Removed in-memory encryption of data. We didn't use it and it was probably
buggy anyway, so this is a good opportunity to get rid of some awkard code. In memory encryption might be properly implemented lateron using the SAM.FSencrypt and SAM.FSdecrypt functions, but I doubt it's worth the trouble. git-svn-id: https://vsmartcard.svn.sourceforge.net/svnroot/vsmartcard@463 96b47cad-a561-4643-ad3b-153ac7d7599c
This commit is contained in:
@@ -214,8 +214,7 @@ def read_protected_string(string, password, cipherspec=None):
|
|||||||
hmac_length = 32 #FIXME: Ugly
|
hmac_length = 32 #FIXME: Ugly
|
||||||
|
|
||||||
#Check if the string has the structure, that is generated by protect_string
|
#Check if the string has the structure, that is generated by protect_string
|
||||||
|
regex = re.compile('\$p5k2\$\$[\w./]*\$')
|
||||||
regex = re.compile('\$p5k2\$\$[\w./]*\$') #TODO: Ensure the right format!
|
|
||||||
match = regex.match(string)
|
match = regex.match(string)
|
||||||
if match != None:
|
if match != None:
|
||||||
crypted = string[match.end():len(string) - hmac_length]
|
crypted = string[match.end():len(string) - hmac_length]
|
||||||
|
|||||||
@@ -61,18 +61,13 @@ class CardContainer:
|
|||||||
|
|
||||||
def __init__(self, PIN=None, cardNumber=None, cardSecret=None):
|
def __init__(self, PIN=None, cardNumber=None, cardSecret=None):
|
||||||
from os import urandom
|
from os import urandom
|
||||||
from virtualsmartcard.CryptoUtils import get_cipher_keylen, cipher
|
|
||||||
|
|
||||||
self.cardNumber = cardNumber
|
self.cardNumber = cardNumber
|
||||||
self.PIN = PIN
|
self.PIN = PIN
|
||||||
self.FSkeys = {}
|
|
||||||
self.cipher = 0x01
|
self.cipher = 0x01
|
||||||
self.master_password = None
|
|
||||||
self.master_key = None
|
|
||||||
self.salt = None
|
|
||||||
self.asym_key = None
|
self.asym_key = None
|
||||||
|
|
||||||
keylen = get_cipher_keylen(get_referenced_cipher(self.cipher))
|
keylen = vsCrypto.get_cipher_keylen(get_referenced_cipher(self.cipher))
|
||||||
if cardSecret is None: #Generate a random card secret
|
if cardSecret is None: #Generate a random card secret
|
||||||
self.cardSecret = urandom(keylen)
|
self.cardSecret = urandom(keylen)
|
||||||
else:
|
else:
|
||||||
@@ -91,36 +86,6 @@ class CardContainer:
|
|||||||
def getCardSecret(self):
|
def getCardSecret(self):
|
||||||
return self.cardSecret
|
return self.cardSecret
|
||||||
|
|
||||||
def addKey(self, path, key):
|
|
||||||
"""
|
|
||||||
Encrypt key and store it in the SAM
|
|
||||||
"""
|
|
||||||
crypted_key = cipher(True, self.cipher, self.master_password, key)
|
|
||||||
if self.FSkeys.has_key(path):
|
|
||||||
print "Overwriting key for path %s" % path
|
|
||||||
self.FSkeys[path] = crypted_key
|
|
||||||
|
|
||||||
def removeKey(self, path):
|
|
||||||
"""
|
|
||||||
Erase a key from the SAM
|
|
||||||
"""
|
|
||||||
if(self.FSkeys.has_key(path)):
|
|
||||||
del self.FSkeys[path]
|
|
||||||
else:
|
|
||||||
raise ValueError
|
|
||||||
|
|
||||||
def getKey(self, path):
|
|
||||||
"""
|
|
||||||
Fetch a key from the SAM, decrypt and return it
|
|
||||||
@return: key if the key is in the container, otherwise None
|
|
||||||
"""
|
|
||||||
if(self.FSkeys.has_key(path)):
|
|
||||||
plain_key = cipher(False, self.cipher, self.master_password,
|
|
||||||
self.FSkeys[path]) #TODO: Error checking
|
|
||||||
return plain_key
|
|
||||||
else:
|
|
||||||
return None
|
|
||||||
|
|
||||||
class SAM(object):
|
class SAM(object):
|
||||||
|
|
||||||
def __init__(self, PIN, cardNumber, mf=None):
|
def __init__(self, PIN, cardNumber, mf=None):
|
||||||
@@ -143,31 +108,19 @@ class SAM(object):
|
|||||||
|
|
||||||
def FSencrypt(self, data):
|
def FSencrypt(self, data):
|
||||||
"""
|
"""
|
||||||
Encrypt the given data, using the parameters stored in the SAM
|
Encrypt the given data, using the parameters stored in the SAM.
|
||||||
|
Right now we do not encrypt the data. In memory encryption might or
|
||||||
|
might not be added in a future version.
|
||||||
"""
|
"""
|
||||||
if self.CardContainer.master_key == None:
|
return data
|
||||||
raise ValueError
|
|
||||||
|
|
||||||
cipher = get_referenced_cipher(self.CardContainer.cipher)
|
|
||||||
padded_data = vsCrypto.append_padding(cipher, data)
|
|
||||||
crypted_data = vsCrypto.encrypt(cipher,
|
|
||||||
self.CardContainer.master_key,
|
|
||||||
padded_data)
|
|
||||||
return crypted_data
|
|
||||||
|
|
||||||
def FSdecrypt(self, data):
|
def FSdecrypt(self, data):
|
||||||
"""
|
"""
|
||||||
Decrypt the given data, using the parameters stored in the SAM
|
Decrypt the given data, using the parameters stored in the SAM.
|
||||||
|
Right now we do not encrypt the data. In memory encryption might or
|
||||||
|
might not be added in a future version.
|
||||||
"""
|
"""
|
||||||
if self.CardContainer.master_key == None:
|
return data
|
||||||
raise ValueError, "No master key set."
|
|
||||||
|
|
||||||
cipher = get_referenced_cipher(self.CardContainer.cipher)
|
|
||||||
decrypted_data = vsCrypto.decrypt(cipher,
|
|
||||||
self.CardContainer.master_key,
|
|
||||||
data)
|
|
||||||
unpadded_data = vsCrypto.strip_padding(cipher, decrypted_data)
|
|
||||||
return unpadded_data
|
|
||||||
|
|
||||||
def set_asym_algorithm(self, cipher, keytype):
|
def set_asym_algorithm(self, cipher, keytype):
|
||||||
"""
|
"""
|
||||||
|
|||||||
Reference in New Issue
Block a user