Remove IV auto-generation workaround.
This workaround prevents use of keys with randomized encryption (IND-CPA). Since randomized encryption is on by default, it's better to keep it working and break non-randomized encryption (until Keymaster is fixed). Bug: 18088752 Change-Id: I4b11ce72cff705be41d3e66f28b507d6ddc1da79
This commit is contained in:
@@ -547,18 +547,12 @@ public abstract class KeyStoreCipherSpi extends CipherSpi implements KeyStoreCry
|
||||
if (mIvRequired) {
|
||||
// IV is needed
|
||||
if ((mIv == null) && (mEncrypting)) {
|
||||
// TODO: Switch to keymaster-generated IV code below once keymaster supports
|
||||
// that.
|
||||
// IV is needed but was not provided by the caller -- generate an IV.
|
||||
mIv = new byte[mBlockSizeBytes];
|
||||
SecureRandom rng = (mRng != null) ? mRng : new SecureRandom();
|
||||
rng.nextBytes(mIv);
|
||||
// // IV was not provided by the caller and thus will be generated by keymaster.
|
||||
// // Mix in some additional entropy from the provided SecureRandom.
|
||||
// if (mRng != null) {
|
||||
// mAdditionalEntropyForBegin = new byte[mBlockSizeBytes];
|
||||
// mRng.nextBytes(mAdditionalEntropyForBegin);
|
||||
// }
|
||||
// IV was not provided by the caller and thus will be generated by keymaster.
|
||||
// Mix in some additional entropy from the provided SecureRandom.
|
||||
if (mRng != null) {
|
||||
mAdditionalEntropyForBegin = new byte[mBlockSizeBytes];
|
||||
mRng.nextBytes(mAdditionalEntropyForBegin);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user