KeyExchangeECCurve25519.cs 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108
  1. using Org.BouncyCastle.Crypto.Agreement;
  2. using Org.BouncyCastle.Crypto.Generators;
  3. using Org.BouncyCastle.Crypto.Parameters;
  4. using Renci.SshNet.Abstractions;
  5. using Renci.SshNet.Common;
  6. using Renci.SshNet.Messages.Transport;
  7. namespace Renci.SshNet.Security
  8. {
  9. internal sealed class KeyExchangeECCurve25519 : KeyExchangeEC
  10. {
  11. private X25519Agreement _keyAgreement;
  12. /// <summary>
  13. /// Gets algorithm name.
  14. /// </summary>
  15. public override string Name
  16. {
  17. get { return "curve25519-sha256"; }
  18. }
  19. /// <summary>
  20. /// Gets the size, in bits, of the computed hash code.
  21. /// </summary>
  22. /// <value>
  23. /// The size, in bits, of the computed hash code.
  24. /// </value>
  25. protected override int HashSize
  26. {
  27. get { return 256; }
  28. }
  29. /// <inheritdoc/>
  30. public override void Start(Session session, KeyExchangeInitMessage message, bool sendClientInitMessage)
  31. {
  32. base.Start(session, message, sendClientInitMessage);
  33. Session.RegisterMessage("SSH_MSG_KEX_ECDH_REPLY");
  34. Session.KeyExchangeEcdhReplyMessageReceived += Session_KeyExchangeEcdhReplyMessageReceived;
  35. var g = new X25519KeyPairGenerator();
  36. g.Init(new X25519KeyGenerationParameters(CryptoAbstraction.SecureRandom));
  37. var aKeyPair = g.GenerateKeyPair();
  38. _keyAgreement = new X25519Agreement();
  39. _keyAgreement.Init(aKeyPair.Private);
  40. _clientExchangeValue = ((X25519PublicKeyParameters)aKeyPair.Public).GetEncoded();
  41. SendMessage(new KeyExchangeEcdhInitMessage(_clientExchangeValue));
  42. }
  43. /// <summary>
  44. /// Finishes key exchange algorithm.
  45. /// </summary>
  46. public override void Finish()
  47. {
  48. base.Finish();
  49. Session.KeyExchangeEcdhReplyMessageReceived -= Session_KeyExchangeEcdhReplyMessageReceived;
  50. }
  51. /// <summary>
  52. /// Hashes the specified data bytes.
  53. /// </summary>
  54. /// <param name="hashData">The hash data.</param>
  55. /// <returns>
  56. /// The hash of the data.
  57. /// </returns>
  58. protected override byte[] Hash(byte[] hashData)
  59. {
  60. return CryptoAbstraction.HashSHA256(hashData);
  61. }
  62. private void Session_KeyExchangeEcdhReplyMessageReceived(object sender, MessageEventArgs<KeyExchangeEcdhReplyMessage> e)
  63. {
  64. var message = e.Message;
  65. // Unregister message once received
  66. Session.UnRegisterMessage("SSH_MSG_KEX_ECDH_REPLY");
  67. HandleServerEcdhReply(message.KS, message.QS, message.Signature);
  68. // When SSH_MSG_KEXDH_REPLY received key exchange is completed
  69. Finish();
  70. }
  71. /// <summary>
  72. /// Handles the server DH reply message.
  73. /// </summary>
  74. /// <param name="hostKey">The host key.</param>
  75. /// <param name="serverExchangeValue">The server exchange value.</param>
  76. /// <param name="signature">The signature.</param>
  77. private void HandleServerEcdhReply(byte[] hostKey, byte[] serverExchangeValue, byte[] signature)
  78. {
  79. _serverExchangeValue = serverExchangeValue;
  80. _hostKey = hostKey;
  81. _signature = signature;
  82. var publicKey = new X25519PublicKeyParameters(serverExchangeValue);
  83. var k1 = new byte[_keyAgreement.AgreementSize];
  84. _keyAgreement.CalculateAgreement(publicKey, k1, 0);
  85. SharedKey = k1.ToBigInteger2().ToByteArray(isBigEndian: true);
  86. }
  87. }
  88. }