/* * Copyright 2021, The Android Open Source Project * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. */ /****************************************************************************** * * The original Work has been changed by NXP. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. * * Copyright 2022-2023 NXP * ******************************************************************************/ #pragma once #include #include #include #include #include #include #include "CborConverter.h" #include "JavacardSecureElement.h" namespace aidl::android::hardware::security::keymint { using ::keymint::javacard::CborConverter; using ::keymint::javacard::JavacardSecureElement; using ndk::ScopedAStatus; using std::shared_ptr; class JavacardRemotelyProvisionedComponentDevice : public BnRemotelyProvisionedComponent { public: explicit JavacardRemotelyProvisionedComponentDevice(shared_ptr card) : card_(std::move(card)) {} virtual ~JavacardRemotelyProvisionedComponentDevice() = default; ScopedAStatus getHardwareInfo(RpcHardwareInfo* info) override; ScopedAStatus generateEcdsaP256KeyPair(bool testMode, MacedPublicKey* macedPublicKey, std::vector* privateKeyHandle) override; ScopedAStatus generateCertificateRequest(bool testMode, const std::vector& keysToSign, const std::vector& endpointEncCertChain, const std::vector& challenge, DeviceInfo* deviceInfo, ProtectedData* protectedData, std::vector* keysToSignMac) override; ScopedAStatus generateCertificateRequestV2(const std::vector& keysToSign, const std::vector& challenge, std::vector* csr) override; // Methods from ::ndk::ICInterface follow. binder_status_t dump(int fd, const char** args, uint32_t num_args) override; private: ScopedAStatus beginSendData(const std::vector& keysToSign, const std::vector& challenge, DeviceInfo* deviceInfo, uint32_t* version, std::string* certificateType); ScopedAStatus updateMacedKey(const std::vector& keysToSign, cppbor::Array& coseKeys); ScopedAStatus finishSendData(std::vector& coseEncryptProtectedHeader, std::vector& signature, uint32_t& version, uint32_t& respFlag); ScopedAStatus getDiceCertChain(std::vector& diceCertChain); ScopedAStatus getUdsCertsChain(std::vector& udsCertsChain); std::shared_ptr card_; CborConverter cbor_; }; } // namespace aidl::android::hardware::security::keymint