From 5faaac356571d17ab7d2dc6350de0d9f30d5a52a Mon Sep 17 00:00:00 2001 From: hai007 Date: Tue, 1 Apr 2025 12:59:08 -0700 Subject: [PATCH] Add back in Ldt stub impl, so it can be used in chromium PiperOrigin-RevId: 742808756 --- presence/implementation/ldt.cc | 2 +- presence/implementation/ldt_stub.c | 47 +++++++++++ presence/implementation/np_ldt.h | 125 +++++++++++++++++++++++++++++ 3 files changed, 173 insertions(+), 1 deletion(-) create mode 100644 presence/implementation/ldt_stub.c create mode 100644 presence/implementation/np_ldt.h diff --git a/presence/implementation/ldt.cc b/presence/implementation/ldt.cc index be1ad33a..28eac763 100644 --- a/presence/implementation/ldt.cc +++ b/presence/implementation/ldt.cc @@ -23,7 +23,7 @@ #include "absl/strings/str_format.h" #include "absl/strings/string_view.h" #ifdef NEARBY_CHROMIUM -#include "third_party/beto-core/src/nearby/presence/ldt_np_adv_ffi/c/include/np_ldt.h" +#include "third_party/nearby/src/presence/implementation/np_ldt.h" #else #include "np_ldt.h" #endif diff --git a/presence/implementation/ldt_stub.c b/presence/implementation/ldt_stub.c new file mode 100644 index 00000000..cc930bd5 --- /dev/null +++ b/presence/implementation/ldt_stub.c @@ -0,0 +1,47 @@ +// Copyright 2025 Google LLC +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +#include "presence/implementation/np_ldt.h" + +// Placeholder, empty implementations of LDT utilities. They will be replaced +// with implementations in Rust. + +NpLdtEncryptHandle NpLdtEncryptCreate(NpLdtKeySeed key_seed) { + NpLdtEncryptHandle handle = {0}; + return handle; +} + +NpLdtDecryptHandle NpLdtDecryptCreate(NpLdtKeySeed key_seed, + NpMetadataKeyHmac hmac_tag) { + NpLdtDecryptHandle handle = {0}; + return handle; +} + +NP_LDT_RESULT NpLdtEncryptClose(NpLdtEncryptHandle handle) { + return NP_LDT_SUCCESS; +} + +NP_LDT_RESULT NpLdtDecryptClose(NpLdtDecryptHandle handle) { + return NP_LDT_SUCCESS; +} + +NP_LDT_RESULT NpLdtEncrypt(NpLdtEncryptHandle handle, uint8_t* buffer, + size_t buffer_len, NpLdtSalt salt) { + return NP_LDT_SUCCESS; +} + +NP_LDT_RESULT NpLdtDecryptAndVerify(NpLdtDecryptHandle handle, uint8_t* buffer, + size_t buffer_len, NpLdtSalt salt) { + return NP_LDT_SUCCESS; +} \ No newline at end of file diff --git a/presence/implementation/np_ldt.h b/presence/implementation/np_ldt.h new file mode 100644 index 00000000..9047c12a --- /dev/null +++ b/presence/implementation/np_ldt.h @@ -0,0 +1,125 @@ +#ifndef THIRD_PARTY_NEARBY_PRESENCE_IMPLEMENTATION_NP_LDT_H_ +#define THIRD_PARTY_NEARBY_PRESENCE_IMPLEMENTATION_NP_LDT_H_ + +// Copyright 2022 Google LLC +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +// C API for Rust implementation of LDT [1], tailored to Nearby Presence's +// BLE 4.2 legacy format advertisement parsing usecase. +// +// [1] https://eprint.iacr.org/2017/841.pdf + +#ifdef __cplusplus +extern "C" { +#endif + +#include +#include + +// Individual encrypt/decrypt API, useful when creating advertisements or when +// decrypting advertisements from a known origin + +// The allocated handle to use for encryption +typedef struct { + uint64_t handle; +} NpLdtEncryptHandle; + +// The allocated handle to use for decryption +typedef struct { + uint64_t handle; +} NpLdtDecryptHandle; + +// Key material from the Nearby Presence credential from which keys will be +// derived. +typedef struct { + uint8_t bytes[32]; +} NpLdtKeySeed; + +typedef struct { + uint8_t bytes[32]; +} NpMetadataKeyHmac; + +typedef struct { + uint8_t bytes[2]; +} NpLdtSalt; + +// Possible result codes returned from the LDT NP API's +typedef enum { + // Call to api was succesful + NP_LDT_SUCCESS = 0, + // Payload of invalid length was provided must be >= 16 and <=31 bytes + NP_LDT_ERROR_INVALID_LENGTH = -1, + // The provided metadata hmac did not match the calculated hmac on call to + // decrypt and verify + NP_LDT_ERROR_MAC_MISMATCH = -2, +} NP_LDT_RESULT; + +// Allocate an LDT-XTS-AES128 Decryption cipher using the "swap" mix function. +// +// `key_seed` is the key material from the Nearby Presence credential from which +// the LDT key will be derived. +// 'hmac_tag' is the hmac auth tag calculated on the metadata key used to verify +// decryption was successful +// +// Returns 0 on error, or a non-zero handle on success. +NpLdtDecryptHandle NpLdtDecryptCreate(NpLdtKeySeed key_seed, + NpMetadataKeyHmac hmac_tag); + +// Allocate an LDT-XTS-AES128 Encryption cipher using the "swap" mix function. +// +// `key_seed` is the key material from the Nearby Presence credential from which +// the LDT key will be derived. +// +// Returns 0 on error, or a non-zero handle on success. +NpLdtEncryptHandle NpLdtEncryptCreate(NpLdtKeySeed key_seed); + +// Release allocated resources for an NpLdtEncryptHandle +// +// Returns 0 on success or an NP_LDT_RESULT error code on failure +NP_LDT_RESULT NpLdtEncryptClose(NpLdtEncryptHandle handle); + +// Release allocated resources for an NpLdtDecryptHandle +// +// Returns 0 on success or an NP_LDT_RESULT error code on failure +NP_LDT_RESULT NpLdtDecryptClose(NpLdtDecryptHandle handle); + +// Encrypt a 16-31 byte buffer in-place. +// +// `buffer` is a pointer to a 16-31 byte plaintext, with length in `buffer_len`. +// `salt` is the big-endian 2 byte salt that will be used in the Nearby +// Presence advertisement, which will be incorporated into the tweaks LDT uses +// while encrypting. +// +// Returns 0 on success, in which case `buffer` will now contain ciphertext. +// Returns an NP_LDT_RESULT error code on failure +NP_LDT_RESULT NpLdtEncrypt(NpLdtEncryptHandle handle, uint8_t* buffer, + size_t buffer_len, NpLdtSalt salt); + +// Decrypt a 16-31 byte buffer in-place. +// +// `buffer` is a pointer to a 16-31 byte ciphertext, with length in +// `buffer_len`. +// `salt` is the big-endian 2 byte salt found in the Nearby Presence +// advertisement, which will be incorporated into the tweaks LDT uses while +// decrypting. +// +// Returns 0 on success, in which case `buffer` will now contain plaintext. +// Returns an NP_LDT_RESULT error code on failure +NP_LDT_RESULT NpLdtDecryptAndVerify(NpLdtDecryptHandle handle, uint8_t* buffer, + size_t buffer_len, NpLdtSalt salt); + +#ifdef __cplusplus +} // extern "C" +#endif + +#endif // THIRD_PARTY_NEARBY_PRESENCE_IMPLEMENTATION_NP_LDT_H_