/** * Cryptographic operations for KLAP v2 and AES transport protocols. * * Reference: python-kasa klapprotocol.py, klaptransport.py, aestransport.py * Uses only node:crypto (no external dependencies). */ import type { KasaCredentials } from "./types.js"; /** * Generate a random local seed for the KLAP handshake. * @param size - Number of random bytes (default 16). */ export declare function generateKlapLocalSeed(size?: number): Buffer; /** * Generate the KLAP v2 auth hash from credentials. * * KLAP v2 uses: SHA256(SHA1(username) + SHA1(password)) * * Reference: KlapTransportV2.generate_auth_hash in klaptransport.py */ export declare function generateKlapAuthHash(credentials: KasaCredentials): Buffer; /** * Generate the local auth hash for handshake1 verification. * * The device sends SHA256(local_seed + remote_seed + auth_hash) as the * server_hash in its handshake1 response. We compute the same to verify. * * KLAP v2 uses: SHA256(local_seed + remote_seed + auth_hash) * * Reference: KlapTransportV2.handshake1_seed_auth_hash */ export declare function generateKlapLocalAuthHash(localSeed: Buffer, remoteSeed: Buffer, authHash: Buffer): Buffer; /** * Generate the remote auth hash for handshake2. * * Sent to the device in handshake2 so it can verify the client. * * KLAP v2 uses: SHA256(remote_seed + local_seed + auth_hash) * * Reference: KlapTransportV2.handshake2_seed_auth_hash */ export declare function generateKlapRemoteAuthHash(remoteSeed: Buffer, localSeed: Buffer, authHash: Buffer): Buffer; /** * Derive the KLAP encryption session keys from seeds and auth hash. * * Returns: * - key: AES-128 key (first 16 bytes of SHA256("lsk" + local + remote + auth)) * - iv: First 12 bytes of SHA256("iv" + local + remote + auth) * - sig: First 28 bytes of SHA256("ldk" + local + remote + auth) * - seq: Last 4 bytes of full IV hash, interpreted as signed big-endian int32 * * Reference: KlapEncryptionSession.__init__ in klapprotocol.py */ export declare function deriveKlapKeys(localSeed: Buffer, remoteSeed: Buffer, authHash: Buffer): { key: Buffer; iv: Buffer; sig: Buffer; seq: number; }; /** * Encrypt data using the KLAP protocol. * * 1. Increment the sequence number * 2. Build the full 16-byte IV: iv(12 bytes) + packSignedInt32BE(seq) * 3. AES-128-CBC encrypt with PKCS7 padding * 4. Compute signature: SHA256(sig + packSignedInt32BE(seq) + ciphertext) * 5. Return signature(32 bytes) + ciphertext, and the new sequence number * * Reference: KlapEncryptionSession.encrypt in klapprotocol.py */ export declare function klapEncrypt(data: Buffer, key: Buffer, iv: Buffer, sig: Buffer, seq: number): { encryptedData: Buffer; seq: number; }; /** * Decrypt data using the KLAP protocol. * * 1. The first 32 bytes are the HMAC-SHA256 signature (skipped for now, * the device is trusted after handshake) * 2. The remaining bytes are AES-128-CBC encrypted with PKCS7 padding * 3. The IV is iv(12 bytes) + packSignedInt32BE(seq) (same seq as encrypt) * * Reference: KlapEncryptionSession.decrypt in klapprotocol.py */ export declare function klapDecrypt(data: Buffer, key: Buffer, iv: Buffer, sig: Buffer, seq: number): Buffer; /** * Generate an RSA 1024-bit key pair for the AES handshake. * Returns PEM-encoded public and private keys. * * Reference: KeyPair.create_key_pair in aestransport.py */ export declare function generateAesKeyPair(): { publicKey: string; privateKey: string; }; /** * Decrypt the AES session key returned by the device during handshake. * * The device encrypts a 32-byte payload with our public key using PKCS1 v1.5. * The first 16 bytes are the AES key, the last 16 bytes are the IV. * * @param encryptedKey - Base64-encoded encrypted key from the handshake response. * @param privateKey - PEM-encoded RSA private key. * * Reference: KeyPair.decrypt_handshake_key and AesEncyptionSession.create_from_keypair */ export declare function decryptAesSessionKey(encryptedKey: string, privateKey: string): { key: Buffer; iv: Buffer; }; /** * AES-128-CBC encrypt a string payload, returning base64. * * Uses PKCS7 padding, matching the python-kasa AesEncyptionSession.encrypt. * * Reference: AesEncyptionSession.encrypt in aestransport.py */ export declare function aesEncrypt(data: string, key: Buffer, iv: Buffer): string; /** * AES-128-CBC decrypt a base64 payload, returning the plaintext string. * * Uses PKCS7 unpadding, matching the python-kasa AesEncyptionSession.decrypt. * * Reference: AesEncyptionSession.decrypt in aestransport.py */ export declare function aesDecrypt(data: string, key: Buffer, iv: Buffer): string; /** * Hash credentials for the AES login_device call. * * username: base64(sha1_hex(username)) * password: base64(password) (login v1, which is the default for Kasa devices) * * Reference: AesTransport.hash_credentials in aestransport.py (login_v2=False path) */ export declare function generateAesLoginHash(credentials: KasaCredentials): { username: string; password: string; }; //# sourceMappingURL=crypto.d.ts.map