Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 1 | /* |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 2 | * Copyright (C) 2013 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | #ifndef DRM_API_H_ |
| 18 | #define DRM_API_H_ |
| 19 | |
| 20 | #include <utils/List.h> |
| 21 | #include <utils/String8.h> |
| 22 | #include <utils/Vector.h> |
| 23 | #include <utils/KeyedVector.h> |
| 24 | #include <utils/RefBase.h> |
Jeff Tinker | 7eafcae | 2013-04-02 13:16:21 -0700 | [diff] [blame] | 25 | #include <utils/Mutex.h> |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 26 | #include <media/stagefright/foundation/ABase.h> |
| 27 | |
| 28 | // Loadable DrmEngine shared libraries should define the entry points |
| 29 | // createDrmFactory and createCryptoFactory as shown below: |
| 30 | // |
| 31 | // extern "C" { |
| 32 | // extern android::DrmFactory *createDrmFactory(); |
| 33 | // extern android::CryptoFactory *createCryptoFactory(); |
| 34 | // } |
| 35 | |
| 36 | namespace android { |
| 37 | |
Jeff Tinker | 7eafcae | 2013-04-02 13:16:21 -0700 | [diff] [blame] | 38 | class DrmPlugin; |
| 39 | class DrmPluginListener; |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 40 | |
| 41 | // DRMs are implemented in DrmEngine plugins, which are dynamically |
| 42 | // loadable shared libraries that implement the entry points |
| 43 | // createDrmFactory and createCryptoFactory. createDrmFactory |
| 44 | // constructs and returns an instance of a DrmFactory object. Similarly, |
| 45 | // createCryptoFactory creates an instance of a CryptoFactory object. |
| 46 | // When a MediaCrypto or MediaDrm object needs to be constructed, all |
| 47 | // available DrmEngines present in the plugins directory on the device |
| 48 | // are scanned for a matching DrmEngine that can support the crypto |
| 49 | // scheme. When a match is found, the DrmEngine's createCryptoPlugin and |
| 50 | // createDrmPlugin methods are used to create CryptoPlugin or |
| 51 | // DrmPlugin instances to support that DRM scheme. |
| 52 | |
| 53 | class DrmFactory { |
| 54 | public: |
| 55 | DrmFactory() {} |
| 56 | virtual ~DrmFactory() {} |
| 57 | |
| 58 | // DrmFactory::isCryptoSchemeSupported can be called to determine |
| 59 | // if the plugin factory is able to construct plugins that support a |
| 60 | // given crypto scheme, which is specified by a UUID. |
| 61 | virtual bool isCryptoSchemeSupported(const uint8_t uuid[16]) = 0; |
| 62 | |
Jeff Tinker | 611d3d4 | 2013-08-21 11:57:40 -0700 | [diff] [blame] | 63 | // DrmFactory::isContentTypeSupported can be called to determine |
| 64 | // if the plugin factory is able to construct plugins that support a |
| 65 | // given media container format specified by mimeType |
| 66 | virtual bool isContentTypeSupported(const String8 &mimeType) = 0; |
| 67 | |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 68 | // Construct a DrmPlugin for the crypto scheme specified by UUID. |
| 69 | virtual status_t createDrmPlugin( |
| 70 | const uint8_t uuid[16], DrmPlugin **plugin) = 0; |
| 71 | |
| 72 | private: |
| 73 | DrmFactory(const DrmFactory &); |
| 74 | DrmFactory &operator=(const DrmFactory &); |
| 75 | }; |
| 76 | |
| 77 | class DrmPlugin { |
| 78 | public: |
| 79 | enum EventType { |
Jeff Tinker | 7eafcae | 2013-04-02 13:16:21 -0700 | [diff] [blame] | 80 | kDrmPluginEventProvisionRequired = 1, |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 81 | kDrmPluginEventKeyNeeded, |
| 82 | kDrmPluginEventKeyExpired, |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 83 | kDrmPluginEventVendorDefined |
| 84 | }; |
| 85 | |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 86 | // Drm keys can be for offline content or for online streaming. |
| 87 | // Offline keys are persisted on the device and may be used when the device |
Jeff Tinker | b84d1ca | 2013-05-07 14:07:10 -0700 | [diff] [blame] | 88 | // is disconnected from the network. The Release type is used to request |
| 89 | // that offline keys be no longer restricted to offline use. |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 90 | enum KeyType { |
| 91 | kKeyType_Offline, |
Jeff Tinker | b84d1ca | 2013-05-07 14:07:10 -0700 | [diff] [blame] | 92 | kKeyType_Streaming, |
| 93 | kKeyType_Release |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 94 | }; |
| 95 | |
| 96 | DrmPlugin() {} |
| 97 | virtual ~DrmPlugin() {} |
| 98 | |
| 99 | // Open a new session with the DrmPlugin object. A session ID is returned |
| 100 | // in the sessionId parameter. |
| 101 | virtual status_t openSession(Vector<uint8_t> &sessionId) = 0; |
| 102 | |
| 103 | // Close a session on the DrmPlugin object. |
| 104 | virtual status_t closeSession(Vector<uint8_t> const &sessionId) = 0; |
| 105 | |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 106 | // A key request/response exchange occurs between the app and a License |
| 107 | // Server to obtain the keys required to decrypt the content. getKeyRequest() |
| 108 | // is used to obtain an opaque key request blob that is delivered to the |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 109 | // license server. |
| 110 | // |
Jeff Tinker | b84d1ca | 2013-05-07 14:07:10 -0700 | [diff] [blame] | 111 | // The scope parameter may be a sessionId or a keySetId, depending on the |
| 112 | // specified keyType. When the keyType is kKeyType_Offline or |
| 113 | // kKeyType_Streaming, scope should be set to the sessionId the keys will be |
| 114 | // provided to. When the keyType is kKeyType_Release, scope should be set to |
| 115 | // the keySetId of the keys being released. Releasing keys from a device |
| 116 | // invalidates them for all sessions. |
| 117 | // |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 118 | // The init data passed to getKeyRequest is container-specific and its |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 119 | // meaning is interpreted based on the mime type provided in the mimeType |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 120 | // parameter to getKeyRequest. It could contain, for example, the content |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 121 | // ID, key ID or other data obtained from the content metadata that is required |
Jeff Tinker | b84d1ca | 2013-05-07 14:07:10 -0700 | [diff] [blame] | 122 | // in generating the key request. Init may be null when keyType is |
| 123 | // kKeyType_Release. |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 124 | // |
Jeff Tinker | b84d1ca | 2013-05-07 14:07:10 -0700 | [diff] [blame] | 125 | // mimeType identifies the mime type of the content |
| 126 | // |
| 127 | // keyType specifies if the keys are to be used for streaming or offline content |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 128 | // |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 129 | // optionalParameters are included in the key request message to allow a |
| 130 | // client application to provide additional message parameters to the server. |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 131 | // |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 132 | // If successful, the opaque key request blob is returned to the caller. |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 133 | virtual status_t |
Jeff Tinker | b84d1ca | 2013-05-07 14:07:10 -0700 | [diff] [blame] | 134 | getKeyRequest(Vector<uint8_t> const &scope, |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 135 | Vector<uint8_t> const &initData, |
| 136 | String8 const &mimeType, KeyType keyType, |
| 137 | KeyedVector<String8, String8> const &optionalParameters, |
| 138 | Vector<uint8_t> &request, String8 &defaultUrl) = 0; |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 139 | |
Jeff Tinker | b84d1ca | 2013-05-07 14:07:10 -0700 | [diff] [blame] | 140 | // |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 141 | // After a key response is received by the app, it is provided to the |
Jeff Tinker | b84d1ca | 2013-05-07 14:07:10 -0700 | [diff] [blame] | 142 | // Drm plugin using provideKeyResponse. |
| 143 | // |
| 144 | // scope may be a sessionId or a keySetId depending on the type of the |
| 145 | // response. Scope should be set to the sessionId when the response is |
| 146 | // for either streaming or offline key requests. Scope should be set to the |
| 147 | // keySetId when the response is for a release request. |
| 148 | // |
| 149 | // When the response is for an offline key request, a keySetId is returned |
| 150 | // in the keySetId vector parameter that can be used to later restore the |
| 151 | // keys to a new session with the method restoreKeys. When the response is |
| 152 | // for a streaming or release request, no keySetId is returned. |
| 153 | // |
| 154 | virtual status_t provideKeyResponse(Vector<uint8_t> const &scope, |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 155 | Vector<uint8_t> const &response, |
| 156 | Vector<uint8_t> &keySetId) = 0; |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 157 | |
Jeff Tinker | b84d1ca | 2013-05-07 14:07:10 -0700 | [diff] [blame] | 158 | // Remove the current keys from a session |
| 159 | virtual status_t removeKeys(Vector<uint8_t> const &sessionId) = 0; |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 160 | |
| 161 | // Restore persisted offline keys into a new session. keySetId identifies |
| 162 | // the keys to load, obtained from a prior call to provideKeyResponse(). |
| 163 | virtual status_t restoreKeys(Vector<uint8_t> const &sessionId, |
| 164 | Vector<uint8_t> const &keySetId) = 0; |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 165 | |
| 166 | // Request an informative description of the license for the session. The status |
| 167 | // is in the form of {name, value} pairs. Since DRM license policies vary by |
| 168 | // vendor, the specific status field names are determined by each DRM vendor. |
| 169 | // Refer to your DRM provider documentation for definitions of the field names |
| 170 | // for a particular DrmEngine. |
| 171 | virtual status_t |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 172 | queryKeyStatus(Vector<uint8_t> const &sessionId, |
| 173 | KeyedVector<String8, String8> &infoMap) const = 0; |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 174 | |
| 175 | // A provision request/response exchange occurs between the app and a |
| 176 | // provisioning server to retrieve a device certificate. getProvisionRequest |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 177 | // is used to obtain an opaque key request blob that is delivered to the |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 178 | // provisioning server. |
| 179 | // |
| 180 | // If successful, the opaque provision request blob is returned to the caller. |
Jeff Tinker | c2f10f2 | 2014-03-04 13:23:56 -0800 | [diff] [blame] | 181 | virtual status_t getProvisionRequest(String8 const &cert_type, |
| 182 | String8 const &cert_authority, |
| 183 | Vector<uint8_t> &request, |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 184 | String8 &defaultUrl) = 0; |
| 185 | |
| 186 | // After a provision response is received by the app, it is provided to the |
| 187 | // Drm plugin using provideProvisionResponse. |
Jeff Tinker | c2f10f2 | 2014-03-04 13:23:56 -0800 | [diff] [blame] | 188 | virtual status_t provideProvisionResponse(Vector<uint8_t> const &response, |
| 189 | Vector<uint8_t> &certificate, |
| 190 | Vector<uint8_t> &wrapped_key) = 0; |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 191 | |
| 192 | // A means of enforcing the contractual requirement for a concurrent stream |
| 193 | // limit per subscriber across devices is provided via SecureStop. SecureStop |
| 194 | // is a means of securely monitoring the lifetime of sessions. Since playback |
| 195 | // on a device can be interrupted due to reboot, power failure, etc. a means |
| 196 | // of persisting the lifetime information on the device is needed. |
| 197 | // |
| 198 | // A signed version of the sessionID is written to persistent storage on the |
| 199 | // device when each MediaCrypto object is created. The sessionID is signed by |
| 200 | // the device private key to prevent tampering. |
| 201 | // |
| 202 | // In the normal case, playback will be completed, the session destroyed and |
| 203 | // the Secure Stops will be queried. The App queries secure stops and forwards |
| 204 | // the secure stop message to the server which verifies the signature and |
| 205 | // notifies the server side database that the session destruction has been |
| 206 | // confirmed. The persisted record on the client is only removed after positive |
| 207 | // confirmation that the server received the message using releaseSecureStops(). |
| 208 | virtual status_t getSecureStops(List<Vector<uint8_t> > &secureStops) = 0; |
| 209 | virtual status_t releaseSecureStops(Vector<uint8_t> const &ssRelease) = 0; |
| 210 | |
| 211 | // Read a property value given the device property string. There are a few forms |
| 212 | // of property access methods, depending on the data type returned. |
| 213 | // Since DRM plugin properties may vary, additional field names may be defined |
| 214 | // by each DRM vendor. Refer to your DRM provider documentation for definitions |
| 215 | // of its additional field names. |
| 216 | // |
| 217 | // Standard values are: |
| 218 | // "vendor" [string] identifies the maker of the plugin |
| 219 | // "version" [string] identifies the version of the plugin |
| 220 | // "description" [string] describes the plugin |
| 221 | // 'deviceUniqueId' [byte array] The device unique identifier is established |
| 222 | // during device provisioning and provides a means of uniquely identifying |
| 223 | // each device. |
| 224 | virtual status_t getPropertyString(String8 const &name, String8 &value ) const = 0; |
| 225 | virtual status_t getPropertyByteArray(String8 const &name, |
| 226 | Vector<uint8_t> &value ) const = 0; |
| 227 | |
| 228 | // Write a property value given the device property string. There are a few forms |
| 229 | // of property setting methods, depending on the data type. |
| 230 | // Since DRM plugin properties may vary, additional field names may be defined |
| 231 | // by each DRM vendor. Refer to your DRM provider documentation for definitions |
| 232 | // of its field names. |
| 233 | virtual status_t setPropertyString(String8 const &name, |
| 234 | String8 const &value ) = 0; |
| 235 | virtual status_t setPropertyByteArray(String8 const &name, |
| 236 | Vector<uint8_t> const &value ) = 0; |
| 237 | |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 238 | // The following methods implement operations on a CryptoSession to support |
| 239 | // encrypt, decrypt, sign verify operations on operator-provided |
| 240 | // session keys. |
| 241 | |
| 242 | // |
| 243 | // The algorithm string conforms to JCA Standard Names for Cipher |
| 244 | // Transforms and is case insensitive. For example "AES/CBC/PKCS5Padding". |
| 245 | // |
| 246 | // Return OK if the algorithm is supported, otherwise return BAD_VALUE |
| 247 | // |
| 248 | virtual status_t setCipherAlgorithm(Vector<uint8_t> const &sessionId, |
| 249 | String8 const &algorithm) = 0; |
| 250 | |
| 251 | // |
| 252 | // The algorithm string conforms to JCA Standard Names for Mac |
| 253 | // Algorithms and is case insensitive. For example "HmacSHA256". |
| 254 | // |
| 255 | // Return OK if the algorithm is supported, otherwise return BAD_VALUE |
| 256 | // |
| 257 | virtual status_t setMacAlgorithm(Vector<uint8_t> const &sessionId, |
| 258 | String8 const &algorithm) = 0; |
| 259 | |
| 260 | // Encrypt the provided input buffer with the cipher algorithm |
| 261 | // specified by setCipherAlgorithm and the key selected by keyId, |
| 262 | // and return the encrypted data. |
| 263 | virtual status_t encrypt(Vector<uint8_t> const &sessionId, |
| 264 | Vector<uint8_t> const &keyId, |
| 265 | Vector<uint8_t> const &input, |
| 266 | Vector<uint8_t> const &iv, |
| 267 | Vector<uint8_t> &output) = 0; |
| 268 | |
| 269 | // Decrypt the provided input buffer with the cipher algorithm |
| 270 | // specified by setCipherAlgorithm and the key selected by keyId, |
| 271 | // and return the decrypted data. |
| 272 | virtual status_t decrypt(Vector<uint8_t> const &sessionId, |
| 273 | Vector<uint8_t> const &keyId, |
| 274 | Vector<uint8_t> const &input, |
| 275 | Vector<uint8_t> const &iv, |
| 276 | Vector<uint8_t> &output) = 0; |
| 277 | |
| 278 | // Compute a signature on the provided message using the mac algorithm |
| 279 | // specified by setMacAlgorithm and the key selected by keyId, |
| 280 | // and return the signature. |
| 281 | virtual status_t sign(Vector<uint8_t> const &sessionId, |
| 282 | Vector<uint8_t> const &keyId, |
| 283 | Vector<uint8_t> const &message, |
| 284 | Vector<uint8_t> &signature) = 0; |
| 285 | |
| 286 | // Compute a signature on the provided message using the mac algorithm |
| 287 | // specified by setMacAlgorithm and the key selected by keyId, |
| 288 | // and compare with the expected result. Set result to true or |
| 289 | // false depending on the outcome. |
| 290 | virtual status_t verify(Vector<uint8_t> const &sessionId, |
| 291 | Vector<uint8_t> const &keyId, |
| 292 | Vector<uint8_t> const &message, |
| 293 | Vector<uint8_t> const &signature, |
| 294 | bool &match) = 0; |
| 295 | |
| 296 | |
Jeff Tinker | c2f10f2 | 2014-03-04 13:23:56 -0800 | [diff] [blame] | 297 | // Compute an RSA signature on the provided message using the algorithm |
| 298 | // specified by algorithm. |
| 299 | virtual status_t signRSA(Vector<uint8_t> const &sessionId, |
| 300 | String8 const &algorithm, |
| 301 | Vector<uint8_t> const &message, |
| 302 | Vector<uint8_t> const &wrapped_key, |
| 303 | Vector<uint8_t> &signature) = 0; |
| 304 | |
| 305 | |
Jeff Tinker | 7eafcae | 2013-04-02 13:16:21 -0700 | [diff] [blame] | 306 | status_t setListener(const sp<DrmPluginListener>& listener) { |
| 307 | Mutex::Autolock lock(mEventLock); |
| 308 | mListener = listener; |
| 309 | return OK; |
| 310 | } |
Jeff Tinker | bcbd78b | 2013-03-30 16:28:20 -0700 | [diff] [blame] | 311 | |
Jeff Tinker | 7eafcae | 2013-04-02 13:16:21 -0700 | [diff] [blame] | 312 | protected: |
| 313 | // Plugins call sendEvent to deliver events to the java app |
| 314 | void sendEvent(EventType eventType, int extra, |
| 315 | Vector<uint8_t> const *sessionId, |
| 316 | Vector<uint8_t> const *data); |
| 317 | |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 318 | private: |
Jeff Tinker | 7eafcae | 2013-04-02 13:16:21 -0700 | [diff] [blame] | 319 | Mutex mEventLock; |
| 320 | sp<DrmPluginListener> mListener; |
| 321 | |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 322 | DISALLOW_EVIL_CONSTRUCTORS(DrmPlugin); |
| 323 | }; |
| 324 | |
Jeff Tinker | 7eafcae | 2013-04-02 13:16:21 -0700 | [diff] [blame] | 325 | class DrmPluginListener: virtual public RefBase |
| 326 | { |
| 327 | public: |
| 328 | virtual void sendEvent(DrmPlugin::EventType eventType, int extra, |
| 329 | Vector<uint8_t> const *sesionId, |
| 330 | Vector<uint8_t> const *data) = 0; |
| 331 | }; |
| 332 | |
| 333 | inline void DrmPlugin::sendEvent(EventType eventType, int extra, |
| 334 | Vector<uint8_t> const *sessionId, |
| 335 | Vector<uint8_t> const *data) { |
| 336 | |
| 337 | mEventLock.lock(); |
| 338 | sp<DrmPluginListener> listener = mListener; |
| 339 | mEventLock.unlock(); |
| 340 | |
| 341 | if (listener != NULL) { |
| 342 | listener->sendEvent(eventType, extra, sessionId, data); |
| 343 | } |
| 344 | } |
| 345 | |
Jeff Tinker | 56c78c4 | 2013-02-07 17:46:18 -0800 | [diff] [blame] | 346 | } // namespace android |
| 347 | |
| 348 | #endif // DRM_API_H_ |