pwd.c 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251
  1. /*
  2. *******************************************************************************
  3. \file pwd.c
  4. \brief Generate and manage passwords
  5. \project bee2/cmd
  6. \created 2022.06.23
  7. \version 2023.12.17
  8. \copyright The Bee2 authors
  9. \license Licensed under the Apache License, Version 2.0 (see LICENSE.txt).
  10. *******************************************************************************
  11. */
  12. #include "../cmd.h"
  13. #include <bee2/core/blob.h>
  14. #include <bee2/core/dec.h>
  15. #include <bee2/core/err.h>
  16. #include <bee2/core/hex.h>
  17. #include <bee2/core/mem.h>
  18. #include <bee2/core/prng.h>
  19. #include <bee2/core/rng.h>
  20. #include <bee2/core/str.h>
  21. #include <bee2/core/util.h>
  22. #include <bee2/crypto/bels.h>
  23. #include <bee2/crypto/belt.h>
  24. #include <bee2/crypto/bign.h>
  25. #include <bee2/crypto/bpki.h>
  26. #include <bee2/crypto/brng.h>
  27. #include <stdio.h>
  28. /*
  29. *******************************************************************************
  30. Утилита pwd
  31. Функционал:
  32. - построение пароля по заданной схеме;
  33. - проверочное определение ранее построенного пароля;
  34. - печать ранее построенного пароля.
  35. Допустимые схемы построения паролей определены в модуле cmd.h при описании
  36. функций cmdPwdGen(), cmdPwdRead().
  37. Пример:
  38. bee2cmd pwd gen share:"-l256 -t3 -crc -pass pass:zed s1 s2 s3 s4 s5"
  39. bee2cmd pwd gen \
  40. share:"-l192 -pass share:\"-crc -pass pass:zed s1 s2 s3\" ss1 ss2 ss3"
  41. bee2cmd pwd val share:"-pass share:\"-pass pass:zed s2 s4 s1\" ss3 ss1"
  42. bee2cmd pwd print share:"-pass share:\"-pass pass:zed s2 s4 s1\" ss3 ss1"
  43. *******************************************************************************
  44. */
  45. static const char _name[] = "pwd";
  46. static const char _descr[] = "generate and manage passwords";
  47. static int pwdUsage()
  48. {
  49. printf(
  50. "bee2cmd/%s: %s\n"
  51. "Usage:\n"
  52. " pwd gen <schema>\n"
  53. " generate a password according to <schema>\n"
  54. " pwd val <schema>\n"
  55. " validate a password built by <schema>\n"
  56. " pwd print <schema>\n"
  57. " print a password built by <schema>\n"
  58. " schemas:\n"
  59. " pass:<pwd> -- direct password\n"
  60. " share:\"[options] <share1> <share2> ...\" -- shared password\n"
  61. " options:\n"
  62. " -t<nn> --- threshold (2 <= <nn> <= 16, 2 by default)\n"
  63. " -l<mmm> --- password bitlen: 128, 192 or 256 (by default)\n"
  64. " -crc --- the password contains 64-bit crc (<mmm> != 128)\n"
  65. " -pass <schema> --- password to protect shares\n"
  66. ,
  67. _name, _descr
  68. );
  69. return -1;
  70. }
  71. /*
  72. *******************************************************************************
  73. Самотестирование
  74. *******************************************************************************
  75. */
  76. static err_t pwdSelfTest()
  77. {
  78. const char pwd[] = "B194BAC80A08F53B";
  79. octet state[1024];
  80. octet buf[5 * (32 + 1)];
  81. octet buf1[32];
  82. // bels-share: разделение и сборка
  83. if (belsShare3(buf, 5, 3, 32, beltH()) != ERR_OK)
  84. return ERR_SELFTEST;
  85. if (belsRecover2(buf1, 1, 32, buf) != ERR_OK ||
  86. memEq(buf1, beltH(), 32))
  87. return ERR_SELFTEST;
  88. if (belsRecover2(buf1, 2, 32, buf) != ERR_OK ||
  89. memEq(buf1, beltH(), 32))
  90. return ERR_SELFTEST;
  91. if (belsRecover2(buf1, 3, 32, buf) != ERR_OK ||
  92. !memEq(buf1, beltH(), 32))
  93. return ERR_SELFTEST;
  94. // brng-ctr: тест Б.2
  95. ASSERT(sizeof(state) >= brngCTR_keep());
  96. memCopy(buf, beltH(), 96);
  97. brngCTRStart(state, beltH() + 128, beltH() + 128 + 64);
  98. brngCTRStepR(buf, 96, state);
  99. if (!hexEq(buf,
  100. "1F66B5B84B7339674533F0329C74F218"
  101. "34281FED0732429E0C79235FC273E269"
  102. "4C0E74B2CD5811AD21F23DE7E0FA742C"
  103. "3ED6EC483C461CE15C33A77AA308B7D2"
  104. "0F51D91347617C20BD4AB07AEF4F26A1"
  105. "AD1362A8F9A3D42FBE1B8E6F1C88AAD5"))
  106. return ERR_SELFTEST;
  107. // pbkdf2 тест E.5
  108. beltPBKDF2(buf, (const octet*)"B194BAC80A08F53B", strLen(pwd), 10000,
  109. beltH() + 128 + 64, 8);
  110. if (!hexEq(buf,
  111. "3D331BBBB1FBBB40E4BF22F6CB9A689E"
  112. "F13A77DC09ECF93291BFE42439A72E7D"))
  113. return FALSE;
  114. // belt-kwp: тест A.21
  115. ASSERT(sizeof(state) >= beltKWP_keep());
  116. beltKWPStart(state, beltH() + 128, 32);
  117. memCopy(buf, beltH(), 32);
  118. memCopy(buf + 32, beltH() + 32, 16);
  119. beltKWPStepE(buf, 48, state);
  120. if (!hexEq(buf,
  121. "49A38EE108D6C742E52B774F00A6EF98"
  122. "B106CBD13EA4FB0680323051BC04DF76"
  123. "E487B055C69BCF541176169F1DC9F6C8"))
  124. return FALSE;
  125. // все нормально
  126. return ERR_OK;
  127. }
  128. /*
  129. *******************************************************************************
  130. Генерация пароля
  131. pwd gen <schema>
  132. *******************************************************************************
  133. */
  134. static err_t pwdGen(int argc, char* argv[])
  135. {
  136. err_t code = ERR_OK;
  137. cmd_pwd_t pwd = 0;
  138. // верное число параметров?
  139. if (argc != 1)
  140. return ERR_BAD_PARAMS;
  141. // самотестирование
  142. code = pwdSelfTest();
  143. ERR_CALL_CHECK(code);
  144. // запустить ГСЧ
  145. code = cmdRngStart(TRUE);
  146. ERR_CALL_CHECK(code);
  147. // генерировать пароль
  148. code = cmdPwdGen(&pwd, *argv);
  149. cmdPwdClose(pwd);
  150. return code;
  151. }
  152. /*
  153. *******************************************************************************
  154. Проверка пароля
  155. pwd val <schema>
  156. *******************************************************************************
  157. */
  158. static err_t pwdVal(int argc, char* argv[])
  159. {
  160. err_t code = ERR_OK;
  161. cmd_pwd_t pwd = 0;
  162. // верное число параметров?
  163. if (argc != 1)
  164. return ERR_BAD_PARAMS;
  165. // самотестирование
  166. code = pwdSelfTest();
  167. ERR_CALL_CHECK(code);
  168. // определить пароль (с одновременной проверкой)
  169. code = cmdPwdRead(&pwd, *argv);
  170. cmdPwdClose(pwd);
  171. return code;
  172. }
  173. /*
  174. *******************************************************************************
  175. Печать пароля
  176. pwd print <schema>
  177. *******************************************************************************
  178. */
  179. static err_t pwdPrint(int argc, char* argv[])
  180. {
  181. err_t code = ERR_OK;
  182. cmd_pwd_t pwd = 0;
  183. // верное число параметров?
  184. if (argc != 1)
  185. return ERR_BAD_PARAMS;
  186. // определить пароль
  187. code = cmdPwdRead(&pwd, *argv);
  188. ERR_CALL_CHECK(code);
  189. // печатать пароль
  190. printf("%s\n", pwd);
  191. cmdPwdClose(pwd);
  192. return code;
  193. }
  194. /*
  195. *******************************************************************************
  196. Главная функция
  197. *******************************************************************************
  198. */
  199. int pwdMain(int argc, char* argv[])
  200. {
  201. err_t code;
  202. // справка
  203. if (argc < 3)
  204. return pwdUsage();
  205. // разбор
  206. ++argv, --argc;
  207. if (strEq(argv[0], "gen"))
  208. code = pwdGen(argc - 1, argv + 1);
  209. else if (strEq(argv[0], "val"))
  210. code = pwdVal(argc - 1, argv + 1);
  211. else if (strEq(argv[0], "print"))
  212. code = pwdPrint(argc - 1, argv + 1);
  213. else
  214. code = ERR_CMD_NOT_FOUND;
  215. // завершить
  216. if (code != ERR_OK || strEq(argv[0], "val"))
  217. printf("bee2cmd/%s: %s\n", _name, errMsg(code));
  218. return code != ERR_OK ? -1 : 0;
  219. }
  220. /*
  221. *******************************************************************************
  222. Инициализация
  223. *******************************************************************************
  224. */
  225. err_t pwdInit()
  226. {
  227. return cmdReg(_name, _descr, pwdMain);
  228. }