Cryptor.php 3.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136
  1. <?php
  2. namespace RNCryptor;
  3. class Cryptor {
  4. const DEFAULT_SCHEMA_VERSION = 3;
  5. protected $_settings;
  6. public function __construct() {
  7. if (!extension_loaded('mcrypt')) {
  8. throw new \Exception('The mcrypt extension is missing.');
  9. }
  10. }
  11. protected function _configureSettings($version) {
  12. $settings = new \stdClass();
  13. $settings->algorithm = MCRYPT_RIJNDAEL_128;
  14. $settings->saltLength = 8;
  15. $settings->ivLength = 16;
  16. $settings->pbkdf2 = new \stdClass();
  17. $settings->pbkdf2->prf = 'sha1';
  18. $settings->pbkdf2->iterations = 10000;
  19. $settings->pbkdf2->keyLength = 32;
  20. $settings->hmac = new \stdClass();
  21. $settings->hmac->length = 32;
  22. switch ($version) {
  23. case 0:
  24. $settings->mode = 'ctr';
  25. $settings->options = 0;
  26. $settings->hmac->includesHeader = false;
  27. $settings->hmac->algorithm = 'sha1';
  28. $settings->hmac->includesPadding = true;
  29. $settings->truncatesMultibytePasswords = true;
  30. break;
  31. case 1:
  32. $settings->mode = 'cbc';
  33. $settings->options = 1;
  34. $settings->hmac->includesHeader = false;
  35. $settings->hmac->algorithm = 'sha256';
  36. $settings->hmac->includesPadding = false;
  37. $settings->truncatesMultibytePasswords = true;
  38. break;
  39. case 2:
  40. $settings->mode = 'cbc';
  41. $settings->options = 1;
  42. $settings->hmac->includesHeader = true;
  43. $settings->hmac->algorithm = 'sha256';
  44. $settings->hmac->includesPadding = false;
  45. $settings->truncatesMultibytePasswords = true;
  46. break;
  47. case 3:
  48. $settings->mode = 'cbc';
  49. $settings->options = 1;
  50. $settings->hmac->includesHeader = true;
  51. $settings->hmac->algorithm = 'sha256';
  52. $settings->hmac->includesPadding = false;
  53. $settings->truncatesMultibytePasswords = false;
  54. break;
  55. default:
  56. throw new \Exception('Unsupported schema version ' . $version);
  57. }
  58. $this->_settings = $settings;
  59. }
  60. /**
  61. * Encrypt or decrypt using AES CTR Little Endian mode
  62. */
  63. protected function _aesCtrLittleEndianCrypt($payload, $key, $iv) {
  64. $numOfBlocks = ceil(strlen($payload) / strlen($iv));
  65. $counter = '';
  66. for ($i = 0; $i < $numOfBlocks; ++$i) {
  67. $counter .= $iv;
  68. // Yes, the next line only ever increments the first character
  69. // of the counter string, ignoring overflow conditions. This
  70. // matches CommonCrypto's behavior!
  71. $iv[0] = chr(ord($iv[0]) + 1);
  72. }
  73. return $payload ^ mcrypt_encrypt($this->_settings->algorithm, $key, $counter, 'ecb');
  74. }
  75. protected function _generateHmac(\stdClass $components, $hmacKey) {
  76. $hmacMessage = '';
  77. if ($this->_settings->hmac->includesHeader) {
  78. $hmacMessage .= $components->headers->version
  79. . $components->headers->options
  80. . (isset($components->headers->encSalt) ? $components->headers->encSalt : '')
  81. . (isset($components->headers->hmacSalt) ? $components->headers->hmacSalt : '')
  82. . $components->headers->iv;
  83. }
  84. $hmacMessage .= $components->ciphertext;
  85. $hmac = hash_hmac($this->_settings->hmac->algorithm, $hmacMessage, $hmacKey, true);
  86. if ($this->_settings->hmac->includesPadding) {
  87. $hmac = str_pad($hmac, $this->_settings->hmac->length, chr(0));
  88. }
  89. return $hmac;
  90. }
  91. /**
  92. * Key derivation -- This method is intended for testing. It merely
  93. * exposes the underlying key-derivation functionality.
  94. */
  95. public function generateKey($salt, $password, $version = self::DEFAULT_SCHEMA_VERSION) {
  96. $this->_configureSettings($version);
  97. return $this->_generateKey($salt, $password);
  98. }
  99. protected function _generateKey($salt, $password) {
  100. if ($this->_settings->truncatesMultibytePasswords) {
  101. $utf8Length = mb_strlen($password, 'utf-8');
  102. $password = substr($password, 0, $utf8Length);
  103. }
  104. return hash_pbkdf2($this->_settings->pbkdf2->prf, $password, $salt, $this->_settings->pbkdf2->iterations, $this->_settings->pbkdf2->keyLength, true);
  105. }
  106. }