use javax api instead of BC for file decryption

This commit is contained in:
Daniel Gultsch 2018-09-17 17:47:51 +02:00
parent 67e7d2cf9e
commit 09eca8478e

View file

@ -6,140 +6,128 @@ import android.content.pm.PackageManager;
import android.os.Build; import android.os.Build;
import android.os.PowerManager; import android.os.PowerManager;
import android.os.SystemClock; import android.os.SystemClock;
import android.util.Log;
import android.util.Pair; import android.util.Pair;
import org.bouncycastle.crypto.engines.AESEngine;
import org.bouncycastle.crypto.modes.AEADBlockCipher;
import org.bouncycastle.crypto.modes.GCMBlockCipher;
import org.bouncycastle.crypto.params.AEADParameters;
import org.bouncycastle.crypto.params.KeyParameter;
import java.io.FileInputStream; import java.io.FileInputStream;
import java.io.FileNotFoundException; import java.io.FileNotFoundException;
import java.io.FileOutputStream; import java.io.FileOutputStream;
import java.io.InputStream; import java.io.InputStream;
import java.io.OutputStream; import java.io.OutputStream;
import java.security.InvalidAlgorithmParameterException;
import java.security.InvalidKeyException;
import java.security.NoSuchAlgorithmException;
import java.util.concurrent.atomic.AtomicLong; import java.util.concurrent.atomic.AtomicLong;
import javax.crypto.Cipher; import javax.crypto.Cipher;
import javax.crypto.CipherInputStream; import javax.crypto.CipherInputStream;
import javax.crypto.CipherOutputStream; import javax.crypto.CipherOutputStream;
import javax.crypto.NoSuchPaddingException;
import javax.crypto.spec.IvParameterSpec; import javax.crypto.spec.IvParameterSpec;
import javax.crypto.spec.SecretKeySpec; import javax.crypto.spec.SecretKeySpec;
import eu.siacs.conversations.Config; import eu.siacs.conversations.Config;
import eu.siacs.conversations.R; import eu.siacs.conversations.R;
import eu.siacs.conversations.entities.DownloadableFile; import eu.siacs.conversations.entities.DownloadableFile;
import eu.siacs.conversations.utils.Compatibility;
public class AbstractConnectionManager { public class AbstractConnectionManager {
protected XmppConnectionService mXmppConnectionService;
private static final int UI_REFRESH_THRESHOLD = 250; private static final String KEYTYPE = "AES";
private static final AtomicLong LAST_UI_UPDATE_CALL = new AtomicLong(0); private static final String CIPHERMODE = "AES/GCM/NoPadding";
private static final String PROVIDER = "BC";
private static final int UI_REFRESH_THRESHOLD = 250;
private static final AtomicLong LAST_UI_UPDATE_CALL = new AtomicLong(0);
protected XmppConnectionService mXmppConnectionService;
public AbstractConnectionManager(XmppConnectionService service) { public AbstractConnectionManager(XmppConnectionService service) {
this.mXmppConnectionService = service; this.mXmppConnectionService = service;
} }
public XmppConnectionService getXmppConnectionService() { public static Pair<InputStream, Integer> createInputStream(DownloadableFile file, boolean gcm) throws FileNotFoundException {
return this.mXmppConnectionService; FileInputStream is;
} int size;
is = new FileInputStream(file);
size = (int) file.getSize();
if (file.getKey() == null) {
return new Pair<>(is, size);
}
try {
if (gcm) {
Cipher cipher = Compatibility.twentyTwo() ? Cipher.getInstance(CIPHERMODE) : Cipher.getInstance(CIPHERMODE, PROVIDER);
SecretKeySpec keySpec = new SecretKeySpec(file.getKey(), KEYTYPE);
IvParameterSpec ivSpec = new IvParameterSpec(file.getIv());
cipher.init(Cipher.ENCRYPT_MODE, keySpec, ivSpec);
return new Pair<>(new CipherInputStream(is, cipher), cipher.getOutputSize(size));
} else {
IvParameterSpec ips = new IvParameterSpec(file.getIv());
Cipher cipher = Cipher.getInstance("AES/CBC/PKCS5Padding");
cipher.init(Cipher.ENCRYPT_MODE, new SecretKeySpec(file.getKey(), KEYTYPE), ips);
return new Pair<>(new CipherInputStream(is, cipher), (size / 16 + 1) * 16);
}
} catch (Exception e) {
throw new AssertionError(e);
}
}
public long getAutoAcceptFileSize() { public static OutputStream createAppendedOutputStream(DownloadableFile file) {
return this.mXmppConnectionService.getLongPreference("auto_accept_file_size",R.integer.auto_accept_filesize); return createOutputStream(file, false, true);
} }
public boolean hasStoragePermission() { public static OutputStream createOutputStream(DownloadableFile file, boolean gcm) {
if (!Config.ONLY_INTERNAL_STORAGE && Build.VERSION.SDK_INT >= Build.VERSION_CODES.M) { return createOutputStream(file, gcm, false);
return mXmppConnectionService.checkSelfPermission(Manifest.permission.WRITE_EXTERNAL_STORAGE) == PackageManager.PERMISSION_GRANTED; }
} else {
return true;
}
}
public static Pair<InputStream,Integer> createInputStream(DownloadableFile file, boolean gcm) throws FileNotFoundException { private static OutputStream createOutputStream(DownloadableFile file, boolean gcm, boolean append) {
FileInputStream is; FileOutputStream os;
int size; try {
is = new FileInputStream(file); os = new FileOutputStream(file, append);
size = (int) file.getSize(); if (file.getKey() == null) {
if (file.getKey() == null) { return os;
return new Pair<>(is,size); }
} } catch (FileNotFoundException e) {
try { return null;
if (gcm) { }
AEADBlockCipher cipher = new GCMBlockCipher(new AESEngine()); try {
cipher.init(true, new AEADParameters(new KeyParameter(file.getKey()), 128, file.getIv())); if (gcm) {
InputStream cis = new org.bouncycastle.crypto.io.CipherInputStream(is, cipher); Cipher cipher = Compatibility.twentyTwo() ? Cipher.getInstance(CIPHERMODE) : Cipher.getInstance(CIPHERMODE, PROVIDER);
return new Pair<>(cis, cipher.getOutputSize(size)); SecretKeySpec keySpec = new SecretKeySpec(file.getKey(), KEYTYPE);
} else { IvParameterSpec ivSpec = new IvParameterSpec(file.getIv());
IvParameterSpec ips = new IvParameterSpec(file.getIv()); cipher.init(Cipher.DECRYPT_MODE, keySpec, ivSpec);
Cipher cipher = Cipher.getInstance("AES/CBC/PKCS5Padding"); return new CipherOutputStream(os, cipher);
cipher.init(Cipher.ENCRYPT_MODE, new SecretKeySpec(file.getKey(), "AES"), ips); } else {
Log.d(Config.LOGTAG, "opening encrypted input stream"); IvParameterSpec ips = new IvParameterSpec(file.getIv());
return new Pair<>(new CipherInputStream(is, cipher),(size / 16 + 1) * 16); Cipher cipher = Cipher.getInstance("AES/CBC/PKCS5Padding");
} cipher.init(Cipher.DECRYPT_MODE, new SecretKeySpec(file.getKey(), KEYTYPE), ips);
} catch (Exception e) { return new CipherOutputStream(os, cipher);
throw new AssertionError(e); }
} } catch (Exception e) {
} throw new AssertionError(e);
}
}
public static OutputStream createAppendedOutputStream(DownloadableFile file) { public XmppConnectionService getXmppConnectionService() {
return createOutputStream(file, false, true); return this.mXmppConnectionService;
} }
public static OutputStream createOutputStream(DownloadableFile file, boolean gcm) { public long getAutoAcceptFileSize() {
return createOutputStream(file, gcm, false); return this.mXmppConnectionService.getLongPreference("auto_accept_file_size", R.integer.auto_accept_filesize);
} }
private static OutputStream createOutputStream(DownloadableFile file, boolean gcm, boolean append) { public boolean hasStoragePermission() {
FileOutputStream os; if (!Config.ONLY_INTERNAL_STORAGE && Build.VERSION.SDK_INT >= Build.VERSION_CODES.M) {
try { return mXmppConnectionService.checkSelfPermission(Manifest.permission.WRITE_EXTERNAL_STORAGE) == PackageManager.PERMISSION_GRANTED;
os = new FileOutputStream(file, append); } else {
if (file.getKey() == null) { return true;
return os; }
} }
} catch (FileNotFoundException e) {
return null;
}
try {
if (gcm) {
AEADBlockCipher cipher = new GCMBlockCipher(new AESEngine());
cipher.init(false, new AEADParameters(new KeyParameter(file.getKey()), 128, file.getIv()));
return new org.bouncycastle.crypto.io.CipherOutputStream(os, cipher);
} else {
IvParameterSpec ips = new IvParameterSpec(file.getIv());
Cipher cipher = Cipher.getInstance("AES/CBC/PKCS5Padding");
cipher.init(Cipher.DECRYPT_MODE, new SecretKeySpec(file.getKey(), "AES"), ips);
Log.d(Config.LOGTAG, "opening encrypted output stream");
return new CipherOutputStream(os, cipher);
}
} catch (InvalidKeyException e) {
return null;
} catch (NoSuchAlgorithmException e) {
return null;
} catch (NoSuchPaddingException e) {
return null;
} catch (InvalidAlgorithmParameterException e) {
return null;
}
}
public void updateConversationUi(boolean force) { public void updateConversationUi(boolean force) {
synchronized (LAST_UI_UPDATE_CALL) { synchronized (LAST_UI_UPDATE_CALL) {
if (force || SystemClock.elapsedRealtime() - LAST_UI_UPDATE_CALL.get() >= UI_REFRESH_THRESHOLD) { if (force || SystemClock.elapsedRealtime() - LAST_UI_UPDATE_CALL.get() >= UI_REFRESH_THRESHOLD) {
LAST_UI_UPDATE_CALL.set(SystemClock.elapsedRealtime()); LAST_UI_UPDATE_CALL.set(SystemClock.elapsedRealtime());
mXmppConnectionService.updateConversationUi(); mXmppConnectionService.updateConversationUi();
} }
} }
} }
public PowerManager.WakeLock createWakeLock(String name) { public PowerManager.WakeLock createWakeLock(String name) {
PowerManager powerManager = (PowerManager) mXmppConnectionService.getSystemService(Context.POWER_SERVICE); PowerManager powerManager = (PowerManager) mXmppConnectionService.getSystemService(Context.POWER_SERVICE);
return powerManager.newWakeLock(PowerManager.PARTIAL_WAKE_LOCK,name); return powerManager.newWakeLock(PowerManager.PARTIAL_WAKE_LOCK, name);
} }
} }