Spomky-Labs /
jose
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
| 1 | <?php |
||
| 2 | |||
| 3 | /* |
||
| 4 | * The MIT License (MIT) |
||
| 5 | * |
||
| 6 | * Copyright (c) 2014-2016 Spomky-Labs |
||
| 7 | * |
||
| 8 | * This software may be modified and distributed under the terms |
||
| 9 | * of the MIT license. See the LICENSE file for details. |
||
| 10 | */ |
||
| 11 | |||
| 12 | namespace Jose\KeyConverter; |
||
| 13 | |||
| 14 | use Assert\Assertion; |
||
| 15 | use Base64Url\Base64Url; |
||
| 16 | use FG\ASN1\Universal\BitString; |
||
| 17 | use FG\ASN1\Universal\Integer; |
||
| 18 | use FG\ASN1\Universal\NullObject; |
||
| 19 | use FG\ASN1\Universal\ObjectIdentifier; |
||
| 20 | use FG\ASN1\Universal\OctetString; |
||
| 21 | use FG\ASN1\Universal\Sequence; |
||
| 22 | use Jose\Object\JWKInterface; |
||
| 23 | use Jose\Util\BigInteger; |
||
| 24 | |||
| 25 | final class RSAKey extends Sequence |
||
| 26 | { |
||
| 27 | /** |
||
| 28 | * @var array |
||
| 29 | */ |
||
| 30 | private $values = []; |
||
| 31 | |||
| 32 | /** |
||
| 33 | * @var \Jose\Util\BigInteger |
||
| 34 | */ |
||
| 35 | private $modulus; |
||
| 36 | |||
| 37 | /** |
||
| 38 | * @var int |
||
| 39 | */ |
||
| 40 | private $modulus_length; |
||
| 41 | |||
| 42 | /** |
||
| 43 | * @var \Jose\Util\BigInteger |
||
| 44 | */ |
||
| 45 | private $public_exponent; |
||
| 46 | |||
| 47 | /** |
||
| 48 | * @var \Jose\Util\BigInteger|null |
||
| 49 | */ |
||
| 50 | private $private_exponent = null; |
||
| 51 | |||
| 52 | /** |
||
| 53 | * @var \Jose\Util\BigInteger[] |
||
| 54 | */ |
||
| 55 | private $primes = []; |
||
| 56 | |||
| 57 | /** |
||
| 58 | * @var \Jose\Util\BigInteger[] |
||
| 59 | */ |
||
| 60 | private $exponents = []; |
||
| 61 | |||
| 62 | /** |
||
| 63 | * @var \Jose\Util\BigInteger|null |
||
| 64 | */ |
||
| 65 | private $coefficient = null; |
||
| 66 | |||
| 67 | /** |
||
| 68 | * @param \Jose\Object\JWKInterface|string|array $data |
||
| 69 | */ |
||
| 70 | public function __construct($data) |
||
| 71 | { |
||
| 72 | parent::__construct(); |
||
| 73 | |||
| 74 | if ($data instanceof JWKInterface) { |
||
| 75 | $this->loadJWK($data->getAll()); |
||
| 76 | } elseif (is_array($data)) { |
||
| 77 | $this->loadJWK($data); |
||
| 78 | } elseif (is_string($data)) { |
||
| 79 | $this->loadPEM($data); |
||
| 80 | } else { |
||
| 81 | throw new \InvalidArgumentException('Unsupported input'); |
||
| 82 | } |
||
| 83 | |||
| 84 | $this->populateBigIntegers(); |
||
| 85 | } |
||
| 86 | |||
| 87 | /** |
||
| 88 | * @return bool |
||
| 89 | */ |
||
| 90 | public function isPublic() |
||
| 91 | { |
||
| 92 | return !$this->isPrivate(); |
||
| 93 | } |
||
| 94 | |||
| 95 | /** |
||
| 96 | * @return bool |
||
| 97 | */ |
||
| 98 | public function isPrivate() |
||
| 99 | { |
||
| 100 | return array_key_exists('d', $this->values); |
||
| 101 | } |
||
| 102 | |||
| 103 | /** |
||
| 104 | * @return \Jose\Util\BigInteger |
||
| 105 | */ |
||
| 106 | public function getModulus() |
||
| 107 | { |
||
| 108 | return $this->modulus; |
||
| 109 | } |
||
| 110 | |||
| 111 | /** |
||
| 112 | * @return int |
||
| 113 | */ |
||
| 114 | public function getModulusLength() |
||
| 115 | { |
||
| 116 | return $this->modulus_length; |
||
| 117 | } |
||
| 118 | |||
| 119 | /** |
||
| 120 | * @return \Jose\Util\BigInteger |
||
| 121 | */ |
||
| 122 | public function getExponent() |
||
| 123 | { |
||
| 124 | $d = $this->getPrivateExponent(); |
||
| 125 | if (null !== $d) { |
||
| 126 | return $d; |
||
| 127 | } |
||
| 128 | |||
| 129 | return $this->getPublicExponent(); |
||
| 130 | } |
||
| 131 | |||
| 132 | /** |
||
| 133 | * @return \Jose\Util\BigInteger |
||
| 134 | */ |
||
| 135 | public function getPublicExponent() |
||
| 136 | { |
||
| 137 | return $this->public_exponent; |
||
| 138 | } |
||
| 139 | |||
| 140 | /** |
||
| 141 | * @return \Jose\Util\BigInteger |
||
| 142 | */ |
||
| 143 | public function getPrivateExponent() |
||
| 144 | { |
||
| 145 | return $this->private_exponent; |
||
| 146 | } |
||
| 147 | |||
| 148 | /** |
||
| 149 | * @return \Jose\Util\BigInteger[] |
||
| 150 | */ |
||
| 151 | public function getPrimes() |
||
| 152 | { |
||
| 153 | return $this->primes; |
||
| 154 | } |
||
| 155 | |||
| 156 | /** |
||
| 157 | * @return \Jose\Util\BigInteger[] |
||
| 158 | */ |
||
| 159 | public function getExponents() |
||
| 160 | { |
||
| 161 | return $this->exponents; |
||
| 162 | } |
||
| 163 | |||
| 164 | /** |
||
| 165 | * @return \Jose\Util\BigInteger|null |
||
| 166 | */ |
||
| 167 | public function getCoefficient() |
||
| 168 | { |
||
| 169 | return $this->coefficient; |
||
| 170 | } |
||
| 171 | |||
| 172 | /** |
||
| 173 | * @param \Jose\KeyConverter\RSAKey $private |
||
| 174 | * |
||
| 175 | * @return \Jose\KeyConverter\RSAKey |
||
| 176 | */ |
||
| 177 | public static function toPublic(RSAKey $private) |
||
| 178 | { |
||
| 179 | $data = $private->toArray(); |
||
| 180 | $keys = ['p', 'd', 'q', 'dp', 'dq', 'qi']; |
||
| 181 | foreach ($keys as $key) { |
||
| 182 | if (array_key_exists($key, $data)) { |
||
| 183 | unset($data[$key]); |
||
| 184 | } |
||
| 185 | } |
||
| 186 | |||
| 187 | return new self($data); |
||
| 188 | } |
||
| 189 | |||
| 190 | public function __toString() |
||
| 191 | { |
||
| 192 | return $this->toPEM(); |
||
| 193 | } |
||
| 194 | |||
| 195 | /** |
||
| 196 | * @return array |
||
| 197 | */ |
||
| 198 | public function toArray() |
||
| 199 | { |
||
| 200 | return $this->values; |
||
| 201 | } |
||
| 202 | |||
| 203 | /** |
||
| 204 | * @return string |
||
| 205 | */ |
||
| 206 | public function toDER() |
||
| 207 | { |
||
| 208 | return $this->getBinary(); |
||
| 209 | } |
||
| 210 | |||
| 211 | /** |
||
| 212 | * @return string |
||
| 213 | */ |
||
| 214 | public function toPEM() |
||
| 215 | { |
||
| 216 | $result = '-----BEGIN '.($this->isPrivate() ? 'RSA PRIVATE' : 'PUBLIC').' KEY-----'.PHP_EOL; |
||
| 217 | $result .= chunk_split(base64_encode($this->getBinary()), 64, PHP_EOL); |
||
| 218 | $result .= '-----END '.($this->isPrivate() ? 'RSA PRIVATE' : 'PUBLIC').' KEY-----'.PHP_EOL; |
||
| 219 | |||
| 220 | return $result; |
||
| 221 | } |
||
| 222 | |||
| 223 | /** |
||
| 224 | * @param string $data |
||
| 225 | * |
||
| 226 | * @throws \Exception |
||
| 227 | * @throws \FG\ASN1\Exception\ParserException |
||
| 228 | * |
||
| 229 | * @return array |
||
| 230 | */ |
||
| 231 | private function loadPEM($data) |
||
| 232 | { |
||
| 233 | $res = openssl_pkey_get_private($data); |
||
| 234 | if (false === $res) { |
||
| 235 | $res = openssl_pkey_get_public($data); |
||
| 236 | } |
||
| 237 | Assertion::false(false === $res, 'Unable to load the key'); |
||
| 238 | |||
| 239 | $details = openssl_pkey_get_details($res); |
||
| 240 | Assertion::keyExists($details, 'rsa', 'Unable to load the key'); |
||
| 241 | |||
| 242 | $this->values['kty'] = 'RSA'; |
||
| 243 | $keys = [ |
||
| 244 | 'n' => 'n', |
||
| 245 | 'e' => 'e', |
||
| 246 | 'd' => 'd', |
||
| 247 | 'p' => 'p', |
||
| 248 | 'q' => 'q', |
||
| 249 | 'dp' => 'dmp1', |
||
| 250 | 'dq' => 'dmq1', |
||
| 251 | 'qi' => 'iqmp', |
||
| 252 | ]; |
||
| 253 | foreach ($details['rsa'] as $key => $value) { |
||
| 254 | if (in_array($key, $keys)) { |
||
| 255 | $value = Base64Url::encode($value); |
||
| 256 | $this->values[array_search($key, $keys)] = $value; |
||
| 257 | } |
||
| 258 | } |
||
| 259 | } |
||
| 260 | |||
| 261 | /** |
||
| 262 | * @param array $jwk |
||
| 263 | */ |
||
| 264 | private function loadJWK(array $jwk) |
||
| 265 | { |
||
| 266 | Assertion::keyExists($jwk, 'kty', 'The key parameter "kty" is missing.'); |
||
| 267 | Assertion::eq($jwk['kty'], 'RSA', 'The JWK is not a RSA key'); |
||
| 268 | |||
| 269 | $this->values = $jwk; |
||
| 270 | if (array_key_exists('d', $jwk)) { |
||
| 271 | $this->populateCRT(); |
||
| 272 | $this->initPrivateKey(); |
||
| 273 | } else { |
||
| 274 | $this->initPublicKey(); |
||
| 275 | } |
||
| 276 | } |
||
| 277 | |||
| 278 | /** |
||
| 279 | * This method adds Chinese Remainder Theorem (CRT) parameters if primes 'p' and 'q' are available. |
||
| 280 | */ |
||
| 281 | private function populateCRT() |
||
| 282 | { |
||
| 283 | if (!array_key_exists('p', $this->values) && !array_key_exists('q', $this->values)) { |
||
| 284 | $d = BigInteger::createFromBinaryString(Base64Url::decode($this->values['d'])); |
||
| 285 | $e = BigInteger::createFromBinaryString(Base64Url::decode($this->values['e'])); |
||
| 286 | $n = BigInteger::createFromBinaryString(Base64Url::decode($this->values['n'])); |
||
| 287 | |||
| 288 | list($p, $q) = $this->findPrimeFactors($d, $e, $n); |
||
| 289 | $this->values['p'] = Base64Url::encode($p->toBytes()); |
||
| 290 | $this->values['q'] = Base64Url::encode($q->toBytes()); |
||
| 291 | } |
||
| 292 | |||
| 293 | if (array_key_exists('dp', $this->values) && array_key_exists('dq', $this->values) && array_key_exists('qi', $this->values)) { |
||
| 294 | return; |
||
| 295 | } |
||
| 296 | |||
| 297 | $one = BigInteger::createFromDecimal(1); |
||
| 298 | $d = BigInteger::createFromBinaryString(Base64Url::decode($this->values['d'])); |
||
| 299 | $p = BigInteger::createFromBinaryString(Base64Url::decode($this->values['p'])); |
||
| 300 | $q = BigInteger::createFromBinaryString(Base64Url::decode($this->values['q'])); |
||
| 301 | |||
| 302 | $this->values['dp'] = Base64Url::encode($d->mod($p->subtract($one))->toBytes()); |
||
| 303 | $this->values['dq'] = Base64Url::encode($d->mod($q->subtract($one))->toBytes()); |
||
| 304 | $this->values['qi'] = Base64Url::encode($q->modInverse($p)->toBytes()); |
||
| 305 | } |
||
| 306 | |||
| 307 | /** |
||
| 308 | * @throws \Exception |
||
| 309 | */ |
||
| 310 | private function initPublicKey() |
||
| 311 | { |
||
| 312 | $oid_sequence = new Sequence(); |
||
| 313 | $oid_sequence->addChild(new ObjectIdentifier('1.2.840.113549.1.1.1')); |
||
| 314 | $oid_sequence->addChild(new NullObject()); |
||
| 315 | $this->addChild($oid_sequence); |
||
| 316 | |||
| 317 | $n = new Integer($this->fromBase64ToInteger($this->values['n'])); |
||
| 318 | $e = new Integer($this->fromBase64ToInteger($this->values['e'])); |
||
| 319 | |||
| 320 | $key_sequence = new Sequence(); |
||
| 321 | $key_sequence->addChild($n); |
||
| 322 | $key_sequence->addChild($e); |
||
| 323 | $key_bit_string = new BitString(bin2hex($key_sequence->getBinary())); |
||
| 324 | $this->addChild($key_bit_string); |
||
| 325 | } |
||
| 326 | |||
| 327 | private function initPrivateKey() |
||
| 328 | { |
||
| 329 | $this->addChild(new Integer(0)); |
||
| 330 | |||
| 331 | $oid_sequence = new Sequence(); |
||
| 332 | $oid_sequence->addChild(new ObjectIdentifier('1.2.840.113549.1.1.1')); |
||
| 333 | $oid_sequence->addChild(new NullObject()); |
||
| 334 | $this->addChild($oid_sequence); |
||
| 335 | |||
| 336 | $v = new Integer(0); |
||
| 337 | $n = new Integer($this->fromBase64ToInteger($this->values['n'])); |
||
| 338 | $e = new Integer($this->fromBase64ToInteger($this->values['e'])); |
||
| 339 | $d = new Integer($this->fromBase64ToInteger($this->values['d'])); |
||
| 340 | $p = new Integer($this->fromBase64ToInteger($this->values['p'])); |
||
| 341 | $q = new Integer($this->fromBase64ToInteger($this->values['q'])); |
||
| 342 | $dp = array_key_exists('dp', $this->values) ? new Integer($this->fromBase64ToInteger($this->values['dp'])) : new Integer(0); |
||
| 343 | $dq = array_key_exists('dq', $this->values) ? new Integer($this->fromBase64ToInteger($this->values['dq'])) : new Integer(0); |
||
| 344 | $qi = array_key_exists('qi', $this->values) ? new Integer($this->fromBase64ToInteger($this->values['qi'])) : new Integer(0); |
||
| 345 | |||
| 346 | $key_sequence = new Sequence(); |
||
| 347 | $key_sequence->addChild($v); |
||
| 348 | $key_sequence->addChild($n); |
||
| 349 | $key_sequence->addChild($e); |
||
| 350 | $key_sequence->addChild($d); |
||
| 351 | $key_sequence->addChild($p); |
||
| 352 | $key_sequence->addChild($q); |
||
| 353 | $key_sequence->addChild($dp); |
||
| 354 | $key_sequence->addChild($dq); |
||
| 355 | $key_sequence->addChild($qi); |
||
| 356 | $key_octet_string = new OctetString(bin2hex($key_sequence->getBinary())); |
||
| 357 | $this->addChild($key_octet_string); |
||
| 358 | } |
||
| 359 | |||
| 360 | /** |
||
| 361 | * @param string $value |
||
| 362 | * |
||
| 363 | * @return string |
||
| 364 | */ |
||
| 365 | private function fromBase64ToInteger($value) |
||
| 366 | { |
||
| 367 | return gmp_strval(gmp_init(current(unpack('H*', Base64Url::decode($value))), 16), 10); |
||
| 368 | } |
||
| 369 | |||
| 370 | private function populateBigIntegers() |
||
| 371 | { |
||
| 372 | $this->modulus = $this->convertBase64StringToBigInteger($this->values['n']); |
||
| 373 | $this->modulus_length = mb_strlen($this->getModulus()->toBytes(), '8bit'); |
||
| 374 | $this->public_exponent = $this->convertBase64StringToBigInteger($this->values['e']); |
||
| 375 | |||
| 376 | if (true === $this->isPrivate()) { |
||
| 377 | $this->private_exponent = $this->convertBase64StringToBigInteger($this->values['d']); |
||
| 378 | |||
| 379 | if (array_key_exists('p', $this->values) && array_key_exists('q', $this->values)) { |
||
| 380 | $this->primes = [ |
||
| 381 | $this->convertBase64StringToBigInteger($this->values['p']), |
||
| 382 | $this->convertBase64StringToBigInteger($this->values['q']), |
||
| 383 | ]; |
||
| 384 | $this->exponents = [ |
||
| 385 | $this->convertBase64StringToBigInteger($this->values['dp']), |
||
| 386 | $this->convertBase64StringToBigInteger($this->values['dq']), |
||
| 387 | ]; |
||
| 388 | $this->coefficient = $this->convertBase64StringToBigInteger($this->values['qi']); |
||
| 389 | } |
||
| 390 | } |
||
| 391 | } |
||
| 392 | |||
| 393 | /** |
||
| 394 | * @param string $value |
||
| 395 | * |
||
| 396 | * @return \Jose\Util\BigInteger |
||
| 397 | */ |
||
| 398 | private function convertBase64StringToBigInteger($value) |
||
| 399 | { |
||
| 400 | return BigInteger::createFromBinaryString(Base64Url::decode($value)); |
||
| 401 | } |
||
| 402 | |||
| 403 | /** |
||
| 404 | * @param BigInteger $d |
||
| 405 | * @param BigInteger $e |
||
| 406 | * @param BigInteger $n |
||
| 407 | * @return array |
||
| 408 | */ |
||
| 409 | private function findPrimeFactors(BigInteger $d, BigInteger $e, BigInteger $n) |
||
| 410 | { |
||
| 411 | $zero = BigInteger::createFromDecimal(0); |
||
| 412 | $one = BigInteger::createFromDecimal(1); |
||
| 413 | $two = BigInteger::createFromDecimal(2); |
||
| 414 | |||
| 415 | $k = $d->multiply($e)->subtract($one); |
||
| 416 | |||
| 417 | if ($k->isEven()) { |
||
| 418 | $r = $k; |
||
| 419 | $t = $zero; |
||
| 420 | |||
| 421 | do { |
||
| 422 | $r = $r->divide($two); |
||
| 423 | $t = $t->add($one); |
||
| 424 | } while ($r->isEven()); |
||
| 425 | |||
| 426 | $found = false; |
||
| 427 | $y = null; |
||
| 428 | |||
| 429 | for($i = 1; $i <= 100; $i++) { |
||
| 430 | $g = BigInteger::random($n->subtract($one)); |
||
| 431 | $y = $g->modPow($r, $n); |
||
| 432 | |||
| 433 | if ($y->equals($one) || $y->equals($n->subtract($one))) { |
||
| 434 | continue; |
||
| 435 | } |
||
| 436 | |||
| 437 | for ($j = $one; $j->lowerThan($t->subtract($one)); $j = $j->add($one)) { |
||
|
0 ignored issues
–
show
|
|||
| 438 | $x = $y->modPow($two, $n); |
||
| 439 | |||
| 440 | if ($x->equals($one)) { |
||
| 441 | $found = true; |
||
| 442 | break; |
||
| 443 | } |
||
| 444 | |||
| 445 | if ($x->equals($n->subtract($one))) { |
||
| 446 | continue; |
||
| 447 | } |
||
| 448 | |||
| 449 | $y = $x; |
||
| 450 | } |
||
| 451 | |||
| 452 | $x = $y->modPow($two, $n); |
||
| 453 | if ($x->equals($one)) { |
||
| 454 | $found = true; |
||
| 455 | break; |
||
| 456 | } |
||
| 457 | } |
||
| 458 | |||
| 459 | if (true === $found) { |
||
| 460 | $p = $y->subtract($one)->gcd($n); |
||
| 461 | $q = $n->divide($p); |
||
| 462 | |||
| 463 | return [$p, $q]; |
||
| 464 | } |
||
| 465 | } |
||
| 466 | |||
| 467 | throw new \InvalidArgumentException('Unable to find prime factors.'); |
||
| 468 | } |
||
| 469 | } |
||
| 470 |
If you have a function call in the test part of a
forloop, this function is executed on each iteration. Often such a function, can be moved to the initialization part and be cached.