1*e1997b9aSAndroid Build Coastguard Worker /* 2*e1997b9aSAndroid Build Coastguard Worker * Copyright (c) 2019, The Android Open Source Project 3*e1997b9aSAndroid Build Coastguard Worker * 4*e1997b9aSAndroid Build Coastguard Worker * Licensed under the Apache License, Version 2.0 (the "License"); 5*e1997b9aSAndroid Build Coastguard Worker * you may not use this file except in compliance with the License. 6*e1997b9aSAndroid Build Coastguard Worker * You may obtain a copy of the License at 7*e1997b9aSAndroid Build Coastguard Worker * 8*e1997b9aSAndroid Build Coastguard Worker * http://www.apache.org/licenses/LICENSE-2.0 9*e1997b9aSAndroid Build Coastguard Worker * 10*e1997b9aSAndroid Build Coastguard Worker * Unless required by applicable law or agreed to in writing, software 11*e1997b9aSAndroid Build Coastguard Worker * distributed under the License is distributed on an "AS IS" BASIS, 12*e1997b9aSAndroid Build Coastguard Worker * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13*e1997b9aSAndroid Build Coastguard Worker * See the License for the specific language governing permissions and 14*e1997b9aSAndroid Build Coastguard Worker * limitations under the License. 15*e1997b9aSAndroid Build Coastguard Worker */ 16*e1997b9aSAndroid Build Coastguard Worker 17*e1997b9aSAndroid Build Coastguard Worker #ifndef SYSTEM_SECURITY_CREDENTIAL_STORE_H_ 18*e1997b9aSAndroid Build Coastguard Worker #define SYSTEM_SECURITY_CREDENTIAL_STORE_H_ 19*e1997b9aSAndroid Build Coastguard Worker 20*e1997b9aSAndroid Build Coastguard Worker #include <string> 21*e1997b9aSAndroid Build Coastguard Worker #include <vector> 22*e1997b9aSAndroid Build Coastguard Worker 23*e1997b9aSAndroid Build Coastguard Worker #include <android/hardware/identity/IIdentityCredentialStore.h> 24*e1997b9aSAndroid Build Coastguard Worker #include <android/security/identity/BnCredentialStore.h> 25*e1997b9aSAndroid Build Coastguard Worker 26*e1997b9aSAndroid Build Coastguard Worker namespace android { 27*e1997b9aSAndroid Build Coastguard Worker namespace security { 28*e1997b9aSAndroid Build Coastguard Worker namespace identity { 29*e1997b9aSAndroid Build Coastguard Worker 30*e1997b9aSAndroid Build Coastguard Worker using ::android::sp; 31*e1997b9aSAndroid Build Coastguard Worker using ::android::binder::Status; 32*e1997b9aSAndroid Build Coastguard Worker using ::std::optional; 33*e1997b9aSAndroid Build Coastguard Worker using ::std::string; 34*e1997b9aSAndroid Build Coastguard Worker using ::std::unique_ptr; 35*e1997b9aSAndroid Build Coastguard Worker using ::std::vector; 36*e1997b9aSAndroid Build Coastguard Worker 37*e1997b9aSAndroid Build Coastguard Worker using ::android::hardware::identity::HardwareInformation; 38*e1997b9aSAndroid Build Coastguard Worker using ::android::hardware::identity::IIdentityCredentialStore; 39*e1997b9aSAndroid Build Coastguard Worker using ::android::hardware::identity::IPresentationSession; 40*e1997b9aSAndroid Build Coastguard Worker using ::android::hardware::identity::IWritableIdentityCredential; 41*e1997b9aSAndroid Build Coastguard Worker using ::android::hardware::security::keymint::IRemotelyProvisionedComponent; 42*e1997b9aSAndroid Build Coastguard Worker 43*e1997b9aSAndroid Build Coastguard Worker class CredentialStore : public BnCredentialStore { 44*e1997b9aSAndroid Build Coastguard Worker public: 45*e1997b9aSAndroid Build Coastguard Worker CredentialStore(const string& dataPath, sp<IIdentityCredentialStore> hal); 46*e1997b9aSAndroid Build Coastguard Worker ~CredentialStore(); 47*e1997b9aSAndroid Build Coastguard Worker 48*e1997b9aSAndroid Build Coastguard Worker bool init(); 49*e1997b9aSAndroid Build Coastguard Worker 50*e1997b9aSAndroid Build Coastguard Worker // Used by both getCredentialByName() and Session::getCredential() 51*e1997b9aSAndroid Build Coastguard Worker // 52*e1997b9aSAndroid Build Coastguard Worker Status getCredentialCommon(const string& credentialName, int32_t cipherSuite, 53*e1997b9aSAndroid Build Coastguard Worker sp<IPresentationSession> halSessionBinder, 54*e1997b9aSAndroid Build Coastguard Worker sp<ICredential>* _aidl_return); 55*e1997b9aSAndroid Build Coastguard Worker 56*e1997b9aSAndroid Build Coastguard Worker // ICredentialStore overrides 57*e1997b9aSAndroid Build Coastguard Worker Status getSecurityHardwareInfo(SecurityHardwareInfoParcel* _aidl_return) override; 58*e1997b9aSAndroid Build Coastguard Worker 59*e1997b9aSAndroid Build Coastguard Worker Status createCredential(const string& credentialName, const string& docType, 60*e1997b9aSAndroid Build Coastguard Worker sp<IWritableCredential>* _aidl_return) override; 61*e1997b9aSAndroid Build Coastguard Worker 62*e1997b9aSAndroid Build Coastguard Worker Status getCredentialByName(const string& credentialName, int32_t cipherSuite, 63*e1997b9aSAndroid Build Coastguard Worker sp<ICredential>* _aidl_return) override; 64*e1997b9aSAndroid Build Coastguard Worker 65*e1997b9aSAndroid Build Coastguard Worker Status createPresentationSession(int32_t cipherSuite, sp<ISession>* _aidl_return) override; 66*e1997b9aSAndroid Build Coastguard Worker 67*e1997b9aSAndroid Build Coastguard Worker private: 68*e1997b9aSAndroid Build Coastguard Worker Status setRemotelyProvisionedAttestationKey(IWritableIdentityCredential* halWritableCredential); 69*e1997b9aSAndroid Build Coastguard Worker 70*e1997b9aSAndroid Build Coastguard Worker string dataPath_; 71*e1997b9aSAndroid Build Coastguard Worker 72*e1997b9aSAndroid Build Coastguard Worker sp<IIdentityCredentialStore> hal_; 73*e1997b9aSAndroid Build Coastguard Worker int halApiVersion_; 74*e1997b9aSAndroid Build Coastguard Worker 75*e1997b9aSAndroid Build Coastguard Worker HardwareInformation hwInfo_; 76*e1997b9aSAndroid Build Coastguard Worker 77*e1997b9aSAndroid Build Coastguard Worker sp<IRemotelyProvisionedComponent> rpc_; 78*e1997b9aSAndroid Build Coastguard Worker }; 79*e1997b9aSAndroid Build Coastguard Worker 80*e1997b9aSAndroid Build Coastguard Worker } // namespace identity 81*e1997b9aSAndroid Build Coastguard Worker } // namespace security 82*e1997b9aSAndroid Build Coastguard Worker } // namespace android 83*e1997b9aSAndroid Build Coastguard Worker 84*e1997b9aSAndroid Build Coastguard Worker #endif // SYSTEM_SECURITY_CREDENTIAL_STORE_H_ 85