1 /* 2 * Copyright 2014 The Android Open Source Project 3 * 4 * Licensed under the Apache License, Version 2.0 (the "License"); 5 * you may not use this file except in compliance with the License. 6 * You may obtain a copy of the License at 7 * 8 * http://www.apache.org/licenses/LICENSE-2.0 9 * 10 * Unless required by applicable law or agreed to in writing, software 11 * distributed under the License is distributed on an "AS IS" BASIS, 12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 * See the License for the specific language governing permissions and 14 * limitations under the License. 15 */ 16 17 #ifndef SYSTEM_KEYMASTER_ECDSA_OPERATION_H_ 18 #define SYSTEM_KEYMASTER_ECDSA_OPERATION_H_ 19 20 #include <openssl/ec.h> 21 #include <openssl/evp.h> 22 23 #include <UniquePtr.h> 24 25 #include "operation.h" 26 27 namespace keymaster { 28 29 class EcdsaOperation : public Operation { 30 public: EcdsaOperation(keymaster_purpose_t purpose,keymaster_digest_t digest,EVP_PKEY * key)31 EcdsaOperation(keymaster_purpose_t purpose, keymaster_digest_t digest, EVP_PKEY* key) 32 : Operation(purpose), digest_(digest), ecdsa_key_(key) { 33 EVP_MD_CTX_init(&digest_ctx_); 34 } 35 ~EcdsaOperation(); 36 Abort()37 keymaster_error_t Abort() override { return KM_ERROR_OK; } 38 39 protected: 40 keymaster_error_t StoreData(const Buffer& input, size_t* input_consumed); 41 keymaster_error_t InitDigest(); 42 43 keymaster_digest_t digest_; 44 const EVP_MD* digest_algorithm_; 45 EVP_PKEY* ecdsa_key_; 46 EVP_MD_CTX digest_ctx_; 47 Buffer data_; 48 }; 49 50 class EcdsaSignOperation : public EcdsaOperation { 51 public: EcdsaSignOperation(keymaster_purpose_t purpose,keymaster_digest_t digest,EVP_PKEY * key)52 EcdsaSignOperation(keymaster_purpose_t purpose, keymaster_digest_t digest, EVP_PKEY* key) 53 : EcdsaOperation(purpose, digest, key) {} 54 keymaster_error_t Begin(const AuthorizationSet& input_params, 55 AuthorizationSet* output_params) override; 56 keymaster_error_t Update(const AuthorizationSet& additional_params, const Buffer& input, 57 AuthorizationSet* output_params, Buffer* output, 58 size_t* input_consumed) override; 59 keymaster_error_t Finish(const AuthorizationSet& additional_params, const Buffer& signature, 60 AuthorizationSet* output_params, Buffer* output) override; 61 }; 62 63 class EcdsaVerifyOperation : public EcdsaOperation { 64 public: EcdsaVerifyOperation(keymaster_purpose_t purpose,keymaster_digest_t digest,EVP_PKEY * key)65 EcdsaVerifyOperation(keymaster_purpose_t purpose, keymaster_digest_t digest, EVP_PKEY* key) 66 : EcdsaOperation(purpose, digest, key) {} 67 keymaster_error_t Begin(const AuthorizationSet& input_params, 68 AuthorizationSet* output_params) override; 69 keymaster_error_t Update(const AuthorizationSet& additional_params, const Buffer& input, 70 AuthorizationSet* output_params, Buffer* output, 71 size_t* input_consumed) override; 72 keymaster_error_t Finish(const AuthorizationSet& additional_params, const Buffer& signature, 73 AuthorizationSet* output_params, Buffer* output) override; 74 }; 75 76 class EcdsaOperationFactory : public OperationFactory { 77 private: registry_key()78 KeyType registry_key() const override { return KeyType(KM_ALGORITHM_EC, purpose()); } 79 Operation* CreateOperation(const Key& key, const AuthorizationSet& begin_params, 80 keymaster_error_t* error) override; 81 const keymaster_digest_t* SupportedDigests(size_t* digest_count) const override; 82 83 virtual keymaster_purpose_t purpose() const = 0; 84 virtual Operation* InstantiateOperation(keymaster_digest_t digest, EVP_PKEY* key) = 0; 85 }; 86 87 class EcdsaSignOperationFactory : public EcdsaOperationFactory { 88 private: purpose()89 keymaster_purpose_t purpose() const override { return KM_PURPOSE_SIGN; } InstantiateOperation(keymaster_digest_t digest,EVP_PKEY * key)90 Operation* InstantiateOperation(keymaster_digest_t digest, EVP_PKEY* key) { 91 return new (std::nothrow) EcdsaSignOperation(purpose(), digest, key); 92 } 93 }; 94 95 class EcdsaVerifyOperationFactory : public EcdsaOperationFactory { 96 public: purpose()97 keymaster_purpose_t purpose() const override { return KM_PURPOSE_VERIFY; } InstantiateOperation(keymaster_digest_t digest,EVP_PKEY * key)98 Operation* InstantiateOperation(keymaster_digest_t digest, EVP_PKEY* key) { 99 return new (std::nothrow) EcdsaVerifyOperation(KM_PURPOSE_VERIFY, digest, key); 100 } 101 }; 102 103 } // namespace keymaster 104 105 #endif // SYSTEM_KEYMASTER_ECDSA_OPERATION_H_ 106