-
Notifications
You must be signed in to change notification settings - Fork 4.8k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Implement AES-GCM with CryptoKit on macOS
With this change, GCM on macOS no longer uses OpenSSL, but routes into the CryptoKit library. This means that tags 12-15 bytes long are no longer supported on macOS.
- Loading branch information
Showing
12 changed files
with
383 additions
and
40 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
77 changes: 77 additions & 0 deletions
77
src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/AesGcm.macOS.cs
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,77 @@ | ||
// Licensed to the .NET Foundation under one or more agreements. | ||
// The .NET Foundation licenses this file to you under the MIT license. | ||
|
||
using System.Diagnostics; | ||
using System.Diagnostics.CodeAnalysis; | ||
using Microsoft.Win32.SafeHandles; | ||
|
||
namespace System.Security.Cryptography | ||
{ | ||
public sealed partial class AesGcm | ||
{ | ||
private byte[]? _key; | ||
|
||
// CryptoKit added AES.GCM in macOS 10.15, which is our minimum target for macOS. | ||
public static bool IsSupported => true; | ||
|
||
// CryptoKit only supports 16 byte tags. | ||
public static KeySizes TagByteSizes { get; } = new KeySizes(16, 16, 1); | ||
|
||
[MemberNotNull(nameof(_key))] | ||
private void ImportKey(ReadOnlySpan<byte> key) | ||
{ | ||
// We should only be calling this in the constructor, so there shouldn't be a previous key. | ||
Debug.Assert(_key is null); | ||
|
||
// Pin the array on the POH so that the GC doesn't move it around to allow zeroing to be more effective. | ||
_key = GC.AllocateArray<byte>(key.Length, pinned: true); | ||
key.CopyTo(_key); | ||
} | ||
|
||
private void EncryptCore( | ||
ReadOnlySpan<byte> nonce, | ||
ReadOnlySpan<byte> plaintext, | ||
Span<byte> ciphertext, | ||
Span<byte> tag, | ||
ReadOnlySpan<byte> associatedData) | ||
{ | ||
CheckDisposed(); | ||
Interop.AppleCrypto.AesGcmEncrypt( | ||
_key, | ||
nonce, | ||
plaintext, | ||
ciphertext, | ||
tag, | ||
associatedData); | ||
} | ||
|
||
private void DecryptCore( | ||
ReadOnlySpan<byte> nonce, | ||
ReadOnlySpan<byte> ciphertext, | ||
ReadOnlySpan<byte> tag, | ||
Span<byte> plaintext, | ||
ReadOnlySpan<byte> associatedData) | ||
{ | ||
CheckDisposed(); | ||
Interop.AppleCrypto.AesGcmDecrypt( | ||
_key, | ||
nonce, | ||
ciphertext, | ||
tag, | ||
plaintext, | ||
associatedData); | ||
} | ||
|
||
public void Dispose() | ||
{ | ||
CryptographicOperations.ZeroMemory(_key); | ||
_key = null; | ||
} | ||
|
||
[MemberNotNull(nameof(_key))] | ||
private void CheckDisposed() | ||
{ | ||
ObjectDisposedException.ThrowIf(_key is null, this); | ||
} | ||
} | ||
} |
Oops, something went wrong.