| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 1 | /* | 
 | 2 |  * Copyright (c) 2019, The Android Open Source Project | 
 | 3 |  * | 
 | 4 |  * Licensed under the Apache License, Version 2.0 (the "License"); | 
 | 5 |  * you may not use this file except in compliance with the License. | 
 | 6 |  * You may obtain a copy of the License at | 
 | 7 |  * | 
 | 8 |  *     http://www.apache.org/licenses/LICENSE-2.0 | 
 | 9 |  * | 
 | 10 |  * Unless required by applicable law or agreed to in writing, software | 
 | 11 |  * distributed under the License is distributed on an "AS IS" BASIS, | 
 | 12 |  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | 
 | 13 |  * See the License for the specific language governing permissions and | 
 | 14 |  * limitations under the License. | 
 | 15 |  */ | 
 | 16 |  | 
 | 17 | #ifndef SYSTEM_SECURITY_CREDENTIAL_STORE_H_ | 
 | 18 | #define SYSTEM_SECURITY_CREDENTIAL_STORE_H_ | 
 | 19 |  | 
 | 20 | #include <string> | 
 | 21 | #include <vector> | 
 | 22 |  | 
| David Zeuthen | a6f9fba | 2020-02-11 22:08:27 -0500 | [diff] [blame] | 23 | #include <android/hardware/identity/IIdentityCredentialStore.h> | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 24 | #include <android/security/identity/BnCredentialStore.h> | 
| Tri Vo | 3ab6f05 | 2022-11-22 10:26:16 -0800 | [diff] [blame] | 25 |  | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 26 | namespace android { | 
 | 27 | namespace security { | 
 | 28 | namespace identity { | 
 | 29 |  | 
 | 30 | using ::android::sp; | 
 | 31 | using ::android::binder::Status; | 
| David Zeuthen | 045a2c8 | 2021-09-11 13:52:17 -0400 | [diff] [blame] | 32 | using ::std::optional; | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 33 | using ::std::string; | 
 | 34 | using ::std::unique_ptr; | 
 | 35 | using ::std::vector; | 
 | 36 |  | 
| David Zeuthen | a6f9fba | 2020-02-11 22:08:27 -0500 | [diff] [blame] | 37 | using ::android::hardware::identity::HardwareInformation; | 
 | 38 | using ::android::hardware::identity::IIdentityCredentialStore; | 
| David Zeuthen | 045a2c8 | 2021-09-11 13:52:17 -0400 | [diff] [blame] | 39 | using ::android::hardware::identity::IPresentationSession; | 
| Seth Moore | 81db378 | 2022-01-18 15:58:47 -0800 | [diff] [blame] | 40 | using ::android::hardware::identity::IWritableIdentityCredential; | 
| Tri Vo | 3ab6f05 | 2022-11-22 10:26:16 -0800 | [diff] [blame] | 41 | using ::android::hardware::security::keymint::IRemotelyProvisionedComponent; | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 42 |  | 
 | 43 | class CredentialStore : public BnCredentialStore { | 
 | 44 |   public: | 
 | 45 |     CredentialStore(const string& dataPath, sp<IIdentityCredentialStore> hal); | 
 | 46 |     ~CredentialStore(); | 
 | 47 |  | 
 | 48 |     bool init(); | 
 | 49 |  | 
| David Zeuthen | 045a2c8 | 2021-09-11 13:52:17 -0400 | [diff] [blame] | 50 |     // Used by both getCredentialByName() and Session::getCredential() | 
 | 51 |     // | 
 | 52 |     Status getCredentialCommon(const string& credentialName, int32_t cipherSuite, | 
 | 53 |                                sp<IPresentationSession> halSessionBinder, | 
 | 54 |                                sp<ICredential>* _aidl_return); | 
 | 55 |  | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 56 |     // ICredentialStore overrides | 
 | 57 |     Status getSecurityHardwareInfo(SecurityHardwareInfoParcel* _aidl_return) override; | 
 | 58 |  | 
 | 59 |     Status createCredential(const string& credentialName, const string& docType, | 
 | 60 |                             sp<IWritableCredential>* _aidl_return) override; | 
 | 61 |  | 
 | 62 |     Status getCredentialByName(const string& credentialName, int32_t cipherSuite, | 
 | 63 |                                sp<ICredential>* _aidl_return) override; | 
 | 64 |  | 
| David Zeuthen | 045a2c8 | 2021-09-11 13:52:17 -0400 | [diff] [blame] | 65 |     Status createPresentationSession(int32_t cipherSuite, sp<ISession>* _aidl_return) override; | 
 | 66 |  | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 67 |   private: | 
| Seth Moore | 81db378 | 2022-01-18 15:58:47 -0800 | [diff] [blame] | 68 |     Status setRemotelyProvisionedAttestationKey(IWritableIdentityCredential* halWritableCredential); | 
 | 69 |  | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 70 |     string dataPath_; | 
 | 71 |  | 
 | 72 |     sp<IIdentityCredentialStore> hal_; | 
| David Zeuthen | 472e6c8 | 2020-10-16 11:50:13 -0400 | [diff] [blame] | 73 |     int halApiVersion_; | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 74 |  | 
| David Zeuthen | a6f9fba | 2020-02-11 22:08:27 -0500 | [diff] [blame] | 75 |     HardwareInformation hwInfo_; | 
| Tri Vo | 3ab6f05 | 2022-11-22 10:26:16 -0800 | [diff] [blame] | 76 |  | 
| Tri Vo | 3ab6f05 | 2022-11-22 10:26:16 -0800 | [diff] [blame] | 77 |     sp<IRemotelyProvisionedComponent> rpc_; | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 78 | }; | 
 | 79 |  | 
 | 80 | }  // namespace identity | 
 | 81 | }  // namespace security | 
 | 82 | }  // namespace android | 
 | 83 |  | 
 | 84 | #endif  // SYSTEM_SECURITY_CREDENTIAL_STORE_H_ |