summaryrefslogtreecommitdiffstats
path: root/src/main/java/com/gitblit/utils/SecureRandom.java
blob: 119533d410db1446d8133314dada70e64232c8c9 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
/*
 * Copyright 2016 gitblit.com
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */
package com.gitblit.utils;

/**
 * Wrapper class for java.security.SecureRandom, which will periodically reseed
 * the PRNG in case an instance of the class has been running for a long time.
 *
 * @author Florian Zschocke
 */
public class SecureRandom {

	/** Period (in ms) after which a new SecureRandom will be created in order to get a fresh random seed. */
	private static final long RESEED_PERIOD = 24 * 60 * 60 * 1000; /* 24 hours */


	private long last;
	private java.security.SecureRandom random;



	public SecureRandom() {
		// Make sure the SecureRandom is seeded right from the start.
		// This also lets any blocks during seeding occur at creation
		// and prevents it from happening when getting next random bytes.
		seed();
	}



	public byte[] randomBytes(int num) {
		byte[] bytes = new byte[num];
		nextBytes(bytes);
		return bytes;
	}


	public void nextBytes(byte[] bytes) {
		random.nextBytes(bytes);
		reseed(false);
	}


	void reseed(boolean forced) {
		long ts = System.currentTimeMillis();
		if (forced || (ts - last) > RESEED_PERIOD) {
			last = ts;
			runReseed();
		}
	}



	private void seed() {
		random = new java.security.SecureRandom();
		random.nextBytes(new byte[0]);
		last = System.currentTimeMillis();
	}


	private void runReseed() {
		// Have some other thread hit the penalty potentially incurred by reseeding,
		// so that we can immediately return and not block the operation in progress.
		new Thread() {
			public void run() {
				seed();
			}
		}.start();
	}
}