty()); // Init must be called before Sign. 555821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 565821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) ScopedOpenSSLSafeSizeBuffer<EVP_MAX_MD_SIZE> result(digest, digest_length); 575821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) return ::HMAC(hash_alg_ == SHA1 ? EVP_sha1() : EVP_sha256(), 585821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) &plat_->key[0], plat_->key.size(), 595821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) reinterpret_cast<const unsigned char*>(data.data()), 605821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) data.size(), 615821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) result.safe_buffer(), NULL); 625821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)} 635821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles) 645821806d5e7f356e8fa4b058a389a808ea183019Torne (Richard Coles)} // namespace crypto 65