Enhancement/security hardening - #329
Draft
PropzSaladaz wants to merge 22 commits into
Draft
PropzSaladaz wants to merge 22 commits into
PropzSaladaz wants to merge 22 commits into
Conversation
…call-from-production-API
…om:skalenetwork/libBLS into bug/remove-unsafe-call-from-production-API
…-production-API Remove unsafe call from public API
…-deterministic-encryption #328 add V2 AAD-bound deterministic encryption; refactor AES encryption
…tionVersion struct
…-bit-entropy-aes Enhancement/331 move to 256 bit entropy aes
…constructions-using-signer-index-0 #333 add rejection conditions for signer index 0 for TE constructs
…-decryption-api-cleanup
…on-api-cleanup Update call names; update & improve docs on library usage
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR includes several fixes / improvements regarding security.
Each issue has been solved separately in its own PR, and is linked below.
It also introduces several breaking changes with previous versions. Some compilation-wise (removed calls), others are more subtle and present under specific use cases.
Changes Included
1. #314 #313 Removal of unsecure fucntion exposed in the API
BLSPublicKeyShare::VerifySigWithHelperandBLSPublicKey::VerifySigWithHelperwere completely removed. Any calls to it will result in compilation failure. Update it to useVerifySiginstead. Uses the same inputs.2. #328 #330 Usage of AAD to derive IV for AES-GCM for deterministic encryption
ThresholdEncryption::encrypt()is now split into normal (non-deterministic)encrypt()andencryptDeterministic(). Callers that previously usedencrypt()for determinstic encryption should update toencryptDeterministic()Seed used for deterministic encryption was moved out of
EncryptMetaData, and is now passed directly into the new methodEncryptMetaDataadditionally requiresAesGcmVersionto be specified. UseV1to keep legacy behavior, andV2for new corrected behaviorThis change does not affect the normal
encryptpath ,since it doesn't use any synthetic IV, nor any validation path. Only affects theencryptDeterministicpath.Although the new functionality preserves deterministic behavior, it differs from the legacy
encryptDeterministicfor the exact same inputs. This means that distributed applications need to use synchronization to keep allencryptDeterministiccallers either usingV1orV2. (updated to V0 and V1 in 3.)3. #331 #332 Upgrade entropy from 128 bits to 256 bits for AESKey
Wire compatibility is one-way:
Existing high-level
encrypt()andencryptDeterministic()call signatures remain unchanged, but their default output is now V1.EncryptMetaData::aesGcmVersionhas been replaced byEncryptMetaData::encryptionVersion. This prevents callers from selecting incompatible TE and AES-GCM combinations.Direct
AesGcmCipherusers must update explicit enum values:AesGcmVersion::V1→ newAesGcmVersion::V0AesGcmVersion::V2→ newAesGcmVersion::V1Distributed systems using
encryptDeterministic()must pinmetadata.encryptionVersionin their protocol or epoch configuration. Nodes using different profiles will intentionally produce different ciphertext bytes for the same seed and plaintext.4. #333 #334 Reject any TE constructs using index 0
0inTEPrivateKeyShare,TEPublicKeyShare, andTEDecryptionShare;1..totalSignersrange inTEDecryptSet;lagrangeCoeffs;