token_encryptor.h 2.6 KB
Newer Older
1 2 3 4 5 6 7
// Copyright 2013 The Chromium Authors. All rights reserved.
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.

#ifndef CHROME_BROWSER_CHROMEOS_SETTINGS_TOKEN_ENCRYPTOR_H_
#define CHROME_BROWSER_CHROMEOS_SETTINGS_TOKEN_ENCRYPTOR_H_

8
#include <memory>
9 10
#include <string>

11
#include "base/macros.h"
12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35

namespace crypto {
class SymmetricKey;
}

namespace chromeos {

// Interface class for classes that encrypt and decrypt tokens using the
// system salt.
class TokenEncryptor {
 public:
  virtual ~TokenEncryptor() {}

  // Encrypts |token| with the system salt key (stable for the lifetime
  // of the device).  Useful to avoid storing plain text in place like
  // Local State.
  virtual std::string EncryptWithSystemSalt(const std::string& token) = 0;

  // Decrypts |token| with the system salt key (stable for the lifetime
  // of the device).
  virtual std::string DecryptWithSystemSalt(
      const std::string& encrypted_token_hex) = 0;
};

36 37
// TokenEncryptor based on the system salt from cryptohome daemon. This
// implementation is used in production.
38 39
class CryptohomeTokenEncryptor : public TokenEncryptor {
 public:
40
  explicit CryptohomeTokenEncryptor(const std::string& system_salt);
41
  ~CryptohomeTokenEncryptor() override;
42 43

  // TokenEncryptor overrides:
44 45
  std::string EncryptWithSystemSalt(const std::string& token) override;
  std::string DecryptWithSystemSalt(
46
      const std::string& encrypted_token_hex) override;
47 48 49

 private:
  // Converts |passphrase| to a SymmetricKey using the given |salt|.
50 51 52
  std::unique_ptr<crypto::SymmetricKey> PassphraseToKey(
      const std::string& passphrase,
      const std::string& salt);
53 54 55 56 57 58 59 60 61 62 63

  // Encrypts (AES) the token given |key| and |salt|.
  std::string EncryptTokenWithKey(crypto::SymmetricKey* key,
                                  const std::string& salt,
                                  const std::string& token);

  // Decrypts (AES) hex encoded encrypted token given |key| and |salt|.
  std::string DecryptTokenWithKey(crypto::SymmetricKey* key,
                                  const std::string& salt,
                                  const std::string& encrypted_token_hex);

64 65
  // The cached system salt passed to the constructor, originally coming
  // from cryptohome daemon.
66 67 68 69
  std::string system_salt_;

  // A key based on the system salt.  Useful for encrypting device-level
  // data for which we have no additional credentials.
70
  std::unique_ptr<crypto::SymmetricKey> system_salt_key_;
71 72 73 74 75 76 77

  DISALLOW_COPY_AND_ASSIGN(CryptohomeTokenEncryptor);
};

}  // namespace chromeos

#endif  // CHROME_BROWSER_CHROMEOS_SETTINGS_TOKEN_ENCRYPTOR_H_