【问题标题】:How to decode non-key ASN1 data?如何解码非关键 ASN1 数据?
【发布时间】:2015-04-15 13:49:22
【问题描述】:

是否可以使用 crypto++ 库来解码我在字节数组中的任意 ASN1 数据(具有几个序列和整数)。 ash.h 包含所有将 BufferedTransformation 作为输入的方法,但该类是不同密码和哈希的接口,这似乎与我的简单案例完全无关。我还在 cryptlib.h 中找到了 ASN1Object,但它是另一个接口,我还没有找到任何实现类。

我是不是觉得它对自己来说太复杂了,还是真的很难解码任意 ASN1 数据?

我实际上是在 Swift/objective-c iOS 应用程序中使用它,所以如果有人有任何其他工具的简单解决方案,请告诉我。

编辑:添加数据的示例结构

SEQUENCE
    SEQUENCE
        INTEGER
        INTEGER
    SEQUENCE
        INTEGER
        INTEGER

总有一个父序列包含 1 到 n 个序列,每个序列包含 2 个整数(elgamal 加密对 (g^r, mh^r))。

【问题讨论】:

  • 简短的回答是 MAYBE,它取决于底层的 ASN.1 类型。你能给我们一个你试图解码的例子吗?用文本描述它并使用缩进来显示与 ASN.1 结构相关的典型层次结构。它将帮助我们向您展示解决方案的外观。通过单击 Edit 将示例添加到您的问题中(不要将其添加到 cmets 中)。
  • 我确实更新了帖子,不确定是你的意思还是过于简化

标签: c++ asn.1 crypto++


【解决方案1】:
SEQUENCE
    SEQUENCE
        INTEGER
        INTEGER
    SEQUENCE
        INTEGER
        INTEGER

为此,您需要类似:

ArraySource as(data, size);    
Integer i1, i2, i3, i4;

BERSequenceDecoder d1(as);
    BERSequenceDecoder d2(d1);
        i1.BERDecode(d2);
        i2.BERDecode(d2);
        d2.MessageEnd();
    BERSequenceDecoder d3(d2);
        i3.BERDecode(d3);
        i4.BERDecode(d3);
        d3.MessageEnd();
  d1.MessageEnd();

每个包含 2 个整数(elgamal 加密对 (g^r, mh^r))。

一旦你有了参数(见下文),你应该用参数调用Initialize 函数之一。 不要调用那些接受 PRNG 的,因为它们会创建参数和键。

有关一些相关的类定义,请参阅gfpcrypt.h。另见ElGamal - Crypto++ Wiki


这是一个示例,它生成整数对并将它们打包成您想要的 ASN.1 结构。然后它将它们读回并在没有任何东西可消耗时停止(即,内部整数对是可选的)。

您可以像./asn1-test.exe./asn1-test.exe 3./asn1-test.exe 6./asn1-test.exe 128 一样运行它。大小仅为 48 位,因此您不会浪费时间生成不需要的整数。

static const unsigned int BIT_COUNT = 48;

int main(int argc, char* argv[])
{
    unsigned int count = 2;
    if(argc >= 2 && argv[1] != NULL)
    {
        istringstream iss(argv[1]);
        iss >> count;

        if(iss.fail()) count = 2;
    }

    cout << "Testing " << count << " integer pairs" << endl;

    // Count to pairs
    count *= 2;

    try
    {            
        AutoSeededRandomPool prng;

        vector<Integer> vv;
        vv.resize(count);

        for(unsigned int i = 0; i < count; i += 2)
        {
            vv[i] = Integer(prng, BIT_COUNT);
            vv[i + 1] = Integer(prng, BIT_COUNT);
        }

        // Scratch for holding ASN.1 encoded structures in Crypto++
        ByteQueue queue;

        // Encode them
        {
            DERSequenceEncoder outer(queue);

            for(unsigned int i = 0; i < count; i += 2)
            {
                DERSequenceEncoder inner(outer);

                vv[i].DEREncode(inner);
                vv[i + 1].DEREncode(inner);

                inner.MessageEnd();
            }

            outer.MessageEnd();
        }

        // Save it to file (use dumpasn1 to view it)
        FileSink fs("sequences.der", true);
        queue.CopyTo(fs);
        fs.MessageEnd();

        // Decode them
        {
            BERSequenceDecoder outer(queue);

            // Ensure we break from the loop based on EndReached()
            for( ; ; )
            {
                if(outer.EndReached()) break;

                BERSequenceDecoder inner(outer);

                Integer i1, i2;

                i1.BERDecode(inner);
                i2.BERDecode(inner);

                cout << "Pair" << endl;
                cout << std::hex << "  Integer: " << i1 << endl;
                cout << std::hex << "  Integer: " << i2 << endl;

                inner.MessageEnd();
            }

            outer.MessageEnd();
        }

    } catch (const Exception& ex) {
        cerr << std::dec << ex.what() << endl;
        exit (1);
    }

    return 0;
}

这是运行和转储的样子:

$ ./asn1-test.exe 3
Testing 3 integer pairs
Pair
  Integer: 301818b3c631h
  Integer: 1ff0ebf1ca4bh
Pair
  Integer: f97e9d28e9cah
  Integer: 94813cab125fh
Pair
  Integer: 8a146ea68e7ch
  Integer: 60d48ef2462fh

$ dumpasn1 sequences.der 
  0  57: SEQUENCE {
  2  16:   SEQUENCE {
  4   6:     INTEGER 30 18 18 B3 C6 31
 12   6:     INTEGER 1F F0 EB F1 CA 4B
       :     }
 20  18:   SEQUENCE {
 22   7:     INTEGER 00 F9 7E 9D 28 E9 CA
 31   7:     INTEGER 00 94 81 3C AB 12 5F
       :     }
 40  17:   SEQUENCE {
 42   7:     INTEGER 00 8A 14 6E A6 8E 7C
 51   6:     INTEGER 60 D4 8E F2 46 2F
       :     }
       :   }

0 warnings, 0 errors.

以下是包含的内容,可让您免去查找它们的麻烦:

#include <iostream>
using std::ostream;
using std::cin;
using std::cout;
using std::cerr;
using std::endl;

#include <string>
using std::string;

#include <vector>
using std::vector;

#include <sstream>
using std::istringstream;

#include <cryptopp/cryptlib.h>
using CryptoPP::Exception;

#include <cryptopp/filters.h>
using CryptoPP::StringSource;
using CryptoPP::StringSink;

#include <cryptopp/files.h>
using CryptoPP::FileSink;

#include <cryptopp/integer.h>
using CryptoPP::Integer;

#include <cryptopp/osrng.h>
using CryptoPP::AutoSeededRandomPool;

#include <cryptopp/asn.h>
#include <cryptopp/oids.h>
namespace ASN1 = CryptoPP::ASN1;
using CryptoPP::DERSequenceEncoder;
using CryptoPP::BERSequenceDecoder;

#include <cryptopp/queue.h>
using CryptoPP::ByteQueue;

【讨论】:

  • 非常感谢。在我看来,即使没有 MessageEnd() 电话,这也有效。这很重要,因为我自己的数据不包括这些。
  • @Kelo - 在此示例中,您可能会避免使用 MessageEnd() 调用,但不要养成这种习惯。你最终会发现你丢失了数据,因为数据没有被刷新。例如,参见HexEncoder and Missing Data。这是过滤器的一个众所周知的问题。 (实际上,这是设计使然,因为过滤器正在等待您告诉它刷新已缓冲的部分数据)。
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 2012-11-20
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多