commit c39a9af8cea1642e81d8b3892f59b0e7f3046f0d Author: Hong Song Date: Mon Apr 19 14:11:20 2021 +0800 keymaster - MMCEI-9460 - CL#135759 - merged Change-Id: If3094fc70a7e21bcfa0bf2c08a241633ee4cbe5a diff --git a/keymaster/4.0/hal/include/syna_cryptokey.h b/keymaster/4.0/hal/include/syna_cryptokey.h index 1bba939..29f0651 100755 --- a/keymaster/4.0/hal/include/syna_cryptokey.h +++ b/keymaster/4.0/hal/include/syna_cryptokey.h @@ -278,6 +278,8 @@ public: return 0; } + + protected: keymaster_error_t CreateKey(keymaster_key_origin_t key_origin, const keymaster_key_param_set_t* params, @@ -286,10 +288,12 @@ protected: keymaster_key_blob_t* key_blob, keymaster_key_characteristics_t** characteristics); + inline const uint8_t* GetKey() const { return iKey; } + inline int GetKeySizeFromCurve (keymaster_ec_curve_t Curve){ int SzBits = 0; @@ -345,6 +349,10 @@ protected: inline keymaster_error_t SetKeySize(size_t key_size_bits) { keymaster_error_t lRes = SupportedKeySize(key_size_bits); + + LOG_FUNCTION_ENTRY; + + if (lRes == KM_ERROR_OK) { if(iAlgo == KM_ALGORITHM_TRIPLE_DES) { /* @@ -370,6 +378,9 @@ protected: iKeySize += 1; } } + + dbg_log("keysize:%d\n", iKeySize); + LOG_FUNCTION_EXIT(lRes); return lRes; } diff --git a/keymaster/4.0/hal/syna_asymcryptokey.cpp b/keymaster/4.0/hal/syna_asymcryptokey.cpp index acd5f68..f02b925 100755 --- a/keymaster/4.0/hal/syna_asymcryptokey.cpp +++ b/keymaster/4.0/hal/syna_asymcryptokey.cpp @@ -347,6 +347,7 @@ keymaster_error_t RsaKey::SetImportKeySize(size_t /*key_size_bits*/) size_t RsaKey::GetKeyBufferSize() const { //N(iKeySize) + PubExpo(4 bytes) + (P, Q, DP, DQ, QInv) of size iKeySize/2 each + dbg_log("GetKeyBufferSize for RSA:%d\n", iKeySize + sizeof(uint32_t) + 5 * (iKeySize >> 1)); return (iKeySize + sizeof(uint32_t) + 5 * (iKeySize >> 1)); } diff --git a/keymaster/4.0/hal/syna_cryptokey.cpp b/keymaster/4.0/hal/syna_cryptokey.cpp index 7939ee6..f70fa34 100755 --- a/keymaster/4.0/hal/syna_cryptokey.cpp +++ b/keymaster/4.0/hal/syna_cryptokey.cpp @@ -142,15 +142,21 @@ keymaster_error_t CryptoKey::CreateKey(keymaster_key_origin_t key_origin, keymaster_key_characteristics_t** characteristics) { keymaster_error_t lRes = KM_ERROR_OK; + + LOG_FUNCTION_ENTRY; + lRes = ValidateKeyParam(*params); if (lRes == KM_ERROR_OK) { - lRes = SetupKeyBuffer(); + + if(key_origin != KM_ORIGIN_SETUP) lRes = SetupKeyBuffer(); + if (lRes == KM_ERROR_OK) { if (key_origin == KM_ORIGIN_GENERATED) { if (lRes == KM_ERROR_OK) lRes = GenerateSecureKey(); } else if (key_origin == KM_ORIGIN_SETUP) { /*nothing to do*/ + dbg_log("KM_ORIGIN_SETUP\n"); } else if (key_origin == KM_ORIGIN_IMPORTED) { lRes = ImportSecureKey(key_format, key_data); if (lRes == KM_ERROR_OK) { @@ -175,6 +181,9 @@ keymaster_error_t CryptoKey::CreateKey(keymaster_key_origin_t key_origin, if (key_origin == KM_ORIGIN_GENERATED) lRes = KM_ERROR_INVALID_ARGUMENT; } + + LOG_FUNCTION_EXIT(lRes); + return lRes; } @@ -233,6 +242,8 @@ uint32_t CryptoKey::CalcSizeofKeyblob ( uint32_t key_blob_size = KEY_CHKSUM_SIZE+KEY_HANDLE_SIZE+sizeof(keymaster_key_origin_t)+sizeof(params->length); keymaster_key_param_t *pParam = NULL; + LOG_FUNCTION_ENTRY; + if(params->length > 0) { pParam = params->params; for (index = 0; index < params->length; index++) { @@ -269,7 +280,10 @@ uint32_t CryptoKey::CalcSizeofKeyblob ( key_blob_size += sizeof(uint32_t); /*iKeySize*/ key_blob_size += sizeof(uint32_t); /*iKeySizeInBits*/ - key_blob_size += iKeySize; /*iKey*/ + key_blob_size += GetKeyBufferSize(); //iKeySize; /*iKey*/ + + LOG_FUNCTION_EXIT(0); + return key_blob_size; } @@ -288,6 +302,8 @@ keymaster_error_t CryptoKey::StoreParamsToKeyblob ( keymaster_key_param_t *pParam = NULL; + LOG_FUNCTION_ENTRY; + if(!key_blob || !params) { return KM_ERROR_INVALID_ARGUMENT; } @@ -370,8 +386,9 @@ keymaster_error_t CryptoKey::StoreParamsToKeyblob ( memcpy((void *)(key_blob->key_material+offset), &iKeySizeInBits, sizeof(iKeySizeInBits)); offset += sizeof(iKeySizeInBits); /*store iKey*/ - memcpy((void *)(key_blob->key_material+offset), iKey, iKeySize); - offset += iKeySize; + + memcpy((void *)(key_blob->key_material+offset), iKey, GetKeyBufferSize()); + offset += GetKeyBufferSize(); } lRes = iImpl->EncryptKeyData((key_blob->key_material_size - (KEY_HANDLE_SIZE + KEY_CHKSUM_SIZE)), @@ -406,6 +423,7 @@ keymaster_error_t CryptoKey::StoreParamsToKeyblob ( memcpy((void *)(key_blob->key_material), &sum, KEY_CHKSUM_SIZE); } + LOG_FUNCTION_EXIT(lRes); return lRes; } @@ -421,7 +439,11 @@ keymaster_error_t CryptoKey::RetrieveParamsFromKeyblob ( uint32_t offset = 0; uint32_t index = 0; - if(!key_blob && !key_origin && !params && !key_format && !key_data) { + + LOG_FUNCTION_ENTRY; + + + if(!key_blob || !key_origin || !params || !key_format || !key_data) { return KM_ERROR_INVALID_ARGUMENT; } @@ -499,19 +521,31 @@ keymaster_error_t CryptoKey::RetrieveParamsFromKeyblob ( * Let's check if it reach the end of key_blob. * if not, we should be able to Retrieve iKey/iKeySize/iKeySizeInBits */ + if((offset+8) <= key_blob->key_material_size) { memcpy(&iKeySize,key_blob->key_material+offset, sizeof(iKeySize)); offset += sizeof(iKeySize); memcpy(&iKeySizeInBits,key_blob->key_material+offset, sizeof(iKeySizeInBits)); offset += sizeof(iKeySizeInBits); } - if((offset+iKeySize) <= key_blob->key_material_size) { - iKey = (UINT8 *)malloc(iKeySize); - memcpy(iKey, key_blob->key_material+offset, iKeySize); - offset += iKeySize; + + + SetupKeyBuffer(); + size_t uKeyBufSize = GetKeyBufferSize(); + + if((offset+uKeyBufSize) <= key_blob->key_material_size) { + + // iKey = (UINT8 *)malloc(uKeyBufSize); + memcpy(iKey, key_blob->key_material+offset, uKeyBufSize); + offset += uKeyBufSize; + dbg_log("uKeyBufSize:%d\n", uKeyBufSize); + }else{ + + dbg_log("cannot copy to key in %s, %d, %d, %d, %d\n", __FUNCTION__, offset, iKeySize, uKeyBufSize, key_blob->key_material_size); } } + LOG_FUNCTION_EXIT(lRes); return lRes; } @@ -560,21 +594,31 @@ keymaster_error_t CryptoKey::SetupKey( keymaster_key_format_t key_format; internal_keymaster_blob_t key_data; + LOG_FUNCTION_ENTRY; + memset(¶ms, 0x0, sizeof(internal_keymaster_key_param_set_t)); memset(&key_data, 0x0, sizeof(internal_keymaster_blob_t)); lRes = RetrieveParamsFromKeyblob((const keymaster_key_blob_t *)key_blob, &key_origin, ¶ms, &key_format, &key_data); + dbg_log("key_origin:%d\n", key_origin); + //KM_TAG_KEY_SIZE will default to the size of the key provided - SetImportKeySize(key_data.data_length << 3); + if(key_origin == KM_ORIGIN_GENERATED) { key_origin = (keymaster_key_origin_t)KM_ORIGIN_SETUP; + }else if(key_origin == KM_ORIGIN_IMPORTED){ + SetImportKeySize(key_data.data_length << 3); } + lRes = CreateKey(key_origin, (keymaster_key_param_set_t *)¶ms, key_format, (keymaster_blob_t *)&key_data, key_blob, characteristics); + lRes = RecycleParamsMemory(¶ms, &key_data); + LOG_FUNCTION_EXIT(lRes); + return lRes; } @@ -854,14 +898,14 @@ keymaster_error_t CryptoKey::ValidateKeyParam(const keymaster_key_param_set_t& p SetKeyActivationTime(params[index].date_time); break; case KM_TAG_ORIGINATION_EXPIRE_DATETIME: - ALOGD("ValidateKeyParam() params[%d].tag = KM_TAG_ORIGINATION_EXPIRE_DATETIME\n", index); + ALOGD("ValidateKeyParam() params[%d].tag = KM_TAG_ORIGINATION_EXPIRE_DATETIME, %llu\n", index, params[index].date_time); SetKeyOriginationExpireTime(params[index].date_time); break; case KM_TAG_CREATION_DATETIME: ALOGD("ValidateKeyParam() params[%d].tag = KM_TAG_CREATION_DATETIME\n", index); break; case KM_TAG_USAGE_EXPIRE_DATETIME: - ALOGD("ValidateKeyParam() params[%d].tag = KM_TAG_USAGE_EXPIRE_DATETIME\n", index); + ALOGD("ValidateKeyParam() params[%d].tag = KM_TAG_USAGE_EXPIRE_DATETIME, %llu\n", index, params[index].date_time); SetKeyUsageExpireTime(params[index].date_time); break; case KM_TAG_MIN_SECONDS_BETWEEN_OPS: @@ -922,9 +966,11 @@ keymaster_error_t CryptoKey::SetupKeyBuffer() keymaster_error_t lRes = KM_ERROR_UNSUPPORTED_KEY_SIZE; size_t uKeyBufSize = 0; //A valid Key-size must be set by now + LOG_FUNCTION_ENTRY; if (iKeySize > 0) { lRes = KM_ERROR_OK; if (iKey) { + dbg_log("delete key content\n"); delete iKey; iKey = NULL; } @@ -934,6 +980,7 @@ keymaster_error_t CryptoKey::SetupKeyBuffer() lRes = KM_ERROR_MEMORY_ALLOCATION_FAILED; } } + LOG_FUNCTION_EXIT(lRes); return lRes; } diff --git a/keymaster/4.0/hal/syna_km_context.cpp b/keymaster/4.0/hal/syna_km_context.cpp index d8b34d2..b8d4e52 100755 --- a/keymaster/4.0/hal/syna_km_context.cpp +++ b/keymaster/4.0/hal/syna_km_context.cpp @@ -763,17 +763,23 @@ keymaster_error_t SynaKMContext::Begin(keymaster_purpose_t purpose, LOG_FUNCTION_ENTRY //Find the crypto key that corresponds to key blob + LogHex("keyblob:", key->key_material, 16); + CryptoKey* pCryptoKey = iKeyList->Find(key); if (!pCryptoKey) { + dbg_log("no key is found, set up key\n"); lRes = SetupKey((keymaster_key_blob_t*)key, &pCharacteristics); } pCryptoKey = iKeyList->Find(key); if (pCryptoKey) { keymaster_algorithm_t algo = pCryptoKey->GetAlgorithm(); + CryptoOperation* pOp = CryptoOperation::CreateCryptoOperation(algo, purpose, &lRes); + dbg_log("CreateCryptoOperation return lRes = %d\n", lRes); if (pOp) { lRes = pOp->Init(pCryptoKey, in_params, out_params, operation_handle); + dbg_log("Init return lRes = %d\n", lRes); if (lRes == KM_ERROR_OK) { iOperationList->Add(pOp); } else { diff --git a/keymaster/4.0/hal/syna_km_util.cpp b/keymaster/4.0/hal/syna_km_util.cpp index 07ac069..df59239 100755 --- a/keymaster/4.0/hal/syna_km_util.cpp +++ b/keymaster/4.0/hal/syna_km_util.cpp @@ -476,8 +476,11 @@ keymaster_error_t IsValidDigest(keymaster_algorithm_t algo, keymaster_digest_t d //Check whether the given time has lapsed current time bool VerifyTimeLapsed(uint64_t timestamp, uint32_t timeout) { - time_t givenTime = (timestamp + timeout) / 1000; - return difftime(time(NULL), givenTime) > 0; + uint64_t givenTime = (timestamp + (uint64_t) timeout) / 1000; + uint64_t cur_time = (uint64_t) time(NULL); + dbg_log("timestamp[%llu], timeout:%u\n", timestamp, timeout); + dbg_log("giventime[%llu], curtime[%llu]\n", givenTime, cur_time); + return (cur_time > givenTime); } //HMAC Signature verification diff --git a/keymaster/4.0/hal/syna_rsaoperation.cpp b/keymaster/4.0/hal/syna_rsaoperation.cpp index 94e39a2..e83cf94 100755 --- a/keymaster/4.0/hal/syna_rsaoperation.cpp +++ b/keymaster/4.0/hal/syna_rsaoperation.cpp @@ -166,7 +166,13 @@ keymaster_error_t RsaOperation::InitOperation(const uint8_t* pKey, size_t uKeySi { keymaster_error_t lRes = KM_ERROR_OK; uint64_t uPubExpo = iKey->GetPubExponent(); + + LOG_FUNCTION_ENTRY; + lRes = iImpl->InitRsaOperation(iPurpose, iPadding, iDigest, uPubExpo, pKey, uKeySize, &iHandle); + + LOG_FUNCTION_EXIT(lRes); + return lRes; }