From d467c204c587231751a6d582b723dd3d8d288090 Mon Sep 17 00:00:00 2001 From: oepen Date: Tue, 23 Aug 2011 14:09:39 +0000 Subject: [PATCH] Cleanup git-svn-id: https://vsmartcard.svn.sourceforge.net/svnroot/vsmartcard@508 96b47cad-a561-4643-ad3b-153ac7d7599c --- .../src/vpicc/virtualsmartcard/CryptoUtils.py | 55 ++----------------- .../virtualsmartcard/cards/cryptoflex.py | 12 ++-- 2 files changed, 12 insertions(+), 55 deletions(-) diff --git a/virtualsmartcard/src/vpicc/virtualsmartcard/CryptoUtils.py b/virtualsmartcard/src/vpicc/virtualsmartcard/CryptoUtils.py index c27f5fd..fff5add 100644 --- a/virtualsmartcard/src/vpicc/virtualsmartcard/CryptoUtils.py +++ b/virtualsmartcard/src/vpicc/virtualsmartcard/CryptoUtils.py @@ -16,8 +16,8 @@ # You should have received a copy of the GNU General Public License along with # virtualsmartcard. If not, see . # -import sys, binascii, utils, random, logging -from Crypto.Cipher import DES3, DES, AES, ARC4 #,IDEA no longer present in python-crypto? @UnusedImport +import sys, binascii, random, logging +from Crypto.Cipher import DES3, DES, AES, ARC4#@UnusedImport from struct import pack from binascii import b2a_hex, a2b_hex from random import randint @@ -243,16 +243,6 @@ def read_protected_string(string, password, cipherspec=None): ## ******************************************************************* ## * Cyberflex specific methods * ## ******************************************************************* -def verify_card_cryptogram(session_key, host_challenge, card_challenge, card_cryptogram): - message = host_challenge + card_challenge - expected = calculate_MAC(session_key, message, CYBERFLEX_IV) - - return card_cryptogram == expected - -def calculate_host_cryptogram(session_key, card_challenge, host_challenge): - message = card_challenge + host_challenge - return calculate_MAC(session_key, message, CYBERFLEX_IV) - def calculate_MAC(session_key, message, iv=CYBERFLEX_IV): """" Cyberflex MAC is the last Block of the input encrypted with DES3-CBC @@ -265,21 +255,6 @@ def calculate_MAC(session_key, message, iv=CYBERFLEX_IV): return crypted[len(padded) - cipher.block_size : ] -def get_derivation_data(host_challenge, card_challenge): - return card_challenge[4:8] + host_challenge[:4] + \ - card_challenge[:4] + host_challenge[4:8] - -def get_session_key(auth_key, host_challenge, card_challenge): - cipher = DES3.new(auth_key, DES3.MODE_ECB) - return cipher.encrypt(get_derivation_data(host_challenge, card_challenge)) - -def generate_host_challenge(): - random.seed() - return "".join([chr(random.randint(0, 255)) for e in range(8)]) - -def andstring(string1, string2): - return operation_on_string(string1, string2, lambda a,b: a & b) - ########################################################################### # PBKDF2.py - PKCS#5 v2.0 Password-Based Key Derivation # @@ -615,37 +590,19 @@ def test_pbkdf2(): print "PBKDF2 self test successfull" if __name__ == "__main__": - default_key = binascii.a2b_hex("404142434445464748494A4B4C4D4E4F") - - host_chal = binascii.a2b_hex("".join("89 45 19 BF BC 1A 5B D8".split())) - card_chal = binascii.a2b_hex("".join("27 4D B7 EA CA 66 CE 44".split())) - card_crypto = binascii.a2b_hex("".join("8A D4 A9 2D 9B 6B 24 E0".split())) - - session_key = get_session_key(default_key, host_chal, card_chal) - print "Session-Key: ", hexdump(session_key) - - print verify_card_cryptogram(session_key, host_chal, card_chal, card_crypto) - - host_crypto = calculate_host_cryptogram(session_key, card_chal, host_chal) - print "Host-Crypto: ", hexdump( host_crypto ) - - external_authenticate = binascii.a2b_hex("".join("84 82 01 00 10".split())) + host_crypto - print hexdump(calculate_MAC(session_key, external_authenticate)) - too_short = binascii.a2b_hex("".join("89 45 19 BF".split())) padded = append_padding("DES3-ECB", too_short) print "Padded data: " + hexdump(padded) unpadded = strip_padding("DES3-ECB", padded) print "Without padding: " + hexdump(unpadded) - teststring = "DEADBEEFistatsyksdvhihewohfwoehcowc8hw8rogfq8whv75tsgohsav8wress" + teststring = "DEADBEEFistatsyksdvhwohfwoehcowc8hw8rogfq8whv75tsgohsav8wress" foo = append_padding("AES", teststring) - print len(foo) - print strip_padding("AES", foo) + assert(strip_padding("AES", foo) == teststring) + testpass = "SomeRandomPassphrase" protectedString = protect_string(teststring, testpass) unprotectedString = read_protected_string(protectedString, testpass) - if teststring != unprotectedString: - print "protect_string test failed" + assert(teststring == unprotectedString) #test_pbkdf2() diff --git a/virtualsmartcard/src/vpicc/virtualsmartcard/cards/cryptoflex.py b/virtualsmartcard/src/vpicc/virtualsmartcard/cards/cryptoflex.py index 4bd9f3d..8928da2 100644 --- a/virtualsmartcard/src/vpicc/virtualsmartcard/cards/cryptoflex.py +++ b/virtualsmartcard/src/vpicc/virtualsmartcard/cards/cryptoflex.py @@ -141,7 +141,7 @@ class CryptoflexMF(MF): # {{{ if data[6] == "\x01": args["data"] = chr(0)*stringtoint(data[2:4]) args["filedescriptor"] = FDB["EFSTRUCTURE_TRANSPARENT"] - file = TransparentStructureEF(**args) + new_file = TransparentStructureEF(**args) elif data[6] == "\x02": if len(data)>16: args["maxrecordsize"] = stringtoint(data[16]) @@ -149,23 +149,23 @@ class CryptoflexMF(MF): # {{{ # if given a number of records args["maxrecordsize"] = (stringtoint(data[2:4])/p2) args["filedescriptor"] = FDB["EFSTRUCTURE_LINEAR_FIXED_NOFURTHERINFO"] - file = RecordStructureEF(**args) + new_file = RecordStructureEF(**args) elif data[6] == "\x03": args["filedescriptor"] = FDB["EFSTRUCTURE_LINEAR_VARIABLE_NOFURTHERINFO"] - file = RecordStructureEF(**args) + new_file = RecordStructureEF(**args) elif data[6] == "\x04": args["filedescriptor"] = FDB["EFSTRUCTURE_CYCLIC_NOFURTHERINFO"] - file = RecordStructureEF(**args) + new_file = RecordStructureEF(**args) elif data[6] == "\x38": if data[12] != "\x03": raise SwError(SW["ERR_INCORRECTPARAMETERS"]) - file = DF(**args) + new_file = DF(**args) else: logging.error("unknown type: 0x%x" % ord(data[6])) raise SwError(SW["ERR_INCORRECTPARAMETERS"]) - return [file] + return [new_file] def recordHandlingDecode(self, p1, p2): if p2 < 4: