| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 1 | /* | 
|  | 2 | * Copyright (c) 2019, The Android Open Source Project | 
|  | 3 | * | 
|  | 4 | * Licensed under the Apache License, Version 2.0 (the "License"); | 
|  | 5 | * you may not use this file except in compliance with the License. | 
|  | 6 | * You may obtain a copy of the License at | 
|  | 7 | * | 
|  | 8 | *     http://www.apache.org/licenses/LICENSE-2.0 | 
|  | 9 | * | 
|  | 10 | * Unless required by applicable law or agreed to in writing, software | 
|  | 11 | * distributed under the License is distributed on an "AS IS" BASIS, | 
|  | 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | 
|  | 13 | * See the License for the specific language governing permissions and | 
|  | 14 | * limitations under the License. | 
|  | 15 | */ | 
|  | 16 |  | 
|  | 17 | #ifndef SYSTEM_SECURITY_CREDENTIAL_STORE_H_ | 
|  | 18 | #define SYSTEM_SECURITY_CREDENTIAL_STORE_H_ | 
|  | 19 |  | 
|  | 20 | #include <string> | 
|  | 21 | #include <vector> | 
|  | 22 |  | 
| David Zeuthen | a6f9fba | 2020-02-11 22:08:27 -0500 | [diff] [blame] | 23 | #include <android/hardware/identity/IIdentityCredentialStore.h> | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 24 | #include <android/security/identity/BnCredentialStore.h> | 
| Tri Vo | 3ab6f05 | 2022-11-22 10:26:16 -0800 | [diff] [blame] | 25 |  | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 26 | namespace android { | 
|  | 27 | namespace security { | 
|  | 28 | namespace identity { | 
|  | 29 |  | 
|  | 30 | using ::android::sp; | 
|  | 31 | using ::android::binder::Status; | 
| David Zeuthen | 045a2c8 | 2021-09-11 13:52:17 -0400 | [diff] [blame] | 32 | using ::std::optional; | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 33 | using ::std::string; | 
|  | 34 | using ::std::unique_ptr; | 
|  | 35 | using ::std::vector; | 
|  | 36 |  | 
| David Zeuthen | a6f9fba | 2020-02-11 22:08:27 -0500 | [diff] [blame] | 37 | using ::android::hardware::identity::HardwareInformation; | 
|  | 38 | using ::android::hardware::identity::IIdentityCredentialStore; | 
| David Zeuthen | 045a2c8 | 2021-09-11 13:52:17 -0400 | [diff] [blame] | 39 | using ::android::hardware::identity::IPresentationSession; | 
| Seth Moore | 81db378 | 2022-01-18 15:58:47 -0800 | [diff] [blame] | 40 | using ::android::hardware::identity::IWritableIdentityCredential; | 
| Tri Vo | 3ab6f05 | 2022-11-22 10:26:16 -0800 | [diff] [blame] | 41 | using ::android::hardware::security::keymint::IRemotelyProvisionedComponent; | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 42 |  | 
|  | 43 | class CredentialStore : public BnCredentialStore { | 
|  | 44 | public: | 
|  | 45 | CredentialStore(const string& dataPath, sp<IIdentityCredentialStore> hal); | 
|  | 46 | ~CredentialStore(); | 
|  | 47 |  | 
|  | 48 | bool init(); | 
|  | 49 |  | 
| David Zeuthen | 045a2c8 | 2021-09-11 13:52:17 -0400 | [diff] [blame] | 50 | // Used by both getCredentialByName() and Session::getCredential() | 
|  | 51 | // | 
|  | 52 | Status getCredentialCommon(const string& credentialName, int32_t cipherSuite, | 
|  | 53 | sp<IPresentationSession> halSessionBinder, | 
|  | 54 | sp<ICredential>* _aidl_return); | 
|  | 55 |  | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 56 | // ICredentialStore overrides | 
|  | 57 | Status getSecurityHardwareInfo(SecurityHardwareInfoParcel* _aidl_return) override; | 
|  | 58 |  | 
|  | 59 | Status createCredential(const string& credentialName, const string& docType, | 
|  | 60 | sp<IWritableCredential>* _aidl_return) override; | 
|  | 61 |  | 
|  | 62 | Status getCredentialByName(const string& credentialName, int32_t cipherSuite, | 
|  | 63 | sp<ICredential>* _aidl_return) override; | 
|  | 64 |  | 
| David Zeuthen | 045a2c8 | 2021-09-11 13:52:17 -0400 | [diff] [blame] | 65 | Status createPresentationSession(int32_t cipherSuite, sp<ISession>* _aidl_return) override; | 
|  | 66 |  | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 67 | private: | 
| Seth Moore | 81db378 | 2022-01-18 15:58:47 -0800 | [diff] [blame] | 68 | Status setRemotelyProvisionedAttestationKey(IWritableIdentityCredential* halWritableCredential); | 
|  | 69 |  | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 70 | string dataPath_; | 
|  | 71 |  | 
|  | 72 | sp<IIdentityCredentialStore> hal_; | 
| David Zeuthen | 472e6c8 | 2020-10-16 11:50:13 -0400 | [diff] [blame] | 73 | int halApiVersion_; | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 74 |  | 
| David Zeuthen | a6f9fba | 2020-02-11 22:08:27 -0500 | [diff] [blame] | 75 | HardwareInformation hwInfo_; | 
| Tri Vo | 3ab6f05 | 2022-11-22 10:26:16 -0800 | [diff] [blame] | 76 |  | 
| Tri Vo | 3ab6f05 | 2022-11-22 10:26:16 -0800 | [diff] [blame] | 77 | sp<IRemotelyProvisionedComponent> rpc_; | 
| David Zeuthen | ab3e565 | 2019-10-28 13:32:48 -0400 | [diff] [blame] | 78 | }; | 
|  | 79 |  | 
|  | 80 | }  // namespace identity | 
|  | 81 | }  // namespace security | 
|  | 82 | }  // namespace android | 
|  | 83 |  | 
|  | 84 | #endif  // SYSTEM_SECURITY_CREDENTIAL_STORE_H_ |