import javax.crypto.*;
import javax.crypto.spec.*;
import java.security.SecureRandom;
+import java.nio.ByteBuffer;
/**
* This class provides a communication API to the webserver. It also
class CloudComm {
private static final int SALT_SIZE = 8;
private static final int TIMEOUT_MILLIS = 2000; // 100
+ public static final int IV_SIZE = 16;
/** Sets the size for the HMAC. */
static final int HMAC_SIZE = 32;
private String baseurl;
- private Cipher encryptCipher;
- private Cipher decryptCipher;
+ private SecretKeySpec key;
private Mac mac;
private String password;
private SecureRandom random;
}
try {
- SecretKeySpec key = initKey();
+ key = initKey();
password = null; // drop password
mac = Mac.getInstance("HmacSHA256");
mac.init(key);
- encryptCipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
- encryptCipher.init(Cipher.ENCRYPT_MODE, key);
- decryptCipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
- decryptCipher.init(Cipher.DECRYPT_MODE, key);
} catch (Exception e) {
e.printStackTrace();
throw new Error("Failed To Initialize Ciphers");
byte[] saltTmp = new byte[SALT_SIZE];
random.nextBytes(saltTmp);
- for(int i = 0; i < SALT_SIZE;i++)
- {
- System.out.println((int)saltTmp[i]&255);
+ for (int i = 0; i < SALT_SIZE; i++) {
+ System.out.println((int)saltTmp[i] & 255);
}
URL url = new URL(baseurl + "?req=setsalt");
-
+
timer.startTime();
URLConnection con = url.openConnection();
HttpURLConnection http = (HttpURLConnection) con;
http.setDoOutput(true);
http.setConnectTimeout(TIMEOUT_MILLIS);
-
+
http.connect();
OutputStream os = http.getOutputStream();
os.write(saltTmp);
os.flush();
-
+
int responsecode = http.getResponseCode();
if (responsecode != HttpURLConnection.HTTP_OK) {
// TODO: Remove this print
http.setConnectTimeout(TIMEOUT_MILLIS);
http.setReadTimeout(TIMEOUT_MILLIS);
-
+
http.connect();
timer.endTime();
} catch (SocketTimeoutException e) {
}
}
+ private byte[] createIV(long machineId, long localSequenceNumber) {
+ ByteBuffer buffer = ByteBuffer.allocate(IV_SIZE);
+ buffer.putLong(machineId);
+ buffer.putLong(localSequenceNumber);
+ return buffer.array();
+
+ }
+
+ private byte[] encryptSlotAndPrependIV(byte[] rawData, byte[] ivBytes) {
+ try {
+ IvParameterSpec ivSpec = new IvParameterSpec(ivBytes);
+ Cipher cipher = Cipher.getInstance("AES/CTR/PKCS5Padding");
+ cipher.init(Cipher.ENCRYPT_MODE, key, ivSpec);
+
+ byte[] encryptedBytes = cipher.doFinal(rawData);
+
+ byte[] bytes = new byte[encryptedBytes.length + IV_SIZE];
+ System.arraycopy(ivBytes, 0, bytes, 0, ivBytes.length);
+ System.arraycopy(encryptedBytes, 0, bytes, IV_SIZE, encryptedBytes.length);
+
+ return bytes;
+
+ } catch (Exception e) {
+ e.printStackTrace();
+ throw new Error("Failed To Encrypt");
+ }
+ }
+
+
+ private byte[] stripIVAndDecryptSlot(byte[] rawData) {
+ try {
+ byte[] ivBytes = new byte[IV_SIZE];
+ byte[] encryptedBytes = new byte[rawData.length - IV_SIZE];
+ System.arraycopy(rawData, 0, ivBytes, 0, IV_SIZE);
+ System.arraycopy(rawData, IV_SIZE, encryptedBytes, 0 , encryptedBytes.length);
+
+ IvParameterSpec ivSpec = new IvParameterSpec(ivBytes);
+
+ Cipher cipher = Cipher.getInstance("AES/CTR/PKCS5Padding");
+ cipher.init(Cipher.DECRYPT_MODE, key, ivSpec);
+
+ return cipher.doFinal(encryptedBytes);
+
+ } catch (Exception e) {
+ e.printStackTrace();
+ throw new Error("Failed To Decrypt");
+ }
+ }
+
+
/*
* API for putting a slot into the queue. Returns null on success.
* On failure, the server will send slots with newer sequence
}
long sequencenumber = slot.getSequenceNumber();
- byte[] bytes = slot.encode(mac);
- bytes = encryptCipher.doFinal(bytes);
+ byte[] slotBytes = slot.encode(mac);
+ // slotBytes = encryptCipher.doFinal(slotBytes);
+ // byte[] iVBytes = slot.getSlotCryptIV();
+ // byte[] bytes = new byte[slotBytes.length + IV_SIZE];
+ // System.arraycopy(iVBytes, 0, bytes, 0, iVBytes.length);
+ // System.arraycopy(slotBytes, 0, bytes, IV_SIZE, slotBytes.length);
+ byte[] bytes = encryptSlotAndPrependIV(slotBytes, slot.getSlotCryptIV());
+
url = buildRequest(true, sequencenumber, max);
timer.startTime();
dis.readFully(resptype);
timer.endTime();
- if (Arrays.equals(resptype, "getslot".getBytes()))
- {
+ if (Arrays.equals(resptype, "getslot".getBytes())) {
return processSlots(dis);
- }
- else if (Arrays.equals(resptype, "putslot".getBytes()))
- {
+ } else if (Arrays.equals(resptype, "putslot".getBytes())) {
return null;
- }
- else
+ } else
throw new Error("Bad response to putslot");
} catch (SocketTimeoutException e) {
- timer.endTime();
+ timer.endTime();
throw new ServerException("putSlot failed", ServerException.TypeInputTimeout);
} catch (Exception e) {
// e.printStackTrace();
http.setConnectTimeout(TIMEOUT_MILLIS);
http.setReadTimeout(TIMEOUT_MILLIS);
-
+
http.connect();
timer.endTime();
}
try {
-
+
timer.startTime();
- InputStream is = http.getInputStream();
+ InputStream is = http.getInputStream();
DataInputStream dis = new DataInputStream(is);
byte[] resptype = new byte[7];
-
+
dis.readFully(resptype);
timer.endTime();
for (int i = 0; i < numberofslots; i++) {
- byte[] data = new byte[sizesofslots[i]];
- dis.readFully(data);
+ byte[] rawData = new byte[sizesofslots[i]];
+ dis.readFully(rawData);
+
+
+ // byte[] data = new byte[rawData.length - IV_SIZE];
+ // System.arraycopy(rawData, IV_SIZE, data, 0, data.length);
+
- data = decryptCipher.doFinal(data);
+ byte[] data = stripIVAndDecryptSlot(rawData);
+
+ // data = decryptCipher.doFinal(data);
slots[i] = Slot.decode(table, data, mac);
}
return slots;
}
- public byte[] sendLocalData(byte[] sendData, String host, int port) {
+ public byte[] sendLocalData(byte[] sendData, long localSequenceNumber, String host, int port) {
if (salt == null) {
return null;
}
try {
-
System.out.println("Passing Locally");
mac.update(sendData);
// Encrypt the data for sending
// byte[] encryptedData = encryptCipher.doFinal(totalData);
- byte[] encryptedData = encryptCipher.doFinal(totalData);
+ // byte[] encryptedData = encryptCipher.doFinal(totalData);
+ byte[] iv = createIV(table.getMachineId(), table.getLocalSequenceNumber());
+ byte[] encryptedData = encryptSlotAndPrependIV(totalData, iv);
// Open a TCP socket connection to a local device
Socket socket = new Socket(host, port);
timer.endTime();
- returnData = decryptCipher.doFinal(returnData);
+ // returnData = decryptCipher.doFinal(returnData);
+ returnData = stripIVAndDecryptSlot(returnData);
+ // returnData = decryptCipher.doFinal(returnData);
// We are done with this socket
socket.close();
System.arraycopy(returnData, 0, returnData2, 0, returnData2.length);
return returnData2;
- } catch (SocketTimeoutException e) {
-
- } catch (BadPaddingException e) {
-
- } catch (IllegalBlockSizeException e) {
-
- } catch (UnknownHostException e) {
-
- } catch (IOException e) {
+ } catch (Exception e) {
+ e.printStackTrace();
+ // throw new Error("Local comms failure...");
}
timer.endTime();
// Decrypt the data
- readData = decryptCipher.doFinal(readData);
+ // readData = decryptCipher.doFinal(readData);
+ readData = stripIVAndDecryptSlot(readData);
mac.update(readData, 0, readData.length - HMAC_SIZE);
byte[] genmac = mac.doFinal();
// byte[] sendData = table.acceptDataFromLocal(readData);
byte[] sendData = table.acceptDataFromLocal(returnData);
+
mac.update(sendData);
byte[] realmac = mac.doFinal();
byte[] totalData = new byte[sendData.length + realmac.length];
System.arraycopy(realmac, 0, totalData, sendData.length, realmac.length);
// Encrypt the data for sending
- byte[] encryptedData = encryptCipher.doFinal(totalData);
+ // byte[] encryptedData = encryptCipher.doFinal(totalData);
+ byte[] iv = createIV(table.getMachineId(), table.getLocalSequenceNumber());
+ byte[] encryptedData = encryptSlotAndPrependIV(totalData, iv);
timer.startTime();
// close the socket
socket.close();
- } catch (SocketTimeoutException e) {
-
- } catch (BadPaddingException e) {
-
- } catch (IllegalBlockSizeException e) {
-
- } catch (UnknownHostException e) {
-
- } catch (IOException e) {
+ } catch (Exception e) {
}
}
super.finalize();
}
}
-
}
/** Reference to Table */
private Table table;
- Slot(Table _table, long _seqnum, long _machineid, byte[] _prevhmac, byte[] _hmac) {
+ private long localSequenceNumber;
+
+ Slot(Table _table, long _seqnum, long _machineid, byte[] _prevhmac, byte[] _hmac, long _localSequenceNumber) {
seqnum = _seqnum;
machineid = _machineid;
prevhmac = _prevhmac;
seqnumlive = true;
freespace = SLOT_SIZE - getBaseSize();
table = _table;
+ localSequenceNumber = _localSequenceNumber;
}
- Slot(Table _table, long _seqnum, long _machineid, byte[] _prevhmac) {
- this(_table, _seqnum, _machineid, _prevhmac, null);
+ Slot(Table _table, long _seqnum, long _machineid, byte[] _prevhmac, long _localSequenceNumber) {
+ this(_table, _seqnum, _machineid, _prevhmac, null, _localSequenceNumber);
}
- Slot(Table _table, long _seqnum, long _machineid) {
- this(_table, _seqnum, _machineid, new byte[HMAC_SIZE], null);
+ Slot(Table _table, long _seqnum, long _machineid, long _localSequenceNumber) {
+ this(_table, _seqnum, _machineid, new byte[HMAC_SIZE], null, _localSequenceNumber);
}
byte[] getHMAC() {
long seqnum = bb.getLong();
long machineid = bb.getLong();
int numentries = bb.getInt();
- Slot slot = new Slot(table, seqnum, machineid, prevhmac, hmac);
+ Slot slot = new Slot(table, seqnum, machineid, prevhmac, hmac, -1);
for (int i = 0; i < numentries; i++) {
slot.addShallowEntry(Entry.decode(slot, bb));
return livecount > 0;
}
+ public byte[] getSlotCryptIV() {
+ ByteBuffer buffer = ByteBuffer.allocate(CloudComm.IV_SIZE);
+ buffer.putLong(machineid);
+ buffer.putLong(localSequenceNumber);
+ return buffer.array();
+ }
+
+
public String toString() {
return "<" + getSequenceNumber() + ">";
}
private long oldestLiveSlotSequenceNumver = 0; // Smallest sequence number of the slot with a live entry
private long localMachineId = 0; // Machine ID of this client device
private long sequenceNumber = 0; // Largest sequence number a client has received
+ private long localSequenceNumber = 0;
+
// private int smallestTableStatusSeen = -1; // Smallest Table Status that was seen in the latest slots sent from the server
// private int largestTableStatusSeen = -1; // Largest Table Status that was seen in the latest slots sent from the server
private long localTransactionSequenceNumber = 0; // Local sequence number counter for transactions
cloud.initSecurity();
// Create the first insertion into the block chain which is the table status
- Slot s = new Slot(this, 1, localMachineId);
+ Slot s = new Slot(this, 1, localMachineId, localSequenceNumber);
+ localSequenceNumber++;
TableStatus status = new TableStatus(s, numberOfSlots);
s.addEntry(status);
Slot[] array = cloud.putSlot(s, numberOfSlots);
bufferResizeThreshold = resizeLower - 1 + random.nextInt(numberOfSlots - resizeLower);
}
+ public long getLocalSequenceNumber() {
+ return localSequenceNumber;
+ }
+
boolean lastInsertedNewKey = false;
// While we have stuff that needs inserting into the block chain
while ((pendingTransactionQueue.size() > 0) || (pendingSendArbitrationRounds.size() > 0) || (newKey != null)) {
-
fromRetry = false;
if (hadPartialSendToServer) {
}
// Create the slot
- Slot slot = new Slot(this, sequenceNumber + 1, localMachineId, buffer.getSlot(sequenceNumber).getHMAC());
+ Slot slot = new Slot(this, sequenceNumber + 1, localMachineId, buffer.getSlot(sequenceNumber).getHMAC(), localSequenceNumber);
+ localSequenceNumber++;
// Try to fill the slot with data
ThreeTuple<Boolean, Integer, Boolean> fillSlotsReturn = fillSlot(slot, false, newKey);
// New Key was successfully inserted into the block chain so dont want to insert it again
newKey = null;
- }
+ }
// Remove the aborts and commit parts that were sent from the pending to send queue
for (Iterator<ArbitrationRound> iter = pendingSendArbitrationRounds.iterator(); iter.hasNext(); ) {
bbEncode.putInt(0);
// Send by local
- byte[] returnData = cloud.sendLocalData(sendData, localCommunicationInformation.getFirst(), localCommunicationInformation.getSecond());
+ byte[] returnData = cloud.sendLocalData(sendData, localSequenceNumber, localCommunicationInformation.getFirst(), localCommunicationInformation.getSecond());
+ localSequenceNumber++;
if (returnData == null) {
// Could not contact server
// Send by local
- byte[] returnData = cloud.sendLocalData(sendData, localCommunicationInformation.getFirst(), localCommunicationInformation.getSecond());
+ byte[] returnData = cloud.sendLocalData(sendData, localSequenceNumber, localCommunicationInformation.getFirst(), localCommunicationInformation.getSecond());
+ localSequenceNumber++;
if (returnData == null) {
// Could not contact server
entry.encode(bbEncode);
}
+
+ localSequenceNumber++;
return returnData;
}
slot.addEntry(newKeyEntry);
inserted = true;
- }
+ }
}
// Clear the transactions, aborts and commits that were sent previously