+#ifndef CLOUDCOMM_H
+#define CLOUDCOMM_H
-
-
-
+#include "common.h"
+#include <pthread.h>
/**
* This class provides a communication API to the webserver. It also
* validates the HMACs on the slots and handles encryption.
* @version 1.0
*/
+#define CloudComm_SALT_SIZE 8
+#define CloudComm_TIMEOUT_MILLIS 5000
+; // 100
+#define CloudComm_IV_SIZE 16
+/** Sets the size for the HMAC. */
+#define CloudComm_HMAC_SIZE 32
+#define HttpURLConnection_HTTP_OK 200
-class CloudComm {
- private static final int SALT_SIZE = 8;
- private static final int TIMEOUT_MILLIS = 5000; // 100
- public static final int IV_SIZE = 16;
-
- /** Sets the size for the HMAC. */
- static final int HMAC_SIZE = 32;
-
- private String baseurl;
- private SecretKeySpec key;
- private Mac mac;
- private String password;
- private SecureRandom random;
- private char salt[];
- private Table table;
- private int listeningPort = -1;
- private Thread localServerThread = NULL;
- private bool doEnd = false;
-
- private TimingSingleton timer = NULL;
+typedef struct {
+ int fd;
+ int numBytes;
+} WebConnection;
- /**
- * Empty Constructor needed for child class.
- */
- CloudComm() {
- timer = TimingSingleton.getInstance();
- }
- /**
- * Constructor for actual use. Takes in the url and password.
- */
- CloudComm(Table _table, String _baseurl, String _password, int _listeningPort) {
- timer = TimingSingleton.getInstance();
- this.table = _table;
- this.baseurl = _baseurl;
- this.password = _password;
- this.random = new SecureRandom();
- this.listeningPort = _listeningPort;
-
- if (this.listeningPort > 0) {
- localServerThread = new Thread(new Runnable() {
- public void run() {
- localServerWorkerFunction();
- }
- });
- localServerThread.start();
- }
- }
+class CloudComm {
+private:
+ IoTString *baseurl;
+ AESKey *key;
+ Mac *mac;
+ IoTString *password;
+ SecureRandom *random;
+ Array<char> *salt;
+ Table *table;
+ int32_t listeningPort;
+ pthread_t localServerThread;
+ bool doEnd;
+ TimingSingleton *timer;
+ Array<char> *getslot;
+ Array<char> *putslot;
/**
* Generates Key from password.
*/
- private SecretKeySpec initKey() {
- try {
- PBEKeySpec keyspec = new PBEKeySpec(password.toCharArray(),
- salt,
- 65536,
- 128);
- SecretKey tmpkey = SecretKeyFactory.getInstance("PBKDF2WithHmacSHA256").generateSecret(keyspec);
- return new SecretKeySpec(tmpkey.getEncoded(), "AES");
- } catch (Exception e) {
- e.printStackTrace();
- throw new Error("Failed generating key.");
- }
- }
-
- /**
- * Inits all the security stuff
- */
- public void initSecurity() throws ServerException {
- // try to get the salt and if one does not exist set one
- if (!getSalt()) {
- //Set the salt
- setSalt();
- }
-
- initCrypt();
- }
+ AESKey *initKey();
/**
* Inits the HMAC generator.
*/
- private void initCrypt() {
-
- if (password == NULL) {
- return;
- }
-
- try {
- key = initKey();
- password = NULL; // drop password
- mac = Mac.getInstance("HmacSHA256");
- mac.init(key);
- } catch (Exception e) {
- e.printStackTrace();
- throw new Error("Failed To Initialize Ciphers");
- }
- }
+ void initCrypt();
/*
* Builds the URL for the given request.
*/
- private URL buildRequest(bool isput, int64_t sequencenumber, int64_t maxentries) throws IOException {
- String reqstring = isput ? "req=putslot" : "req=getslot";
- String urlstr = baseurl + "?" + reqstring + "&seq=" + sequencenumber;
- if (maxentries != 0)
- urlstr += "&max=" + maxentries;
- return new URL(urlstr);
- }
-
- private void setSalt() throws ServerException {
-
- if (salt != NULL) {
- // Salt already sent to server so dont set it again
- return;
- }
-
- try {
- char[] saltTmp = new char[SALT_SIZE];
- random.nextBytes(saltTmp);
-
- for (int i = 0; i < SALT_SIZE; i++) {
- System.out.println((int)saltTmp[i] & 255);
- }
-
-
- URL url = new URL(baseurl + "?req=setsalt");
-
- timer.startTime();
- URLConnection con = url.openConnection();
- HttpURLConnection http = (HttpURLConnection) con;
-
- http.setRequestMethod("POST");
- http.setFixedLengthStreamingMode(saltTmp.length);
- http.setDoOutput(true);
- http.setConnectTimeout(TIMEOUT_MILLIS);
-
-
- http.connect();
-
- OutputStream os = http.getOutputStream();
- os.write(saltTmp);
- os.flush();
-
- int responsecode = http.getResponseCode();
- if (responsecode != HttpURLConnection.HTTP_OK) {
- // TODO: Remove this print
- System.out.println(responsecode);
- throw new Error("Invalid response");
- }
-
- timer.endTime();
-
- salt = saltTmp;
- } catch (Exception e) {
- // e.printStackTrace();
- timer.endTime();
- throw new ServerException("Failed setting salt", ServerException.TypeConnectTimeout);
- }
- }
-
- private bool getSalt() throws ServerException {
- URL url = NULL;
- URLConnection con = NULL;
- HttpURLConnection http = NULL;
-
- try {
- url = new URL(baseurl + "?req=getsalt");
- } catch (Exception e) {
- // e.printStackTrace();
- throw new Error("getSlot failed");
- }
- try {
+ IoTString *buildRequest(bool isput, int64_t sequencenumber, int64_t maxentries);
+ void setSalt();
+ bool getSalt();
+ Array<char> *createIV(int64_t machineId, int64_t localSequenceNumber);
+ Array<char> *encryptSlotAndPrependIV(Array<char> *rawData, Array<char> *ivBytes);
+ Array<char> *stripIVAndDecryptSlot(Array<char> *rawData);
+ Array<Slot *> *processSlots(WebConnection *wc);
- timer.startTime();
- con = url.openConnection();
- http = (HttpURLConnection) con;
- http.setRequestMethod("POST");
- http.setConnectTimeout(TIMEOUT_MILLIS);
- http.setReadTimeout(TIMEOUT_MILLIS);
+public:
+ /**
+ * Empty Constructor needed for child class.
+ */
+ CloudComm();
- http.connect();
- timer.endTime();
- } catch (SocketTimeoutException e) {
- timer.endTime();
- throw new ServerException("getSalt failed", ServerException.TypeConnectTimeout);
- } catch (Exception e) {
- // e.printStackTrace();
- throw new Error("getSlot failed");
- }
-
- try {
-
- timer.startTime();
-
- int responsecode = http.getResponseCode();
- if (responsecode != HttpURLConnection.HTTP_OK) {
- // TODO: Remove this print
- // System.out.println(responsecode);
- throw new Error("Invalid response");
- }
-
- InputStream is = http.getInputStream();
- if (is.available() > 0) {
- DataInputStream dis = new DataInputStream(is);
- int salt_length = dis.readInt();
- char [] tmp = new char[salt_length];
- dis.readFully(tmp);
- salt = tmp;
- timer.endTime();
-
- return true;
- } else {
- timer.endTime();
-
- return false;
- }
- } catch (SocketTimeoutException e) {
- timer.endTime();
-
- throw new ServerException("getSalt failed", ServerException.TypeInputTimeout);
- } catch (Exception e) {
- // e.printStackTrace();
- throw new Error("getSlot failed");
- }
- }
-
- private char[] createIV(int64_t machineId, int64_t localSequenceNumber) {
- ByteBuffer buffer = ByteBuffer.allocate(IV_SIZE);
- buffer.putLong(machineId);
- int64_t localSequenceNumberShifted = localSequenceNumber << 16;
- buffer.putLong(localSequenceNumberShifted);
- return buffer.array();
-
- }
-
- private char[] encryptSlotAndPrependIV(char[] rawData, char[] ivBytes) {
- try {
- IvParameterSpec ivSpec = new IvParameterSpec(ivBytes);
- Cipher cipher = Cipher.getInstance("AES/CTR/NoPadding");
- cipher.init(Cipher.ENCRYPT_MODE, key, ivSpec);
-
- char[] encryptedBytes = cipher.doFinal(rawData);
-
- char[] chars = new char[encryptedBytes.length + IV_SIZE];
- System.arraycopy(ivBytes, 0, chars, 0, ivBytes.length);
- System.arraycopy(encryptedBytes, 0, chars, IV_SIZE, encryptedBytes.length);
-
- return chars;
-
- } catch (Exception e) {
- e.printStackTrace();
- throw new Error("Failed To Encrypt");
- }
- }
-
-
- private char[] stripIVAndDecryptSlot(char[] rawData) {
- try {
- char[] ivBytes = new char[IV_SIZE];
- char[] encryptedBytes = new char[rawData.length - IV_SIZE];
- System.arraycopy(rawData, 0, ivBytes, 0, IV_SIZE);
- System.arraycopy(rawData, IV_SIZE, encryptedBytes, 0 , encryptedBytes.length);
-
- IvParameterSpec ivSpec = new IvParameterSpec(ivBytes);
-
- Cipher cipher = Cipher.getInstance("AES/CTR/NoPadding");
- cipher.init(Cipher.DECRYPT_MODE, key, ivSpec);
- return cipher.doFinal(encryptedBytes);
-
- } catch (Exception e) {
- e.printStackTrace();
- throw new Error("Failed To Decrypt");
- }
- }
+ /**
+ * Constructor for actual use. Takes in the url and password.
+ */
+ CloudComm(Table *_table, IoTString *_baseurl, IoTString *_password, int _listeningPort);
+ ~CloudComm();
+ /**
+ * Inits all the security stuff
+ */
+ void initSecurity();
/*
* API for putting a slot into the queue. Returns NULL on success.
* On failure, the server will send slots with newer sequence
* numbers.
*/
- public Slot[] putSlot(Slot slot, int max) throws ServerException {
- URL url = NULL;
- URLConnection con = NULL;
- HttpURLConnection http = NULL;
-
- try {
- if (salt == NULL) {
- if (!getSalt()) {
- throw new ServerException("putSlot failed", ServerException.TypeSalt);
- }
- initCrypt();
- }
-
- int64_t sequencenumber = slot.getSequenceNumber();
- char[] slotBytes = slot.encode(mac);
- // slotBytes = encryptCipher.doFinal(slotBytes);
-
- // char[] iVBytes = slot.getSlotCryptIV();
-
- // char[] chars = new char[slotBytes.length + IV_SIZE];
- // System.arraycopy(iVBytes, 0, chars, 0, iVBytes.length);
- // System.arraycopy(slotBytes, 0, chars, IV_SIZE, slotBytes.length);
-
-
- char[] chars = encryptSlotAndPrependIV(slotBytes, slot.getSlotCryptIV());
-
- url = buildRequest(true, sequencenumber, max);
-
- timer.startTime();
- con = url.openConnection();
- http = (HttpURLConnection) con;
-
- http.setRequestMethod("POST");
- http.setFixedLengthStreamingMode(chars.length);
- http.setDoOutput(true);
- http.setConnectTimeout(TIMEOUT_MILLIS);
- http.setReadTimeout(TIMEOUT_MILLIS);
- http.connect();
-
- OutputStream os = http.getOutputStream();
- os.write(chars);
- os.flush();
-
- timer.endTime();
-
-
- // System.out.println("Bytes Sent: " + chars.length);
- } catch (ServerException e) {
- timer.endTime();
-
- throw e;
- } catch (SocketTimeoutException e) {
- timer.endTime();
-
- throw new ServerException("putSlot failed", ServerException.TypeConnectTimeout);
- } catch (Exception e) {
- // e.printStackTrace();
- throw new Error("putSlot failed");
- }
-
-
-
- try {
- timer.startTime();
- InputStream is = http.getInputStream();
- DataInputStream dis = new DataInputStream(is);
- char[] resptype = new char[7];
- dis.readFully(resptype);
- timer.endTime();
-
- if (Arrays.equals(resptype, "getslot".getBytes())) {
- return processSlots(dis);
- } else if (Arrays.equals(resptype, "putslot".getBytes())) {
- return NULL;
- } else
- throw new Error("Bad response to putslot");
-
- } catch (SocketTimeoutException e) {
- timer.endTime();
- throw new ServerException("putSlot failed", ServerException.TypeInputTimeout);
- } catch (Exception e) {
- // e.printStackTrace();
- throw new Error("putSlot failed");
- }
- }
+ Array<Slot *> *putSlot(Slot *slot, int max);
/**
* Request the server to send all slots with the given
* sequencenumber or newer.
*/
- public Slot[] getSlots(int64_t sequencenumber) throws ServerException {
- URL url = NULL;
- URLConnection con = NULL;
- HttpURLConnection http = NULL;
-
- try {
- if (salt == NULL) {
- if (!getSalt()) {
- throw new ServerException("getSlots failed", ServerException.TypeSalt);
- }
- initCrypt();
- }
-
- url = buildRequest(false, sequencenumber, 0);
- timer.startTime();
- con = url.openConnection();
- http = (HttpURLConnection) con;
- http.setRequestMethod("POST");
- http.setConnectTimeout(TIMEOUT_MILLIS);
- http.setReadTimeout(TIMEOUT_MILLIS);
-
-
-
- http.connect();
- timer.endTime();
-
- } catch (SocketTimeoutException e) {
- timer.endTime();
-
- throw new ServerException("getSlots failed", ServerException.TypeConnectTimeout);
- } catch (ServerException e) {
- timer.endTime();
-
- throw e;
- } catch (Exception e) {
- // e.printStackTrace();
- throw new Error("getSlots failed");
- }
+ Array<Slot *> *getSlots(int64_t sequencenumber);
- try {
-
- timer.startTime();
- InputStream is = http.getInputStream();
- DataInputStream dis = new DataInputStream(is);
- char[] resptype = new char[7];
-
- dis.readFully(resptype);
- timer.endTime();
-
- if (!Arrays.equals(resptype, "getslot".getBytes()))
- throw new Error("Bad Response: " + new String(resptype));
-
- return processSlots(dis);
- } catch (SocketTimeoutException e) {
- timer.endTime();
-
- throw new ServerException("getSlots failed", ServerException.TypeInputTimeout);
- } catch (Exception e) {
- // e.printStackTrace();
- throw new Error("getSlots failed");
- }
- }
/**
* Method that actually handles building Slot objects from the
* server response. Shared by both putSlot and getSlots.
*/
- private Slot[] processSlots(DataInputStream dis) throws Exception {
- int numberofslots = dis.readInt();
- int[] sizesofslots = new int[numberofslots];
-
- Slot[] slots = new Slot[numberofslots];
- for (int i = 0; i < numberofslots; i++)
- sizesofslots[i] = dis.readInt();
-
- for (int i = 0; i < numberofslots; i++) {
-
- char[] rawData = new char[sizesofslots[i]];
- dis.readFully(rawData);
-
-
- // char[] data = new char[rawData.length - IV_SIZE];
- // System.arraycopy(rawData, IV_SIZE, data, 0, data.length);
-
-
- char[] data = stripIVAndDecryptSlot(rawData);
-
- // data = decryptCipher.doFinal(data);
-
- slots[i] = Slot.decode(table, data, mac);
- }
- dis.close();
- return slots;
- }
-
- public char[] sendLocalData(char[] sendData, int64_t localSequenceNumber, String host, int port) {
-
- if (salt == NULL) {
- return NULL;
- }
- try {
- System.out.println("Passing Locally");
-
- mac.update(sendData);
- char[] genmac = mac.doFinal();
- char[] totalData = new char[sendData.length + genmac.length];
- System.arraycopy(sendData, 0, totalData, 0, sendData.length);
- System.arraycopy(genmac, 0, totalData, sendData.length, genmac.length);
-
- // Encrypt the data for sending
- // char[] encryptedData = encryptCipher.doFinal(totalData);
- // char[] encryptedData = encryptCipher.doFinal(totalData);
- char[] iv = createIV(table.getMachineId(), table.getLocalSequenceNumber());
- char[] encryptedData = encryptSlotAndPrependIV(totalData, iv);
-
- // Open a TCP socket connection to a local device
- Socket socket = new Socket(host, port);
- socket.setReuseAddress(true);
- DataOutputStream output = new DataOutputStream(socket.getOutputStream());
- DataInputStream input = new DataInputStream(socket.getInputStream());
-
-
- timer.startTime();
- // Send data to output (length of data, the data)
- output.writeInt(encryptedData.length);
- output.write(encryptedData, 0, encryptedData.length);
- output.flush();
-
- int lengthOfReturnData = input.readInt();
- char[] returnData = new char[lengthOfReturnData];
- input.readFully(returnData);
-
- timer.endTime();
-
- // returnData = decryptCipher.doFinal(returnData);
- returnData = stripIVAndDecryptSlot(returnData);
- // returnData = decryptCipher.doFinal(returnData);
-
- // We are done with this socket
- socket.close();
-
- mac.update(returnData, 0, returnData.length - HMAC_SIZE);
- char[] realmac = mac.doFinal();
- char[] recmac = new char[HMAC_SIZE];
- System.arraycopy(returnData, returnData.length - realmac.length, recmac, 0, realmac.length);
-
- if (!Arrays.equals(recmac, realmac))
- throw new Error("Local Error: Invalid HMAC! Potential Attack!");
-
- char[] returnData2 = new char[lengthOfReturnData - recmac.length];
- System.arraycopy(returnData, 0, returnData2, 0, returnData2.length);
-
- return returnData2;
- } catch (Exception e) {
- e.printStackTrace();
- // throw new Error("Local comms failure...");
-
- }
-
- return NULL;
- }
-
- private void localServerWorkerFunction() {
-
- ServerSocket inputSocket = NULL;
-
- try {
- // Local server socket
- inputSocket = new ServerSocket(listeningPort);
- inputSocket.setReuseAddress(true);
- inputSocket.setSoTimeout(TIMEOUT_MILLIS);
- } catch (Exception e) {
- e.printStackTrace();
- throw new Error("Local server setup failure...");
- }
-
- while (!doEnd) {
-
- try {
- // Accept incoming socket
- Socket socket = inputSocket.accept();
-
- DataInputStream input = new DataInputStream(socket.getInputStream());
- DataOutputStream output = new DataOutputStream(socket.getOutputStream());
-
- // Get the encrypted data from the server
- int dataSize = input.readInt();
- char[] readData = new char[dataSize];
- input.readFully(readData);
-
- timer.endTime();
-
- // Decrypt the data
- // readData = decryptCipher.doFinal(readData);
- readData = stripIVAndDecryptSlot(readData);
-
- mac.update(readData, 0, readData.length - HMAC_SIZE);
- char[] genmac = mac.doFinal();
- char[] recmac = new char[HMAC_SIZE];
- System.arraycopy(readData, readData.length - recmac.length, recmac, 0, recmac.length);
-
- if (!Arrays.equals(recmac, genmac))
- throw new Error("Local Error: Invalid HMAC! Potential Attack!");
-
- char[] returnData = new char[readData.length - recmac.length];
- System.arraycopy(readData, 0, returnData, 0, returnData.length);
-
- // Process the data
- // char[] sendData = table.acceptDataFromLocal(readData);
- char[] sendData = table.acceptDataFromLocal(returnData);
-
-
- mac.update(sendData);
- char[] realmac = mac.doFinal();
- char[] totalData = new char[sendData.length + realmac.length];
- System.arraycopy(sendData, 0, totalData, 0, sendData.length);
- System.arraycopy(realmac, 0, totalData, sendData.length, realmac.length);
-
- // Encrypt the data for sending
- // char[] encryptedData = encryptCipher.doFinal(totalData);
- char[] iv = createIV(table.getMachineId(), table.getLocalSequenceNumber());
- char[] encryptedData = encryptSlotAndPrependIV(totalData, iv);
-
-
- timer.startTime();
- // Send data to output (length of data, the data)
- output.writeInt(encryptedData.length);
- output.write(encryptedData, 0, encryptedData.length);
- output.flush();
-
- // close the socket
- socket.close();
- } catch (Exception e) {
-
- }
- }
-
- if (inputSocket != NULL) {
- try {
- inputSocket.close();
- } catch (Exception e) {
- e.printStackTrace();
- throw new Error("Local server close failure...");
- }
- }
- }
-
- public void close() {
- doEnd = true;
-
- if (localServerThread != NULL) {
- try {
- localServerThread.join();
- } catch (Exception e) {
- e.printStackTrace();
- throw new Error("Local Server thread join issue...");
- }
- }
-
- // System.out.println("Done Closing Cloud Comm");
- }
- protected void finalize() throws Throwable {
- try {
- close(); // close open files
- } finally {
- super.finalize();
- }
- }
-}
+ Array<char> *sendLocalData(Array<char> *sendData, int64_t localSequenceNumber, IoTString *host, int port);
+ void closeCloud();
+ void localServerWorkerFunction();
+};
+#endif