1 /* 2 * Copyright (C) 2016 The Android Open Source Project 3 * 4 * Licensed under the Apache License, Version 2.0 (the "License"); 5 * you may not use this file except in compliance with the License. 6 * You may obtain a copy of the License at 7 * 8 * http://www.apache.org/licenses/LICENSE-2.0 9 * 10 * Unless required by applicable law or agreed to in writing, software 11 * distributed under the License is distributed on an "AS IS" BASIS, 12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 * See the License for the specific language governing permissions and 14 * limitations under the License. 15 */ 16 17 #ifndef ANDROID_VOLD_KEYSTORAGE_H 18 #define ANDROID_VOLD_KEYSTORAGE_H 19 20 #include <string> 21 22 namespace android { 23 namespace vold { 24 25 // Represents the information needed to decrypt a disk encryption key. 26 // If "token" is nonempty, it is passed in as a required Gatekeeper auth token. 27 // If "token" and "secret" are nonempty, "secret" is appended to the application-specific 28 // binary needed to unlock. 29 // If only "secret" is nonempty, it is used to decrypt in a non-Keymaster process. 30 class KeyAuthentication { 31 public: KeyAuthentication(std::string t,std::string s)32 KeyAuthentication(std::string t, std::string s) : token{t}, secret{s} {}; 33 usesKeymaster()34 bool usesKeymaster() const { return !token.empty() || secret.empty(); }; 35 36 const std::string token; 37 const std::string secret; 38 }; 39 40 extern const KeyAuthentication kEmptyAuthentication; 41 42 // Create a directory at the named path, and store "key" in it, 43 // in such a way that it can only be retrieved via Keymaster and 44 // can be securely deleted. 45 // It's safe to move/rename the directory after creation. 46 bool storeKey(const std::string& dir, const KeyAuthentication& auth, const std::string& key); 47 48 // Retrieve the key from the named directory. 49 bool retrieveKey(const std::string& dir, const KeyAuthentication& auth, std::string* key); 50 51 // Securely destroy the key stored in the named directory and delete the directory. 52 bool destroyKey(const std::string& dir); 53 54 bool runSecdiscardSingle(const std::string& file); 55 } // namespace vold 56 } // namespace android 57 58 #endif 59