2021-02-27 00:00:37 +00:00
|
|
|
// Copyright 2018-2021 Signal Messenger, LLC
|
2020-10-30 20:34:04 +00:00
|
|
|
// SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
/* eslint-disable class-methods-use-this */
|
2018-10-18 01:01:21 +00:00
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
import * as CiphertextMessage from './CiphertextMessage';
|
|
|
|
import {
|
2018-10-18 01:01:21 +00:00
|
|
|
bytesFromString,
|
|
|
|
concatenateBytes,
|
|
|
|
constantTimeEqual,
|
|
|
|
decryptAesCtr,
|
|
|
|
encryptAesCtr,
|
|
|
|
fromEncodedBinaryToArrayBuffer,
|
|
|
|
getViewOfArrayBuffer,
|
|
|
|
getZeroes,
|
|
|
|
highBitsToInt,
|
|
|
|
hmacSha256,
|
|
|
|
intsToByteHighAndLow,
|
|
|
|
splitBytes,
|
|
|
|
trimBytes,
|
2021-02-27 00:00:37 +00:00
|
|
|
} from '../Crypto';
|
2018-10-18 01:01:21 +00:00
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
import { SignalProtocolAddressClass } from '../libsignal.d';
|
2018-10-18 01:01:21 +00:00
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
const REVOKED_CERTIFICATES: Array<number> = [];
|
|
|
|
const CIPHERTEXT_VERSION = 1;
|
|
|
|
const UNIDENTIFIED_DELIVERY_PREFIX = 'UnidentifiedDelivery';
|
2018-10-18 01:01:21 +00:00
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
type MeType = {
|
|
|
|
number?: string;
|
|
|
|
uuid?: string;
|
|
|
|
deviceId: number;
|
|
|
|
};
|
2021-02-08 22:19:35 +00:00
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
type ValidatorType = {
|
|
|
|
validate(
|
|
|
|
certificate: SenderCertificateType,
|
|
|
|
validationTime: number
|
|
|
|
): Promise<void>;
|
|
|
|
};
|
2018-10-18 01:01:21 +00:00
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
export type SerializedCertificateType = {
|
|
|
|
serialized: ArrayBuffer;
|
|
|
|
};
|
|
|
|
|
|
|
|
type ServerCertificateType = {
|
|
|
|
id: number;
|
|
|
|
key: ArrayBuffer;
|
|
|
|
};
|
|
|
|
|
|
|
|
type ServerCertificateWrapperType = {
|
|
|
|
certificate: ArrayBuffer;
|
|
|
|
signature: ArrayBuffer;
|
|
|
|
};
|
|
|
|
|
|
|
|
type SenderCertificateType = {
|
|
|
|
sender?: string;
|
|
|
|
senderUuid?: string;
|
|
|
|
senderDevice: number;
|
|
|
|
expires: number;
|
|
|
|
identityKey: ArrayBuffer;
|
|
|
|
signer: ServerCertificateType;
|
|
|
|
};
|
|
|
|
|
|
|
|
type SenderCertificateWrapperType = {
|
|
|
|
certificate: ArrayBuffer;
|
|
|
|
signature: ArrayBuffer;
|
|
|
|
};
|
|
|
|
|
|
|
|
type MessageType = {
|
|
|
|
ephemeralPublic: ArrayBuffer;
|
|
|
|
encryptedStatic: ArrayBuffer;
|
|
|
|
encryptedMessage: ArrayBuffer;
|
|
|
|
};
|
|
|
|
|
|
|
|
type InnerMessageType = {
|
|
|
|
type: number;
|
|
|
|
senderCertificate: SenderCertificateWrapperType;
|
|
|
|
content: ArrayBuffer;
|
|
|
|
};
|
|
|
|
|
|
|
|
export type ExplodedServerCertificateType = ServerCertificateType &
|
|
|
|
ServerCertificateWrapperType &
|
|
|
|
SerializedCertificateType;
|
|
|
|
|
|
|
|
export type ExplodedSenderCertificateType = SenderCertificateType &
|
|
|
|
SenderCertificateWrapperType &
|
|
|
|
SerializedCertificateType & {
|
|
|
|
signer: ExplodedServerCertificateType;
|
|
|
|
};
|
|
|
|
|
|
|
|
type ExplodedMessageType = MessageType &
|
|
|
|
SerializedCertificateType & { version: number };
|
|
|
|
|
|
|
|
type ExplodedInnerMessageType = InnerMessageType &
|
|
|
|
SerializedCertificateType & {
|
|
|
|
senderCertificate: ExplodedSenderCertificateType;
|
|
|
|
};
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
// public CertificateValidator(ECPublicKey trustRoot)
|
2021-02-27 00:00:37 +00:00
|
|
|
export function createCertificateValidator(
|
|
|
|
trustRoot: ArrayBuffer
|
|
|
|
): ValidatorType {
|
2018-10-18 01:01:21 +00:00
|
|
|
return {
|
|
|
|
// public void validate(SenderCertificate certificate, long validationTime)
|
2021-02-27 00:00:37 +00:00
|
|
|
async validate(
|
|
|
|
certificate: ExplodedSenderCertificateType,
|
|
|
|
validationTime: number
|
|
|
|
): Promise<void> {
|
2018-10-18 01:01:21 +00:00
|
|
|
const serverCertificate = certificate.signer;
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
await window.libsignal.Curve.async.verifySignature(
|
2018-10-18 01:01:21 +00:00
|
|
|
trustRoot,
|
|
|
|
serverCertificate.certificate,
|
|
|
|
serverCertificate.signature
|
|
|
|
);
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
const serverCertId = serverCertificate.id;
|
2018-10-18 01:01:21 +00:00
|
|
|
if (REVOKED_CERTIFICATES.includes(serverCertId)) {
|
|
|
|
throw new Error(
|
|
|
|
`Server certificate id ${serverCertId} has been revoked`
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
await window.libsignal.Curve.async.verifySignature(
|
2018-10-18 01:01:21 +00:00
|
|
|
serverCertificate.key,
|
|
|
|
certificate.certificate,
|
|
|
|
certificate.signature
|
|
|
|
);
|
|
|
|
|
|
|
|
if (validationTime > certificate.expires) {
|
|
|
|
throw new Error('Certificate is expired');
|
|
|
|
}
|
|
|
|
},
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
function _decodePoint(serialized: ArrayBuffer, offset = 0): ArrayBuffer {
|
2018-10-18 01:01:21 +00:00
|
|
|
const view =
|
|
|
|
offset > 0
|
|
|
|
? getViewOfArrayBuffer(serialized, offset, serialized.byteLength)
|
|
|
|
: serialized;
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
return window.libsignal.Curve.validatePubKeyFormat(view);
|
2018-10-18 01:01:21 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// public ServerCertificate(byte[] serialized)
|
2021-02-27 00:00:37 +00:00
|
|
|
export function _createServerCertificateFromBuffer(
|
|
|
|
serialized: ArrayBuffer
|
|
|
|
): ExplodedServerCertificateType {
|
|
|
|
const wrapper = window.textsecure.protobuf.ServerCertificate.decode(
|
|
|
|
serialized
|
|
|
|
);
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
if (!wrapper.certificate || !wrapper.signature) {
|
|
|
|
throw new Error('Missing fields');
|
|
|
|
}
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
const certificate = window.textsecure.protobuf.ServerCertificate.Certificate.decode(
|
2018-10-18 01:01:21 +00:00
|
|
|
wrapper.certificate.toArrayBuffer()
|
|
|
|
);
|
|
|
|
|
|
|
|
if (!certificate.id || !certificate.key) {
|
|
|
|
throw new Error('Missing fields');
|
|
|
|
}
|
|
|
|
|
|
|
|
return {
|
|
|
|
id: certificate.id,
|
|
|
|
key: certificate.key.toArrayBuffer(),
|
|
|
|
serialized,
|
|
|
|
certificate: wrapper.certificate.toArrayBuffer(),
|
|
|
|
|
|
|
|
signature: wrapper.signature.toArrayBuffer(),
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
// public SenderCertificate(byte[] serialized)
|
2021-02-27 00:00:37 +00:00
|
|
|
export function _createSenderCertificateFromBuffer(
|
|
|
|
serialized: ArrayBuffer
|
|
|
|
): ExplodedSenderCertificateType {
|
|
|
|
const wrapper = window.textsecure.protobuf.SenderCertificate.decode(
|
|
|
|
serialized
|
|
|
|
);
|
|
|
|
|
|
|
|
const { signature, certificate } = wrapper;
|
2018-10-18 01:01:21 +00:00
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
if (!signature || !certificate) {
|
2018-10-18 01:01:21 +00:00
|
|
|
throw new Error('Missing fields');
|
|
|
|
}
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
const senderCertificate = window.textsecure.protobuf.SenderCertificate.Certificate.decode(
|
2018-10-18 01:01:21 +00:00
|
|
|
wrapper.certificate.toArrayBuffer()
|
|
|
|
);
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
const {
|
|
|
|
signer,
|
|
|
|
identityKey,
|
|
|
|
senderDevice,
|
|
|
|
expires,
|
|
|
|
sender,
|
|
|
|
senderUuid,
|
|
|
|
} = senderCertificate;
|
|
|
|
|
2018-10-18 01:01:21 +00:00
|
|
|
if (
|
2021-02-27 00:00:37 +00:00
|
|
|
!signer ||
|
|
|
|
!identityKey ||
|
|
|
|
!senderDevice ||
|
|
|
|
!expires ||
|
|
|
|
!(sender || senderUuid)
|
2018-10-18 01:01:21 +00:00
|
|
|
) {
|
|
|
|
throw new Error('Missing fields');
|
|
|
|
}
|
|
|
|
|
|
|
|
return {
|
2021-02-27 00:00:37 +00:00
|
|
|
sender,
|
|
|
|
senderUuid,
|
|
|
|
senderDevice,
|
|
|
|
expires: expires.toNumber(),
|
|
|
|
identityKey: identityKey.toArrayBuffer(),
|
|
|
|
signer: _createServerCertificateFromBuffer(signer.toArrayBuffer()),
|
2018-10-18 01:01:21 +00:00
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
certificate: certificate.toArrayBuffer(),
|
|
|
|
signature: signature.toArrayBuffer(),
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
serialized,
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
// public UnidentifiedSenderMessage(byte[] serialized)
|
2021-02-27 00:00:37 +00:00
|
|
|
function _createUnidentifiedSenderMessageFromBuffer(
|
|
|
|
serialized: ArrayBuffer
|
|
|
|
): ExplodedMessageType {
|
|
|
|
const uintArray = new Uint8Array(serialized);
|
|
|
|
const version = highBitsToInt(uintArray[0]);
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
if (version > CIPHERTEXT_VERSION) {
|
2021-02-27 00:00:37 +00:00
|
|
|
throw new Error(`Unknown version: ${version}`);
|
2018-10-18 01:01:21 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
const view = getViewOfArrayBuffer(serialized, 1, serialized.byteLength);
|
2021-02-27 00:00:37 +00:00
|
|
|
const unidentifiedSenderMessage = window.textsecure.protobuf.UnidentifiedSenderMessage.decode(
|
2018-10-18 01:01:21 +00:00
|
|
|
view
|
|
|
|
);
|
|
|
|
|
|
|
|
if (
|
|
|
|
!unidentifiedSenderMessage.ephemeralPublic ||
|
|
|
|
!unidentifiedSenderMessage.encryptedStatic ||
|
|
|
|
!unidentifiedSenderMessage.encryptedMessage
|
|
|
|
) {
|
|
|
|
throw new Error('Missing fields');
|
|
|
|
}
|
|
|
|
|
|
|
|
return {
|
|
|
|
version,
|
|
|
|
|
|
|
|
ephemeralPublic: unidentifiedSenderMessage.ephemeralPublic.toArrayBuffer(),
|
|
|
|
encryptedStatic: unidentifiedSenderMessage.encryptedStatic.toArrayBuffer(),
|
|
|
|
encryptedMessage: unidentifiedSenderMessage.encryptedMessage.toArrayBuffer(),
|
|
|
|
|
|
|
|
serialized,
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
// public UnidentifiedSenderMessage(
|
|
|
|
// ECPublicKey ephemeral, byte[] encryptedStatic, byte[] encryptedMessage) {
|
|
|
|
function _createUnidentifiedSenderMessage(
|
2021-02-27 00:00:37 +00:00
|
|
|
ephemeralPublic: ArrayBuffer,
|
|
|
|
encryptedStatic: ArrayBuffer,
|
|
|
|
encryptedMessage: ArrayBuffer
|
|
|
|
): ExplodedMessageType {
|
2018-10-18 01:01:21 +00:00
|
|
|
const versionBytes = new Uint8Array([
|
|
|
|
intsToByteHighAndLow(CIPHERTEXT_VERSION, CIPHERTEXT_VERSION),
|
|
|
|
]);
|
2021-02-27 00:00:37 +00:00
|
|
|
const unidentifiedSenderMessage = new window.textsecure.protobuf.UnidentifiedSenderMessage();
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
unidentifiedSenderMessage.encryptedMessage = encryptedMessage;
|
|
|
|
unidentifiedSenderMessage.encryptedStatic = encryptedStatic;
|
|
|
|
unidentifiedSenderMessage.ephemeralPublic = ephemeralPublic;
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
const messageBytes = unidentifiedSenderMessage.toArrayBuffer();
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
return {
|
|
|
|
version: CIPHERTEXT_VERSION,
|
|
|
|
|
|
|
|
ephemeralPublic,
|
|
|
|
encryptedStatic,
|
|
|
|
encryptedMessage,
|
|
|
|
|
|
|
|
serialized: concatenateBytes(versionBytes, messageBytes),
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
// public UnidentifiedSenderMessageContent(byte[] serialized)
|
2021-02-27 00:00:37 +00:00
|
|
|
function _createUnidentifiedSenderMessageContentFromBuffer(
|
|
|
|
serialized: ArrayBuffer
|
|
|
|
): ExplodedInnerMessageType {
|
|
|
|
const TypeEnum =
|
|
|
|
window.textsecure.protobuf.UnidentifiedSenderMessage.Message.Type;
|
2018-10-18 01:01:21 +00:00
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
const message = window.textsecure.protobuf.UnidentifiedSenderMessage.Message.decode(
|
2018-10-18 01:01:21 +00:00
|
|
|
serialized
|
|
|
|
);
|
|
|
|
|
|
|
|
if (!message.type || !message.senderCertificate || !message.content) {
|
|
|
|
throw new Error('Missing fields');
|
|
|
|
}
|
|
|
|
|
|
|
|
let type;
|
|
|
|
switch (message.type) {
|
|
|
|
case TypeEnum.MESSAGE:
|
|
|
|
type = CiphertextMessage.WHISPER_TYPE;
|
|
|
|
break;
|
|
|
|
case TypeEnum.PREKEY_MESSAGE:
|
|
|
|
type = CiphertextMessage.PREKEY_TYPE;
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
throw new Error(`Unknown type: ${message.type}`);
|
|
|
|
}
|
|
|
|
|
|
|
|
return {
|
|
|
|
type,
|
|
|
|
senderCertificate: _createSenderCertificateFromBuffer(
|
|
|
|
message.senderCertificate.toArrayBuffer()
|
|
|
|
),
|
|
|
|
content: message.content.toArrayBuffer(),
|
|
|
|
|
|
|
|
serialized,
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
// private int getProtoType(int type)
|
2021-02-27 00:00:37 +00:00
|
|
|
function _getProtoMessageType(type: number): number {
|
|
|
|
const TypeEnum =
|
|
|
|
window.textsecure.protobuf.UnidentifiedSenderMessage.Message.Type;
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
switch (type) {
|
|
|
|
case CiphertextMessage.WHISPER_TYPE:
|
|
|
|
return TypeEnum.MESSAGE;
|
|
|
|
case CiphertextMessage.PREKEY_TYPE:
|
|
|
|
return TypeEnum.PREKEY_MESSAGE;
|
|
|
|
default:
|
|
|
|
throw new Error(`_getProtoMessageType: type '${type}' does not exist`);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// public UnidentifiedSenderMessageContent(
|
|
|
|
// int type, SenderCertificate senderCertificate, byte[] content)
|
|
|
|
function _createUnidentifiedSenderMessageContent(
|
2021-02-27 00:00:37 +00:00
|
|
|
type: number,
|
|
|
|
senderCertificate: SerializedCertificateType,
|
|
|
|
content: ArrayBuffer
|
|
|
|
): ArrayBuffer {
|
|
|
|
const innerMessage = new window.textsecure.protobuf.UnidentifiedSenderMessage.Message();
|
2018-10-18 01:01:21 +00:00
|
|
|
innerMessage.type = _getProtoMessageType(type);
|
2021-02-27 00:00:37 +00:00
|
|
|
innerMessage.senderCertificate = window.textsecure.protobuf.SenderCertificate.decode(
|
2018-10-18 01:01:21 +00:00
|
|
|
senderCertificate.serialized
|
|
|
|
);
|
|
|
|
innerMessage.content = content;
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
return innerMessage.toArrayBuffer();
|
2018-10-18 01:01:21 +00:00
|
|
|
}
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
export class SecretSessionCipher {
|
|
|
|
storage: typeof window.textsecure.storage.protocol;
|
|
|
|
|
|
|
|
options: { messageKeysLimit?: number | boolean };
|
|
|
|
|
|
|
|
SessionCipher: typeof window.libsignal.SessionCipher;
|
|
|
|
|
|
|
|
constructor(
|
|
|
|
storage: typeof window.textsecure.storage.protocol,
|
|
|
|
options?: { messageKeysLimit?: number | boolean }
|
|
|
|
) {
|
|
|
|
this.storage = storage;
|
|
|
|
|
|
|
|
// Do this on construction because libsignal won't be available when this file loads
|
|
|
|
const { SessionCipher } = window.libsignal;
|
|
|
|
this.SessionCipher = SessionCipher;
|
|
|
|
|
|
|
|
this.options = options || {};
|
|
|
|
}
|
|
|
|
|
2018-10-18 01:01:21 +00:00
|
|
|
// public byte[] encrypt(
|
|
|
|
// SignalProtocolAddress destinationAddress,
|
|
|
|
// SenderCertificate senderCertificate,
|
|
|
|
// byte[] paddedPlaintext
|
|
|
|
// )
|
2021-02-27 00:00:37 +00:00
|
|
|
async encrypt(
|
|
|
|
destinationAddress: SignalProtocolAddressClass,
|
|
|
|
senderCertificate: SerializedCertificateType,
|
|
|
|
paddedPlaintext: ArrayBuffer
|
|
|
|
): Promise<ArrayBuffer> {
|
2018-10-18 01:01:21 +00:00
|
|
|
// Capture this.xxx variables to replicate Java's implicit this syntax
|
|
|
|
const { SessionCipher } = this;
|
|
|
|
const signalProtocolStore = this.storage;
|
|
|
|
|
|
|
|
const sessionCipher = new SessionCipher(
|
|
|
|
signalProtocolStore,
|
2021-02-08 22:19:35 +00:00
|
|
|
destinationAddress,
|
|
|
|
this.options
|
2018-10-18 01:01:21 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
const message = await sessionCipher.encrypt(paddedPlaintext);
|
|
|
|
const ourIdentity = await signalProtocolStore.getIdentityKeyPair();
|
2021-02-27 00:00:37 +00:00
|
|
|
const theirIdentityData = await signalProtocolStore.loadIdentityKey(
|
|
|
|
destinationAddress.getName()
|
2018-10-18 01:01:21 +00:00
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
if (!theirIdentityData) {
|
|
|
|
throw new Error(
|
|
|
|
'SecretSessionCipher.encrypt: No identity data for recipient!'
|
|
|
|
);
|
|
|
|
}
|
|
|
|
const theirIdentity =
|
|
|
|
typeof theirIdentityData === 'string'
|
|
|
|
? fromEncodedBinaryToArrayBuffer(theirIdentityData)
|
|
|
|
: theirIdentityData;
|
2018-10-18 01:01:21 +00:00
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
const ephemeral = await window.libsignal.Curve.async.generateKeyPair();
|
2018-10-18 01:01:21 +00:00
|
|
|
const ephemeralSalt = concatenateBytes(
|
|
|
|
bytesFromString(UNIDENTIFIED_DELIVERY_PREFIX),
|
|
|
|
theirIdentity,
|
|
|
|
ephemeral.pubKey
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const ephemeralKeys = await this._calculateEphemeralKeys(
|
2018-10-18 01:01:21 +00:00
|
|
|
theirIdentity,
|
|
|
|
ephemeral.privKey,
|
|
|
|
ephemeralSalt
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const staticKeyCiphertext = await this._encryptWithSecretKeys(
|
2018-10-18 01:01:21 +00:00
|
|
|
ephemeralKeys.cipherKey,
|
|
|
|
ephemeralKeys.macKey,
|
|
|
|
ourIdentity.pubKey
|
|
|
|
);
|
|
|
|
|
|
|
|
const staticSalt = concatenateBytes(
|
|
|
|
ephemeralKeys.chainKey,
|
|
|
|
staticKeyCiphertext
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const staticKeys = await this._calculateStaticKeys(
|
2018-10-18 01:01:21 +00:00
|
|
|
theirIdentity,
|
|
|
|
ourIdentity.privKey,
|
|
|
|
staticSalt
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const serializedMessage = _createUnidentifiedSenderMessageContent(
|
2018-10-18 01:01:21 +00:00
|
|
|
message.type,
|
|
|
|
senderCertificate,
|
|
|
|
fromEncodedBinaryToArrayBuffer(message.body)
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const messageBytes = await this._encryptWithSecretKeys(
|
2018-10-18 01:01:21 +00:00
|
|
|
staticKeys.cipherKey,
|
|
|
|
staticKeys.macKey,
|
2021-02-27 00:00:37 +00:00
|
|
|
serializedMessage
|
2018-10-18 01:01:21 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
const unidentifiedSenderMessage = _createUnidentifiedSenderMessage(
|
|
|
|
ephemeral.pubKey,
|
|
|
|
staticKeyCiphertext,
|
|
|
|
messageBytes
|
|
|
|
);
|
|
|
|
|
|
|
|
return unidentifiedSenderMessage.serialized;
|
2021-02-27 00:00:37 +00:00
|
|
|
}
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
// public Pair<SignalProtocolAddress, byte[]> decrypt(
|
|
|
|
// CertificateValidator validator, byte[] ciphertext, long timestamp)
|
2021-02-27 00:00:37 +00:00
|
|
|
async decrypt(
|
|
|
|
validator: ValidatorType,
|
|
|
|
ciphertext: ArrayBuffer,
|
|
|
|
timestamp: number,
|
|
|
|
me?: MeType
|
|
|
|
): Promise<{
|
|
|
|
isMe?: boolean;
|
|
|
|
sender?: SignalProtocolAddressClass;
|
|
|
|
senderUuid?: SignalProtocolAddressClass;
|
|
|
|
content?: ArrayBuffer;
|
|
|
|
}> {
|
2018-10-18 01:01:21 +00:00
|
|
|
const signalProtocolStore = this.storage;
|
|
|
|
const ourIdentity = await signalProtocolStore.getIdentityKeyPair();
|
|
|
|
const wrapper = _createUnidentifiedSenderMessageFromBuffer(ciphertext);
|
|
|
|
const ephemeralSalt = concatenateBytes(
|
|
|
|
bytesFromString(UNIDENTIFIED_DELIVERY_PREFIX),
|
|
|
|
ourIdentity.pubKey,
|
|
|
|
wrapper.ephemeralPublic
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const ephemeralKeys = await this._calculateEphemeralKeys(
|
2018-10-18 01:01:21 +00:00
|
|
|
wrapper.ephemeralPublic,
|
|
|
|
ourIdentity.privKey,
|
|
|
|
ephemeralSalt
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const staticKeyBytes = await this._decryptWithSecretKeys(
|
2018-10-18 01:01:21 +00:00
|
|
|
ephemeralKeys.cipherKey,
|
|
|
|
ephemeralKeys.macKey,
|
|
|
|
wrapper.encryptedStatic
|
|
|
|
);
|
|
|
|
|
|
|
|
const staticKey = _decodePoint(staticKeyBytes, 0);
|
|
|
|
const staticSalt = concatenateBytes(
|
|
|
|
ephemeralKeys.chainKey,
|
|
|
|
wrapper.encryptedStatic
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const staticKeys = await this._calculateStaticKeys(
|
2018-10-18 01:01:21 +00:00
|
|
|
staticKey,
|
|
|
|
ourIdentity.privKey,
|
|
|
|
staticSalt
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const messageBytes = await this._decryptWithSecretKeys(
|
2018-10-18 01:01:21 +00:00
|
|
|
staticKeys.cipherKey,
|
|
|
|
staticKeys.macKey,
|
|
|
|
wrapper.encryptedMessage
|
|
|
|
);
|
|
|
|
|
|
|
|
const content = _createUnidentifiedSenderMessageContentFromBuffer(
|
|
|
|
messageBytes
|
|
|
|
);
|
|
|
|
|
|
|
|
await validator.validate(content.senderCertificate, timestamp);
|
|
|
|
if (
|
|
|
|
!constantTimeEqual(content.senderCertificate.identityKey, staticKeyBytes)
|
|
|
|
) {
|
|
|
|
throw new Error(
|
|
|
|
"Sender's certificate key does not match key used in message"
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
2020-03-05 21:14:58 +00:00
|
|
|
const { sender, senderUuid, senderDevice } = content.senderCertificate;
|
|
|
|
if (
|
2021-02-27 00:00:37 +00:00
|
|
|
me &&
|
2020-03-05 21:14:58 +00:00
|
|
|
((sender && me.number && sender === me.number) ||
|
|
|
|
(senderUuid && me.uuid && senderUuid === me.uuid)) &&
|
|
|
|
senderDevice === me.deviceId
|
|
|
|
) {
|
2018-10-18 01:01:21 +00:00
|
|
|
return {
|
|
|
|
isMe: true,
|
|
|
|
};
|
|
|
|
}
|
2021-02-27 00:00:37 +00:00
|
|
|
const addressE164 = sender
|
|
|
|
? new window.libsignal.SignalProtocolAddress(sender, senderDevice)
|
|
|
|
: undefined;
|
|
|
|
const addressUuid = senderUuid
|
|
|
|
? new window.libsignal.SignalProtocolAddress(
|
|
|
|
senderUuid.toLowerCase(),
|
|
|
|
senderDevice
|
|
|
|
)
|
|
|
|
: undefined;
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
try {
|
|
|
|
return {
|
2020-03-05 21:14:58 +00:00
|
|
|
sender: addressE164,
|
|
|
|
senderUuid: addressUuid,
|
2021-02-27 00:00:37 +00:00
|
|
|
content: await this._decryptWithUnidentifiedSenderMessage(content),
|
2018-10-18 01:01:21 +00:00
|
|
|
};
|
|
|
|
} catch (error) {
|
2019-02-13 19:56:43 +00:00
|
|
|
if (!error) {
|
|
|
|
// eslint-disable-next-line no-ex-assign
|
|
|
|
error = new Error('Decryption error was falsey!');
|
|
|
|
}
|
|
|
|
|
2020-03-05 21:14:58 +00:00
|
|
|
error.sender = addressE164;
|
|
|
|
error.senderUuid = addressUuid;
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
throw error;
|
|
|
|
}
|
2021-02-27 00:00:37 +00:00
|
|
|
}
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
// public int getSessionVersion(SignalProtocolAddress remoteAddress) {
|
2021-02-27 00:00:37 +00:00
|
|
|
getSessionVersion(
|
|
|
|
remoteAddress: SignalProtocolAddressClass
|
|
|
|
): Promise<number> {
|
2018-10-18 01:01:21 +00:00
|
|
|
const { SessionCipher } = this;
|
|
|
|
const signalProtocolStore = this.storage;
|
|
|
|
|
2021-02-08 22:19:35 +00:00
|
|
|
const cipher = new SessionCipher(
|
|
|
|
signalProtocolStore,
|
|
|
|
remoteAddress,
|
|
|
|
this.options
|
|
|
|
);
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
return cipher.getSessionVersion();
|
2021-02-27 00:00:37 +00:00
|
|
|
}
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
// public int getRemoteRegistrationId(SignalProtocolAddress remoteAddress) {
|
2021-02-27 00:00:37 +00:00
|
|
|
getRemoteRegistrationId(
|
|
|
|
remoteAddress: SignalProtocolAddressClass
|
|
|
|
): Promise<number> {
|
2018-10-18 01:01:21 +00:00
|
|
|
const { SessionCipher } = this;
|
|
|
|
const signalProtocolStore = this.storage;
|
|
|
|
|
2021-02-08 22:19:35 +00:00
|
|
|
const cipher = new SessionCipher(
|
|
|
|
signalProtocolStore,
|
|
|
|
remoteAddress,
|
|
|
|
this.options
|
|
|
|
);
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
return cipher.getRemoteRegistrationId();
|
2021-02-27 00:00:37 +00:00
|
|
|
}
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
// Used by outgoing_message.js
|
2021-02-27 00:00:37 +00:00
|
|
|
closeOpenSessionForDevice(
|
|
|
|
remoteAddress: SignalProtocolAddressClass
|
|
|
|
): Promise<void> {
|
2018-10-18 01:01:21 +00:00
|
|
|
const { SessionCipher } = this;
|
|
|
|
const signalProtocolStore = this.storage;
|
|
|
|
|
2021-02-08 22:19:35 +00:00
|
|
|
const cipher = new SessionCipher(
|
|
|
|
signalProtocolStore,
|
|
|
|
remoteAddress,
|
|
|
|
this.options
|
|
|
|
);
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
return cipher.closeOpenSessionForDevice();
|
2021-02-27 00:00:37 +00:00
|
|
|
}
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
// private EphemeralKeys calculateEphemeralKeys(
|
|
|
|
// ECPublicKey ephemeralPublic, ECPrivateKey ephemeralPrivate, byte[] salt)
|
2021-02-27 00:00:37 +00:00
|
|
|
private async _calculateEphemeralKeys(
|
|
|
|
ephemeralPublic: ArrayBuffer,
|
|
|
|
ephemeralPrivate: ArrayBuffer,
|
|
|
|
salt: ArrayBuffer
|
|
|
|
): Promise<{
|
|
|
|
chainKey: ArrayBuffer;
|
|
|
|
cipherKey: ArrayBuffer;
|
|
|
|
macKey: ArrayBuffer;
|
|
|
|
}> {
|
|
|
|
const ephemeralSecret = await window.libsignal.Curve.async.calculateAgreement(
|
2018-10-18 01:01:21 +00:00
|
|
|
ephemeralPublic,
|
|
|
|
ephemeralPrivate
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const ephemeralDerivedParts = await window.libsignal.HKDF.deriveSecrets(
|
2018-10-18 01:01:21 +00:00
|
|
|
ephemeralSecret,
|
|
|
|
salt,
|
2021-02-27 00:00:37 +00:00
|
|
|
new ArrayBuffer(0)
|
2018-10-18 01:01:21 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
// private EphemeralKeys(byte[] chainKey, byte[] cipherKey, byte[] macKey)
|
|
|
|
return {
|
|
|
|
chainKey: ephemeralDerivedParts[0],
|
|
|
|
cipherKey: ephemeralDerivedParts[1],
|
|
|
|
macKey: ephemeralDerivedParts[2],
|
|
|
|
};
|
2021-02-27 00:00:37 +00:00
|
|
|
}
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
// private StaticKeys calculateStaticKeys(
|
|
|
|
// ECPublicKey staticPublic, ECPrivateKey staticPrivate, byte[] salt)
|
2021-02-27 00:00:37 +00:00
|
|
|
private async _calculateStaticKeys(
|
|
|
|
staticPublic: ArrayBuffer,
|
|
|
|
staticPrivate: ArrayBuffer,
|
|
|
|
salt: ArrayBuffer
|
|
|
|
): Promise<{ cipherKey: ArrayBuffer; macKey: ArrayBuffer }> {
|
|
|
|
const staticSecret = await window.libsignal.Curve.async.calculateAgreement(
|
2018-10-18 01:01:21 +00:00
|
|
|
staticPublic,
|
|
|
|
staticPrivate
|
|
|
|
);
|
2021-02-27 00:00:37 +00:00
|
|
|
const staticDerivedParts = await window.libsignal.HKDF.deriveSecrets(
|
2018-10-18 01:01:21 +00:00
|
|
|
staticSecret,
|
|
|
|
salt,
|
2021-02-27 00:00:37 +00:00
|
|
|
new ArrayBuffer(0)
|
2018-10-18 01:01:21 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
// private StaticKeys(byte[] cipherKey, byte[] macKey)
|
|
|
|
return {
|
|
|
|
cipherKey: staticDerivedParts[1],
|
|
|
|
macKey: staticDerivedParts[2],
|
|
|
|
};
|
2021-02-27 00:00:37 +00:00
|
|
|
}
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
// private byte[] decrypt(UnidentifiedSenderMessageContent message)
|
2021-02-27 00:00:37 +00:00
|
|
|
private _decryptWithUnidentifiedSenderMessage(
|
|
|
|
message: ExplodedInnerMessageType
|
|
|
|
): Promise<ArrayBuffer> {
|
2018-10-18 01:01:21 +00:00
|
|
|
const { SessionCipher } = this;
|
|
|
|
const signalProtocolStore = this.storage;
|
|
|
|
|
2021-02-27 00:00:37 +00:00
|
|
|
if (!message.senderCertificate) {
|
|
|
|
throw new Error(
|
|
|
|
'_decryptWithUnidentifiedSenderMessage: Message had no senderCertificate'
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
|
|
|
const { senderUuid, sender, senderDevice } = message.senderCertificate;
|
|
|
|
const target = senderUuid || sender;
|
|
|
|
if (!senderDevice || !target) {
|
|
|
|
throw new Error(
|
|
|
|
'_decryptWithUnidentifiedSenderMessage: Missing sender information in senderCertificate'
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
|
|
|
const address = new window.libsignal.SignalProtocolAddress(
|
|
|
|
target,
|
|
|
|
senderDevice
|
2018-10-18 01:01:21 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
switch (message.type) {
|
|
|
|
case CiphertextMessage.WHISPER_TYPE:
|
|
|
|
return new SessionCipher(
|
|
|
|
signalProtocolStore,
|
2021-02-27 00:00:37 +00:00
|
|
|
address,
|
2021-02-08 22:19:35 +00:00
|
|
|
this.options
|
2018-10-18 01:01:21 +00:00
|
|
|
).decryptWhisperMessage(message.content);
|
|
|
|
case CiphertextMessage.PREKEY_TYPE:
|
|
|
|
return new SessionCipher(
|
|
|
|
signalProtocolStore,
|
2021-02-27 00:00:37 +00:00
|
|
|
address,
|
2021-02-08 22:19:35 +00:00
|
|
|
this.options
|
2018-10-18 01:01:21 +00:00
|
|
|
).decryptPreKeyWhisperMessage(message.content);
|
|
|
|
default:
|
|
|
|
throw new Error(`Unknown type: ${message.type}`);
|
|
|
|
}
|
2021-02-27 00:00:37 +00:00
|
|
|
}
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
// private byte[] encrypt(
|
|
|
|
// SecretKeySpec cipherKey, SecretKeySpec macKey, byte[] plaintext)
|
2021-02-27 00:00:37 +00:00
|
|
|
private async _encryptWithSecretKeys(
|
|
|
|
cipherKey: ArrayBuffer,
|
|
|
|
macKey: ArrayBuffer,
|
|
|
|
plaintext: ArrayBuffer
|
|
|
|
): Promise<ArrayBuffer> {
|
2018-10-18 01:01:21 +00:00
|
|
|
// Cipher const cipher = Cipher.getInstance('AES/CTR/NoPadding');
|
|
|
|
// cipher.init(Cipher.ENCRYPT_MODE, cipherKey, new IvParameterSpec(new byte[16]));
|
|
|
|
|
|
|
|
// Mac const mac = Mac.getInstance('HmacSHA256');
|
|
|
|
// mac.init(macKey);
|
|
|
|
|
|
|
|
// byte[] const ciphertext = cipher.doFinal(plaintext);
|
|
|
|
const ciphertext = await encryptAesCtr(cipherKey, plaintext, getZeroes(16));
|
|
|
|
|
|
|
|
// byte[] const ourFullMac = mac.doFinal(ciphertext);
|
|
|
|
const ourFullMac = await hmacSha256(macKey, ciphertext);
|
|
|
|
const ourMac = trimBytes(ourFullMac, 10);
|
|
|
|
|
|
|
|
return concatenateBytes(ciphertext, ourMac);
|
2021-02-27 00:00:37 +00:00
|
|
|
}
|
2018-10-18 01:01:21 +00:00
|
|
|
|
|
|
|
// private byte[] decrypt(
|
|
|
|
// SecretKeySpec cipherKey, SecretKeySpec macKey, byte[] ciphertext)
|
2021-02-27 00:00:37 +00:00
|
|
|
private async _decryptWithSecretKeys(
|
|
|
|
cipherKey: ArrayBuffer,
|
|
|
|
macKey: ArrayBuffer,
|
|
|
|
ciphertext: ArrayBuffer
|
|
|
|
): Promise<ArrayBuffer> {
|
2018-10-18 01:01:21 +00:00
|
|
|
if (ciphertext.byteLength < 10) {
|
|
|
|
throw new Error('Ciphertext not long enough for MAC!');
|
|
|
|
}
|
|
|
|
|
|
|
|
const ciphertextParts = splitBytes(
|
|
|
|
ciphertext,
|
|
|
|
ciphertext.byteLength - 10,
|
|
|
|
10
|
|
|
|
);
|
|
|
|
|
|
|
|
// Mac const mac = Mac.getInstance('HmacSHA256');
|
|
|
|
// mac.init(macKey);
|
|
|
|
|
|
|
|
// byte[] const digest = mac.doFinal(ciphertextParts[0]);
|
|
|
|
const digest = await hmacSha256(macKey, ciphertextParts[0]);
|
|
|
|
const ourMac = trimBytes(digest, 10);
|
|
|
|
const theirMac = ciphertextParts[1];
|
|
|
|
|
|
|
|
if (!constantTimeEqual(ourMac, theirMac)) {
|
2021-02-27 00:00:37 +00:00
|
|
|
throw new Error('SecretSessionCipher/_decryptWithSecretKeys: Bad MAC!');
|
2018-10-18 01:01:21 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Cipher const cipher = Cipher.getInstance('AES/CTR/NoPadding');
|
|
|
|
// cipher.init(Cipher.DECRYPT_MODE, cipherKey, new IvParameterSpec(new byte[16]));
|
|
|
|
|
|
|
|
// return cipher.doFinal(ciphertextParts[0]);
|
|
|
|
return decryptAesCtr(cipherKey, ciphertextParts[0], getZeroes(16));
|
2021-02-27 00:00:37 +00:00
|
|
|
}
|
|
|
|
}
|