Decryptor.h 3.6 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253
  1. //#include <map>
  2. #include "ECDSASignatureBox.h"
  3. #include "HybridEncryptionBox.h"
  4. #include "LocalAttestationTrusted.h"
  5. class Decryptor {
  6. static ECDSASignatureBox signatureBox;
  7. static HybridEncryptionBox hybridEncryptionBoxClient;
  8. static uint8_t verifier_mr_enclave[32]; // = {0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0};
  9. static SymmetricEncryptionBox symmetricEncryptionBoxApache;
  10. static SymmetricEncryptionBox symmetricEncryptionBoxVerifier;
  11. static uint8_t apache_mr_signer[32]; // = {0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0};
  12. static uint8_t plaintext_mitigator_header_H[ECDH_PUBLIC_KEY_SIZE + 32 + 64];
  13. static uint8_t first_decryption_output[1092]; // 1000 bytes of ciphertext data + 12 IV + 16 Tag + 64 clients public key
  14. static uint8_t plaintext_client_data[1000];
  15. static uint32_t create_mitigator_token_M(uint8_t* token);
  16. static uint32_t create_mitigator_header_H(uint8_t* signature_data_and_signature);
  17. static uint32_t create_long_term_signing_keypair(uint8_t* private_public_key_string);
  18. static uint32_t initialize_symmetric_key_decrypt_client_data(uint8_t* plaintext_client_public_key_plus_encrypted_data_plus_tag, uint32_t total_length, uint8_t* plaintext_client_data, uint32_t* plaintext_client_data_length);
  19. static uint32_t encrypt_decrypt_fields_list(SymmetricEncryptionBox &symmetricEncryptionBox, uint32_t encrypt_decrypt, uint8_t *input_fields_list,
  20. uint32_t *input_field_sizes, uint32_t no_of_fields,
  21. uint8_t *output_fields_list, uint32_t *output_field_sizes, uint32_t* total_output_length);
  22. public:
  23. static void calculate_sealed_keypair_size(uint32_t* output_length);
  24. static uint32_t verify_peer_enclave_trust(uint8_t* given_mr_enclave, uint8_t* given_mr_signer, uint8_t* dhaek);
  25. static uint32_t create_and_seal_long_term_signing_key_pair(uint32_t* sealed_data_length, uint8_t* sealed_data);
  26. static uint32_t create_and_encrypt_mitigator_header_H(uint8_t* ciphertext_token_H_plus_tag, uint32_t* length);
  27. static uint32_t unseal_and_restore_long_term_signing_key_pair(uint8_t* sealed_data, uint32_t* sgx_sealed_data_length);
  28. static uint32_t decrypt_verifiers_message_set_apache_mrsigner(uint8_t* ciphertext_plus_tag);
  29. static uint32_t process_apache_message_generate_response(uint8_t* input_ciphertext, uint32_t input_ciphertext_plus_tag_length, uint8_t* output_ciphertext, uint32_t* output_ciphertext_plus_tag_length);
  30. static uint32_t decrypt_client_data(uint8_t *input_fields_list, uint32_t *input_field_sizes,
  31. uint32_t no_of_fields, uint32_t total_input_size,
  32. uint8_t *output_fields_list,
  33. uint32_t *output_field_sizes);
  34. static uint32_t process_verifiers_message(uint8_t* input_ciphertext, uint32_t length);
  35. static void testing_get_verifier_mrenclave_apache_mrsigner(uint8_t* output);
  36. static void testing_get_short_term_public_key(uint8_t* output);
  37. static void testing_long_term_verification_key(uint8_t* output);
  38. static void testing_get_apache_iv(uint8_t*);
  39. };
  40. //ECDSASignatureBox Decryptor::signatureBox();
  41. //HybridEncryptionBox Decryptor::hybridEncryptionBoxClient();
  42. //SymmetricEncryptionBox Decryptor::symmetricEncryptionBoxApache();
  43. //SymmetricEncryptionBox Decryptor::symmetricEncryptionBoxVerifier();
  44. //uint8_t Decryptor::verifier_mr_enclave = {0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0};
  45. //uint8_t Decryptor::apache_mr_signer = {0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0};