pycryptodome/lib/Crypto/Cipher/AES.py

251 lines
9.3 KiB
Python
Raw Normal View History

# -*- coding: utf-8 -*-
#
# Cipher/AES.py : AES
#
# ===================================================================
# The contents of this file are dedicated to the public domain. To
# the extent that dedication to the public domain is not available,
# everyone is granted a worldwide, perpetual, royalty-free,
# non-exclusive license to exercise all rights associated with the
# contents of this file for any purpose whatsoever.
# No rights are reserved.
#
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
# SOFTWARE.
# ===================================================================
2017-07-25 23:46:12 +02:00
"""
Module's constants for the modes of operation supported with AES:
2018-04-03 22:24:17 +02:00
:var MODE_ECB: :ref:`Electronic Code Book (ECB) <ecb_mode>`
:var MODE_CBC: :ref:`Cipher-Block Chaining (CBC) <cbc_mode>`
:var MODE_CFB: :ref:`Cipher FeedBack (CFB) <cfb_mode>`
:var MODE_OFB: :ref:`Output FeedBack (OFB) <ofb_mode>`
:var MODE_CTR: :ref:`CounTer Mode (CTR) <ctr_mode>`
:var MODE_OPENPGP: :ref:`OpenPGP Mode <openpgp_mode>`
:var MODE_CCM: :ref:`Counter with CBC-MAC (CCM) Mode <ccm_mode>`
:var MODE_EAX: :ref:`EAX Mode <eax_mode>`
:var MODE_GCM: :ref:`Galois Counter Mode (GCM) <gcm_mode>`
:var MODE_SIV: :ref:`Syntethic Initialization Vector (SIV) <siv_mode>`
:var MODE_OCB: :ref:`Offset Code Book (OCB) <ocb_mode>`
"""
2014-12-16 07:50:48 +01:00
import sys
from Crypto.Cipher import _create_cipher
from Crypto.Util._raw_api import (load_pycryptodome_raw_lib,
VoidPointer, SmartPointer,
2018-03-06 13:48:00 +01:00
c_size_t, c_uint8_ptr)
from Crypto.Util import _cpu_features
2018-10-02 19:11:18 +02:00
from Crypto.Random import get_random_bytes
2015-01-23 15:24:21 +00:00
2015-12-23 23:19:37 +01:00
_cproto = """
int AES_start_operation(const uint8_t key[],
size_t key_len,
void **pResult);
int AES_encrypt(const void *state,
const uint8_t *in,
uint8_t *out,
size_t data_len);
int AES_decrypt(const void *state,
const uint8_t *in,
uint8_t *out,
size_t data_len);
int AES_stop_operation(void *state);
"""
2018-05-31 22:41:26 +02:00
# Load portable AES
_raw_aes_lib = load_pycryptodome_raw_lib("Crypto.Cipher._raw_aes",
2015-12-23 23:19:37 +01:00
_cproto)
2014-12-16 07:50:48 +01:00
2018-05-31 22:41:26 +02:00
# Try to load AES with AES NI instructions
2013-02-04 14:44:29 +01:00
try:
2018-05-31 22:41:26 +02:00
_raw_aesni_lib = None
if _cpu_features.have_aes_ni():
_raw_aesni_lib = load_pycryptodome_raw_lib("Crypto.Cipher._raw_aesni",
2015-12-23 23:19:37 +01:00
_cproto.replace("AES",
2018-05-31 22:41:26 +02:00
"AESNI"))
# _raw_aesni may not have been compiled in
2014-12-16 07:50:48 +01:00
except OSError:
pass
def _create_base_cipher(dict_parameters):
2015-03-09 21:43:24 +01:00
"""This method instantiates and returns a handle to a low-level
base cipher. It will absorb named parameters in the process."""
2014-12-16 07:50:48 +01:00
use_aesni = dict_parameters.pop("use_aesni", True)
try:
key = dict_parameters.pop("key")
except KeyError:
raise TypeError("Missing 'key' parameter")
if len(key) not in key_size:
raise ValueError("Incorrect AES key length (%d bytes)" % len(key))
if use_aesni and _raw_aesni_lib:
start_operation = _raw_aesni_lib.AESNI_start_operation
stop_operation = _raw_aesni_lib.AESNI_stop_operation
2013-02-04 14:44:29 +01:00
else:
2014-12-16 07:50:48 +01:00
start_operation = _raw_aes_lib.AES_start_operation
stop_operation = _raw_aes_lib.AES_stop_operation
cipher = VoidPointer()
2018-03-06 13:48:00 +01:00
result = start_operation(c_uint8_ptr(key),
c_size_t(len(key)),
cipher.address_of())
2014-12-16 07:50:48 +01:00
if result:
raise ValueError("Error %X while instantiating the AES cipher"
% result)
return SmartPointer(cipher.get(), stop_operation)
2018-09-23 20:46:01 +02:00
def _derive_Poly1305_key_pair(key, nonce):
"""Derive a tuple (r, s, nonce) for a Poly1305 MAC.
If nonce is ``None``, a new 16-byte nonce is generated.
"""
if len(key) != 32:
raise ValueError("Poly1305 with AES requires a 32-byte key")
if nonce is None:
nonce = get_random_bytes(16)
elif len(nonce) != 16:
raise ValueError("Poly1305 with AES requires a 16-byte nonce")
s = new(key[:16], MODE_ECB).encrypt(nonce)
return key[16:], s, nonce
def new(key, mode, *args, **kwargs):
2017-07-25 23:46:12 +02:00
"""Create a new AES cipher.
2017-07-25 23:46:12 +02:00
:param key:
The secret key to use in the symmetric cipher.
2015-12-23 23:19:37 +01:00
2017-07-25 23:46:12 +02:00
It must be 16, 24 or 32 bytes long (respectively for *AES-128*,
*AES-192* or *AES-256*).
2015-12-23 23:19:37 +01:00
2017-07-25 23:46:12 +02:00
For ``MODE_SIV`` only, it doubles to 32, 48, or 64 bytes.
2018-04-03 22:24:17 +02:00
:type key: bytes/bytearray/memoryview
2017-07-25 23:46:12 +02:00
:param mode:
The chaining mode to use for encryption or decryption.
If in doubt, use ``MODE_EAX``.
:type mode: One of the supported ``MODE_*`` constants
2017-07-25 23:46:12 +02:00
:Keyword Arguments:
2018-04-03 22:24:17 +02:00
* **iv** (*bytes*, *bytearray*, *memoryview*) --
2017-07-25 23:46:12 +02:00
(Only applicable for ``MODE_CBC``, ``MODE_CFB``, ``MODE_OFB``,
and ``MODE_OPENPGP`` modes).
2015-12-23 23:19:37 +01:00
2017-07-25 23:46:12 +02:00
The initialization vector to use for encryption or decryption.
2015-12-23 23:19:37 +01:00
2017-07-25 23:46:12 +02:00
For ``MODE_CBC``, ``MODE_CFB``, and ``MODE_OFB`` it must be 16 bytes long.
2017-07-25 23:46:12 +02:00
For ``MODE_OPENPGP`` mode only,
it must be 16 bytes long for encryption
and 18 bytes for decryption (in the latter case, it is
actually the *encrypted* IV which was prefixed to the ciphertext).
2017-07-31 23:56:54 +02:00
If not provided, a random byte string is generated (you must then
2017-07-25 23:46:12 +02:00
read its value with the :attr:`iv` attribute).
2018-04-03 22:24:17 +02:00
* **nonce** (*bytes*, *bytearray*, *memoryview*) --
2017-07-25 23:46:12 +02:00
(Only applicable for ``MODE_CCM``, ``MODE_EAX``, ``MODE_GCM``,
``MODE_SIV``, ``MODE_OCB``, and ``MODE_CTR``).
2017-07-25 23:46:12 +02:00
A value that must never be reused for any other encryption done
2018-07-19 14:26:41 +02:00
with this key (except possibly for ``MODE_SIV``, see below).
2017-07-25 23:46:12 +02:00
For ``MODE_EAX``, ``MODE_GCM`` and ``MODE_SIV`` there are no
restrictions on its length (recommended: **16** bytes).
2015-12-23 23:19:37 +01:00
2017-07-25 23:46:12 +02:00
For ``MODE_CCM``, its length must be in the range **[7..13]**.
Bear in mind that with CCM there is a trade-off between nonce
length and maximum message size. Recommendation: **11** bytes.
2015-12-23 23:19:37 +01:00
2017-07-25 23:46:12 +02:00
For ``MODE_OCB``, its length must be in the range **[1..15]**
(recommended: **15**).
2015-12-23 23:19:37 +01:00
2017-07-25 23:46:12 +02:00
For ``MODE_CTR``, its length must be in the range **[0..15]**
(recommended: **8**).
2018-07-19 14:26:41 +02:00
For ``MODE_SIV``, the nonce is optional, if it is not specified,
then no nonce is being used, which renders the encryption
deterministic.
If not provided, for modes other than ``MODE_SIV```, a random
byte string of the recommended length is used (you must then
read its value with the :attr:`nonce` attribute).
2015-12-23 23:19:37 +01:00
2018-04-03 22:24:17 +02:00
* **segment_size** (*integer*) --
2017-07-25 23:46:12 +02:00
(Only ``MODE_CFB``).The number of **bits** the plaintext and ciphertext
are segmented in. It must be a multiple of 8.
If not specified, it will be assumed to be 8.
2018-04-03 22:24:17 +02:00
* **mac_len** : (*integer*) --
2017-07-25 23:46:12 +02:00
(Only ``MODE_EAX``, ``MODE_GCM``, ``MODE_OCB``, ``MODE_CCM``)
Length of the authentication tag, in bytes.
2015-12-23 23:19:37 +01:00
2017-07-25 23:46:12 +02:00
It must be even and in the range **[4..16]**.
The recommended value (and the default, if not specified) is **16**.
2015-12-23 23:19:37 +01:00
2018-04-03 22:24:17 +02:00
* **msg_len** : (*integer*) --
2017-07-25 23:46:12 +02:00
(Only ``MODE_CCM``). Length of the message to (de)cipher.
If not specified, ``encrypt`` must be called with the entire message.
Similarly, ``decrypt`` can only be called once.
2015-12-23 23:19:37 +01:00
2018-04-03 22:24:17 +02:00
* **assoc_len** : (*integer*) --
2017-07-25 23:46:12 +02:00
(Only ``MODE_CCM``). Length of the associated data.
If not specified, all associated data is buffered internally,
which may represent a problem for very large messages.
2018-11-11 22:14:15 +01:00
* **initial_value** : (*integer* or *bytes/bytearray/memoryview*) --
(Only ``MODE_CTR``).
The initial value for the counter. If not present, the cipher will
start counting from 0. The value is incremented by one for each block.
The counter number is encoded in big endian mode.
* **counter** : (*object*) --
Instance of ``Crypto.Util.Counter``, which allows full customization
of the counter block. This parameter is incompatible to both ``nonce``
and ``initial_value``.
2018-04-03 22:24:17 +02:00
* **use_aesni** : (*boolean*) --
2017-07-25 23:46:12 +02:00
Use Intel AES-NI hardware extensions (default: use if available).
2017-07-25 23:46:12 +02:00
:Return: an AES object, of the applicable mode.
"""
kwargs["add_aes_modes"] = True
2014-12-16 07:50:48 +01:00
return _create_cipher(sys.modules[__name__], key, mode, *args, **kwargs)
2018-05-31 22:41:26 +02:00
MODE_ECB = 1
MODE_CBC = 2
MODE_CFB = 3
MODE_OFB = 5
MODE_CTR = 6
2012-05-17 13:28:24 +02:00
MODE_OPENPGP = 7
MODE_CCM = 8
MODE_EAX = 9
Add support for SIV (Synthetic IV) mode This patch add supports for SIV, an AEAD block cipher mode defined in RFC5297. SIV is only valid for AES. The PRF of SIV (S2V) is factored out in the Protocol.KDF module. See the following example to get a feeling of the API (slightly different than other AEAD mode, during decryption). Encryption (Python 2): >>> from Crypto.Cipher import AES >>> key = b'0'*32 >>> siv = AES.new(key, AES.MODE_SIV) >>> ct = siv.encrypt(b'Message') >>> mac = siv.digest() Decryption (Python 2): >>> from Crypto.Cipher import AES, MacMismatchError >>> key = b'0'*32 >>> siv = AES.new(key, AES.MODE_SIV) >>> pt = siv.decrypt(ct + mac) >>> try: >>> siv.verify(mac) >>> print "Plaintext", pt >>> except MacMismatchError: >>> print "Error" This change also fixes the description/design of AEAD API. With SIV (RFC5297), decryption can only start when the MAC is known. The original AEAD API did not support that. For SIV the MAC is now exceptionally passed together with the ciphertext to the decrypt() method. [dlitz@dlitz.net: Included changes from the following commits from the author's pull request:] - [9c13f9c] Rename 'IV' parameter to 'nonce' for AEAD modes. - [d7727fb] Fix description/design of AEAD API. - [fb62fae] ApiUsageError becomes TypeError [whitespace] - [4ec64d8] Removed last references to ApiUsageError [whitespace] - [ee46922] Removed most 'import *' statements - [ca460a7] Made blockalgo.py more PEP-8 compliant; The second parameter of the _GHASH constructor is now the length of the block (block_size) and not the full module. [dlitz@dlitz.net: A conflict that was not resolved in the previous commit was originally resolved here. Moved the resolution to the previous commit.] [dlitz@dlitz.net: Replaced MacMismatchError with ValueError] [dlitz@dlitz.net: Replaced ApiUsageError with TypeError] [dlitz@dlitz.net: Whitespace fixed with "git rebase --whitespace=fix"]
2013-05-22 22:18:35 +02:00
MODE_SIV = 10
MODE_GCM = 11
2015-05-03 15:06:42 -04:00
MODE_OCB = 12
2015-03-09 21:43:24 +01:00
2017-07-25 23:46:12 +02:00
# Size of a data block (in bytes)
block_size = 16
2017-07-25 23:46:12 +02:00
# Size of a key (in bytes)
2014-12-16 07:50:48 +01:00
key_size = (16, 24, 32)