blob: 091412e6a9e710d2aa108daccf227b35e1afacc1 [file] [log] [blame]
henrike@webrtc.orga7b98182014-02-21 15:51:43 +00001/*
kjellander65c7f672016-02-12 00:05:01 -08002 * Copyright 2014 The WebRTC project authors. All Rights Reserved.
henrike@webrtc.orga7b98182014-02-21 15:51:43 +00003 *
kjellander65c7f672016-02-12 00:05:01 -08004 * Use of this source code is governed by a BSD-style license
5 * that can be found in the LICENSE file in the root of the source
6 * tree. An additional intellectual property rights grant can be found
7 * in the file PATENTS. All contributing project authors may
8 * be found in the AUTHORS file in the root of the source tree.
henrike@webrtc.orga7b98182014-02-21 15:51:43 +00009 */
10
terelius8c011e52016-04-26 05:28:11 -070011#ifndef WEBRTC_PC_EXTERNALHMAC_H_
12#define WEBRTC_PC_EXTERNALHMAC_H_
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000013
14// External libsrtp HMAC auth module which implements methods defined in
15// auth_type_t.
16// The default auth module will be replaced only when the ENABLE_EXTERNAL_AUTH
17// flag is enabled. This allows us to access to authentication keys,
18// as the default auth implementation doesn't provide access and avoids
19// hashing each packet twice.
20
21// How will libsrtp select this module?
22// Libsrtp defines authentication function types identified by an unsigned
mattdr8cab52d2016-10-10 15:33:37 -070023// integer, e.g. SRTP_HMAC_SHA1 is 3. Using authentication ids, the
24// application can plug any desired authentication modules into libsrtp.
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000025// libsrtp also provides a mechanism to select different auth functions for
26// individual streams. This can be done by setting the right value in
27// the auth_type of srtp_policy_t. The application must first register auth
28// functions and the corresponding authentication id using
29// crypto_kernel_replace_auth_type function.
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000030
buildbot@webrtc.orgd4e598d2014-07-29 17:36:52 +000031#include "webrtc/base/basictypes.h"
mattdr51f29192016-09-28 14:08:46 -070032#ifdef HAVE_SRTP
jiayl@webrtc.orga197a5e2015-03-23 22:11:49 +000033extern "C" {
kjellander7bc7c062016-04-22 04:57:49 -070034#ifdef SRTP_RELATIVE_PATH
35#include "auth.h" // NOLINT
36#else
mattdr51f29192016-09-28 14:08:46 -070037#include "third_party/libsrtp/crypto/include/auth.h"
kjellander7bc7c062016-04-22 04:57:49 -070038#endif // SRTP_RELATIVE_PATH
jiayl@webrtc.orga197a5e2015-03-23 22:11:49 +000039}
mattdr51f29192016-09-28 14:08:46 -070040#endif // HAVE_SRTP
41
mattdr8cab52d2016-10-10 15:33:37 -070042#if defined(HAVE_SRTP) && !defined(SRTP_HMAC_SHA1)
43// Include compatibility shims to compile against libsrtp 1.x.
44// TODO(mattdr): Remove once Chromium uses libsrtp 2.
45
46// Remember that the definition of SRTP_HMAC_SHA1 is synthetic.
47#define COMPILING_AGAINST_LIBSRTP1 1
48
49#define SRTP_HMAC_SHA1 HMAC_SHA1
50#define srtp_auth_t auth_t
51#endif
52
mattdr51f29192016-09-28 14:08:46 -070053#if defined(HAVE_SRTP) && defined(ENABLE_EXTERNAL_AUTH)
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000054
mattdr8cab52d2016-10-10 15:33:37 -070055#define EXTERNAL_HMAC_SHA1 SRTP_HMAC_SHA1 + 1
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000056#define HMAC_KEY_LENGTH 20
57
58// The HMAC context structure used to store authentication keys.
59// The pointer to the key will be allocated in the external_hmac_init function.
60// This pointer is owned by srtp_t in a template context.
61typedef struct {
Peter Boström0c4e06b2015-10-07 12:23:21 +020062 uint8_t key[HMAC_KEY_LENGTH];
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000063 int key_length;
pbos@webrtc.orga9cf0792014-12-18 09:12:21 +000064} ExternalHmacContext;
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000065
mattdr8cab52d2016-10-10 15:33:37 -070066srtp_err_status_t external_hmac_alloc(srtp_auth_t** a,
67 int key_len,
68 int out_len);
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000069
mattdr8cab52d2016-10-10 15:33:37 -070070srtp_err_status_t external_hmac_dealloc(srtp_auth_t* a);
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000071
mattdr8cab52d2016-10-10 15:33:37 -070072srtp_err_status_t external_hmac_init(ExternalHmacContext* state,
73 const uint8_t* key,
74 int key_len);
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000075
mattdr8cab52d2016-10-10 15:33:37 -070076srtp_err_status_t external_hmac_start(ExternalHmacContext* state);
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000077
mattdr8cab52d2016-10-10 15:33:37 -070078srtp_err_status_t external_hmac_update(ExternalHmacContext* state,
79 const uint8_t* message,
80 int msg_octets);
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000081
mattdr8cab52d2016-10-10 15:33:37 -070082srtp_err_status_t external_hmac_compute(ExternalHmacContext* state,
83 const void* message,
84 int msg_octets,
85 int tag_len,
86 uint8_t* result);
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000087
mattdr8cab52d2016-10-10 15:33:37 -070088srtp_err_status_t external_crypto_init();
henrike@webrtc.orga7b98182014-02-21 15:51:43 +000089
90#endif // defined(HAVE_SRTP) && defined(ENABLE_EXTERNAL_AUTH)
terelius8c011e52016-04-26 05:28:11 -070091#endif // WEBRTC_PC_EXTERNALHMAC_H_