• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 // Copyright (c) 2013 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
4 //
5 // Some helpers for quic crypto
6 
7 #ifndef NET_QUIC_CRYPTO_CRYPTO_UTILS_H_
8 #define NET_QUIC_CRYPTO_CRYPTO_UTILS_H_
9 
10 #include <string>
11 
12 #include "base/strings/string_piece.h"
13 #include "net/base/net_export.h"
14 #include "net/quic/crypto/crypto_handshake.h"
15 #include "net/quic/crypto/crypto_protocol.h"
16 #include "net/quic/quic_protocol.h"
17 #include "net/quic/quic_time.h"
18 
19 namespace net {
20 
21 class QuicTime;
22 class QuicRandom;
23 struct QuicCryptoNegotiatedParameters;
24 
25 class NET_EXPORT_PRIVATE CryptoUtils {
26  public:
27   enum Perspective {
28     SERVER,
29     CLIENT,
30   };
31 
32   // Generates the connection nonce. The nonce is formed as:
33   //   <4 bytes> current time
34   //   <8 bytes> |orbit| (or random if |orbit| is empty)
35   //   <20 bytes> random
36   static void GenerateNonce(QuicWallTime now,
37                             QuicRandom* random_generator,
38                             base::StringPiece orbit,
39                             std::string* nonce);
40 
41   // Returns true if the sni is valid, false otherwise.
42   //  (1) disallow IP addresses;
43   //  (2) check that the hostname contains valid characters only; and
44   //  (3) contains at least one dot.
45   static bool IsValidSNI(base::StringPiece sni);
46 
47   // Convert hostname to lowercase and remove the trailing '.'.
48   // Returns |hostname|. NormalizeHostname() doesn't support IP address
49   // literals. IsValidSNI() should be called before calling NormalizeHostname().
50   static std::string NormalizeHostname(const char* hostname);
51 
52   // DeriveKeys populates |out->encrypter| and |out->decrypter| given the
53   // contents of |premaster_secret|, |client_nonce|, |server_nonce| and
54   // |hkdf_input|. |aead| determines which cipher will be used. |perspective|
55   // controls whether the server's keys are assigned to |encrypter| or
56   // |decrypter|. |server_nonce| is optional and, if non-empty, is mixed into
57   // the key derivation.
58   static bool DeriveKeys(base::StringPiece premaster_secret,
59                          QuicTag aead,
60                          base::StringPiece client_nonce,
61                          base::StringPiece server_nonce,
62                          const std::string& hkdf_input,
63                          Perspective perspective,
64                          CrypterPair* out);
65 
66  private:
67   DISALLOW_COPY_AND_ASSIGN(CryptoUtils);
68 };
69 
70 }  // namespace net
71 
72 #endif  // NET_QUIC_CRYPTO_CRYPTO_UTILS_H_
73