From 6f9e90c414c165ff76cd7546b9898b51660a2440 Mon Sep 17 00:00:00 2001 From: Jakob Unterwurzacher Date: Sun, 13 Sep 2015 21:47:18 +0200 Subject: Encrypt key with scrypt-hashed password --- cryptfs/kdf.go | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 cryptfs/kdf.go (limited to 'cryptfs/kdf.go') diff --git a/cryptfs/kdf.go b/cryptfs/kdf.go new file mode 100644 index 0000000..275c72e --- /dev/null +++ b/cryptfs/kdf.go @@ -0,0 +1,38 @@ +package cryptfs + +import ( + "fmt" + "golang.org/x/crypto/scrypt" +) + +const ( + // 1 << 16 uses 64MB of memory, + // takes 4 seconds on my Atom Z3735F netbook + SCRYPT_DEFAULT_N = 1 << 16 +) + +type scryptKdf struct { + Salt []byte + N int + R int + P int + KeyLen int +} + +func NewScryptKdf() scryptKdf { + var s scryptKdf + s.Salt = RandBytes(KEY_LEN) + s.N = SCRYPT_DEFAULT_N + s.R = 8 // Always 8 + s.P = 1 // Always 1 + s.KeyLen = KEY_LEN + return s +} + +func (s *scryptKdf) DeriveKey(pw string) []byte { + k, err := scrypt.Key([]byte(pw), s.Salt, s.N, s.R, s.P, s.KeyLen) + if err != nil { + panic(fmt.Sprintf("DeriveKey failed: %s", err.Error())) + } + return k +} -- cgit v1.2.3