cinlin | 32df1e5 | 2022-10-03 11:55:50 -0700 | [diff] [blame] | 1 | // Copyright 2022 Google LLC |
| 2 | // |
| 3 | // Licensed under the Apache License, Version 2.0 (the "License"); |
| 4 | // you may not use this file except in compliance with the License. |
| 5 | // You may obtain a copy of the License at |
| 6 | // |
| 7 | // http://www.apache.org/licenses/LICENSE-2.0 |
| 8 | // |
| 9 | // Unless required by applicable law or agreed to in writing, software |
| 10 | // distributed under the License is distributed on an "AS IS" BASIS, |
| 11 | // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 12 | // See the License for the specific language governing permissions and |
| 13 | // limitations under the License. |
| 14 | // |
| 15 | //////////////////////////////////////////////////////////////////////////////// |
| 16 | |
| 17 | package keyderivation |
| 18 | |
| 19 | import ( |
| 20 | "errors" |
| 21 | "fmt" |
| 22 | |
| 23 | "google.golang.org/protobuf/proto" |
| 24 | "github.com/google/tink/go/core/registry" |
| 25 | "github.com/google/tink/go/keyset" |
| 26 | prfderpb "github.com/google/tink/go/proto/prf_based_deriver_go_proto" |
| 27 | tinkpb "github.com/google/tink/go/proto/tink_go_proto" |
| 28 | ) |
| 29 | |
| 30 | const ( |
| 31 | prfBasedDeriverKeyVersion = 0 |
| 32 | prfBasedDeriverTypeURL = "type.googleapis.com/google.crypto.tink.PrfBasedDeriverKey" |
| 33 | ) |
| 34 | |
| 35 | var ( |
| 36 | errInvalidPRFBasedDeriverKey = errors.New("prf_based_deriver_key_manager: invalid key") |
| 37 | errInvalidPRFBasedDeriverKeyFormat = errors.New("prf_based_deriver_key_manager: invalid key format") |
| 38 | ) |
| 39 | |
| 40 | type prfBasedDeriverKeyManager struct{} |
| 41 | |
| 42 | var _ registry.KeyManager = (*prfBasedDeriverKeyManager)(nil) |
| 43 | |
| 44 | func (km *prfBasedDeriverKeyManager) Primitive(serializedKey []byte) (interface{}, error) { |
| 45 | if len(serializedKey) == 0 { |
| 46 | return nil, errInvalidPRFBasedDeriverKey |
| 47 | } |
| 48 | key := &prfderpb.PrfBasedDeriverKey{} |
| 49 | if err := proto.Unmarshal(serializedKey, key); err != nil { |
| 50 | return nil, errInvalidPRFBasedDeriverKey |
| 51 | } |
| 52 | if keyset.ValidateKeyVersion(key.GetVersion(), prfBasedDeriverKeyVersion) != nil { |
| 53 | return nil, errInvalidPRFBasedDeriverKey |
| 54 | } |
| 55 | return newPRFBasedDeriver(key.GetPrfKey(), key.GetParams().GetDerivedKeyTemplate()) |
| 56 | } |
| 57 | |
| 58 | func (km *prfBasedDeriverKeyManager) NewKey(serializedKeyFormat []byte) (proto.Message, error) { |
| 59 | if len(serializedKeyFormat) == 0 { |
| 60 | return nil, errInvalidPRFBasedDeriverKeyFormat |
| 61 | } |
| 62 | keyFormat := &prfderpb.PrfBasedDeriverKeyFormat{} |
| 63 | if err := proto.Unmarshal(serializedKeyFormat, keyFormat); err != nil { |
| 64 | return nil, errInvalidPRFBasedDeriverKeyFormat |
| 65 | } |
| 66 | if keyFormat.GetParams() == nil { |
| 67 | return nil, errors.New("prf_based_deriver_key_manager: nil PRF-Based Deriver params") |
| 68 | } |
| 69 | prfKey, err := registry.NewKeyData(keyFormat.GetPrfKeyTemplate()) |
| 70 | if err != nil { |
| 71 | return nil, errors.New("prf_based_deriver_key_manager: failed to generate key from PRF key template") |
| 72 | } |
| 73 | // Validate PRF key data and derived key template. |
| 74 | if _, err := newPRFBasedDeriver(prfKey, keyFormat.GetParams().GetDerivedKeyTemplate()); err != nil { |
| 75 | return nil, fmt.Errorf("prf_based_deriver_key_manager: %v", err) |
| 76 | } |
| 77 | return &prfderpb.PrfBasedDeriverKey{ |
| 78 | Version: prfBasedDeriverKeyVersion, |
| 79 | PrfKey: prfKey, |
| 80 | Params: keyFormat.GetParams(), |
| 81 | }, nil |
| 82 | } |
| 83 | |
| 84 | func (km *prfBasedDeriverKeyManager) NewKeyData(serializedKeyFormat []byte) (*tinkpb.KeyData, error) { |
| 85 | key, err := km.NewKey(serializedKeyFormat) |
| 86 | if err != nil { |
| 87 | return nil, err |
| 88 | } |
| 89 | serializedKey, err := proto.Marshal(key) |
| 90 | if err != nil { |
| 91 | return nil, errInvalidPRFBasedDeriverKeyFormat |
| 92 | } |
| 93 | return &tinkpb.KeyData{ |
| 94 | TypeUrl: prfBasedDeriverTypeURL, |
| 95 | Value: serializedKey, |
| 96 | KeyMaterialType: tinkpb.KeyData_SYMMETRIC, |
| 97 | }, nil |
| 98 | } |
| 99 | |
| 100 | func (km *prfBasedDeriverKeyManager) DoesSupport(typeURL string) bool { |
| 101 | return typeURL == prfBasedDeriverTypeURL |
| 102 | } |
| 103 | |
| 104 | func (km *prfBasedDeriverKeyManager) TypeURL() string { |
| 105 | return prfBasedDeriverTypeURL |
| 106 | } |