1 /* 2 * Copyright (C) 2012 The Android Open Source Project 3 * 4 * Licensed under the Apache License, Version 2.0 (the "License"); 5 * you may not use this file except in compliance with the License. 6 * You may obtain a copy of the License at 7 * 8 * http://www.apache.org/licenses/LICENSE-2.0 9 * 10 * Unless required by applicable law or agreed to in writing, software 11 * distributed under the License is distributed on an "AS IS" BASIS, 12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 * See the License for the specific language governing permissions and 14 * limitations under the License. 15 */ 16 17 #ifndef KEYSTORE_IKEYSTORESERVICE_H 18 #define KEYSTORE_IKEYSTORESERVICE_H 19 20 #include <hardware/keymaster_defs.h> 21 #include <utils/RefBase.h> 22 #include <binder/IInterface.h> 23 #include <binder/Parcel.h> 24 #include <vector> 25 26 namespace android { 27 28 class KeystoreArg : public RefBase { 29 public: 30 KeystoreArg(const void *data, size_t len); 31 ~KeystoreArg(); 32 33 const void* data() const; 34 size_t size() const; 35 36 private: 37 const void* mData; 38 size_t mSize; 39 }; 40 41 struct MallocDeleter { operatorMallocDeleter42 void operator()(uint8_t* p) { free(p); } 43 }; 44 45 // struct for serializing/deserializing a list of keymaster_key_param_t's 46 struct KeymasterArguments { 47 KeymasterArguments(); 48 ~KeymasterArguments(); 49 void readFromParcel(const Parcel& in); 50 void writeToParcel(Parcel* out) const; 51 52 std::vector<keymaster_key_param_t> params; 53 }; 54 55 // struct for serializing the results of begin/update/finish 56 struct OperationResult { 57 OperationResult(); 58 ~OperationResult(); 59 void readFromParcel(const Parcel& in); 60 void writeToParcel(Parcel* out) const; 61 62 int resultCode; 63 sp<IBinder> token; 64 keymaster_operation_handle_t handle; 65 int inputConsumed; 66 std::unique_ptr<uint8_t[], MallocDeleter> data; 67 size_t dataLength; 68 KeymasterArguments outParams; 69 }; 70 71 // struct for serializing the results of export 72 struct ExportResult { 73 ExportResult(); 74 ~ExportResult(); 75 void readFromParcel(const Parcel& in); 76 void writeToParcel(Parcel* out) const; 77 78 int resultCode; 79 std::unique_ptr<uint8_t[], MallocDeleter> exportData; 80 size_t dataLength; 81 }; 82 83 // struct for serializing keymaster_key_characteristics_t's 84 struct KeyCharacteristics { 85 KeyCharacteristics(); 86 ~KeyCharacteristics(); 87 void readFromParcel(const Parcel& in); 88 void writeToParcel(Parcel* out) const; 89 90 keymaster_key_characteristics_t characteristics; 91 }; 92 93 bool readKeymasterArgumentFromParcel(const Parcel& in, keymaster_key_param_t* out); 94 void writeKeymasterArgumentToParcel(const keymaster_key_param_t& param, Parcel* out); 95 96 /* 97 * This must be kept manually in sync with frameworks/base's IKeystoreService.java 98 */ 99 class IKeystoreService: public IInterface { 100 public: 101 enum { 102 GET_STATE = IBinder::FIRST_CALL_TRANSACTION + 0, 103 GET = IBinder::FIRST_CALL_TRANSACTION + 1, 104 INSERT = IBinder::FIRST_CALL_TRANSACTION + 2, 105 DEL = IBinder::FIRST_CALL_TRANSACTION + 3, 106 EXIST = IBinder::FIRST_CALL_TRANSACTION + 4, 107 LIST = IBinder::FIRST_CALL_TRANSACTION + 5, 108 RESET = IBinder::FIRST_CALL_TRANSACTION + 6, 109 ON_USER_PASSWORD_CHANGED = IBinder::FIRST_CALL_TRANSACTION + 7, 110 LOCK = IBinder::FIRST_CALL_TRANSACTION + 8, 111 UNLOCK = IBinder::FIRST_CALL_TRANSACTION + 9, 112 IS_EMPTY = IBinder::FIRST_CALL_TRANSACTION + 10, 113 GENERATE = IBinder::FIRST_CALL_TRANSACTION + 11, 114 IMPORT = IBinder::FIRST_CALL_TRANSACTION + 12, 115 SIGN = IBinder::FIRST_CALL_TRANSACTION + 13, 116 VERIFY = IBinder::FIRST_CALL_TRANSACTION + 14, 117 GET_PUBKEY = IBinder::FIRST_CALL_TRANSACTION + 15, 118 GRANT = IBinder::FIRST_CALL_TRANSACTION + 16, 119 UNGRANT = IBinder::FIRST_CALL_TRANSACTION + 17, 120 GETMTIME = IBinder::FIRST_CALL_TRANSACTION + 18, 121 DUPLICATE = IBinder::FIRST_CALL_TRANSACTION + 19, 122 IS_HARDWARE_BACKED = IBinder::FIRST_CALL_TRANSACTION + 20, 123 CLEAR_UID = IBinder::FIRST_CALL_TRANSACTION + 21, 124 ADD_RNG_ENTROPY = IBinder::FIRST_CALL_TRANSACTION + 22, 125 GENERATE_KEY = IBinder::FIRST_CALL_TRANSACTION + 23, 126 GET_KEY_CHARACTERISTICS = IBinder::FIRST_CALL_TRANSACTION + 24, 127 IMPORT_KEY = IBinder::FIRST_CALL_TRANSACTION + 25, 128 EXPORT_KEY = IBinder::FIRST_CALL_TRANSACTION + 26, 129 BEGIN = IBinder::FIRST_CALL_TRANSACTION + 27, 130 UPDATE = IBinder::FIRST_CALL_TRANSACTION + 28, 131 FINISH = IBinder::FIRST_CALL_TRANSACTION + 29, 132 ABORT = IBinder::FIRST_CALL_TRANSACTION + 30, 133 IS_OPERATION_AUTHORIZED = IBinder::FIRST_CALL_TRANSACTION + 31, 134 ADD_AUTH_TOKEN = IBinder::FIRST_CALL_TRANSACTION + 32, 135 ON_USER_ADDED = IBinder::FIRST_CALL_TRANSACTION + 33, 136 ON_USER_REMOVED = IBinder::FIRST_CALL_TRANSACTION + 34, 137 }; 138 139 DECLARE_META_INTERFACE(KeystoreService); 140 141 virtual int32_t getState(int32_t userId) = 0; 142 143 virtual int32_t get(const String16& name, uint8_t** item, size_t* itemLength) = 0; 144 145 virtual int32_t insert(const String16& name, const uint8_t* item, size_t itemLength, int uid, 146 int32_t flags) = 0; 147 148 virtual int32_t del(const String16& name, int uid) = 0; 149 150 virtual int32_t exist(const String16& name, int uid) = 0; 151 152 virtual int32_t list(const String16& prefix, int uid, Vector<String16>* matches) = 0; 153 154 virtual int32_t reset() = 0; 155 156 virtual int32_t onUserPasswordChanged(int32_t userId, const String16& newPassword) = 0; 157 158 virtual int32_t lock(int32_t userId) = 0; 159 160 virtual int32_t unlock(int32_t userId, const String16& password) = 0; 161 162 virtual bool isEmpty(int32_t userId) = 0; 163 164 virtual int32_t generate(const String16& name, int32_t uid, int32_t keyType, int32_t keySize, 165 int32_t flags, Vector<sp<KeystoreArg> >* args) = 0; 166 167 virtual int32_t import(const String16& name, const uint8_t* data, size_t length, int uid, 168 int32_t flags) = 0; 169 170 virtual int32_t sign(const String16& name, const uint8_t* data, size_t length, uint8_t** out, 171 size_t* outLength) = 0; 172 173 virtual int32_t verify(const String16& name, const uint8_t* data, size_t dataLength, 174 const uint8_t* signature, size_t signatureLength) = 0; 175 176 virtual int32_t get_pubkey(const String16& name, uint8_t** pubkey, size_t* pubkeyLength) = 0; 177 178 virtual int32_t grant(const String16& name, int32_t granteeUid) = 0; 179 180 virtual int32_t ungrant(const String16& name, int32_t granteeUid) = 0; 181 182 virtual int64_t getmtime(const String16& name) = 0; 183 184 virtual int32_t duplicate(const String16& srcKey, int32_t srcUid, const String16& destKey, 185 int32_t destUid) = 0; 186 187 virtual int32_t is_hardware_backed(const String16& keyType) = 0; 188 189 virtual int32_t clear_uid(int64_t uid) = 0; 190 191 virtual int32_t addRngEntropy(const uint8_t* data, size_t dataLength) = 0; 192 193 virtual int32_t generateKey(const String16& name, const KeymasterArguments& params, 194 const uint8_t* entropy, size_t entropyLength, int uid, int flags, 195 KeyCharacteristics* outCharacteristics) = 0; 196 197 virtual int32_t getKeyCharacteristics(const String16& name, 198 const keymaster_blob_t* clientId, 199 const keymaster_blob_t* appData, 200 KeyCharacteristics* outCharacteristics) = 0; 201 202 virtual int32_t importKey(const String16& name, const KeymasterArguments& params, 203 keymaster_key_format_t format, const uint8_t *keyData, 204 size_t keyLength, int uid, int flags, 205 KeyCharacteristics* outCharacteristics) = 0; 206 207 virtual void exportKey(const String16& name, keymaster_key_format_t format, 208 const keymaster_blob_t* clientId, 209 const keymaster_blob_t* appData, ExportResult* result) = 0; 210 211 virtual void begin(const sp<IBinder>& apptoken, const String16& name, 212 keymaster_purpose_t purpose, bool pruneable, 213 const KeymasterArguments& params, const uint8_t* entropy, 214 size_t entropyLength, OperationResult* result) = 0; 215 216 virtual void update(const sp<IBinder>& token, const KeymasterArguments& params, 217 const uint8_t* data, size_t dataLength, OperationResult* result) = 0; 218 219 virtual void finish(const sp<IBinder>& token, const KeymasterArguments& params, 220 const uint8_t* signature, size_t signatureLength, 221 const uint8_t* entropy, size_t entropyLength, 222 OperationResult* result) = 0; 223 224 virtual int32_t abort(const sp<IBinder>& handle) = 0; 225 226 virtual bool isOperationAuthorized(const sp<IBinder>& handle) = 0; 227 228 virtual int32_t addAuthToken(const uint8_t* token, size_t length) = 0; 229 230 virtual int32_t onUserAdded(int32_t userId, int32_t parentId) = 0; 231 232 virtual int32_t onUserRemoved(int32_t userId) = 0; 233 234 }; 235 236 // ---------------------------------------------------------------------------- 237 238 class BnKeystoreService: public BnInterface<IKeystoreService> { 239 public: 240 virtual status_t onTransact(uint32_t code, const Parcel& data, Parcel* reply, 241 uint32_t flags = 0); 242 }; 243 244 } // namespace android 245 246 #endif 247