Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 1 | /* |
| 2 | * Copyright 2014 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | #ifndef SYSTEM_KEYMASTER_RSA_OPERATION_H_ |
| 18 | #define SYSTEM_KEYMASTER_RSA_OPERATION_H_ |
| 19 | |
| 20 | #include <UniquePtr.h> |
| 21 | |
Shawn Willden | 63ac043 | 2014-12-29 14:07:08 -0700 | [diff] [blame] | 22 | #include <openssl/evp.h> |
| 23 | #include <openssl/rsa.h> |
| 24 | |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 25 | #include <keymaster/key_blob.h> |
| 26 | |
| 27 | #include "operation.h" |
| 28 | |
| 29 | namespace keymaster { |
| 30 | |
Shawn Willden | 6190236 | 2014-12-18 10:33:24 -0700 | [diff] [blame^] | 31 | /** |
| 32 | * Base class for all RSA operations. |
| 33 | * |
| 34 | * This class provides RSA key management, plus buffering of data for non-digesting modes. |
| 35 | */ |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 36 | class RsaOperation : public Operation { |
| 37 | public: |
Shawn Willden | 567a4a0 | 2014-12-31 12:14:46 -0700 | [diff] [blame] | 38 | RsaOperation(keymaster_purpose_t purpose, keymaster_padding_t padding, RSA* key) |
| 39 | : Operation(purpose), rsa_key_(key), padding_(padding) {} |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 40 | ~RsaOperation(); |
| 41 | |
Shawn Willden | 111edb3 | 2015-02-05 22:44:24 -0700 | [diff] [blame] | 42 | virtual keymaster_error_t Begin(const AuthorizationSet& /* input_params */, |
| 43 | AuthorizationSet* /* output_params */) { |
| 44 | return KM_ERROR_OK; |
| 45 | } |
Shawn Willden | 6bfbff0 | 2015-02-06 19:48:24 -0700 | [diff] [blame] | 46 | virtual keymaster_error_t Update(const AuthorizationSet& additional_params, const Buffer& input, |
| 47 | Buffer* output, size_t* input_consumed); |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 48 | virtual keymaster_error_t Abort() { return KM_ERROR_OK; } |
| 49 | |
| 50 | protected: |
Shawn Willden | b736113 | 2014-12-08 08:15:14 -0700 | [diff] [blame] | 51 | keymaster_error_t StoreData(const Buffer& input, size_t* input_consumed); |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 52 | |
| 53 | RSA* rsa_key_; |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 54 | keymaster_padding_t padding_; |
| 55 | Buffer data_; |
| 56 | }; |
| 57 | |
Shawn Willden | 6190236 | 2014-12-18 10:33:24 -0700 | [diff] [blame^] | 58 | /** |
| 59 | * Base class for all RSA operations. |
| 60 | * |
| 61 | * This class adds digesting support, for digesting modes. For non-digesting modes, it falls back |
| 62 | * on the RsaOperation input buffering. |
| 63 | */ |
| 64 | class RsaDigestingOperation : public RsaOperation { |
| 65 | public: |
| 66 | RsaDigestingOperation(keymaster_purpose_t purpose, keymaster_digest_t digest, |
| 67 | keymaster_padding_t padding, RSA* key); |
| 68 | ~RsaDigestingOperation(); |
| 69 | |
| 70 | virtual keymaster_error_t Begin(const AuthorizationSet& input_params, |
| 71 | AuthorizationSet* output_params); |
| 72 | virtual keymaster_error_t Update(const AuthorizationSet& additional_params, const Buffer& input, |
| 73 | Buffer* output, size_t* input_consumed); |
| 74 | |
| 75 | protected: |
| 76 | uint8_t* FinishDigest(unsigned* digest_size); |
| 77 | |
| 78 | const keymaster_digest_t digest_; |
| 79 | const EVP_MD* digest_algorithm_; |
| 80 | EVP_MD_CTX digest_ctx_; |
| 81 | }; |
| 82 | |
| 83 | /** |
| 84 | * RSA private key signing operation. |
| 85 | */ |
| 86 | class RsaSignOperation : public RsaDigestingOperation { |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 87 | public: |
Shawn Willden | 567a4a0 | 2014-12-31 12:14:46 -0700 | [diff] [blame] | 88 | RsaSignOperation(keymaster_digest_t digest, keymaster_padding_t padding, RSA* key) |
Shawn Willden | 6190236 | 2014-12-18 10:33:24 -0700 | [diff] [blame^] | 89 | : RsaDigestingOperation(KM_PURPOSE_SIGN, digest, padding, key) {} |
Shawn Willden | 6bfbff0 | 2015-02-06 19:48:24 -0700 | [diff] [blame] | 90 | virtual keymaster_error_t Finish(const AuthorizationSet& additional_params, |
| 91 | const Buffer& signature, Buffer* output); |
Shawn Willden | 4200f21 | 2014-12-02 07:01:21 -0700 | [diff] [blame] | 92 | |
| 93 | private: |
Shawn Willden | 6190236 | 2014-12-18 10:33:24 -0700 | [diff] [blame^] | 94 | int SignUndigested(Buffer* output); |
| 95 | int SignDigested(Buffer* output); |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 96 | }; |
| 97 | |
Shawn Willden | 6190236 | 2014-12-18 10:33:24 -0700 | [diff] [blame^] | 98 | /** |
| 99 | * RSA public key verification operation. |
| 100 | */ |
| 101 | class RsaVerifyOperation : public RsaDigestingOperation { |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 102 | public: |
Shawn Willden | 567a4a0 | 2014-12-31 12:14:46 -0700 | [diff] [blame] | 103 | RsaVerifyOperation(keymaster_digest_t digest, keymaster_padding_t padding, RSA* key) |
Shawn Willden | 6190236 | 2014-12-18 10:33:24 -0700 | [diff] [blame^] | 104 | : RsaDigestingOperation(KM_PURPOSE_VERIFY, digest, padding, key) {} |
Shawn Willden | 6bfbff0 | 2015-02-06 19:48:24 -0700 | [diff] [blame] | 105 | virtual keymaster_error_t Finish(const AuthorizationSet& additional_params, |
| 106 | const Buffer& signature, Buffer* output); |
Shawn Willden | 4200f21 | 2014-12-02 07:01:21 -0700 | [diff] [blame] | 107 | |
| 108 | private: |
Shawn Willden | 6190236 | 2014-12-18 10:33:24 -0700 | [diff] [blame^] | 109 | keymaster_error_t VerifyUndigested(uint8_t* decrypted_data); |
| 110 | keymaster_error_t VerifyDigested(uint8_t* decrypted_data); |
Shawn Willden | 4200f21 | 2014-12-02 07:01:21 -0700 | [diff] [blame] | 111 | }; |
| 112 | |
Shawn Willden | 6190236 | 2014-12-18 10:33:24 -0700 | [diff] [blame^] | 113 | /** |
| 114 | * RSA public key encryption operation. |
| 115 | */ |
Shawn Willden | 4200f21 | 2014-12-02 07:01:21 -0700 | [diff] [blame] | 116 | class RsaEncryptOperation : public RsaOperation { |
| 117 | public: |
Shawn Willden | 567a4a0 | 2014-12-31 12:14:46 -0700 | [diff] [blame] | 118 | RsaEncryptOperation(keymaster_padding_t padding, RSA* key) |
| 119 | : RsaOperation(KM_PURPOSE_ENCRYPT, padding, key) {} |
Shawn Willden | 6bfbff0 | 2015-02-06 19:48:24 -0700 | [diff] [blame] | 120 | virtual keymaster_error_t Finish(const AuthorizationSet& additional_params, |
| 121 | const Buffer& signature, Buffer* output); |
Shawn Willden | 4200f21 | 2014-12-02 07:01:21 -0700 | [diff] [blame] | 122 | }; |
| 123 | |
Shawn Willden | 6190236 | 2014-12-18 10:33:24 -0700 | [diff] [blame^] | 124 | /** |
| 125 | * RSA private key decryption operation. |
| 126 | */ |
Shawn Willden | 4200f21 | 2014-12-02 07:01:21 -0700 | [diff] [blame] | 127 | class RsaDecryptOperation : public RsaOperation { |
| 128 | public: |
Shawn Willden | 567a4a0 | 2014-12-31 12:14:46 -0700 | [diff] [blame] | 129 | RsaDecryptOperation(keymaster_padding_t padding, RSA* key) |
| 130 | : RsaOperation(KM_PURPOSE_DECRYPT, padding, key) {} |
Shawn Willden | 6bfbff0 | 2015-02-06 19:48:24 -0700 | [diff] [blame] | 131 | virtual keymaster_error_t Finish(const AuthorizationSet& additional_params, |
| 132 | const Buffer& signature, Buffer* output); |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 133 | }; |
| 134 | |
| 135 | } // namespace keymaster |
| 136 | |
| 137 | #endif // SYSTEM_KEYMASTER_RSA_OPERATION_H_ |