eap-sim-file plugin can store pseudonym information volatile in memory
This commit is contained in:
@@ -16,6 +16,7 @@
|
||||
#include "eap_sim_file_card.h"
|
||||
|
||||
#include <daemon.h>
|
||||
#include <utils/hashtable.h>
|
||||
|
||||
typedef struct private_eap_sim_file_card_t private_eap_sim_file_card_t;
|
||||
|
||||
@@ -33,8 +34,50 @@ struct private_eap_sim_file_card_t {
|
||||
* source of triplets
|
||||
*/
|
||||
eap_sim_file_triplets_t *triplets;
|
||||
|
||||
/**
|
||||
* Permanent -> pseudonym mappongs
|
||||
*/
|
||||
hashtable_t *pseudonym;
|
||||
|
||||
/**
|
||||
* Pseudonym -> permanent mappings
|
||||
*/
|
||||
hashtable_t *permanent;
|
||||
};
|
||||
|
||||
/**
|
||||
* hashtable hash function
|
||||
*/
|
||||
static u_int hash(identification_t *key)
|
||||
{
|
||||
return chunk_hash(key->get_encoding(key));
|
||||
}
|
||||
|
||||
/**
|
||||
* hashtable equals function
|
||||
*/
|
||||
static bool equals(identification_t *key1, identification_t *key2)
|
||||
{
|
||||
return key1->equals(key1, key2);
|
||||
}
|
||||
|
||||
/**
|
||||
* Lookup the permanent identity of pseudonym, if any
|
||||
*/
|
||||
static identification_t *lookup_permanent(private_eap_sim_file_card_t *this,
|
||||
identification_t *pseudonym)
|
||||
{
|
||||
identification_t *permanent;
|
||||
|
||||
permanent = this->permanent->get(this->permanent, pseudonym);
|
||||
if (permanent)
|
||||
{
|
||||
return permanent;
|
||||
}
|
||||
return pseudonym;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of sim_card_t.get_triplet
|
||||
*/
|
||||
@@ -45,6 +88,7 @@ static bool get_triplet(private_eap_sim_file_card_t *this,
|
||||
identification_t *id;
|
||||
char *c_rand, *c_sres, *c_kc;
|
||||
|
||||
imsi = lookup_permanent(this, imsi);
|
||||
DBG2(DBG_CFG, "looking for triplet: %Y rand %b", imsi, rand, SIM_RAND_LEN);
|
||||
|
||||
enumerator = this->triplets->create_enumerator(this->triplets);
|
||||
@@ -68,6 +112,41 @@ static bool get_triplet(private_eap_sim_file_card_t *this,
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of sim_card_t.get_pseudonym
|
||||
*/
|
||||
static identification_t *get_pseudonym(private_eap_sim_file_card_t *this,
|
||||
identification_t *id)
|
||||
{
|
||||
identification_t *pseudonym;
|
||||
|
||||
pseudonym = this->pseudonym->get(this->pseudonym, id);
|
||||
if (pseudonym)
|
||||
{
|
||||
return pseudonym->clone(pseudonym);
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of sim_card_t.set_pseudonym
|
||||
*/
|
||||
static void set_pseudonym(private_eap_sim_file_card_t *this,
|
||||
identification_t *id, identification_t *pseudonym)
|
||||
{
|
||||
identification_t *permanent;
|
||||
|
||||
/* create new entries */
|
||||
id = id->clone(id);
|
||||
pseudonym = pseudonym->clone(pseudonym);
|
||||
permanent = this->permanent->put(this->permanent, pseudonym, id);
|
||||
pseudonym = this->pseudonym->put(this->pseudonym, id, pseudonym);
|
||||
|
||||
/* delete old entries */
|
||||
DESTROY_IF(permanent);
|
||||
DESTROY_IF(pseudonym);
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of sim_card_t.get_quintuplet
|
||||
*/
|
||||
@@ -81,6 +160,25 @@ static bool get_quintuplet()
|
||||
*/
|
||||
static void destroy(private_eap_sim_file_card_t *this)
|
||||
{
|
||||
enumerator_t *enumerator;
|
||||
identification_t *key, *value;
|
||||
|
||||
enumerator = this->pseudonym->create_enumerator(this->pseudonym);
|
||||
while (enumerator->enumerate(enumerator, &key, &value))
|
||||
{
|
||||
value->destroy(value);
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
|
||||
enumerator = this->permanent->create_enumerator(this->permanent);
|
||||
while (enumerator->enumerate(enumerator, &key, &value))
|
||||
{
|
||||
value->destroy(value);
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
|
||||
this->pseudonym->destroy(this->pseudonym);
|
||||
this->permanent->destroy(this->permanent);
|
||||
free(this);
|
||||
}
|
||||
|
||||
@@ -94,13 +192,15 @@ eap_sim_file_card_t *eap_sim_file_card_create(eap_sim_file_triplets_t *triplets)
|
||||
this->public.card.get_triplet = (bool(*)(sim_card_t*, identification_t *imsi, char rand[SIM_RAND_LEN], char sres[SIM_SRES_LEN], char kc[SIM_KC_LEN]))get_triplet;
|
||||
this->public.card.get_quintuplet = (status_t(*)(sim_card_t*, identification_t *imsi, char rand[AKA_RAND_LEN], char autn[AKA_AUTN_LEN], char ck[AKA_CK_LEN], char ik[AKA_IK_LEN], char res[AKA_RES_LEN]))get_quintuplet;
|
||||
this->public.card.resync = (bool(*)(sim_card_t*, identification_t *imsi, char rand[AKA_RAND_LEN], char auts[AKA_AUTS_LEN]))return_false;
|
||||
this->public.card.get_pseudonym = (identification_t*(*)(sim_card_t*, identification_t *perm))return_null;
|
||||
this->public.card.set_pseudonym = (void(*)(sim_card_t*, identification_t *perm, identification_t *pseudonym))nop;
|
||||
this->public.card.get_pseudonym = (identification_t*(*)(sim_card_t*, identification_t *perm))get_pseudonym;
|
||||
this->public.card.set_pseudonym = (void(*)(sim_card_t*, identification_t *perm, identification_t *pseudonym))set_pseudonym;
|
||||
this->public.card.get_reauth = (identification_t*(*)(sim_card_t*, identification_t *perm, char mk[HASH_SIZE_SHA1], u_int16_t *counter))return_null;
|
||||
this->public.card.set_reauth = (void(*)(sim_card_t*, identification_t *perm, identification_t* next, char mk[HASH_SIZE_SHA1], u_int16_t counter))nop;
|
||||
this->public.destroy = (void(*)(eap_sim_file_card_t*))destroy;
|
||||
|
||||
this->triplets = triplets;
|
||||
this->pseudonym = hashtable_create((void*)hash, (void*)equals, 0);
|
||||
this->permanent = hashtable_create((void*)hash, (void*)equals, 0);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
|
||||
@@ -73,8 +73,14 @@ plugin_t *plugin_create()
|
||||
this->public.plugin.destroy = (void(*)(plugin_t*))destroy;
|
||||
|
||||
this->triplets = eap_sim_file_triplets_create(TRIPLET_FILE);
|
||||
this->card = eap_sim_file_card_create(this->triplets);
|
||||
this->provider = eap_sim_file_provider_create(this->triplets);
|
||||
if (!this->provider)
|
||||
{
|
||||
this->triplets->destroy(this->triplets);
|
||||
free(this);
|
||||
return NULL;
|
||||
}
|
||||
this->card = eap_sim_file_card_create(this->triplets);
|
||||
|
||||
charon->sim->add_card(charon->sim, &this->card->card);
|
||||
charon->sim->add_provider(charon->sim, &this->provider->provider);
|
||||
|
||||
@@ -15,6 +15,9 @@
|
||||
|
||||
#include "eap_sim_file_provider.h"
|
||||
|
||||
#include <daemon.h>
|
||||
#include <utils/hashtable.h>
|
||||
|
||||
typedef struct private_eap_sim_file_provider_t private_eap_sim_file_provider_t;
|
||||
|
||||
/**
|
||||
@@ -31,8 +34,55 @@ struct private_eap_sim_file_provider_t {
|
||||
* source of triplets
|
||||
*/
|
||||
eap_sim_file_triplets_t *triplets;
|
||||
|
||||
/**
|
||||
* Permanent -> pseudonym mappongs
|
||||
*/
|
||||
hashtable_t *pseudonym;
|
||||
|
||||
/**
|
||||
* Pseudonym -> permanent mappings
|
||||
*/
|
||||
hashtable_t *permanent;
|
||||
|
||||
/**
|
||||
* RNG for pseudonyms
|
||||
*/
|
||||
rng_t *rng;
|
||||
};
|
||||
|
||||
/**
|
||||
* hashtable hash function
|
||||
*/
|
||||
static u_int hash(identification_t *key)
|
||||
{
|
||||
return chunk_hash(key->get_encoding(key));
|
||||
}
|
||||
|
||||
/**
|
||||
* hashtable equals function
|
||||
*/
|
||||
static bool equals(identification_t *key1, identification_t *key2)
|
||||
{
|
||||
return key1->equals(key1, key2);
|
||||
}
|
||||
|
||||
/**
|
||||
* Lookup the permanent identity of pseudonym, if any
|
||||
*/
|
||||
static identification_t *lookup_permanent(private_eap_sim_file_provider_t *this,
|
||||
identification_t *pseudonym)
|
||||
{
|
||||
identification_t *permanent;
|
||||
|
||||
permanent = this->permanent->get(this->permanent, pseudonym);
|
||||
if (permanent)
|
||||
{
|
||||
return permanent;
|
||||
}
|
||||
return pseudonym;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of sim_provider_t.get_triplet
|
||||
*/
|
||||
@@ -44,6 +94,8 @@ static bool get_triplet(private_eap_sim_file_provider_t *this,
|
||||
identification_t *id;
|
||||
char *c_rand, *c_sres, *c_kc;
|
||||
|
||||
imsi = lookup_permanent(this, imsi);
|
||||
|
||||
enumerator = this->triplets->create_enumerator(this->triplets);
|
||||
while (enumerator->enumerate(enumerator, &id, &c_rand, &c_sres, &c_kc))
|
||||
{
|
||||
@@ -60,11 +112,65 @@ static bool get_triplet(private_eap_sim_file_provider_t *this,
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of sim_provider_t.get_triplet
|
||||
*/
|
||||
static identification_t* gen_pseudonym(private_eap_sim_file_provider_t *this,
|
||||
identification_t *id)
|
||||
{
|
||||
identification_t *pseudonym, *permanent;
|
||||
char buf[8], hex[sizeof(buf) * 2 + 1];
|
||||
|
||||
/* remove old entry */
|
||||
pseudonym = this->pseudonym->remove(this->pseudonym, id);
|
||||
if (pseudonym)
|
||||
{
|
||||
permanent = this->permanent->remove(this->permanent, pseudonym);
|
||||
if (permanent)
|
||||
{
|
||||
permanent->destroy(permanent);
|
||||
}
|
||||
pseudonym->destroy(pseudonym);
|
||||
}
|
||||
|
||||
/* generate new pseudonym */
|
||||
this->rng->get_bytes(this->rng, sizeof(buf), buf);
|
||||
chunk_to_hex(chunk_create(buf, sizeof(buf)), hex, FALSE);
|
||||
pseudonym = identification_create_from_string(hex);
|
||||
|
||||
/* create new entries */
|
||||
id = id->clone(id);
|
||||
this->pseudonym->put(this->pseudonym, id, pseudonym);
|
||||
this->permanent->put(this->permanent, pseudonym, id);
|
||||
|
||||
return pseudonym->clone(pseudonym);
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of eap_sim_file_provider_t.destroy.
|
||||
*/
|
||||
static void destroy(private_eap_sim_file_provider_t *this)
|
||||
{
|
||||
enumerator_t *enumerator;
|
||||
identification_t *key, *value;
|
||||
|
||||
enumerator = this->pseudonym->create_enumerator(this->pseudonym);
|
||||
while (enumerator->enumerate(enumerator, &key, &value))
|
||||
{
|
||||
value->destroy(value);
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
|
||||
enumerator = this->permanent->create_enumerator(this->permanent);
|
||||
while (enumerator->enumerate(enumerator, &key, &value))
|
||||
{
|
||||
value->destroy(value);
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
|
||||
this->pseudonym->destroy(this->pseudonym);
|
||||
this->permanent->destroy(this->permanent);
|
||||
this->rng->destroy(this->rng);
|
||||
free(this);
|
||||
}
|
||||
|
||||
@@ -79,12 +185,20 @@ eap_sim_file_provider_t *eap_sim_file_provider_create(
|
||||
this->public.provider.get_triplet = (bool(*)(sim_provider_t*, identification_t *imsi, char rand[SIM_RAND_LEN], char sres[SIM_SRES_LEN], char kc[SIM_KC_LEN]))get_triplet;
|
||||
this->public.provider.get_quintuplet = (bool(*)(sim_provider_t*, identification_t *imsi, char rand[AKA_RAND_LEN], char xres[AKA_RES_LEN], char ck[AKA_CK_LEN], char ik[AKA_IK_LEN], char autn[AKA_AUTN_LEN]))return_false;
|
||||
this->public.provider.resync = (bool(*)(sim_provider_t*, identification_t *imsi, char rand[AKA_RAND_LEN], char auts[AKA_AUTS_LEN]))return_false;
|
||||
this->public.provider.gen_pseudonym = (identification_t*(*)(sim_provider_t*, identification_t *id))return_null;
|
||||
this->public.provider.gen_pseudonym = (identification_t*(*)(sim_provider_t*, identification_t *id))gen_pseudonym;
|
||||
this->public.provider.is_reauth = (bool(*)(sim_provider_t*, identification_t *id, char [HASH_SIZE_SHA1], u_int16_t *counter))return_false;
|
||||
this->public.provider.gen_reauth = (identification_t*(*)(sim_provider_t*, identification_t *id, char mk[HASH_SIZE_SHA1]))return_null;
|
||||
this->public.destroy = (void(*)(eap_sim_file_provider_t*))destroy;
|
||||
|
||||
this->triplets = triplets;
|
||||
this->rng = lib->crypto->create_rng(lib->crypto, RNG_WEAK);
|
||||
if (!this->rng)
|
||||
{
|
||||
free(this);
|
||||
return NULL;
|
||||
}
|
||||
this->pseudonym = hashtable_create((void*)hash, (void*)equals, 0);
|
||||
this->permanent = hashtable_create((void*)hash, (void*)equals, 0);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
|
||||
@@ -60,7 +60,7 @@ typedef struct {
|
||||
*/
|
||||
static void triplet_destroy(triplet_t *this)
|
||||
{
|
||||
this->imsi->destroy(this->imsi);
|
||||
DESTROY_IF(this->imsi);
|
||||
free(this);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user