Repository navigation
QUIC: enforce AEAD usage limits and initiate key updates #217
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
ef31208
e7ab354
866641c
68c7453
7189db5
cd507e3
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -1762,6 +1762,136 @@ final class ProtectorTests: XCTestCase { | |
| ) | ||
| } | ||
|
|
||
| private func sealOne( | ||
| _ protector: inout Protector, | ||
| number: Int64, | ||
| keyState: PacketKeyState | ||
| ) throws { | ||
| var frame = Frame(copyBuffer: [UInt8](repeating: 0, count: 133)) | ||
| defer { | ||
| frame.finalize(success: true) | ||
| } | ||
| var packet = Packet( | ||
| number: PacketNumber(number), | ||
| lastAcked: 0, | ||
| keyState: keyState | ||
| ) | ||
| packet.overrideSentNumberSize = .twoBytes | ||
|
|
||
| packet.headerLength = 17 | ||
| packet.payloadLength = 116 | ||
| packet.tagLength = 16 | ||
| packet.packetNumberLength = 2 | ||
|
|
||
| try protector.seal(&packet, frame: &frame) | ||
| } | ||
|
|
||
| func testConfidentialityLimit() throws { | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Could you please add a test for failedDecryptionCount?
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Added testIntegrityLimit in
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. nb section 6.6 goes 2^52 limit for aes gcm and 2^36 for chacha20-poly1305, documented in the description |
||
| let cid = QUICConnectionID([0x59, 0x26, 0xf7, 0x05, 0xd0, 0xe0, 0x97, 0x98])! | ||
| let secret = SymmetricKey(data: [UInt8](repeating: 0x2a, count: 32)) | ||
| let defaultProtector = Protector( | ||
| isClient: true, | ||
| destinationCID: cid, | ||
| logPrefixer: protectorTestsLogPrefixer | ||
| ) | ||
| XCTAssertEqual(defaultProtector.aesGCMConfidentialityLimit, 1 << 23) | ||
|
|
||
| var protector = Protector( | ||
| isClient: true, | ||
| destinationCID: cid, | ||
| logPrefixer: protectorTestsLogPrefixer, | ||
| aesGCMConfidentialityLimit: 4 | ||
| ) | ||
| for isWrite in [true, false] { | ||
| protector.keyUpdate( | ||
| for: .application, | ||
| cipherSuite: .aesGCM128SHA256, | ||
| secret: secret, | ||
| isWrite: isWrite | ||
| ) | ||
| } | ||
| XCTAssertEqual(protector.integrityLimit(for: .phase0), 1 << 52) | ||
|
|
||
| try sealOne(&protector, number: 0, keyState: .phase0) | ||
| XCTAssertFalse(protector.keyUpdateNeeded(for: .phase0)) | ||
| try sealOne(&protector, number: 1, keyState: .phase0) | ||
| XCTAssertTrue(protector.keyUpdateNeeded(for: .phase0)) | ||
| XCTAssertFalse(protector.sealLimitImminent(for: .phase0)) | ||
| try sealOne(&protector, number: 2, keyState: .phase0) | ||
| // Only the packet kept for a CONNECTION_CLOSE is left | ||
| XCTAssertTrue(protector.sealLimitImminent(for: .phase0)) | ||
| try sealOne(&protector, number: 3, keyState: .phase0) | ||
| // The key has reached its limit and must not seal another packet | ||
| XCTAssertThrowsError(try sealOne(&protector, number: 4, keyState: .phase0)) | ||
|
|
||
| // The updated key starts a new count | ||
| protector.trafficUpdate(previousKeyState: .phase0) | ||
| XCTAssertFalse(protector.keyUpdateNeeded(for: .phase1)) | ||
| try sealOne(&protector, number: 4, keyState: .phase1) | ||
|
|
||
| // ChaCha20-Poly1305 has no confidentiality limit to enforce | ||
| var chachaProtector = Protector( | ||
| isClient: true, | ||
| destinationCID: cid, | ||
| logPrefixer: protectorTestsLogPrefixer, | ||
| aesGCMConfidentialityLimit: 4 | ||
| ) | ||
| for isWrite in [true, false] { | ||
| chachaProtector.keyUpdate( | ||
| for: .application, | ||
| cipherSuite: .chacha20Poly1350SHA256, | ||
| secret: secret, | ||
| isWrite: isWrite | ||
| ) | ||
| } | ||
| XCTAssertEqual(chachaProtector.integrityLimit(for: .phase0), 1 << 36) | ||
| for number: Int64 in 0..<5 { | ||
| try sealOne(&chachaProtector, number: number, keyState: .phase0) | ||
| } | ||
| XCTAssertFalse(chachaProtector.keyUpdateNeeded(for: .phase0)) | ||
| } | ||
|
|
||
| func testIntegrityLimit() throws { | ||
| let cid = QUICConnectionID([0x59, 0x26, 0xf7, 0x05, 0xd0, 0xe0, 0x97, 0x98])! | ||
| let secret = SymmetricKey(data: [UInt8](repeating: 0x2a, count: 32)) | ||
| let limits: [(TLSCipherSuite, UInt64)] = [ | ||
| (.aesGCM128SHA256, 1 << 52), | ||
| (.chacha20Poly1350SHA256, 1 << 36), | ||
| ] | ||
| for (cipherSuite, limit) in limits { | ||
| var protector = Protector( | ||
| isClient: true, | ||
| destinationCID: cid, | ||
| logPrefixer: protectorTestsLogPrefixer | ||
| ) | ||
| for isWrite in [true, false] { | ||
| protector.keyUpdate( | ||
| for: .application, | ||
| cipherSuite: cipherSuite, | ||
| secret: secret, | ||
| isWrite: isWrite | ||
| ) | ||
| } | ||
| XCTAssertEqual(protector.integrityLimit(for: .phase0), limit) | ||
| XCTAssertEqual(protector.failedDecryptionCount, 0) | ||
|
|
||
| XCTAssertFalse(protector.failedDecryption(for: .phase0)) | ||
| XCTAssertEqual(protector.failedDecryptionCount, 1) | ||
|
|
||
| // The count covers all keys, so a key update does not reset it | ||
| protector.trafficUpdate(previousKeyState: .phase0) | ||
| XCTAssertFalse(protector.failedDecryption(for: .phase1)) | ||
| XCTAssertEqual(protector.failedDecryptionCount, 2) | ||
|
|
||
| // Reaching the limit is allowed, exceeding it is not | ||
| protector.failedDecryptionCount = limit - 1 | ||
| XCTAssertFalse(protector.failedDecryption(for: .phase1)) | ||
| XCTAssertEqual(protector.failedDecryptionCount, limit) | ||
| XCTAssertTrue(protector.failedDecryption(for: .phase1)) | ||
| XCTAssertEqual(protector.failedDecryptionCount, limit + 1) | ||
| } | ||
| } | ||
|
|
||
| func testRetryProtectionOpen() throws { | ||
| // RFC 9001 Appendix A.4 Retry | ||
| let retryPacket: [UInt8] = [ | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The RFC uses a conservative value. In practice, packets are never 64KB, so our limit is around ~2^28, but we do need to limit it based on the RFC.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Agreed, kept 2^23 cuz cheap and unconditional