Compare commits
20 Commits
2b8bdd7e47
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
9961daf420
|
|||
|
8f80ceaf7f
|
|||
|
d4c316ae00
|
|||
|
70937e8547
|
|||
|
124f6a21a3
|
|||
|
ab33fe3670
|
|||
|
f78b10f565
|
|||
|
8686be3346
|
|||
|
8644c79167
|
|||
|
1537dd1be3
|
|||
|
8552d3dd2e
|
|||
|
9a9543a1ff
|
|||
|
d6449e647a
|
|||
|
a43cf1467d
|
|||
|
26cff5d331
|
|||
|
8f21a346db
|
|||
|
6dec2fea74
|
|||
|
ca71d9427f
|
|||
|
1d0a60bb12
|
|||
|
e15d4e6414
|
@@ -1,36 +0,0 @@
|
|||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
|
|
||||||
env:
|
|
||||||
GIT__TOKEN: ${{ secrets.TOKEN }}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
publish:
|
|
||||||
runs-on: linux
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- uses: actions/cache/restore@v4
|
|
||||||
with:
|
|
||||||
key: gradle
|
|
||||||
path: |
|
|
||||||
~/.gradle/caches/
|
|
||||||
~/.gradle/wrapper/
|
|
||||||
~/.konan/
|
|
||||||
|
|
||||||
- uses: actions/setup-java@v4
|
|
||||||
with:
|
|
||||||
java-version: '24'
|
|
||||||
distribution: 'temurin'
|
|
||||||
|
|
||||||
- run: ./gradlew publish
|
|
||||||
|
|
||||||
- uses: actions/cache/save@v4
|
|
||||||
with:
|
|
||||||
key: gradle
|
|
||||||
path: |
|
|
||||||
~/.gradle/caches/
|
|
||||||
~/.gradle/wrapper/
|
|
||||||
~/.konan/
|
|
||||||
47
.gitea/workflows/publish.yaml
Normal file
47
.gitea/workflows/publish.yaml
Normal file
@@ -0,0 +1,47 @@
|
|||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [ main ]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
publish:
|
||||||
|
runs-on: linux
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
java-version: '24'
|
||||||
|
distribution: 'temurin'
|
||||||
|
|
||||||
|
- name: Cache Gradle
|
||||||
|
uses: actions/cache@v4
|
||||||
|
with:
|
||||||
|
key: gradle-${{ hashFiles('**/libs.versions.toml') }}
|
||||||
|
restore-keys: gradle
|
||||||
|
path: |
|
||||||
|
~/.gradle/caches/
|
||||||
|
~/.gradle/wrapper/
|
||||||
|
|
||||||
|
- name: Cache Konan
|
||||||
|
uses: actions/cache@v4
|
||||||
|
with:
|
||||||
|
key: konan-${{ hashFiles('**/libs.versions.toml') }}
|
||||||
|
restore-keys: konan
|
||||||
|
path: |
|
||||||
|
~/.konan/
|
||||||
|
|
||||||
|
- name: Cache Node
|
||||||
|
uses: actions/cache@v4
|
||||||
|
with:
|
||||||
|
key: node-${{ hashFiles('**/libs.versions.toml') }}
|
||||||
|
restore-keys: node
|
||||||
|
path: |
|
||||||
|
~/.gradle/nodejs
|
||||||
|
~/.gradle/yarn
|
||||||
|
|
||||||
|
- name: Publish
|
||||||
|
run: ./gradlew publish
|
||||||
|
env:
|
||||||
|
INFENDRO__TOKEN: ${{ secrets.TOKEN }}
|
||||||
28
.gitea/workflows/test.yaml
Normal file
28
.gitea/workflows/test.yaml
Normal file
@@ -0,0 +1,28 @@
|
|||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
branches: [ main ]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
test:
|
||||||
|
runs-on: linux
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
java-version: '24'
|
||||||
|
distribution: 'temurin'
|
||||||
|
|
||||||
|
- name: Cache Gradle
|
||||||
|
uses: actions/cache@v4
|
||||||
|
with:
|
||||||
|
key: gradle-${{ hashFiles('**/libs.versions.toml') }}
|
||||||
|
restore-keys: gradle
|
||||||
|
path: |
|
||||||
|
~/.gradle/caches/
|
||||||
|
~/.gradle/wrapper/
|
||||||
|
|
||||||
|
- name: Test
|
||||||
|
run: ./gradlew jvmTest
|
||||||
35
README.md
Normal file
35
README.md
Normal file
@@ -0,0 +1,35 @@
|
|||||||
|
# kdf-kt
|
||||||
|
|
||||||
|
`kdf-kt` is a Kotlin Multiplatform library that provides common [Key Derivation Functions](https://en.wikipedia.org/wiki/Key_derivation_function).
|
||||||
|
|
||||||
|
Supported algorithms:
|
||||||
|
- PBKDF2
|
||||||
|
|
||||||
|
## Installation
|
||||||
|
|
||||||
|
Add the following to your `build.gradle.kts`.
|
||||||
|
|
||||||
|
```kotlin
|
||||||
|
repositories {
|
||||||
|
maven("https://git.infendro.com/api/packages/Infendro/maven")
|
||||||
|
}
|
||||||
|
|
||||||
|
dependencies {
|
||||||
|
implementation("com.infendro:kdf:1.2.1")
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
## Usage
|
||||||
|
|
||||||
|
```kotlin
|
||||||
|
fun main() {
|
||||||
|
// create a PBKDF2 instance using HMAC SHA-256
|
||||||
|
// this example uses 32 bytes of length and 100_000 iterations
|
||||||
|
val kdf = PBKDF2(32, 100_000, `SHA-256`())
|
||||||
|
|
||||||
|
// securely hash value with some salt
|
||||||
|
val value = "password".encodeToByteArray()
|
||||||
|
val salt = "salt".encodeToByteArray()
|
||||||
|
val hash = kdf.hash(value, salt)
|
||||||
|
}
|
||||||
|
```
|
||||||
@@ -1,57 +1,46 @@
|
|||||||
group = "com.infendro"
|
@file:OptIn(ExperimentalWasmDsl::class)
|
||||||
version = "1.0.2"
|
|
||||||
|
|
||||||
repositories {
|
import com.infendro.plugin.infendro
|
||||||
maven("https://git.infendro.com/api/packages/Infendro/maven")
|
import com.infendro.plugin.token
|
||||||
mavenCentral()
|
import org.jetbrains.kotlin.gradle.ExperimentalWasmDsl
|
||||||
}
|
|
||||||
|
group = "com.infendro"
|
||||||
|
version = "1.2.1"
|
||||||
|
|
||||||
plugins {
|
plugins {
|
||||||
|
alias(libs.plugins.infendro)
|
||||||
alias(libs.plugins.multiplatform)
|
alias(libs.plugins.multiplatform)
|
||||||
id("maven-publish")
|
id("maven-publish")
|
||||||
}
|
}
|
||||||
|
|
||||||
kotlin {
|
kotlin {
|
||||||
jvm()
|
jvm()
|
||||||
js {
|
|
||||||
nodejs()
|
|
||||||
}
|
|
||||||
linuxX64()
|
linuxX64()
|
||||||
|
linuxArm64()
|
||||||
|
mingwX64()
|
||||||
|
macosX64()
|
||||||
|
macosArm64()
|
||||||
|
js { nodejs() }
|
||||||
|
wasmJs { nodejs() }
|
||||||
|
wasmWasi { nodejs() }
|
||||||
|
|
||||||
|
repositories {
|
||||||
|
infendro()
|
||||||
|
mavenCentral()
|
||||||
|
}
|
||||||
|
|
||||||
sourceSets {
|
sourceSets {
|
||||||
commonMain.dependencies {
|
commonMain.dependencies {
|
||||||
implementation(libs.mac)
|
implementation(libs.bytes)
|
||||||
implementation(libs.hash)
|
implementation(libs.hash)
|
||||||
implementation(libs.bytearray)
|
implementation(libs.mac)
|
||||||
|
}
|
||||||
|
commonTest.dependencies {
|
||||||
|
implementation(libs.test)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
publishing {
|
publishing.repositories {
|
||||||
repositories {
|
infendro(token)
|
||||||
maven {
|
|
||||||
url = uri("https://git.infendro.com/api/packages/Infendro/maven")
|
|
||||||
authentication.create("header", HttpHeaderAuthentication::class)
|
|
||||||
credentials(HttpHeaderCredentials::class) {
|
|
||||||
val token = secret("git.token") ?: throw GradleException()
|
|
||||||
|
|
||||||
name = "Authorization"
|
|
||||||
value = "token $token"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
fun secret(
|
|
||||||
key: String,
|
|
||||||
): String? {
|
|
||||||
val property = key
|
|
||||||
val environment = key
|
|
||||||
.uppercase()
|
|
||||||
.replace(".", "__")
|
|
||||||
|
|
||||||
val prop = properties[property] as String?
|
|
||||||
val env = System.getenv(environment)
|
|
||||||
|
|
||||||
return prop ?: env
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,13 +1,16 @@
|
|||||||
[versions]
|
[versions]
|
||||||
kotlin = "2.2.10"
|
infendro = "1.1.0"
|
||||||
mac = "1.1.2"
|
kotlin = "2.3.0"
|
||||||
hash = "1.2.2"
|
bytes = "1.4.2"
|
||||||
bytearray = "1.1.1"
|
hash = "1.7.0"
|
||||||
|
mac = "1.5.0"
|
||||||
|
|
||||||
[plugins]
|
[plugins]
|
||||||
|
infendro = { id = "com.infendro.plugin", version.ref = "infendro" }
|
||||||
multiplatform = { id = "org.jetbrains.kotlin.multiplatform", version.ref = "kotlin" }
|
multiplatform = { id = "org.jetbrains.kotlin.multiplatform", version.ref = "kotlin" }
|
||||||
|
|
||||||
[libraries]
|
[libraries]
|
||||||
mac = { module = "com.infendro:mac", version.ref = "mac" }
|
bytes = { module = "com.infendro:bytes", version.ref = "bytes" }
|
||||||
hash = { module = "com.infendro:hash", version.ref = "hash" }
|
hash = { module = "com.infendro:hash", version.ref = "hash" }
|
||||||
bytearray = { module = "com.infendro:bytearray", version.ref = "bytearray" }
|
mac = { module = "com.infendro:mac", version.ref = "mac" }
|
||||||
|
test = { module = "org.jetbrains.kotlin:kotlin-test", version.ref = "kotlin" }
|
||||||
|
|||||||
@@ -1 +1,6 @@
|
|||||||
rootProject.name = "kdf"
|
rootProject.name = "kdf"
|
||||||
|
|
||||||
|
pluginManagement.repositories {
|
||||||
|
maven("https://git.infendro.com/api/packages/Infendro/maven")
|
||||||
|
mavenCentral()
|
||||||
|
}
|
||||||
|
|||||||
15
src/commonMain/kotlin/com/infendro/kdf/KDF.kt
Normal file
15
src/commonMain/kotlin/com/infendro/kdf/KDF.kt
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
package com.infendro.kdf
|
||||||
|
|
||||||
|
interface KDF {
|
||||||
|
val bytes: Int
|
||||||
|
val bits: Int
|
||||||
|
get() = bytes * 8
|
||||||
|
|
||||||
|
fun hashInto(value: ByteArray, salt: ByteArray, destination: ByteArray, destinationOffset: Int = 0)
|
||||||
|
|
||||||
|
fun hash(value: ByteArray, salt: ByteArray): ByteArray {
|
||||||
|
val result = ByteArray(bytes)
|
||||||
|
hashInto(value, salt, result)
|
||||||
|
return result
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,39 +1,41 @@
|
|||||||
package com.infendro.kdf
|
package com.infendro.kdf
|
||||||
|
|
||||||
import com.infendro.bytearray.addAll
|
import com.infendro.bytes.bytearray.xorWith
|
||||||
import com.infendro.bytearray.toByteArray
|
import com.infendro.bytes.int.toByteArray
|
||||||
import com.infendro.bytearray.xor
|
|
||||||
import com.infendro.hash.HashFunction
|
import com.infendro.hash.HashFunction
|
||||||
|
import com.infendro.kdf.util.ceilDiv
|
||||||
import com.infendro.mac.HMAC
|
import com.infendro.mac.HMAC
|
||||||
|
|
||||||
class PBKDF2(
|
class PBKDF2(
|
||||||
|
override val bytes: Int,
|
||||||
|
private val iterations: Int,
|
||||||
function: HashFunction,
|
function: HashFunction,
|
||||||
) {
|
) : KDF {
|
||||||
|
init {
|
||||||
|
require(bytes > 0)
|
||||||
|
require(iterations > 0)
|
||||||
|
}
|
||||||
|
|
||||||
private val hmac = HMAC(function)
|
private val hmac = HMAC(function)
|
||||||
|
private val buffer = ByteArray(hmac.bytes)
|
||||||
|
|
||||||
fun hash(
|
override fun hashInto(value: ByteArray, salt: ByteArray, destination: ByteArray, destinationOffset: Int) {
|
||||||
value: ByteArray,
|
hmac.init(value)
|
||||||
salt: ByteArray,
|
|
||||||
iterations: Int,
|
|
||||||
length: Int,
|
|
||||||
): ByteArray {
|
|
||||||
val key = buildList {
|
|
||||||
for (i in 1..(length + size - 1) / size) {
|
|
||||||
val input = salt + i.toUInt().toByteArray()
|
|
||||||
|
|
||||||
var u = hmac.hash(value, input)
|
for (block in 1..bytes.ceilDiv(hmac.bytes)) {
|
||||||
var result = u
|
val offset = (block - 1) * hmac.bytes
|
||||||
|
val bytes = minOf(bytes - offset, hmac.bytes)
|
||||||
|
|
||||||
|
hmac.update(salt)
|
||||||
|
hmac.update(block.toByteArray())
|
||||||
|
hmac.digestInto(buffer)
|
||||||
|
buffer.copyInto(destination, destinationOffset + offset, endIndex = bytes)
|
||||||
repeat(iterations - 1) {
|
repeat(iterations - 1) {
|
||||||
u = hmac.hash(value, u)
|
hmac.update(buffer)
|
||||||
result = result xor u
|
hmac.digestInto(buffer)
|
||||||
}
|
val offset = destinationOffset + offset
|
||||||
|
destination.xorWith(buffer, offset, offset + bytes)
|
||||||
addAll(result)
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return key
|
|
||||||
.take(length)
|
|
||||||
.toByteArray()
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
4
src/commonMain/kotlin/com/infendro/kdf/util/Math.kt
Normal file
4
src/commonMain/kotlin/com/infendro/kdf/util/Math.kt
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
package com.infendro.kdf.util
|
||||||
|
|
||||||
|
internal fun Int.ceilDiv(n: Int): Int =
|
||||||
|
(this + n - 1) / n
|
||||||
118
src/commonTest/kotlin/com/infendro/kdf/PBKDF2.kt
Normal file
118
src/commonTest/kotlin/com/infendro/kdf/PBKDF2.kt
Normal file
@@ -0,0 +1,118 @@
|
|||||||
|
package com.infendro.kdf
|
||||||
|
|
||||||
|
import com.infendro.hash.sha2.`SHA-256`
|
||||||
|
import kotlin.test.Test
|
||||||
|
import kotlin.test.assertContentEquals
|
||||||
|
|
||||||
|
class `PBKDF2 Test` {
|
||||||
|
@Test
|
||||||
|
fun `32 bytes 1 iteration`() {
|
||||||
|
val function = PBKDF2(32, 1, `SHA-256`())
|
||||||
|
|
||||||
|
val expected = byteArrayOf(
|
||||||
|
+0x12, +0x0f, -0x4a, -0x31, -0x04, -0x08, -0x4d, +0x2c,
|
||||||
|
+0x43, -0x19, +0x22, +0x52, +0x56, -0x3c, -0x08, +0x37,
|
||||||
|
-0x58, +0x65, +0x48, -0x37, +0x2c, -0x34, +0x35, +0x48,
|
||||||
|
+0x08, +0x05, -0x68, +0x7c, -0x49, +0x0b, -0x1f, +0x7b,
|
||||||
|
)
|
||||||
|
val actual = function.hash(
|
||||||
|
"password".encodeToByteArray(),
|
||||||
|
"salt".encodeToByteArray(),
|
||||||
|
)
|
||||||
|
assertContentEquals(expected, actual)
|
||||||
|
}
|
||||||
|
|
||||||
|
@Test
|
||||||
|
fun `32 bytes 2 iterations`() {
|
||||||
|
val function = PBKDF2(32, 2, `SHA-256`())
|
||||||
|
|
||||||
|
val expected = byteArrayOf(
|
||||||
|
-0x52, +0x4d, +0x0c, -0x6b, -0x51, +0x6b, +0x46, -0x2d,
|
||||||
|
+0x2d, +0x0a, -0x21, -0x07, +0x28, -0x10, +0x6d, -0x30,
|
||||||
|
+0x2a, +0x30, +0x3f, -0x72, -0x0d, -0x3e, +0x51, -0x21,
|
||||||
|
-0x2a, -0x1e, -0x28, +0x5a, -0x6b, +0x47, +0x4c, +0x43,
|
||||||
|
)
|
||||||
|
val actual = function.hash(
|
||||||
|
"password".encodeToByteArray(),
|
||||||
|
"salt".encodeToByteArray(),
|
||||||
|
)
|
||||||
|
assertContentEquals(expected, actual)
|
||||||
|
}
|
||||||
|
|
||||||
|
@Test
|
||||||
|
fun `32 bytes 4096 iterations`() {
|
||||||
|
val function = PBKDF2(32, 4096, `SHA-256`())
|
||||||
|
|
||||||
|
val expected = byteArrayOf(
|
||||||
|
-0x3b, -0x1c, +0x78, -0x2b, -0x6e, -0x78, -0x38, +0x41,
|
||||||
|
-0x56, +0x53, +0x0d, -0x4a, -0x7c, +0x5c, +0x4c, -0x73,
|
||||||
|
-0x6a, +0x28, -0x6d, -0x60, +0x01, -0x32, +0x4e, +0x11,
|
||||||
|
-0x5c, -0x6a, +0x38, +0x73, -0x56, -0x68, +0x13, +0x4a,
|
||||||
|
)
|
||||||
|
val actual = function.hash(
|
||||||
|
"password".encodeToByteArray(),
|
||||||
|
"salt".encodeToByteArray(),
|
||||||
|
)
|
||||||
|
assertContentEquals(expected, actual)
|
||||||
|
}
|
||||||
|
|
||||||
|
@Test
|
||||||
|
fun `40 bytes 4096 iterations`() {
|
||||||
|
val function = PBKDF2(40, 4096, `SHA-256`())
|
||||||
|
|
||||||
|
val expected = byteArrayOf(
|
||||||
|
-0x3b, -0x1c, +0x78, -0x2b, -0x6e, -0x78, -0x38, +0x41,
|
||||||
|
-0x56, +0x53, +0x0d, -0x4a, -0x7c, +0x5c, +0x4c, -0x73,
|
||||||
|
-0x6a, +0x28, -0x6d, -0x60, +0x01, -0x32, +0x4e, +0x11,
|
||||||
|
-0x5c, -0x6a, +0x38, +0x73, -0x56, -0x68, +0x13, +0x4a,
|
||||||
|
-0x09, -0x53, -0x68, -0x3f, -0x4c, +0x58, -0x32, +0x3f,
|
||||||
|
)
|
||||||
|
val actual = function.hash(
|
||||||
|
"password".encodeToByteArray(),
|
||||||
|
"salt".encodeToByteArray(),
|
||||||
|
)
|
||||||
|
assertContentEquals(expected, actual)
|
||||||
|
}
|
||||||
|
|
||||||
|
@Test
|
||||||
|
fun `64 bytes 1 iteration`() {
|
||||||
|
val function = PBKDF2(64, 1, `SHA-256`())
|
||||||
|
|
||||||
|
val expected = byteArrayOf(
|
||||||
|
+0x55, -0x54, +0x04, +0x6e, +0x56, -0x1d, +0x08, -0x61,
|
||||||
|
-0x14, +0x16, -0x6f, -0x3e, +0x25, +0x44, -0x4a, +0x05,
|
||||||
|
-0x07, +0x41, -0x7b, +0x21, +0x6d, -0x22, +0x04, +0x65,
|
||||||
|
-0x1a, -0x75, -0x63, +0x57, -0x3e, +0x0d, -0x54, -0x44,
|
||||||
|
+0x49, -0x36, -0x64, -0x34, -0x0f, +0x79, -0x4a, +0x45,
|
||||||
|
-0x67, +0x16, +0x64, -0x4d, -0x63, +0x77, -0x11, +0x31,
|
||||||
|
+0x7c, +0x71, -0x48, +0x45, -0x4f, -0x1d, +0x0b, -0x2b,
|
||||||
|
+0x09, +0x11, +0x20, +0x41, -0x2d, -0x5f, -0x69, -0x7d,
|
||||||
|
)
|
||||||
|
val actual = function.hash(
|
||||||
|
"passwd".encodeToByteArray(),
|
||||||
|
"salt".encodeToByteArray(),
|
||||||
|
)
|
||||||
|
assertContentEquals(expected, actual)
|
||||||
|
}
|
||||||
|
|
||||||
|
@Test
|
||||||
|
fun `64 bytes 80000 iterations`() {
|
||||||
|
val function = PBKDF2(64, 80_000, `SHA-256`())
|
||||||
|
|
||||||
|
val expected = byteArrayOf(
|
||||||
|
+0x4d, -0x24, -0x28, -0x0a, +0x0b, -0x68, -0x42, +0x21,
|
||||||
|
-0x7d, +0x0c, -0x12, +0x5e, -0x0e, +0x27, +0x01, -0x07,
|
||||||
|
+0x64, +0x1a, +0x44, +0x18, -0x30, +0x4c, +0x04, +0x14,
|
||||||
|
-0x52, -0x01, +0x08, -0x79, +0x6b, +0x34, -0x55, +0x56,
|
||||||
|
-0x5f, -0x2c, +0x25, -0x5f, +0x22, +0x58, +0x33, +0x54,
|
||||||
|
-0x66, -0x25, -0x7c, +0x1b, +0x51, -0x37, -0x4d, +0x17,
|
||||||
|
+0x6a, +0x27, +0x2b, -0x22, -0x45, -0x5f, -0x30, +0x78,
|
||||||
|
+0x47, -0x71, +0x62, -0x4d, -0x69, -0x0d, +0x3c, -0x73,
|
||||||
|
)
|
||||||
|
val actual = function.hash(
|
||||||
|
"Password".encodeToByteArray(),
|
||||||
|
"NaCl".encodeToByteArray(),
|
||||||
|
)
|
||||||
|
assertContentEquals(expected, actual)
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user