| | | 1 | | using AsiBackbone.Core.Signing; |
| | | 2 | | |
| | | 3 | | namespace AsiBackbone.Core.Integrity; |
| | | 4 | | |
| | | 5 | | /// <summary> |
| | | 6 | | /// Verifies provider-neutral append-only audit integrity chains. |
| | | 7 | | /// </summary> |
| | | 8 | | public static class AuditIntegrityVerifier |
| | | 9 | | { |
| | | 10 | | /// <summary> |
| | | 11 | | /// Verifies that the supplied links form one continuous append-only chain in the supplied order. |
| | | 12 | | /// </summary> |
| | | 13 | | /// <param name="links">The links to verify, in chain order.</param> |
| | | 14 | | /// <param name="expectedChainId">The chain identifier every link must carry. Defaults to the first link's chain ide |
| | | 15 | | /// <param name="requireGenesis">When <see langword="true" />, the first link must be the genesis link at sequence 1 |
| | | 16 | | /// <param name="expectedPreviousLinkHash"> |
| | | 17 | | /// The link hash the first supplied link must point back to. Required when <paramref name="requireGenesis" /> is |
| | | 18 | | /// <see langword="false" /> and the first supplied link is not the genesis link, because a partial chain is anchore |
| | | 19 | | /// only by the hash of the link preceding it. |
| | | 20 | | /// </param> |
| | | 21 | | /// <param name="expectedTipLinkHash">When supplied, the final link's hash must equal this value, which detects a tr |
| | | 22 | | /// <param name="expectedTipSequence">When supplied, the final link's sequence must equal this value, which detects |
| | | 23 | | /// <remarks> |
| | | 24 | | /// Link metadata is not part of the link hash, so metadata is not authenticated by chain verification and must not |
| | | 25 | | /// relied on as tamper-evident. |
| | | 26 | | /// </remarks> |
| | | 27 | | public static AuditIntegrityVerificationResult Verify( |
| | | 28 | | IEnumerable<AuditIntegrityLink> links, |
| | | 29 | | string? expectedChainId = null, |
| | | 30 | | bool requireGenesis = true, |
| | | 31 | | string? expectedPreviousLinkHash = null, |
| | | 32 | | string? expectedTipLinkHash = null, |
| | | 33 | | long? expectedTipSequence = null) |
| | | 34 | | { |
| | 21 | 35 | | ArgumentNullException.ThrowIfNull(links); |
| | | 36 | | |
| | 21 | 37 | | List<AuditIntegrityLink> orderedLinks = [.. links]; |
| | | 38 | | |
| | 21 | 39 | | if (orderedLinks.Count == 0) |
| | | 40 | | { |
| | 1 | 41 | | return AuditIntegrityVerificationResult.Failed( |
| | 1 | 42 | | AuditIntegrityVerificationCategory.EmptyChain, |
| | 1 | 43 | | "integrity.chain-empty", |
| | 1 | 44 | | "No integrity links were supplied."); |
| | | 45 | | } |
| | | 46 | | |
| | 20 | 47 | | string chainId = string.IsNullOrWhiteSpace(expectedChainId) |
| | 20 | 48 | | ? orderedLinks[0].ChainId |
| | 20 | 49 | | : expectedChainId.Trim(); |
| | 20 | 50 | | HashSet<long> observedSequences = []; |
| | 20 | 51 | | long expectedSequence = requireGenesis ? 1 : orderedLinks[0].Sequence; |
| | | 52 | | |
| | 20 | 53 | | AuditIntegrityVerificationResult? anchorResult = ResolveExpectedPreviousHash( |
| | 20 | 54 | | orderedLinks[0], |
| | 20 | 55 | | requireGenesis, |
| | 20 | 56 | | expectedPreviousLinkHash, |
| | 20 | 57 | | out string expectedPreviousHash); |
| | | 58 | | |
| | 20 | 59 | | if (anchorResult is not null) |
| | | 60 | | { |
| | 1 | 61 | | return anchorResult; |
| | | 62 | | } |
| | | 63 | | |
| | 102 | 64 | | foreach (AuditIntegrityLink link in orderedLinks) |
| | | 65 | | { |
| | 39 | 66 | | AuditIntegrityVerificationResult? result = VerifyLink( |
| | 39 | 67 | | link, |
| | 39 | 68 | | chainId, |
| | 39 | 69 | | expectedSequence, |
| | 39 | 70 | | expectedPreviousHash, |
| | 39 | 71 | | observedSequences, |
| | 39 | 72 | | requireGenesis); |
| | | 73 | | |
| | 39 | 74 | | if (result is not null) |
| | | 75 | | { |
| | 14 | 76 | | return result; |
| | | 77 | | } |
| | | 78 | | |
| | 25 | 79 | | _ = observedSequences.Add(link.Sequence); |
| | 25 | 80 | | expectedPreviousHash = link.LinkHash; |
| | 25 | 81 | | expectedSequence = link.Sequence + 1; |
| | | 82 | | } |
| | | 83 | | |
| | 5 | 84 | | AuditIntegrityLink tip = orderedLinks[^1]; |
| | | 85 | | |
| | 5 | 86 | | return VerifyTip(tip, expectedTipLinkHash, expectedTipSequence) |
| | 5 | 87 | | ?? AuditIntegrityVerificationResult.Valid(chainId, orderedLinks.Count, tip.LinkHash); |
| | 14 | 88 | | } |
| | | 89 | | |
| | | 90 | | /// <summary> |
| | | 91 | | /// Determines the link hash the first supplied link must point back to. |
| | | 92 | | /// </summary> |
| | | 93 | | /// <remarks> |
| | | 94 | | /// A partial chain starting at sequence N greater than 1 points back to link N-1, whose hash is non-empty by |
| | | 95 | | /// construction. Seeding the expected previous hash with an empty string in that case both rejects genuine partial |
| | | 96 | | /// chains and accepts a forged restart whose links were rewritten to claim no predecessor, so the caller must suppl |
| | | 97 | | /// the anchoring hash instead. |
| | | 98 | | /// </remarks> |
| | | 99 | | private static AuditIntegrityVerificationResult? ResolveExpectedPreviousHash( |
| | | 100 | | AuditIntegrityLink firstLink, |
| | | 101 | | bool requireGenesis, |
| | | 102 | | string? expectedPreviousLinkHash, |
| | | 103 | | out string expectedPreviousHash) |
| | | 104 | | { |
| | 20 | 105 | | expectedPreviousHash = string.Empty; |
| | | 106 | | |
| | 20 | 107 | | if (requireGenesis || firstLink.Sequence == 1) |
| | | 108 | | { |
| | 16 | 109 | | return string.IsNullOrWhiteSpace(expectedPreviousLinkHash) |
| | 16 | 110 | | ? null |
| | 16 | 111 | | : AuditIntegrityVerificationResult.Failed( |
| | 16 | 112 | | AuditIntegrityVerificationCategory.MissingAnchor, |
| | 16 | 113 | | "integrity.anchor-not-applicable", |
| | 16 | 114 | | "An expected previous link hash cannot apply to a chain that starts at the genesis link.", |
| | 16 | 115 | | firstLink); |
| | | 116 | | } |
| | | 117 | | |
| | 4 | 118 | | if (string.IsNullOrWhiteSpace(expectedPreviousLinkHash)) |
| | | 119 | | { |
| | 1 | 120 | | return AuditIntegrityVerificationResult.Failed( |
| | 1 | 121 | | AuditIntegrityVerificationCategory.MissingAnchor, |
| | 1 | 122 | | "integrity.expected-previous-hash-required", |
| | 1 | 123 | | "A partial chain that does not start at the genesis link must supply the expected previous link hash.", |
| | 1 | 124 | | firstLink); |
| | | 125 | | } |
| | | 126 | | |
| | 3 | 127 | | expectedPreviousHash = expectedPreviousLinkHash.Trim(); |
| | 3 | 128 | | return null; |
| | | 129 | | } |
| | | 130 | | |
| | | 131 | | /// <summary> |
| | | 132 | | /// Rejects a chain that verifies internally but does not reach the tip the caller expected. |
| | | 133 | | /// </summary> |
| | | 134 | | private static AuditIntegrityVerificationResult? VerifyTip( |
| | | 135 | | AuditIntegrityLink tip, |
| | | 136 | | string? expectedTipLinkHash, |
| | | 137 | | long? expectedTipSequence) |
| | | 138 | | { |
| | 5 | 139 | | return !string.IsNullOrWhiteSpace(expectedTipLinkHash) |
| | 5 | 140 | | && !string.Equals(tip.LinkHash, expectedTipLinkHash.Trim(), StringComparison.Ordinal) |
| | 5 | 141 | | ? AuditIntegrityVerificationResult.Failed( |
| | 5 | 142 | | AuditIntegrityVerificationCategory.TruncatedChain, |
| | 5 | 143 | | "integrity.chain-truncated", |
| | 5 | 144 | | "The final link does not match the expected tip link hash.", |
| | 5 | 145 | | tip, |
| | 5 | 146 | | new Dictionary<string, string>(StringComparer.Ordinal) |
| | 5 | 147 | | { |
| | 5 | 148 | | ["expected_tip_link_hash"] = expectedTipLinkHash.Trim(), |
| | 5 | 149 | | ["actual_tip_link_hash"] = tip.LinkHash |
| | 5 | 150 | | }) |
| | 5 | 151 | | : expectedTipSequence.HasValue && tip.Sequence != expectedTipSequence.Value |
| | 5 | 152 | | ? AuditIntegrityVerificationResult.Failed( |
| | 5 | 153 | | AuditIntegrityVerificationCategory.TruncatedChain, |
| | 5 | 154 | | "integrity.chain-truncated", |
| | 5 | 155 | | "The final link does not match the expected tip sequence.", |
| | 5 | 156 | | tip, |
| | 5 | 157 | | new Dictionary<string, string>(StringComparer.Ordinal) |
| | 5 | 158 | | { |
| | 5 | 159 | | ["expected_tip_sequence"] = expectedTipSequence.Value.ToString(System.Globalization.CultureInfo.Inva |
| | 5 | 160 | | ["actual_tip_sequence"] = tip.Sequence.ToString(System.Globalization.CultureInfo.InvariantCulture) |
| | 5 | 161 | | }) |
| | 5 | 162 | | : null; |
| | | 163 | | } |
| | | 164 | | |
| | | 165 | | private static AuditIntegrityVerificationResult? VerifyLink( |
| | | 166 | | AuditIntegrityLink link, |
| | | 167 | | string expectedChainId, |
| | | 168 | | long expectedSequence, |
| | | 169 | | string expectedPreviousHash, |
| | | 170 | | HashSet<long> observedSequences, |
| | | 171 | | bool requireGenesis) |
| | | 172 | | { |
| | 39 | 173 | | if (!string.Equals(link.HashAlgorithm, CanonicalPayloadOptions.DefaultHashAlgorithm, StringComparison.Ordinal)) |
| | | 174 | | { |
| | 1 | 175 | | return AuditIntegrityVerificationResult.Failed( |
| | 1 | 176 | | AuditIntegrityVerificationCategory.UnsupportedAlgorithm, |
| | 1 | 177 | | "integrity.hash-algorithm-unsupported", |
| | 1 | 178 | | "The integrity link uses an unsupported hash algorithm.", |
| | 1 | 179 | | link); |
| | | 180 | | } |
| | | 181 | | |
| | 38 | 182 | | if (!string.Equals(link.ChainId, expectedChainId, StringComparison.Ordinal)) |
| | | 183 | | { |
| | 1 | 184 | | return AuditIntegrityVerificationResult.Failed( |
| | 1 | 185 | | AuditIntegrityVerificationCategory.WrongChain, |
| | 1 | 186 | | "integrity.chain-id-mismatch", |
| | 1 | 187 | | "The integrity link belongs to a different chain.", |
| | 1 | 188 | | link); |
| | | 189 | | } |
| | | 190 | | |
| | 37 | 191 | | if (observedSequences.Contains(link.Sequence)) |
| | | 192 | | { |
| | 4 | 193 | | return AuditIntegrityVerificationResult.Failed( |
| | 4 | 194 | | AuditIntegrityVerificationCategory.ForkedChain, |
| | 4 | 195 | | "integrity.sequence-duplicate", |
| | 4 | 196 | | "Multiple links claim the same chain sequence.", |
| | 4 | 197 | | link); |
| | | 198 | | } |
| | | 199 | | |
| | 33 | 200 | | if (link.Sequence != expectedSequence) |
| | | 201 | | { |
| | 3 | 202 | | AuditIntegrityVerificationCategory category = link.Sequence > expectedSequence |
| | 3 | 203 | | ? AuditIntegrityVerificationCategory.MissingRecord |
| | 3 | 204 | | : AuditIntegrityVerificationCategory.ReorderedRecord; |
| | | 205 | | |
| | 3 | 206 | | return AuditIntegrityVerificationResult.Failed( |
| | 3 | 207 | | category, |
| | 3 | 208 | | category is AuditIntegrityVerificationCategory.MissingRecord |
| | 3 | 209 | | ? "integrity.sequence-missing" |
| | 3 | 210 | | : "integrity.sequence-reordered", |
| | 3 | 211 | | "The integrity link sequence is not continuous in the supplied order.", |
| | 3 | 212 | | link, |
| | 3 | 213 | | new Dictionary<string, string>(StringComparer.Ordinal) |
| | 3 | 214 | | { |
| | 3 | 215 | | ["expected_sequence"] = expectedSequence.ToString(System.Globalization.CultureInfo.InvariantCulture) |
| | 3 | 216 | | ["actual_sequence"] = link.Sequence.ToString(System.Globalization.CultureInfo.InvariantCulture) |
| | 3 | 217 | | }); |
| | | 218 | | } |
| | | 219 | | |
| | 30 | 220 | | if (requireGenesis && link.Sequence == 1 && link.PreviousLinkHash.Length != 0) |
| | | 221 | | { |
| | 1 | 222 | | return AuditIntegrityVerificationResult.Failed( |
| | 1 | 223 | | AuditIntegrityVerificationCategory.HashMismatch, |
| | 1 | 224 | | "integrity.genesis-previous-hash-present", |
| | 1 | 225 | | "The genesis link must not point to a previous link hash.", |
| | 1 | 226 | | link); |
| | | 227 | | } |
| | | 228 | | |
| | 29 | 229 | | if (link.Sequence > 1 && link.PreviousLinkHash.Length == 0) |
| | | 230 | | { |
| | 1 | 231 | | return AuditIntegrityVerificationResult.Failed( |
| | 1 | 232 | | AuditIntegrityVerificationCategory.HashMismatch, |
| | 1 | 233 | | "integrity.previous-link-hash-missing", |
| | 1 | 234 | | "A link after the genesis link must point to a previous link hash.", |
| | 1 | 235 | | link); |
| | | 236 | | } |
| | | 237 | | |
| | 28 | 238 | | if (!string.Equals(link.PreviousLinkHash, expectedPreviousHash, StringComparison.Ordinal)) |
| | | 239 | | { |
| | 2 | 240 | | return AuditIntegrityVerificationResult.Failed( |
| | 2 | 241 | | AuditIntegrityVerificationCategory.HashMismatch, |
| | 2 | 242 | | "integrity.previous-link-hash-mismatch", |
| | 2 | 243 | | "The integrity link does not point to the previous link hash.", |
| | 2 | 244 | | link, |
| | 2 | 245 | | new Dictionary<string, string>(StringComparer.Ordinal) |
| | 2 | 246 | | { |
| | 2 | 247 | | ["expected_previous_hash"] = expectedPreviousHash, |
| | 2 | 248 | | ["actual_previous_hash"] = link.PreviousLinkHash |
| | 2 | 249 | | }); |
| | | 250 | | } |
| | | 251 | | |
| | 26 | 252 | | string expectedLinkHash = link.ComputeExpectedLinkHash(); |
| | 26 | 253 | | return !string.Equals(link.LinkHash, expectedLinkHash, StringComparison.Ordinal) |
| | 26 | 254 | | ? AuditIntegrityVerificationResult.Failed( |
| | 26 | 255 | | AuditIntegrityVerificationCategory.ModifiedRecord, |
| | 26 | 256 | | "integrity.link-hash-mismatch", |
| | 26 | 257 | | "The integrity link hash no longer matches its canonical fields.", |
| | 26 | 258 | | link, |
| | 26 | 259 | | new Dictionary<string, string>(StringComparer.Ordinal) |
| | 26 | 260 | | { |
| | 26 | 261 | | ["expected_link_hash"] = expectedLinkHash, |
| | 26 | 262 | | ["actual_link_hash"] = link.LinkHash |
| | 26 | 263 | | }) |
| | 26 | 264 | | : null; |
| | | 265 | | } |
| | | 266 | | } |