1*e7b1675dSTing-Kang Chang // Copyright 2019 Google LLC 2*e7b1675dSTing-Kang Chang // 3*e7b1675dSTing-Kang Chang // Licensed under the Apache License, Version 2.0 (the "License"); 4*e7b1675dSTing-Kang Chang // you may not use this file except in compliance with the License. 5*e7b1675dSTing-Kang Chang // You may obtain a copy of the License at 6*e7b1675dSTing-Kang Chang // 7*e7b1675dSTing-Kang Chang // http://www.apache.org/licenses/LICENSE-2.0 8*e7b1675dSTing-Kang Chang // 9*e7b1675dSTing-Kang Chang // Unless required by applicable law or agreed to in writing, software 10*e7b1675dSTing-Kang Chang // distributed under the License is distributed on an "AS IS" BASIS, 11*e7b1675dSTing-Kang Chang // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12*e7b1675dSTing-Kang Chang // See the License for the specific language governing permissions and 13*e7b1675dSTing-Kang Chang // limitations under the License. 14*e7b1675dSTing-Kang Chang // 15*e7b1675dSTing-Kang Chang /////////////////////////////////////////////////////////////////////////////// 16*e7b1675dSTing-Kang Chang 17*e7b1675dSTing-Kang Chang #ifndef TINK_AEAD_KMS_ENVELOPE_AEAD_H_ 18*e7b1675dSTing-Kang Chang #define TINK_AEAD_KMS_ENVELOPE_AEAD_H_ 19*e7b1675dSTing-Kang Chang 20*e7b1675dSTing-Kang Chang #include <memory> 21*e7b1675dSTing-Kang Chang #include <string> 22*e7b1675dSTing-Kang Chang #include <utility> 23*e7b1675dSTing-Kang Chang 24*e7b1675dSTing-Kang Chang #include "absl/strings/string_view.h" 25*e7b1675dSTing-Kang Chang #include "tink/aead.h" 26*e7b1675dSTing-Kang Chang #include "tink/util/status.h" 27*e7b1675dSTing-Kang Chang #include "tink/util/statusor.h" 28*e7b1675dSTing-Kang Chang #include "proto/tink.pb.h" 29*e7b1675dSTing-Kang Chang 30*e7b1675dSTing-Kang Chang namespace crypto { 31*e7b1675dSTing-Kang Chang namespace tink { 32*e7b1675dSTing-Kang Chang 33*e7b1675dSTing-Kang Chang // An implementation of KMS Envelope AEAD encryption 34*e7b1675dSTing-Kang Chang // (https://cloud.google.com/kms/docs/data-encryption-keys). 35*e7b1675dSTing-Kang Chang // 36*e7b1675dSTing-Kang Chang // In envelope encryption user generates a data encryption key (DEK) locally, 37*e7b1675dSTing-Kang Chang // encrypts data with DEK, sends DEK to a KMS to be encrypted (with a key 38*e7b1675dSTing-Kang Chang // managed by KMS), and stores encrypted DEK with encrypted data; at a later 39*e7b1675dSTing-Kang Chang // point user can retrieve encrypted data and DEK, use KMS to decrypt DEK, 40*e7b1675dSTing-Kang Chang // and use decrypted DEK to decrypt the data. 41*e7b1675dSTing-Kang Chang // 42*e7b1675dSTing-Kang Chang // The ciphertext structure is as follows: 43*e7b1675dSTing-Kang Chang // - Length of encrypted DEK: 4 bytes (big endian) 44*e7b1675dSTing-Kang Chang // - Encrypted DEK: variable length that is equal to the value 45*e7b1675dSTing-Kang Chang // specified in the last 4 bytes. 46*e7b1675dSTing-Kang Chang // - AEAD payload: variable length. 47*e7b1675dSTing-Kang Chang class KmsEnvelopeAead : public Aead { 48*e7b1675dSTing-Kang Chang public: 49*e7b1675dSTing-Kang Chang static crypto::tink::util::StatusOr<std::unique_ptr<Aead>> New( 50*e7b1675dSTing-Kang Chang const google::crypto::tink::KeyTemplate& dek_template, 51*e7b1675dSTing-Kang Chang std::unique_ptr<Aead> remote_aead); 52*e7b1675dSTing-Kang Chang 53*e7b1675dSTing-Kang Chang crypto::tink::util::StatusOr<std::string> Encrypt( 54*e7b1675dSTing-Kang Chang absl::string_view plaintext, 55*e7b1675dSTing-Kang Chang absl::string_view associated_data) const override; 56*e7b1675dSTing-Kang Chang 57*e7b1675dSTing-Kang Chang crypto::tink::util::StatusOr<std::string> Decrypt( 58*e7b1675dSTing-Kang Chang absl::string_view ciphertext, 59*e7b1675dSTing-Kang Chang absl::string_view associated_data) const override; 60*e7b1675dSTing-Kang Chang 61*e7b1675dSTing-Kang Chang ~KmsEnvelopeAead() override = default; 62*e7b1675dSTing-Kang Chang 63*e7b1675dSTing-Kang Chang private: KmsEnvelopeAead(const google::crypto::tink::KeyTemplate & dek_template,std::unique_ptr<Aead> remote_aead)64*e7b1675dSTing-Kang Chang KmsEnvelopeAead(const google::crypto::tink::KeyTemplate& dek_template, 65*e7b1675dSTing-Kang Chang std::unique_ptr<Aead> remote_aead) : 66*e7b1675dSTing-Kang Chang dek_template_(dek_template), remote_aead_(std::move(remote_aead)) {} 67*e7b1675dSTing-Kang Chang 68*e7b1675dSTing-Kang Chang google::crypto::tink::KeyTemplate dek_template_; 69*e7b1675dSTing-Kang Chang std::unique_ptr<Aead> remote_aead_; 70*e7b1675dSTing-Kang Chang }; 71*e7b1675dSTing-Kang Chang 72*e7b1675dSTing-Kang Chang } // namespace tink 73*e7b1675dSTing-Kang Chang } // namespace crypto 74*e7b1675dSTing-Kang Chang 75*e7b1675dSTing-Kang Chang #endif // TINK_AEAD_KMS_ENVELOPE_AEAD_H_ 76