From 2d112ca31011a9ba2b14f3e1226e9508fedb898a Mon Sep 17 00:00:00 2001 From: Martin Willi Date: Mon, 26 Oct 2009 16:11:40 +0100 Subject: [PATCH] eap-sim-file plugin can store pseudonym information volatile in memory --- .../plugins/eap_sim_file/eap_sim_file_card.c | 104 +++++++++++++++- .../eap_sim_file/eap_sim_file_plugin.c | 8 +- .../eap_sim_file/eap_sim_file_provider.c | 116 +++++++++++++++++- .../eap_sim_file/eap_sim_file_triplets.c | 2 +- 4 files changed, 225 insertions(+), 5 deletions(-) diff --git a/src/charon/plugins/eap_sim_file/eap_sim_file_card.c b/src/charon/plugins/eap_sim_file/eap_sim_file_card.c index 95ce38344..77e06e09a 100644 --- a/src/charon/plugins/eap_sim_file/eap_sim_file_card.c +++ b/src/charon/plugins/eap_sim_file/eap_sim_file_card.c @@ -16,6 +16,7 @@ #include "eap_sim_file_card.h" #include +#include typedef struct private_eap_sim_file_card_t private_eap_sim_file_card_t; @@ -33,8 +34,50 @@ struct private_eap_sim_file_card_t { * source of triplets */ eap_sim_file_triplets_t *triplets; + + /** + * Permanent -> pseudonym mappongs + */ + hashtable_t *pseudonym; + + /** + * Pseudonym -> permanent mappings + */ + hashtable_t *permanent; }; +/** + * hashtable hash function + */ +static u_int hash(identification_t *key) +{ + return chunk_hash(key->get_encoding(key)); +} + +/** + * hashtable equals function + */ +static bool equals(identification_t *key1, identification_t *key2) +{ + return key1->equals(key1, key2); +} + +/** + * Lookup the permanent identity of pseudonym, if any + */ +static identification_t *lookup_permanent(private_eap_sim_file_card_t *this, + identification_t *pseudonym) +{ + identification_t *permanent; + + permanent = this->permanent->get(this->permanent, pseudonym); + if (permanent) + { + return permanent; + } + return pseudonym; +} + /** * Implementation of sim_card_t.get_triplet */ @@ -45,6 +88,7 @@ static bool get_triplet(private_eap_sim_file_card_t *this, identification_t *id; char *c_rand, *c_sres, *c_kc; + imsi = lookup_permanent(this, imsi); DBG2(DBG_CFG, "looking for triplet: %Y rand %b", imsi, rand, SIM_RAND_LEN); enumerator = this->triplets->create_enumerator(this->triplets); @@ -68,6 +112,41 @@ static bool get_triplet(private_eap_sim_file_card_t *this, return FALSE; } +/** + * Implementation of sim_card_t.get_pseudonym + */ +static identification_t *get_pseudonym(private_eap_sim_file_card_t *this, + identification_t *id) +{ + identification_t *pseudonym; + + pseudonym = this->pseudonym->get(this->pseudonym, id); + if (pseudonym) + { + return pseudonym->clone(pseudonym); + } + return NULL; +} + +/** + * Implementation of sim_card_t.set_pseudonym + */ +static void set_pseudonym(private_eap_sim_file_card_t *this, + identification_t *id, identification_t *pseudonym) +{ + identification_t *permanent; + + /* create new entries */ + id = id->clone(id); + pseudonym = pseudonym->clone(pseudonym); + permanent = this->permanent->put(this->permanent, pseudonym, id); + pseudonym = this->pseudonym->put(this->pseudonym, id, pseudonym); + + /* delete old entries */ + DESTROY_IF(permanent); + DESTROY_IF(pseudonym); +} + /** * Implementation of sim_card_t.get_quintuplet */ @@ -81,6 +160,25 @@ static bool get_quintuplet() */ static void destroy(private_eap_sim_file_card_t *this) { + enumerator_t *enumerator; + identification_t *key, *value; + + enumerator = this->pseudonym->create_enumerator(this->pseudonym); + while (enumerator->enumerate(enumerator, &key, &value)) + { + value->destroy(value); + } + enumerator->destroy(enumerator); + + enumerator = this->permanent->create_enumerator(this->permanent); + while (enumerator->enumerate(enumerator, &key, &value)) + { + value->destroy(value); + } + enumerator->destroy(enumerator); + + this->pseudonym->destroy(this->pseudonym); + this->permanent->destroy(this->permanent); free(this); } @@ -94,13 +192,15 @@ eap_sim_file_card_t *eap_sim_file_card_create(eap_sim_file_triplets_t *triplets) this->public.card.get_triplet = (bool(*)(sim_card_t*, identification_t *imsi, char rand[SIM_RAND_LEN], char sres[SIM_SRES_LEN], char kc[SIM_KC_LEN]))get_triplet; this->public.card.get_quintuplet = (status_t(*)(sim_card_t*, identification_t *imsi, char rand[AKA_RAND_LEN], char autn[AKA_AUTN_LEN], char ck[AKA_CK_LEN], char ik[AKA_IK_LEN], char res[AKA_RES_LEN]))get_quintuplet; this->public.card.resync = (bool(*)(sim_card_t*, identification_t *imsi, char rand[AKA_RAND_LEN], char auts[AKA_AUTS_LEN]))return_false; - this->public.card.get_pseudonym = (identification_t*(*)(sim_card_t*, identification_t *perm))return_null; - this->public.card.set_pseudonym = (void(*)(sim_card_t*, identification_t *perm, identification_t *pseudonym))nop; + this->public.card.get_pseudonym = (identification_t*(*)(sim_card_t*, identification_t *perm))get_pseudonym; + this->public.card.set_pseudonym = (void(*)(sim_card_t*, identification_t *perm, identification_t *pseudonym))set_pseudonym; this->public.card.get_reauth = (identification_t*(*)(sim_card_t*, identification_t *perm, char mk[HASH_SIZE_SHA1], u_int16_t *counter))return_null; this->public.card.set_reauth = (void(*)(sim_card_t*, identification_t *perm, identification_t* next, char mk[HASH_SIZE_SHA1], u_int16_t counter))nop; this->public.destroy = (void(*)(eap_sim_file_card_t*))destroy; this->triplets = triplets; + this->pseudonym = hashtable_create((void*)hash, (void*)equals, 0); + this->permanent = hashtable_create((void*)hash, (void*)equals, 0); return &this->public; } diff --git a/src/charon/plugins/eap_sim_file/eap_sim_file_plugin.c b/src/charon/plugins/eap_sim_file/eap_sim_file_plugin.c index eedaa3060..22ad31703 100644 --- a/src/charon/plugins/eap_sim_file/eap_sim_file_plugin.c +++ b/src/charon/plugins/eap_sim_file/eap_sim_file_plugin.c @@ -73,8 +73,14 @@ plugin_t *plugin_create() this->public.plugin.destroy = (void(*)(plugin_t*))destroy; this->triplets = eap_sim_file_triplets_create(TRIPLET_FILE); - this->card = eap_sim_file_card_create(this->triplets); this->provider = eap_sim_file_provider_create(this->triplets); + if (!this->provider) + { + this->triplets->destroy(this->triplets); + free(this); + return NULL; + } + this->card = eap_sim_file_card_create(this->triplets); charon->sim->add_card(charon->sim, &this->card->card); charon->sim->add_provider(charon->sim, &this->provider->provider); diff --git a/src/charon/plugins/eap_sim_file/eap_sim_file_provider.c b/src/charon/plugins/eap_sim_file/eap_sim_file_provider.c index fc2beb3a5..802de48bc 100644 --- a/src/charon/plugins/eap_sim_file/eap_sim_file_provider.c +++ b/src/charon/plugins/eap_sim_file/eap_sim_file_provider.c @@ -15,6 +15,9 @@ #include "eap_sim_file_provider.h" +#include +#include + typedef struct private_eap_sim_file_provider_t private_eap_sim_file_provider_t; /** @@ -31,8 +34,55 @@ struct private_eap_sim_file_provider_t { * source of triplets */ eap_sim_file_triplets_t *triplets; + + /** + * Permanent -> pseudonym mappongs + */ + hashtable_t *pseudonym; + + /** + * Pseudonym -> permanent mappings + */ + hashtable_t *permanent; + + /** + * RNG for pseudonyms + */ + rng_t *rng; }; +/** + * hashtable hash function + */ +static u_int hash(identification_t *key) +{ + return chunk_hash(key->get_encoding(key)); +} + +/** + * hashtable equals function + */ +static bool equals(identification_t *key1, identification_t *key2) +{ + return key1->equals(key1, key2); +} + +/** + * Lookup the permanent identity of pseudonym, if any + */ +static identification_t *lookup_permanent(private_eap_sim_file_provider_t *this, + identification_t *pseudonym) +{ + identification_t *permanent; + + permanent = this->permanent->get(this->permanent, pseudonym); + if (permanent) + { + return permanent; + } + return pseudonym; +} + /** * Implementation of sim_provider_t.get_triplet */ @@ -44,6 +94,8 @@ static bool get_triplet(private_eap_sim_file_provider_t *this, identification_t *id; char *c_rand, *c_sres, *c_kc; + imsi = lookup_permanent(this, imsi); + enumerator = this->triplets->create_enumerator(this->triplets); while (enumerator->enumerate(enumerator, &id, &c_rand, &c_sres, &c_kc)) { @@ -60,11 +112,65 @@ static bool get_triplet(private_eap_sim_file_provider_t *this, return FALSE; } +/** + * Implementation of sim_provider_t.get_triplet + */ +static identification_t* gen_pseudonym(private_eap_sim_file_provider_t *this, + identification_t *id) +{ + identification_t *pseudonym, *permanent; + char buf[8], hex[sizeof(buf) * 2 + 1]; + + /* remove old entry */ + pseudonym = this->pseudonym->remove(this->pseudonym, id); + if (pseudonym) + { + permanent = this->permanent->remove(this->permanent, pseudonym); + if (permanent) + { + permanent->destroy(permanent); + } + pseudonym->destroy(pseudonym); + } + + /* generate new pseudonym */ + this->rng->get_bytes(this->rng, sizeof(buf), buf); + chunk_to_hex(chunk_create(buf, sizeof(buf)), hex, FALSE); + pseudonym = identification_create_from_string(hex); + + /* create new entries */ + id = id->clone(id); + this->pseudonym->put(this->pseudonym, id, pseudonym); + this->permanent->put(this->permanent, pseudonym, id); + + return pseudonym->clone(pseudonym); +} + /** * Implementation of eap_sim_file_provider_t.destroy. */ static void destroy(private_eap_sim_file_provider_t *this) { + enumerator_t *enumerator; + identification_t *key, *value; + + enumerator = this->pseudonym->create_enumerator(this->pseudonym); + while (enumerator->enumerate(enumerator, &key, &value)) + { + value->destroy(value); + } + enumerator->destroy(enumerator); + + enumerator = this->permanent->create_enumerator(this->permanent); + while (enumerator->enumerate(enumerator, &key, &value)) + { + value->destroy(value); + } + enumerator->destroy(enumerator); + + this->pseudonym->destroy(this->pseudonym); + this->permanent->destroy(this->permanent); + this->rng->destroy(this->rng); free(this); } @@ -79,12 +185,20 @@ eap_sim_file_provider_t *eap_sim_file_provider_create( this->public.provider.get_triplet = (bool(*)(sim_provider_t*, identification_t *imsi, char rand[SIM_RAND_LEN], char sres[SIM_SRES_LEN], char kc[SIM_KC_LEN]))get_triplet; this->public.provider.get_quintuplet = (bool(*)(sim_provider_t*, identification_t *imsi, char rand[AKA_RAND_LEN], char xres[AKA_RES_LEN], char ck[AKA_CK_LEN], char ik[AKA_IK_LEN], char autn[AKA_AUTN_LEN]))return_false; this->public.provider.resync = (bool(*)(sim_provider_t*, identification_t *imsi, char rand[AKA_RAND_LEN], char auts[AKA_AUTS_LEN]))return_false; - this->public.provider.gen_pseudonym = (identification_t*(*)(sim_provider_t*, identification_t *id))return_null; + this->public.provider.gen_pseudonym = (identification_t*(*)(sim_provider_t*, identification_t *id))gen_pseudonym; this->public.provider.is_reauth = (bool(*)(sim_provider_t*, identification_t *id, char [HASH_SIZE_SHA1], u_int16_t *counter))return_false; this->public.provider.gen_reauth = (identification_t*(*)(sim_provider_t*, identification_t *id, char mk[HASH_SIZE_SHA1]))return_null; this->public.destroy = (void(*)(eap_sim_file_provider_t*))destroy; this->triplets = triplets; + this->rng = lib->crypto->create_rng(lib->crypto, RNG_WEAK); + if (!this->rng) + { + free(this); + return NULL; + } + this->pseudonym = hashtable_create((void*)hash, (void*)equals, 0); + this->permanent = hashtable_create((void*)hash, (void*)equals, 0); return &this->public; } diff --git a/src/charon/plugins/eap_sim_file/eap_sim_file_triplets.c b/src/charon/plugins/eap_sim_file/eap_sim_file_triplets.c index 6b4d90736..12d3a6fe2 100644 --- a/src/charon/plugins/eap_sim_file/eap_sim_file_triplets.c +++ b/src/charon/plugins/eap_sim_file/eap_sim_file_triplets.c @@ -60,7 +60,7 @@ typedef struct { */ static void triplet_destroy(triplet_t *this) { - this->imsi->destroy(this->imsi); + DESTROY_IF(this->imsi); free(this); }