1 /* 2 * Copyright 2014 The Android Open Source Project 3 * 4 * Licensed under the Apache License, Version 2.0 (the "License"); 5 * you may not use this file except in compliance with the License. 6 * You may obtain a copy of the License at 7 * 8 * http://www.apache.org/licenses/LICENSE-2.0 9 * 10 * Unless required by applicable law or agreed to in writing, software 11 * distributed under the License is distributed on an "AS IS" BASIS, 12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 * See the License for the specific language governing permissions and 14 * limitations under the License. 15 */ 16 17 #ifndef SYSTEM_KEYMASTER_ECDSA_OPERATION_H_ 18 #define SYSTEM_KEYMASTER_ECDSA_OPERATION_H_ 19 20 #include <openssl/ec.h> 21 #include <openssl/evp.h> 22 23 #include <UniquePtr.h> 24 25 #include "operation.h" 26 27 namespace keymaster { 28 29 class EcdsaOperation : public Operation { 30 public: EcdsaOperation(keymaster_purpose_t purpose,keymaster_digest_t digest,EVP_PKEY * key)31 EcdsaOperation(keymaster_purpose_t purpose, keymaster_digest_t digest, EVP_PKEY* key) 32 : Operation(purpose), digest_(digest), ecdsa_key_(key) { 33 EVP_MD_CTX_init(&digest_ctx_); 34 } 35 ~EcdsaOperation(); 36 Abort()37 keymaster_error_t Abort() override { return KM_ERROR_OK; } 38 39 protected: 40 keymaster_error_t StoreData(const Buffer& input, size_t* input_consumed); 41 keymaster_error_t InitDigest(); 42 43 keymaster_digest_t digest_; 44 const EVP_MD* digest_algorithm_; 45 EVP_PKEY* ecdsa_key_; 46 EVP_MD_CTX digest_ctx_; 47 Buffer data_; 48 }; 49 50 class EcdsaSignOperation : public EcdsaOperation { 51 public: EcdsaSignOperation(keymaster_digest_t digest,EVP_PKEY * key)52 EcdsaSignOperation(keymaster_digest_t digest, EVP_PKEY* key) 53 : EcdsaOperation(KM_PURPOSE_SIGN, digest, key) {} 54 keymaster_error_t Begin(const AuthorizationSet& input_params, 55 AuthorizationSet* output_params) override; 56 keymaster_error_t Update(const AuthorizationSet& additional_params, const Buffer& input, 57 AuthorizationSet* output_params, Buffer* output, 58 size_t* input_consumed) override; 59 keymaster_error_t Finish(const AuthorizationSet& additional_params, const Buffer& input, 60 const Buffer& signature, AuthorizationSet* output_params, 61 Buffer* output) override; 62 }; 63 64 class EcdsaVerifyOperation : public EcdsaOperation { 65 public: EcdsaVerifyOperation(keymaster_digest_t digest,EVP_PKEY * key)66 EcdsaVerifyOperation(keymaster_digest_t digest, EVP_PKEY* key) 67 : EcdsaOperation(KM_PURPOSE_VERIFY, digest, key) {} 68 keymaster_error_t Begin(const AuthorizationSet& input_params, 69 AuthorizationSet* output_params) override; 70 keymaster_error_t Update(const AuthorizationSet& additional_params, const Buffer& input, 71 AuthorizationSet* output_params, Buffer* output, 72 size_t* input_consumed) override; 73 keymaster_error_t Finish(const AuthorizationSet& additional_params, const Buffer& input, 74 const Buffer& signature, AuthorizationSet* output_params, 75 Buffer* output) override; 76 }; 77 78 class EcdsaOperationFactory : public OperationFactory { 79 private: registry_key()80 KeyType registry_key() const override { return KeyType(KM_ALGORITHM_EC, purpose()); } 81 Operation* CreateOperation(const Key& key, const AuthorizationSet& begin_params, 82 keymaster_error_t* error) override; 83 const keymaster_digest_t* SupportedDigests(size_t* digest_count) const override; 84 85 virtual keymaster_purpose_t purpose() const = 0; 86 virtual Operation* InstantiateOperation(keymaster_digest_t digest, EVP_PKEY* key) = 0; 87 }; 88 89 class EcdsaSignOperationFactory : public EcdsaOperationFactory { 90 private: purpose()91 keymaster_purpose_t purpose() const override { return KM_PURPOSE_SIGN; } InstantiateOperation(keymaster_digest_t digest,EVP_PKEY * key)92 Operation* InstantiateOperation(keymaster_digest_t digest, EVP_PKEY* key) { 93 return new (std::nothrow) EcdsaSignOperation(digest, key); 94 } 95 }; 96 97 class EcdsaVerifyOperationFactory : public EcdsaOperationFactory { 98 public: purpose()99 keymaster_purpose_t purpose() const override { return KM_PURPOSE_VERIFY; } InstantiateOperation(keymaster_digest_t digest,EVP_PKEY * key)100 Operation* InstantiateOperation(keymaster_digest_t digest, EVP_PKEY* key) { 101 return new (std::nothrow) EcdsaVerifyOperation(digest, key); 102 } 103 }; 104 105 } // namespace keymaster 106 107 #endif // SYSTEM_KEYMASTER_ECDSA_OPERATION_H_ 108