Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 1 | /* |
| 2 | * Copyright 2014 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | #ifndef SYSTEM_KEYMASTER_OPERATION_H_ |
| 18 | #define SYSTEM_KEYMASTER_OPERATION_H_ |
| 19 | |
| 20 | #include <assert.h> |
| 21 | #include <stdint.h> |
| 22 | #include <stdlib.h> |
| 23 | |
Shawn Willden | b9d584d | 2015-01-22 16:35:00 -0700 | [diff] [blame] | 24 | #include <hardware/keymaster_defs.h> |
Shawn Willden | ada4850 | 2015-06-25 06:26:05 -0700 | [diff] [blame] | 25 | #include <keymaster/android_keymaster_utils.h> |
| 26 | #include <keymaster/authorization_set.h> |
Shawn Willden | f6ca3a3 | 2014-09-11 15:11:32 -0600 | [diff] [blame] | 27 | #include <keymaster/logger.h> |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 28 | |
| 29 | namespace keymaster { |
| 30 | |
Shawn Willden | 111edb3 | 2015-02-05 22:44:24 -0700 | [diff] [blame] | 31 | class AuthorizationSet; |
Shawn Willden | 63ac043 | 2014-12-29 14:07:08 -0700 | [diff] [blame] | 32 | class Key; |
| 33 | class Operation; |
Janis Danisevskis | dc877ae | 2017-05-15 13:57:25 -0700 | [diff] [blame] | 34 | using OperationPtr = UniquePtr<Operation>; |
| 35 | |
Shawn Willden | 63ac043 | 2014-12-29 14:07:08 -0700 | [diff] [blame] | 36 | class OperationFactory { |
| 37 | public: |
| 38 | virtual ~OperationFactory() {} |
| 39 | |
| 40 | // Required for registry |
| 41 | struct KeyType { |
| 42 | KeyType(keymaster_algorithm_t alg, keymaster_purpose_t purp) |
| 43 | : algorithm(alg), purpose(purp) {} |
| 44 | |
| 45 | keymaster_algorithm_t algorithm; |
| 46 | keymaster_purpose_t purpose; |
| 47 | |
| 48 | bool operator==(const KeyType& rhs) const { |
| 49 | return algorithm == rhs.algorithm && purpose == rhs.purpose; |
| 50 | } |
| 51 | }; |
| 52 | virtual KeyType registry_key() const = 0; |
| 53 | |
| 54 | // Factory methods |
Shawn Willden | deffcb7 | 2018-01-07 23:34:58 -0700 | [diff] [blame] | 55 | virtual OperationPtr CreateOperation(Key&& key, const AuthorizationSet& begin_params, |
Matthew Maurer | a47727e | 2019-04-04 00:09:39 +0000 | [diff] [blame] | 56 | keymaster_error_t* error) = 0; |
Shawn Willden | 63ac043 | 2014-12-29 14:07:08 -0700 | [diff] [blame] | 57 | |
| 58 | // Informational methods. The returned arrays reference static memory and must not be |
| 59 | // deallocated or modified. |
| 60 | virtual const keymaster_padding_t* SupportedPaddingModes(size_t* padding_count) const { |
| 61 | *padding_count = 0; |
Yi Kong | 3712b27 | 2018-07-30 15:53:23 -0700 | [diff] [blame] | 62 | return nullptr; |
Shawn Willden | 63ac043 | 2014-12-29 14:07:08 -0700 | [diff] [blame] | 63 | } |
| 64 | virtual const keymaster_block_mode_t* SupportedBlockModes(size_t* block_mode_count) const { |
| 65 | *block_mode_count = 0; |
Yi Kong | 3712b27 | 2018-07-30 15:53:23 -0700 | [diff] [blame] | 66 | return nullptr; |
Shawn Willden | 63ac043 | 2014-12-29 14:07:08 -0700 | [diff] [blame] | 67 | } |
| 68 | virtual const keymaster_digest_t* SupportedDigests(size_t* digest_count) const { |
| 69 | *digest_count = 0; |
Yi Kong | 3712b27 | 2018-07-30 15:53:23 -0700 | [diff] [blame] | 70 | return nullptr; |
Shawn Willden | 63ac043 | 2014-12-29 14:07:08 -0700 | [diff] [blame] | 71 | } |
Shawn Willden | d92591d | 2014-12-30 18:19:10 -0700 | [diff] [blame] | 72 | |
| 73 | // Convenience methods |
| 74 | bool supported(keymaster_padding_t padding) const; |
| 75 | bool supported(keymaster_block_mode_t padding) const; |
| 76 | bool supported(keymaster_digest_t padding) const; |
Shawn Willden | 117a0cc | 2015-06-01 07:05:41 -0600 | [diff] [blame] | 77 | |
Shawn Willden | 294a2db | 2015-06-17 11:20:56 -0600 | [diff] [blame] | 78 | bool is_public_key_operation() const; |
| 79 | |
Shawn Willden | 117a0cc | 2015-06-01 07:05:41 -0600 | [diff] [blame] | 80 | bool GetAndValidatePadding(const AuthorizationSet& begin_params, const Key& key, |
| 81 | keymaster_padding_t* padding, keymaster_error_t* error) const; |
| 82 | bool GetAndValidateDigest(const AuthorizationSet& begin_params, const Key& key, |
| 83 | keymaster_digest_t* digest, keymaster_error_t* error) const; |
Matthew Maurer | 90174bd | 2019-05-10 16:31:00 -0700 | [diff] [blame] | 84 | bool GetAndValidateDigest(const AuthorizationSet& begin_params, const Key& key, |
| 85 | keymaster_digest_t* digest, keymaster_error_t* error, |
| 86 | bool require_explicit_digest) const; |
Shawn Willden | 63ac043 | 2014-12-29 14:07:08 -0700 | [diff] [blame] | 87 | }; |
| 88 | |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 89 | /** |
| 90 | * Abstract base for all cryptographic operations. |
| 91 | */ |
| 92 | class Operation { |
| 93 | public: |
Shawn Willden | deffcb7 | 2018-01-07 23:34:58 -0700 | [diff] [blame] | 94 | explicit Operation(keymaster_purpose_t purpose, AuthorizationSet&& hw_enforced, |
| 95 | AuthorizationSet&& sw_enforced) |
| 96 | : purpose_(purpose), hw_enforced_(move(hw_enforced)), sw_enforced_(move(sw_enforced)) {} |
Shawn Willden | f6ca3a3 | 2014-09-11 15:11:32 -0600 | [diff] [blame] | 97 | virtual ~Operation() {} |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 98 | |
Shawn Willden | deffcb7 | 2018-01-07 23:34:58 -0700 | [diff] [blame] | 99 | Operation(const Operation&) = delete; |
| 100 | void operator=(const Operation&) = delete; |
| 101 | |
Shawn Willden | f6ca3a3 | 2014-09-11 15:11:32 -0600 | [diff] [blame] | 102 | keymaster_purpose_t purpose() const { return purpose_; } |
| 103 | |
Shawn Willden | ada4850 | 2015-06-25 06:26:05 -0700 | [diff] [blame] | 104 | void set_key_id(uint64_t key_id) { key_id_ = key_id; } |
| 105 | uint64_t key_id() const { return key_id_; } |
Janis Danisevskis | f3dc0b8 | 2017-05-15 11:19:44 -0700 | [diff] [blame] | 106 | virtual keymaster_operation_handle_t operation_handle() const { return operation_handle_; } |
Shawn Willden | ada4850 | 2015-06-25 06:26:05 -0700 | [diff] [blame] | 107 | |
Shawn Willden | deffcb7 | 2018-01-07 23:34:58 -0700 | [diff] [blame] | 108 | AuthProxy authorizations() const { return AuthProxy(hw_enforced_, sw_enforced_); } |
Shawn Willden | ada4850 | 2015-06-25 06:26:05 -0700 | [diff] [blame] | 109 | |
Shawn Willden | 111edb3 | 2015-02-05 22:44:24 -0700 | [diff] [blame] | 110 | virtual keymaster_error_t Begin(const AuthorizationSet& input_params, |
| 111 | AuthorizationSet* output_params) = 0; |
Shawn Willden | ded8e7d | 2015-06-01 15:29:12 -0600 | [diff] [blame] | 112 | virtual keymaster_error_t Update(const AuthorizationSet& input_params, const Buffer& input, |
| 113 | AuthorizationSet* output_params, Buffer* output, |
| 114 | size_t* input_consumed) = 0; |
Shawn Willden | cb647fe | 2016-01-27 12:59:13 -0700 | [diff] [blame] | 115 | virtual keymaster_error_t Finish(const AuthorizationSet& input_params, const Buffer& input, |
| 116 | const Buffer& signature, AuthorizationSet* output_params, |
| 117 | Buffer* output) = 0; |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 118 | virtual keymaster_error_t Abort() = 0; |
| 119 | |
Shawn Willden | deffcb7 | 2018-01-07 23:34:58 -0700 | [diff] [blame] | 120 | protected: |
Shawn Willden | cb647fe | 2016-01-27 12:59:13 -0700 | [diff] [blame] | 121 | // Helper function for implementing Finish() methods that need to call Update() to process |
| 122 | // input, but don't expect any output. |
| 123 | keymaster_error_t UpdateForFinish(const AuthorizationSet& input_params, const Buffer& input); |
Janis Danisevskis | f3dc0b8 | 2017-05-15 11:19:44 -0700 | [diff] [blame] | 124 | keymaster_operation_handle_t operation_handle_; |
Shawn Willden | cb647fe | 2016-01-27 12:59:13 -0700 | [diff] [blame] | 125 | |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 126 | private: |
| 127 | const keymaster_purpose_t purpose_; |
Shawn Willden | deffcb7 | 2018-01-07 23:34:58 -0700 | [diff] [blame] | 128 | AuthorizationSet hw_enforced_; |
| 129 | AuthorizationSet sw_enforced_; |
Shawn Willden | ada4850 | 2015-06-25 06:26:05 -0700 | [diff] [blame] | 130 | uint64_t key_id_; |
Shawn Willden | 0a4df7e | 2014-08-28 16:09:05 -0600 | [diff] [blame] | 131 | }; |
| 132 | |
| 133 | } // namespace keymaster |
| 134 | |
| 135 | #endif // SYSTEM_KEYMASTER_OPERATION_H_ |