mirror of
https://github.com/bitcoin/bitcoin.git
synced 2026-09-16 08:16:38 +02:00
CHMAC_SHA256 and CHMAC_SHA512 leave two stack buffers populated on return: rkey[] holds K' XOR ipad after the constructor, and temp[] holds the inner-hash output after Finalize(). When the HMAC is keyed with sensitive material (chain code in BIP32Hash() in hash.cpp for BIP32 child key derivation; PRK in HKDF-Expand in hkdf_sha256_32.cpp, used for BIP324 transport keying), rkey is one constant XOR from that key, and temp is a one-way digest covering it. Cleanse both buffers with memory_cleanse(), matching the convention in chacha20.cpp and chacha20poly1305.cpp. No observable change for callers.
41 lines
1.0 KiB
C++
41 lines
1.0 KiB
C++
// Copyright (c) 2014-present The Bitcoin Core developers
|
|
// Distributed under the MIT software license, see the accompanying
|
|
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
|
|
|
|
#include <crypto/hmac_sha256.h>
|
|
|
|
#include <crypto/sha256.h>
|
|
#include <support/cleanse.h>
|
|
|
|
#include <cstring>
|
|
|
|
CHMAC_SHA256::CHMAC_SHA256(const unsigned char* key, size_t keylen)
|
|
{
|
|
unsigned char rkey[64];
|
|
if (keylen <= 64) {
|
|
memcpy(rkey, key, keylen);
|
|
memset(rkey + keylen, 0, 64 - keylen);
|
|
} else {
|
|
CSHA256().Write(key, keylen).Finalize(rkey);
|
|
memset(rkey + 32, 0, 32);
|
|
}
|
|
|
|
for (int n = 0; n < 64; n++)
|
|
rkey[n] ^= 0x5c;
|
|
outer.Write(rkey, 64);
|
|
|
|
for (int n = 0; n < 64; n++)
|
|
rkey[n] ^= 0x5c ^ 0x36;
|
|
inner.Write(rkey, 64);
|
|
|
|
memory_cleanse(rkey, sizeof(rkey));
|
|
}
|
|
|
|
void CHMAC_SHA256::Finalize(unsigned char hash[OUTPUT_SIZE])
|
|
{
|
|
unsigned char temp[32];
|
|
inner.Finalize(temp);
|
|
outer.Write(temp, 32).Finalize(hash);
|
|
memory_cleanse(temp, sizeof(temp));
|
|
}
|