jdk/src/java.base/share/classes/sun/security/ssl/Authenticator.java
author martin
Tue, 15 Sep 2015 21:56:04 -0700
changeset 32649 2ee9017c7597
parent 30904 ec0224270f90
permissions -rw-r--r--
8136583: Core libraries should use blessed modifier order Summary: Run blessed-modifier-order script (see bug) Reviewed-by: psandoz, chegar, alanb, plevart
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
     1
/*
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
     2
 * Copyright (c) 2012, 2015, Oracle and/or its affiliates. All rights reserved.
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
     3
 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
     4
 *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
     5
 * This code is free software; you can redistribute it and/or modify it
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
     6
 * under the terms of the GNU General Public License version 2 only, as
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
     7
 * published by the Free Software Foundation.  Oracle designates this
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
     8
 * particular file as subject to the "Classpath" exception as provided
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
     9
 * by Oracle in the LICENSE file that accompanied this code.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    10
 *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    11
 * This code is distributed in the hope that it will be useful, but WITHOUT
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    12
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    13
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    14
 * version 2 for more details (a copy is included in the LICENSE file that
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    15
 * accompanied this code).
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    16
 *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    17
 * You should have received a copy of the GNU General Public License version
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    18
 * 2 along with this work; if not, write to the Free Software Foundation,
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    19
 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    20
 *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    21
 * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    22
 * or visit www.oracle.com if you need additional information or have any
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    23
 * questions.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    24
 */
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    25
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    26
package sun.security.ssl;
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    27
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    28
import java.util.Arrays;
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    29
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    30
/**
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    31
 * This class represents an SSL/TLS/DTLS message authentication token,
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    32
 * which encapsulates a sequence number and ensures that attempts to
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    33
 * delete or reorder messages can be detected.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    34
 *
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    35
 * Each connection state contains a sequence number, which is maintained
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    36
 * separately for read and write states.
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    37
 *
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    38
 * For SSL/TLS protocols, the sequence number MUST be set to zero
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    39
 * whenever a connection state is made the active state.
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    40
 *
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    41
 * DTLS uses an explicit sequence number, rather than an implicit one.
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    42
 * Sequence numbers are maintained separately for each epoch, with
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    43
 * each sequence number initially being 0 for each epoch.  The sequence
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    44
 * number used to compute the DTLS MAC is the 64-bit value formed by
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    45
 * concatenating the epoch and the sequence number.
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    46
 *
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    47
 * Sequence numbers do not wrap.  If an implementation would need to wrap
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    48
 * a sequence number, it must renegotiate instead.  A sequence number is
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    49
 * incremented after each record: specifically, the first record transmitted
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    50
 * under a particular connection state MUST use sequence number 0.
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    51
 */
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    52
class Authenticator {
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    53
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    54
    // byte array containing the additional authentication information for
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    55
    // each record
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    56
    private final byte[] block;
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    57
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    58
    // the block size of SSL v3.0:
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    59
    // sequence number + record type + + record length
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    60
    private static final int BLOCK_SIZE_SSL = 8 + 1 + 2;
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    61
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    62
    // the block size of TLS v1.0 and later:
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    63
    // sequence number + record type + protocol version + record length
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    64
    private static final int BLOCK_SIZE_TLS = 8 + 1 + 2 + 2;
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    65
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    66
    // the block size of DTLS v1.0 and later:
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    67
    // epoch + sequence number + record type + protocol version + record length
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    68
    private static final int BLOCK_SIZE_DTLS = 2 + 6 + 1 + 2 + 2;
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    69
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    70
    private final boolean isDTLS;
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    71
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    72
    /**
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    73
     * Default construct, no message authentication token is initialized.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    74
     *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    75
     * Note that this construct can only be called for null MAC
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    76
     */
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    77
    protected Authenticator(boolean isDTLS) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    78
        if (isDTLS) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    79
            // For DTLS protocols, plaintexts use explicit epoch and
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    80
            // sequence number in each record.  The first 8 byte of
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    81
            // the block is initialized for null MAC so that the
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    82
            // epoch and sequence number can be acquired to generate
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    83
            // plaintext records.
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    84
            block = new byte[8];
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    85
        } else {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    86
            block = new byte[0];
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    87
        }
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    88
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    89
        this.isDTLS = isDTLS;
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    90
    }
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    91
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    92
    /**
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    93
     * Constructs the message authentication token for the specified
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    94
     * SSL/TLS protocol.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    95
     */
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
    96
    Authenticator(ProtocolVersion protocolVersion) {
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    97
        if (protocolVersion.isDTLSProtocol()) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    98
            block = new byte[BLOCK_SIZE_DTLS];
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
    99
            block[9] = protocolVersion.major;
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   100
            block[10] = protocolVersion.minor;
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   101
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   102
            this.isDTLS = true;
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   103
        } else if (protocolVersion.v >= ProtocolVersion.TLS10.v) {
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   104
            block = new byte[BLOCK_SIZE_TLS];
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   105
            block[9] = protocolVersion.major;
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   106
            block[10] = protocolVersion.minor;
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   107
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   108
            this.isDTLS = false;
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   109
        } else {
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   110
            block = new byte[BLOCK_SIZE_SSL];
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   111
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   112
            this.isDTLS = false;
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   113
        }
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   114
    }
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   115
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   116
    /**
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   117
     * Checks whether the sequence number is close to wrap.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   118
     *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   119
     * Sequence numbers are of type uint64 and may not exceed 2^64-1.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   120
     * Sequence numbers do not wrap. When the sequence number is near
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   121
     * to wrap, we need to close the connection immediately.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   122
     *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   123
     * @return true if the sequence number is close to wrap
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   124
     */
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   125
    final boolean seqNumOverflow() {
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   126
        /*
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   127
         * Conservatively, we don't allow more records to be generated
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   128
         * when there are only 2^8 sequence numbers left.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   129
         */
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   130
        if (isDTLS) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   131
            return (block.length != 0 &&
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   132
                // no epoch bytes, block[0] and block[1]
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   133
                block[2] == (byte)0xFF && block[3] == (byte)0xFF &&
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   134
                block[4] == (byte)0xFF && block[5] == (byte)0xFF &&
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   135
                block[6] == (byte)0xFF);
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   136
        } else {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   137
            return (block.length != 0 &&
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   138
                block[0] == (byte)0xFF && block[1] == (byte)0xFF &&
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   139
                block[2] == (byte)0xFF && block[3] == (byte)0xFF &&
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   140
                block[4] == (byte)0xFF && block[5] == (byte)0xFF &&
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   141
                block[6] == (byte)0xFF);
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   142
        }
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   143
    }
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   144
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   145
    /**
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   146
     * Checks whether the sequence number close to renew.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   147
     *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   148
     * Sequence numbers are of type uint64 and may not exceed 2^64-1.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   149
     * Sequence numbers do not wrap.  If a TLS
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   150
     * implementation would need to wrap a sequence number, it must
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   151
     * renegotiate instead.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   152
     *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   153
     * @return true if the sequence number is huge enough to renew
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   154
     */
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   155
    final boolean seqNumIsHuge() {
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   156
        /*
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   157
         * Conservatively, we should ask for renegotiation when there are
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   158
         * only 2^32 sequence numbers left.
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   159
         */
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   160
        if (isDTLS) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   161
            return (block.length != 0 &&
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   162
                // no epoch bytes, block[0] and block[1]
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   163
                block[2] == (byte)0xFF && block[3] == (byte)0xFF);
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   164
        } else {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   165
            return (block.length != 0 &&
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   166
                block[0] == (byte)0xFF && block[1] == (byte)0xFF &&
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   167
                block[2] == (byte)0xFF && block[3] == (byte)0xFF);
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   168
        }
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   169
    }
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   170
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   171
    /**
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   172
     * Gets the current sequence number, including the epoch number for
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   173
     * DTLS protocols.
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   174
     *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   175
     * @return the byte array of the current sequence number
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   176
     */
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   177
    final byte[] sequenceNumber() {
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   178
        return Arrays.copyOf(block, 8);
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   179
    }
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   180
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   181
    /**
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   182
     * Sets the epoch number (only apply to DTLS protocols).
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   183
     */
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   184
    final void setEpochNumber(int epoch) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   185
        if (!isDTLS) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   186
            throw new RuntimeException(
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   187
                "Epoch numbers apply to DTLS protocols only");
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   188
        }
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   189
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   190
        block[0] = (byte)((epoch >> 8) & 0xFF);
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   191
        block[1] = (byte)(epoch & 0xFF);
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   192
    }
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   193
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   194
    /**
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   195
     * Increase the sequence number.
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   196
     */
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   197
    final void increaseSequenceNumber() {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   198
        /*
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   199
         * The sequence number in the block array is a 64-bit
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   200
         * number stored in big-endian format.
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   201
         */
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   202
        int k = 7;
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   203
        while ((k >= 0) && (++block[k] == 0)) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   204
            k--;
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   205
        }
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   206
    }
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   207
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   208
    /**
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   209
     * Acquires the current message authentication information with the
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   210
     * specified record type and fragment length, and then increases the
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   211
     * sequence number.
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   212
     *
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   213
     * @param  type the record type
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   214
     * @param  length the fragment of the record
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   215
     * @param  sequence the explicit sequence number of the record
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   216
     *
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   217
     * @return the byte array of the current message authentication information
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   218
     */
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   219
    final byte[] acquireAuthenticationBytes(
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   220
            byte type, int length, byte[] sequence) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   221
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   222
        byte[] copy = block.clone();
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   223
        if (sequence != null) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   224
            if (sequence.length != 8) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   225
                throw new RuntimeException(
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   226
                        "Insufficient explicit sequence number bytes");
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   227
            }
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   228
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   229
            System.arraycopy(sequence, 0, copy, 0, sequence.length);
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   230
        }   // Otherwise, use the implicit sequence number.
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   231
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   232
        if (block.length != 0) {
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   233
            copy[8] = type;
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   234
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   235
            copy[copy.length - 2] = (byte)(length >> 8);
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   236
            copy[copy.length - 1] = (byte)(length);
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   237
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   238
            if (sequence == null || sequence.length != 0) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   239
                // Increase the implicit sequence number in the block array.
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   240
                increaseSequenceNumber();
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   241
            }
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   242
        }
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   243
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   244
        return copy;
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   245
    }
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   246
32649
2ee9017c7597 8136583: Core libraries should use blessed modifier order
martin
parents: 30904
diff changeset
   247
    static final long toLong(byte[] recordEnS) {
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   248
        if (recordEnS != null && recordEnS.length == 8) {
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   249
            return ((recordEnS[0] & 0xFFL) << 56) |
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   250
                   ((recordEnS[1] & 0xFFL) << 48) |
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   251
                   ((recordEnS[2] & 0xFFL) << 40) |
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   252
                   ((recordEnS[3] & 0xFFL) << 32) |
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   253
                   ((recordEnS[4] & 0xFFL) << 24) |
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   254
                   ((recordEnS[5] & 0xFFL) << 16) |
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   255
                   ((recordEnS[6] & 0xFFL) <<  8) |
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   256
                    (recordEnS[7] & 0xFFL);
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   257
        }
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   258
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   259
        return -1L;
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 25859
diff changeset
   260
    }
16913
a6f4d1626ad9 8011680: Re-integrate AEAD implementation of JSSE
xuelei
parents:
diff changeset
   261
}