-
Notifications
You must be signed in to change notification settings - Fork 273
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[COMPRESS-633] Add encryption support for SevenZ (#332)
* feat: Encyrption support for Seven7 Implementation of password-based encryption for 7z compressor COMPRESS-633 * feat: Encyrption support for Seven7 without `AES/CBC/PKCS5Padding` As `AES/CBC/PKCS5Padding` is raised as weak of security, a manual implementation to fill cither block size is done COMPRESS-633 * feat: Encyrption support for SevenZ - implementation without storing password in a clear way - several corrections suggeested by reviewers COMPRESS-633 * feat: Encyrption support for SevenZ typo COMPRESS-633 * feat: Encyrption support for SevenZ Avoid incrasing the public API surface with uneccessary method COMPRESS-633 * feat: Encyrption support for SevenZ no IDE specifi config files COMPRESS-633 * Fix spelling * Update super class from master * AES256Options does not need to be public * Fix spelling in Javadoc Co-authored-by: Gary Gregory <[email protected]>
- Loading branch information
1 parent
f4eb199
commit f0d13f9
Showing
6 changed files
with
379 additions
and
55 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -3,6 +3,7 @@ target | |
.classpath | ||
.settings | ||
.idea | ||
.vscode | ||
*.iml | ||
*~ | ||
/.externalToolBuilders/ | ||
|
100 changes: 100 additions & 0 deletions
100
src/main/java/org/apache/commons/compress/archivers/sevenz/AES256Options.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,100 @@ | ||
/* | ||
* Licensed to the Apache Software Foundation (ASF) under one or more | ||
* contributor license agreements. See the NOTICE file distributed with | ||
* this work for additional information regarding copyright ownership. | ||
* The ASF licenses this file to You under the Apache License, Version 2.0 | ||
* (the "License"); you may not use this file except in compliance with | ||
* the License. You may obtain a copy of the License at | ||
* | ||
* http://www.apache.org/licenses/LICENSE-2.0 | ||
* | ||
* Unless required by applicable law or agreed to in writing, software | ||
* distributed under the License is distributed on an "AS IS" BASIS, | ||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
* See the License for the specific language governing permissions and | ||
* limitations under the License. | ||
* | ||
*/ | ||
package org.apache.commons.compress.archivers.sevenz; | ||
|
||
import java.security.GeneralSecurityException; | ||
import java.security.NoSuchAlgorithmException; | ||
import java.security.SecureRandom; | ||
import javax.crypto.Cipher; | ||
import javax.crypto.SecretKey; | ||
import javax.crypto.spec.IvParameterSpec; | ||
import javax.crypto.spec.SecretKeySpec; | ||
|
||
/** | ||
* Options for {@link SevenZMethod#AES256SHA256} encoder | ||
* | ||
* @since 1.23 | ||
* @see AES256SHA256Decoder | ||
*/ | ||
class AES256Options { | ||
|
||
private final byte[] salt; | ||
private final byte[] iv; | ||
private final int numCyclesPower; | ||
private final Cipher cipher; | ||
|
||
/** | ||
* @param password password used for encryption | ||
*/ | ||
public AES256Options(char[] password) { | ||
this(password, new byte[0], randomBytes(16), 19); | ||
} | ||
|
||
/** | ||
* @param password password used for encryption | ||
* @param salt for password hash salting (enforce password security) | ||
* @param iv Initialization Vector (IV) used by cipher algorithm | ||
* @param numCyclesPower another password security enforcer parameter that controls the cycles of password hashing. More the | ||
* this number is high, more security you'll have but also high CPU usage | ||
*/ | ||
public AES256Options(char[] password, byte[] salt, byte[] iv, int numCyclesPower) { | ||
this.salt = salt; | ||
this.iv = iv; | ||
this.numCyclesPower = numCyclesPower; | ||
|
||
// NOTE: for security purposes, password is wrapped in a Cipher as soon as possible to not stay in memory | ||
final byte[] aesKeyBytes = AES256SHA256Decoder.sha256Password(password, numCyclesPower, salt); | ||
final SecretKey aesKey = new SecretKeySpec(aesKeyBytes, "AES"); | ||
|
||
try { | ||
cipher = Cipher.getInstance("AES/CBC/NoPadding"); | ||
cipher.init(Cipher.ENCRYPT_MODE, aesKey, new IvParameterSpec(iv)); | ||
} catch (final GeneralSecurityException generalSecurityException) { | ||
throw new IllegalStateException( | ||
"Encryption error (do you have the JCE Unlimited Strength Jurisdiction Policy Files installed?)", | ||
generalSecurityException | ||
); | ||
} | ||
} | ||
|
||
byte[] getIv() { | ||
return iv; | ||
} | ||
|
||
int getNumCyclesPower() { | ||
return numCyclesPower; | ||
} | ||
|
||
byte[] getSalt() { | ||
return salt; | ||
} | ||
|
||
Cipher getCipher() { | ||
return cipher; | ||
} | ||
|
||
private static byte[] randomBytes(int size) { | ||
byte[] bytes = new byte[size]; | ||
try { | ||
SecureRandom.getInstanceStrong().nextBytes(bytes); | ||
} catch (NoSuchAlgorithmException e) { | ||
throw new IllegalStateException("No strong secure random available to generate strong AES key", e); | ||
} | ||
return bytes; | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.