-
Notifications
You must be signed in to change notification settings - Fork 247
Expand file tree
/
Copy pathatjwt.py
More file actions
115 lines (93 loc) · 4.19 KB
/
Copy pathatjwt.py
File metadata and controls
115 lines (93 loc) · 4.19 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
"""
JWT: Extension to the jwt module with hardware based security
"""
# Copyright (C) 2015-2026 Microchip Technology Inc. and its subsidiaries.
#
# Subject to your compliance with these terms, you may use Microchip software
# and any derivatives exclusively with Microchip products. It is your
# responsibility to comply with third party license terms applicable to your
# use of third party software (including open source software) that may
# accompany Microchip software.
#
# THIS SOFTWARE IS SUPPLIED BY MICROCHIP "AS IS". NO WARRANTIES, WHETHER
# EXPRESS, IMPLIED OR STATUTORY, APPLY TO THIS SOFTWARE, INCLUDING ANY IMPLIED
# WARRANTIES OF NON-INFRINGEMENT, MERCHANTABILITY, AND FITNESS FOR A
# PARTICULAR PURPOSE. IN NO EVENT WILL MICROCHIP BE LIABLE FOR ANY INDIRECT,
# SPECIAL, PUNITIVE, INCIDENTAL OR CONSEQUENTIAL LOSS, DAMAGE, COST OR EXPENSE
# OF ANY KIND WHATSOEVER RELATED TO THE SOFTWARE, HOWEVER CAUSED, EVEN IF
# MICROCHIP HAS BEEN ADVISED OF THE POSSIBILITY OR THE DAMAGES ARE
# FORESEEABLE. TO THE FULLEST EXTENT ALLOWED BY LAW, MICROCHIP'S TOTAL
# LIABILITY ON ALL CLAIMS IN ANY WAY RELATED TO THIS SOFTWARE WILL NOT EXCEED
# THE AMOUNT OF FEES, IF ANY, THAT YOU HAVE PAID DIRECTLY TO MICROCHIP FOR
# THIS SOFTWARE.
# pylint: disable-msg=too-few-public-methods
try:
import hmac
from jwt import PyJWT as Jwt
from jwt.api_jws import register_algorithm, unregister_algorithm
from jwt.algorithms import ECAlgorithm, HMACAlgorithm
from cryptography.hazmat.backends import default_backend
from cryptography.hazmat.primitives import hashes
from .status import check_status
from .atcab import atcab_init, atcab_release, atcab_sign, atcab_sha_hmac, atcab_nonce_rand
class HwEcAlgorithm(ECAlgorithm):
"""
Extended Algorithm with hardware based elliptic curve support
"""
def __init__(self, hash_alg, slot, iface_cfg):
super(HwEcAlgorithm, self).__init__(hash_alg)
self._cfg = iface_cfg
self._slot = slot
def sign(self, msg, _):
"""
Return a signature of the JWT with hardware ECDSA
"""
if self._cfg is not None:
check_status(atcab_init(self._cfg))
digest = hashes.Hash(self.hash_alg(), backend=default_backend())
digest.update(msg)
digest = digest.finalize()
signature = bytearray(64)
check_status(atcab_sign(self._slot, digest, signature))
if self._cfg is not None:
check_status(atcab_release())
return signature
class HwHmacAlgorithm(HMACAlgorithm):
"""
Extended Algorithm with hardware based HMAC support
"""
def __init__(self, hash_alg, slot, iface_cfg):
super(HwHmacAlgorithm, self).__init__(hash_alg)
self._cfg = iface_cfg
self._slot = slot
def sign(self, msg, _):
"""
Return a signature of the JWT with hardware SHA256 HMAC and stored key
"""
if self._cfg is not None:
check_status(atcab_init(self._cfg))
check_status(atcab_nonce_rand(bytearray(20), bytearray(32)))
digest = bytearray(32)
check_status(atcab_sha_hmac(msg, len(msg), self._slot, digest, 0))
if self._cfg is not None:
check_status(atcab_release())
return bytes(digest)
def verify(self, msg, key, sig):
"""
Verify a signature using the software HMAC module
"""
return sig == hmac.new(key, msg, self.hash_alg).digest()
class PyJWT(Jwt):
"""
Extended PyJWT class from the pyjwt module
"""
def __init__(self, slot=0, iface_cfg=None, options=None):
super(PyJWT, self).__init__(options=options)
self.register_algorithm('ES256', HwEcAlgorithm(HwEcAlgorithm.SHA256, slot, iface_cfg))
self.register_algorithm('HS256', HwHmacAlgorithm(HwHmacAlgorithm.SHA256, slot, iface_cfg))
def register_algorithm(self, alg_id, algorithm):
unregister_algorithm(alg_id)
register_algorithm(alg_id,algorithm)
__all__ = ['PyJWT']
except ImportError:
pass