blob: 1a9b50829564d28c64340fc075c396f0aac7c96e [file] [log] [blame]
Janis Danisevskisc7a9fa22016-10-13 18:43:45 +01001/*
2 **
3 ** Copyright 2016, The Android Open Source Project
4 **
5 ** Licensed under the Apache License, Version 2.0 (the "License");
6 ** you may not use this file except in compliance with the License.
7 ** You may obtain a copy of the License at
8 **
9 ** http://www.apache.org/licenses/LICENSE-2.0
10 **
11 ** Unless required by applicable law or agreed to in writing, software
12 ** distributed under the License is distributed on an "AS IS" BASIS,
13 ** WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 ** See the License for the specific language governing permissions and
15 ** limitations under the License.
16 */
17
18#define LOG_TAG "android.hardware.keymaster@3.0-impl"
19
20#include "legacy_keymaster_device_wrapper.h"
21
22#include <cutils/log.h>
23
24#include <hardware/keymaster2.h>
25#include <hardware/keymaster_defs.h>
26#include <keymaster/keymaster_configuration.h>
27#include <keymaster/soft_keymaster_device.h>
28
29namespace android {
30namespace keystore {
31
32using ::keymaster::SoftKeymasterDevice;
33
34LegacyKeymasterDeviceWrapper::LegacyKeymasterDeviceWrapper(keymaster2_device_t* dev)
35 : keymaster_device_(dev) {}
36
37LegacyKeymasterDeviceWrapper::~LegacyKeymasterDeviceWrapper() {
38 if (keymaster_device_) keymaster_device_->common.close(&keymaster_device_->common);
39}
40
41static inline keymaster_tag_type_t typeFromTag(const keymaster_tag_t tag) {
42 return keymaster_tag_get_type(tag);
43}
44
45/**
46 * legacy_enum_conversion converts enums from hidl to keymaster and back. Currently, this is just a
47 * cast to make the compiler happy. One of two thigs should happen though:
48 * TODO The keymaster enums should become aliases for the hidl generated enums so that we have a
49 * single point of truth. Then this cast function can go away.
50 */
51inline static keymaster_tag_t legacy_enum_conversion(const Tag value) {
52 return keymaster_tag_t(value);
53}
54inline static Tag legacy_enum_conversion(const keymaster_tag_t value) {
55 return Tag(value);
56}
57inline static keymaster_purpose_t legacy_enum_conversion(const KeyPurpose value) {
58 return keymaster_purpose_t(value);
59}
60inline static keymaster_key_format_t legacy_enum_conversion(const KeyFormat value) {
61 return keymaster_key_format_t(value);
62}
63inline static ErrorCode legacy_enum_conversion(const keymaster_error_t value) {
64 return ErrorCode(value);
65}
66
67class KmParamSet : public keymaster_key_param_set_t {
68 public:
69 KmParamSet(const hidl_vec<KeyParameter>& keyParams) {
70 params = new keymaster_key_param_t[keyParams.size()];
71 length = keyParams.size();
72 for (size_t i = 0; i < keyParams.size(); ++i) {
73 auto tag = legacy_enum_conversion(keyParams[i].tag);
74 switch (typeFromTag(tag)) {
75 case KM_ENUM:
76 case KM_ENUM_REP:
77 params[i] = keymaster_param_enum(tag, keyParams[i].f.integer);
78 break;
79 case KM_UINT:
80 case KM_UINT_REP:
81 params[i] = keymaster_param_int(tag, keyParams[i].f.integer);
82 break;
83 case KM_ULONG:
84 case KM_ULONG_REP:
85 params[i] = keymaster_param_long(tag, keyParams[i].f.longInteger);
86 break;
87 case KM_DATE:
88 params[i] = keymaster_param_date(tag, keyParams[i].f.dateTime);
89 break;
90 case KM_BOOL:
91 if (keyParams[i].f.boolValue)
92 params[i] = keymaster_param_bool(tag);
93 else
94 params[i].tag = KM_TAG_INVALID;
95 break;
96 case KM_BIGNUM:
97 case KM_BYTES:
98 params[i] =
99 keymaster_param_blob(tag, &keyParams[i].blob[0], keyParams[i].blob.size());
100 break;
101 case KM_INVALID:
102 default:
103 params[i].tag = KM_TAG_INVALID;
104 /* just skip */
105 break;
106 }
107 }
108 }
109 KmParamSet(KmParamSet&& other) : keymaster_key_param_set_t{other.params, other.length} {
110 other.length = 0;
111 other.params = nullptr;
112 }
113 KmParamSet(const KmParamSet&) = delete;
114 ~KmParamSet() { delete[] params; }
115};
116
117inline static KmParamSet hidlParams2KmParamSet(const hidl_vec<KeyParameter>& params) {
118 return KmParamSet(params);
119}
120
121inline static keymaster_blob_t hidlVec2KmBlob(const hidl_vec<uint8_t>& blob) {
122 /* hidl unmarshals funny pointers if the the blob is empty */
123 if (blob.size()) return {&blob[0], blob.size()};
124 return {};
125}
126
127inline static keymaster_key_blob_t hidlVec2KmKeyBlob(const hidl_vec<uint8_t>& blob) {
128 /* hidl unmarshals funny pointers if the the blob is empty */
129 if (blob.size()) return {&blob[0], blob.size()};
130 return {};
131}
132
133inline static hidl_vec<uint8_t> kmBlob2hidlVec(const keymaster_key_blob_t& blob) {
134 hidl_vec<uint8_t> result;
135 result.setToExternal(const_cast<unsigned char*>(blob.key_material), blob.key_material_size);
136 return result;
137}
138inline static hidl_vec<uint8_t> kmBlob2hidlVec(const keymaster_blob_t& blob) {
139 hidl_vec<uint8_t> result;
140 result.setToExternal(const_cast<unsigned char*>(blob.data), blob.data_length);
141 return result;
142}
143
144inline static hidl_vec<hidl_vec<uint8_t>>
145kmCertChain2Hidl(const keymaster_cert_chain_t* cert_chain) {
146 hidl_vec<hidl_vec<uint8_t>> result;
147 if (!cert_chain || cert_chain->entry_count == 0 || !cert_chain->entries) return result;
148
149 result.resize(cert_chain->entry_count);
150 for (size_t i = 0; i < cert_chain->entry_count; ++i) {
151 auto& entry = cert_chain->entries[i];
152 result[i] = kmBlob2hidlVec(entry);
153 }
154
155 return result;
156}
157
158static inline hidl_vec<KeyParameter> kmParamSet2Hidl(const keymaster_key_param_set_t& set) {
159 hidl_vec<KeyParameter> result;
160 if (set.length == 0 || set.params == nullptr) return result;
161
162 result.resize(set.length);
163 keymaster_key_param_t* params = set.params;
164 for (size_t i = 0; i < set.length; ++i) {
165 auto tag = params[i].tag;
166 result[i].tag = legacy_enum_conversion(tag);
167 switch (typeFromTag(tag)) {
168 case KM_ENUM:
169 case KM_ENUM_REP:
170 result[i].f.integer = params[i].enumerated;
171 break;
172 case KM_UINT:
173 case KM_UINT_REP:
174 result[i].f.integer = params[i].integer;
175 break;
176 case KM_ULONG:
177 case KM_ULONG_REP:
178 result[i].f.longInteger = params[i].long_integer;
179 break;
180 case KM_DATE:
181 result[i].f.dateTime = params[i].date_time;
182 break;
183 case KM_BOOL:
184 result[i].f.boolValue = params[i].boolean;
185 break;
186 case KM_BIGNUM:
187 case KM_BYTES:
188 result[i].blob.setToExternal(const_cast<unsigned char*>(params[i].blob.data),
189 params[i].blob.data_length);
190 break;
191 case KM_INVALID:
192 default:
193 params[i].tag = KM_TAG_INVALID;
194 /* just skip */
195 break;
196 }
197 }
198 return result;
199}
200
201// Methods from ::android::hardware::keymaster::V3_0::IKeymasterDevice follow.
202Return<void> LegacyKeymasterDeviceWrapper::getHardwareFeatures(getHardwareFeatures_cb _hidl_cb) {
Shawn Willdenb8550a02017-02-23 11:06:05 -0700203 _hidl_cb(false, false, false, false, false, "Fallback Device", "Google Android Security");
Janis Danisevskisc7a9fa22016-10-13 18:43:45 +0100204 return Void();
205}
206
Shawn Willden76f21b22017-02-17 12:29:42 -0700207Return<void>
208LegacyKeymasterDeviceWrapper::parseHardwareAuthToken(const hidl_vec<uint8_t>& /* token */,
209 parseHardwareAuthToken_cb _hidl_cb) {
210 // parseHardwareAuthToken is only called on a real HAL, never on the fallback device.
211 _hidl_cb(ErrorCode::UNIMPLEMENTED, HardwareAuthTokenInfo());
212 return Void();
213}
Janis Danisevskisc7a9fa22016-10-13 18:43:45 +0100214Return<ErrorCode> LegacyKeymasterDeviceWrapper::addRngEntropy(const hidl_vec<uint8_t>& data) {
215 return legacy_enum_conversion(
216 keymaster_device_->add_rng_entropy(keymaster_device_, &data[0], data.size()));
217}
218
219Return<void> LegacyKeymasterDeviceWrapper::generateKey(const hidl_vec<KeyParameter>& keyParams,
220 generateKey_cb _hidl_cb) {
221 // result variables for the wire
222 KeyCharacteristics resultCharacteristics;
223 hidl_vec<uint8_t> resultKeyBlob;
224
225 // result variables the backend understands
226 keymaster_key_blob_t key_blob{nullptr, 0};
227 keymaster_key_characteristics_t key_characteristics{{nullptr, 0}, {nullptr, 0}};
228
229 // convert the parameter set to something our backend understands
230 auto kmParams = hidlParams2KmParamSet(keyParams);
231
232 auto rc = keymaster_device_->generate_key(keymaster_device_, &kmParams, &key_blob,
233 &key_characteristics);
234
235 if (rc == KM_ERROR_OK) {
236 // on success convert the result to wire format
237 resultKeyBlob = kmBlob2hidlVec(key_blob);
238 resultCharacteristics.softwareEnforced = kmParamSet2Hidl(key_characteristics.sw_enforced);
239 resultCharacteristics.teeEnforced = kmParamSet2Hidl(key_characteristics.hw_enforced);
240 }
241
242 // send results off to the client
243 _hidl_cb(legacy_enum_conversion(rc), resultKeyBlob, resultCharacteristics);
244
245 // free buffers that we are responsible for
246 if (key_blob.key_material) free(const_cast<uint8_t*>(key_blob.key_material));
247 keymaster_free_characteristics(&key_characteristics);
248
249 return Void();
250}
251
252Return<void> LegacyKeymasterDeviceWrapper::getKeyCharacteristics(
253 const hidl_vec<uint8_t>& keyBlob, const hidl_vec<uint8_t>& clientId,
254 const hidl_vec<uint8_t>& appData, getKeyCharacteristics_cb _hidl_cb) {
255 // result variables for the wire
256 KeyCharacteristics resultCharacteristics;
257
258 // result variables the backend understands
259 keymaster_key_characteristics_t key_characteristics{{nullptr, 0}, {nullptr, 0}};
260
261 auto kmKeyBlob = hidlVec2KmKeyBlob(keyBlob);
262 auto kmClientId = hidlVec2KmBlob(clientId);
263 auto kmAppData = hidlVec2KmBlob(appData);
264
265 auto rc = keymaster_device_->get_key_characteristics(
266 keymaster_device_, keyBlob.size() ? &kmKeyBlob : nullptr,
267 clientId.size() ? &kmClientId : nullptr, appData.size() ? &kmAppData : nullptr,
268 &key_characteristics);
269
270 if (rc == KM_ERROR_OK) {
271 resultCharacteristics.softwareEnforced = kmParamSet2Hidl(key_characteristics.sw_enforced);
272 resultCharacteristics.teeEnforced = kmParamSet2Hidl(key_characteristics.hw_enforced);
273 }
274
275 _hidl_cb(legacy_enum_conversion(rc), resultCharacteristics);
276
277 keymaster_free_characteristics(&key_characteristics);
278
279 return Void();
280}
281
282Return<void> LegacyKeymasterDeviceWrapper::importKey(const hidl_vec<KeyParameter>& params,
283 KeyFormat keyFormat,
284 const hidl_vec<uint8_t>& keyData,
285 importKey_cb _hidl_cb) {
286 // result variables for the wire
287 KeyCharacteristics resultCharacteristics;
288 hidl_vec<uint8_t> resultKeyBlob;
289
290 // result variables the backend understands
291 keymaster_key_blob_t key_blob{nullptr, 0};
292 keymaster_key_characteristics_t key_characteristics{{nullptr, 0}, {nullptr, 0}};
293
294 auto kmParams = hidlParams2KmParamSet(params);
295 auto kmKeyData = hidlVec2KmBlob(keyData);
296
297 auto rc = keymaster_device_->import_key(keymaster_device_, &kmParams,
298 legacy_enum_conversion(keyFormat), &kmKeyData,
299 &key_blob, &key_characteristics);
300
301 if (rc == KM_ERROR_OK) {
302 // on success convert the result to wire format
303 resultKeyBlob = kmBlob2hidlVec(key_blob);
304 resultCharacteristics.softwareEnforced = kmParamSet2Hidl(key_characteristics.sw_enforced);
305 resultCharacteristics.teeEnforced = kmParamSet2Hidl(key_characteristics.hw_enforced);
306 }
307
308 _hidl_cb(legacy_enum_conversion(rc), resultKeyBlob, resultCharacteristics);
309
310 // free buffers that we are responsible for
311 if (key_blob.key_material) free(const_cast<uint8_t*>(key_blob.key_material));
312 keymaster_free_characteristics(&key_characteristics);
313
314 return Void();
315}
316
317Return<void> LegacyKeymasterDeviceWrapper::exportKey(KeyFormat exportFormat,
318 const hidl_vec<uint8_t>& keyBlob,
319 const hidl_vec<uint8_t>& clientId,
320 const hidl_vec<uint8_t>& appData,
321 exportKey_cb _hidl_cb) {
322
323 // result variables for the wire
324 hidl_vec<uint8_t> resultKeyBlob;
325
326 // result variables the backend understands
327 keymaster_blob_t out_blob = {};
328
329 auto kmKeyBlob = hidlVec2KmKeyBlob(keyBlob);
330 auto kmClientId = hidlVec2KmBlob(clientId);
331 auto kmAppData = hidlVec2KmBlob(appData);
332
333 auto rc = keymaster_device_->export_key(keymaster_device_, legacy_enum_conversion(exportFormat),
334 keyBlob.size() ? &kmKeyBlob : nullptr,
335 clientId.size() ? &kmClientId : nullptr,
336 appData.size() ? &kmAppData : nullptr, &out_blob);
337
338 if (rc == KM_ERROR_OK) {
339 // on success convert the result to wire format
340 // (Can we assume that key_blob is {nullptr, 0} or a valid buffer description?)
341 resultKeyBlob = kmBlob2hidlVec(out_blob);
342 }
343
344 _hidl_cb(legacy_enum_conversion(rc), resultKeyBlob);
345
346 // free buffers that we are responsible for
347 if (out_blob.data) free(const_cast<uint8_t*>(out_blob.data));
348
349 return Void();
350}
351
352Return<void> LegacyKeymasterDeviceWrapper::attestKey(const hidl_vec<uint8_t>& keyToAttest,
353 const hidl_vec<KeyParameter>& attestParams,
354 attestKey_cb _hidl_cb) {
355
356 hidl_vec<hidl_vec<uint8_t>> resultCertChain;
357
Bartosz Fabianowskia9452d92017-01-23 22:21:11 +0100358 for (size_t i = 0; i < attestParams.size(); ++i) {
359 switch (attestParams[i].tag) {
360 case Tag::ATTESTATION_ID_BRAND:
361 case Tag::ATTESTATION_ID_DEVICE:
362 case Tag::ATTESTATION_ID_PRODUCT:
363 case Tag::ATTESTATION_ID_SERIAL:
364 case Tag::ATTESTATION_ID_IMEI:
365 case Tag::ATTESTATION_ID_MEID:
Bartosz Fabianowski634a1aa2017-03-20 14:02:32 +0100366 case Tag::ATTESTATION_ID_MANUFACTURER:
367 case Tag::ATTESTATION_ID_MODEL:
Bartosz Fabianowskia9452d92017-01-23 22:21:11 +0100368 // Device id attestation may only be supported if the device is able to permanently
369 // destroy its knowledge of the ids. This device is unable to do this, so it must
370 // never perform any device id attestation.
371 _hidl_cb(ErrorCode::CANNOT_ATTEST_IDS, resultCertChain);
372 return Void();
373 default:
374 break;
375 }
376 }
377
Janis Danisevskisc7a9fa22016-10-13 18:43:45 +0100378 keymaster_cert_chain_t cert_chain = {};
379
380 auto kmKeyToAttest = hidlVec2KmKeyBlob(keyToAttest);
381 auto kmAttestParams = hidlParams2KmParamSet(attestParams);
382
383 auto rc = keymaster_device_->attest_key(keymaster_device_, &kmKeyToAttest, &kmAttestParams,
384 &cert_chain);
385
386 if (rc == KM_ERROR_OK) {
387 resultCertChain = kmCertChain2Hidl(&cert_chain);
388 }
389
390 _hidl_cb(legacy_enum_conversion(rc), resultCertChain);
391
392 keymaster_free_cert_chain(&cert_chain);
393
394 return Void();
395}
396
397Return<void> LegacyKeymasterDeviceWrapper::upgradeKey(const hidl_vec<uint8_t>& keyBlobToUpgrade,
398 const hidl_vec<KeyParameter>& upgradeParams,
399 upgradeKey_cb _hidl_cb) {
400
401 // result variables for the wire
402 hidl_vec<uint8_t> resultKeyBlob;
403
404 // result variables the backend understands
405 keymaster_key_blob_t key_blob = {};
406
407 auto kmKeyBlobToUpgrade = hidlVec2KmKeyBlob(keyBlobToUpgrade);
408 auto kmUpgradeParams = hidlParams2KmParamSet(upgradeParams);
409
410 auto rc = keymaster_device_->upgrade_key(keymaster_device_, &kmKeyBlobToUpgrade,
411 &kmUpgradeParams, &key_blob);
412
413 if (rc == KM_ERROR_OK) {
414 // on success convert the result to wire format
415 resultKeyBlob = kmBlob2hidlVec(key_blob);
416 }
417
418 _hidl_cb(legacy_enum_conversion(rc), resultKeyBlob);
419
420 if (key_blob.key_material) free(const_cast<uint8_t*>(key_blob.key_material));
421
422 return Void();
423}
424
425Return<ErrorCode> LegacyKeymasterDeviceWrapper::deleteKey(const hidl_vec<uint8_t>& keyBlob) {
426 auto kmKeyBlob = hidlVec2KmKeyBlob(keyBlob);
427 return legacy_enum_conversion(keymaster_device_->delete_key(keymaster_device_, &kmKeyBlob));
428}
429
430Return<ErrorCode> LegacyKeymasterDeviceWrapper::deleteAllKeys() {
431 return legacy_enum_conversion(keymaster_device_->delete_all_keys(keymaster_device_));
432}
433
Bartosz Fabianowskia9452d92017-01-23 22:21:11 +0100434Return<ErrorCode> LegacyKeymasterDeviceWrapper::destroyAttestationIds() {
435 return ErrorCode::UNIMPLEMENTED;
436}
437
Janis Danisevskisc7a9fa22016-10-13 18:43:45 +0100438Return<void> LegacyKeymasterDeviceWrapper::begin(KeyPurpose purpose, const hidl_vec<uint8_t>& key,
439 const hidl_vec<KeyParameter>& inParams,
440 begin_cb _hidl_cb) {
441
442 // result variables for the wire
443 hidl_vec<KeyParameter> resultParams;
444 uint64_t resultOpHandle = 0;
445
446 // result variables the backend understands
447 keymaster_key_param_set_t out_params{nullptr, 0};
448 keymaster_operation_handle_t& operation_handle = resultOpHandle;
449
450 auto kmKey = hidlVec2KmKeyBlob(key);
451 auto kmInParams = hidlParams2KmParamSet(inParams);
452
453 auto rc = keymaster_device_->begin(keymaster_device_, legacy_enum_conversion(purpose), &kmKey,
454 &kmInParams, &out_params, &operation_handle);
455
456 if (rc == KM_ERROR_OK) resultParams = kmParamSet2Hidl(out_params);
457
458 _hidl_cb(legacy_enum_conversion(rc), resultParams, resultOpHandle);
459
460 keymaster_free_param_set(&out_params);
461
462 return Void();
463}
464
465Return<void> LegacyKeymasterDeviceWrapper::update(uint64_t operationHandle,
466 const hidl_vec<KeyParameter>& inParams,
467 const hidl_vec<uint8_t>& input,
468 update_cb _hidl_cb) {
469 // result variables for the wire
470 uint32_t resultConsumed = 0;
471 hidl_vec<KeyParameter> resultParams;
472 hidl_vec<uint8_t> resultBlob;
473
474 // result variables the backend understands
475 size_t consumed = 0;
476 keymaster_key_param_set_t out_params = {};
477 keymaster_blob_t out_blob = {};
478
479 auto kmInParams = hidlParams2KmParamSet(inParams);
480 auto kmInput = hidlVec2KmBlob(input);
481
482 auto rc = keymaster_device_->update(keymaster_device_, operationHandle, &kmInParams, &kmInput,
483 &consumed, &out_params, &out_blob);
484
485 if (rc == KM_ERROR_OK) {
486 resultConsumed = consumed;
487 resultParams = kmParamSet2Hidl(out_params);
488 resultBlob = kmBlob2hidlVec(out_blob);
489 }
490
491 _hidl_cb(legacy_enum_conversion(rc), resultConsumed, resultParams, resultBlob);
492
493 keymaster_free_param_set(&out_params);
494 if (out_blob.data) free(const_cast<uint8_t*>(out_blob.data));
495
496 return Void();
497}
498
499Return<void> LegacyKeymasterDeviceWrapper::finish(uint64_t operationHandle,
500 const hidl_vec<KeyParameter>& inParams,
501 const hidl_vec<uint8_t>& input,
502 const hidl_vec<uint8_t>& signature,
503 finish_cb _hidl_cb) {
504 // result variables for the wire
505 hidl_vec<KeyParameter> resultParams;
506 hidl_vec<uint8_t> resultBlob;
507
508 // result variables the backend understands
509 keymaster_key_param_set_t out_params = {};
510 keymaster_blob_t out_blob = {};
511
512 auto kmInParams = hidlParams2KmParamSet(inParams);
513 auto kmInput = hidlVec2KmBlob(input);
514 auto kmSignature = hidlVec2KmBlob(signature);
515
516 auto rc = keymaster_device_->finish(keymaster_device_, operationHandle, &kmInParams, &kmInput,
517 &kmSignature, &out_params, &out_blob);
518
519 if (rc == KM_ERROR_OK) {
520 resultParams = kmParamSet2Hidl(out_params);
521 resultBlob = kmBlob2hidlVec(out_blob);
522 }
523
524 _hidl_cb(legacy_enum_conversion(rc), resultParams, resultBlob);
525
526 keymaster_free_param_set(&out_params);
527 if (out_blob.data) free(const_cast<uint8_t*>(out_blob.data));
528
529 return Void();
530}
531
532Return<ErrorCode> LegacyKeymasterDeviceWrapper::abort(uint64_t operationHandle) {
533 return legacy_enum_conversion(keymaster_device_->abort(keymaster_device_, operationHandle));
534}
535
536sp<IKeymasterDevice> makeSoftwareKeymasterDevice() {
537 keymaster2_device_t* dev = nullptr;
538 dev = (new SoftKeymasterDevice)->keymaster2_device();
539
540 auto kmrc = ::keymaster::ConfigureDevice(dev);
541 if (kmrc != KM_ERROR_OK) {
542 dev->common.close(&dev->common);
543 return nullptr;
544 }
545
546 return new LegacyKeymasterDeviceWrapper(dev);
547}
548
549} // namespace keystore
550} // namespace android