Added a EAP-SIM/AKA backend reading triplets/quintuplets from a SQL database
[strongswan.git] / src / libcharon / plugins / eap_simaka_sql / eap_simaka_sql_card.c
1 /*
2 * Copyright (C) 2010 Martin Willi
3 * Copyright (C) 2010 revosec AG
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "eap_simaka_sql_card.h"
17
18 #include <time.h>
19
20 #include <daemon.h>
21
22 typedef struct private_eap_simaka_sql_card_t private_eap_simaka_sql_card_t;
23
24 /**
25 * Private data of an eap_simaka_sql_card_t object.
26 */
27 struct private_eap_simaka_sql_card_t {
28
29 /**
30 * Public eap_simaka_sql_card_t interface.
31 */
32 eap_simaka_sql_card_t public;
33
34 /**
35 * Triplet/quintuplet database
36 */
37 database_t *db;
38
39 /**
40 * Remove used triplets/quintuplets from database
41 */
42 bool remove_used;
43 };
44
45 METHOD(sim_card_t, get_triplet, bool,
46 private_eap_simaka_sql_card_t *this, identification_t *id,
47 char rand[SIM_RAND_LEN], char sres[SIM_SRES_LEN], char kc[SIM_KC_LEN])
48 {
49 chunk_t sres_chunk, kc_chunk;
50 enumerator_t *query;
51 bool found = FALSE;
52 char buf[128];
53
54 snprintf(buf, sizeof(buf), "%Y", id);
55 query = this->db->query(this->db,
56 "select sres, kc from triplets where rand = ? and id = ? "
57 "order by use limit 1",
58 DB_BLOB, chunk_create(rand, SIM_RAND_LEN), DB_TEXT, buf,
59 DB_BLOB, DB_BLOB);
60 if (query)
61 {
62 if (query->enumerate(query, &sres_chunk, &kc_chunk))
63 {
64 if (sres_chunk.len == SIM_SRES_LEN &&
65 kc_chunk.len == SIM_KC_LEN)
66 {
67 memcpy(sres, sres_chunk.ptr, SIM_SRES_LEN);
68 memcpy(kc, kc_chunk.ptr, SIM_KC_LEN);
69 found = TRUE;
70 }
71 }
72 query->destroy(query);
73 }
74 if (found)
75 {
76 if (this->remove_used)
77 {
78 this->db->execute(this->db, NULL,
79 "delete from triplets where id = ? and rand = ?",
80 DB_TEXT, buf, DB_BLOB, chunk_create(rand, SIM_RAND_LEN));
81 }
82 else
83 {
84 this->db->execute(this->db, NULL,
85 "update triplets set use = ? where id = ? and rand = ?",
86 DB_UINT, time(NULL), DB_TEXT, buf,
87 DB_BLOB, chunk_create(rand, SIM_RAND_LEN));
88 }
89 }
90 return found;
91 }
92
93 METHOD(sim_card_t, get_quintuplet, status_t,
94 private_eap_simaka_sql_card_t *this, identification_t *id,
95 char rand[AKA_RAND_LEN], char autn[AKA_AUTN_LEN], char ck[AKA_CK_LEN],
96 char ik[AKA_IK_LEN], char res[AKA_RES_MAX], int *res_len)
97 {
98 chunk_t ck_chunk, ik_chunk, res_chunk;
99 enumerator_t *query;
100 status_t found = FAILED;
101 char buf[128];
102
103 snprintf(buf, sizeof(buf), "%Y", id);
104 query = this->db->query(this->db, "select ck, ik, res from quintuplets "
105 "where rand = ? and autn = ? and id = ? order by use limit 1",
106 DB_BLOB, chunk_create(rand, AKA_RAND_LEN),
107 DB_BLOB, chunk_create(autn, AKA_AUTN_LEN), DB_TEXT, buf,
108 DB_BLOB, DB_BLOB, DB_BLOB);
109 if (query)
110 {
111 if (query->enumerate(query, &ck_chunk, &ik_chunk, &res_chunk))
112 {
113 if (ck_chunk.len == AKA_CK_LEN &&
114 ik_chunk.len == AKA_IK_LEN &&
115 res_chunk.len <= AKA_RES_MAX)
116 {
117 memcpy(ck, ck_chunk.ptr, AKA_CK_LEN);
118 memcpy(ik, ik_chunk.ptr, AKA_IK_LEN);
119 memcpy(res, res_chunk.ptr, res_chunk.len);
120 *res_len = res_chunk.len;
121 found = SUCCESS;
122 }
123 }
124 query->destroy(query);
125 }
126 if (found == SUCCESS)
127 {
128 if (this->remove_used)
129 {
130 this->db->execute(this->db, NULL,
131 "delete from quintuplets where id = ? and rand = ?",
132 DB_TEXT, buf, DB_BLOB, chunk_create(rand, SIM_RAND_LEN));
133 }
134 else
135 {
136 this->db->execute(this->db, NULL,
137 "update quintuplets set use = ? where id = ? and rand = ?",
138 DB_UINT, time(NULL), DB_TEXT, buf,
139 DB_BLOB, chunk_create(rand, AKA_RAND_LEN));
140 }
141 }
142 return found;
143 }
144
145 METHOD(eap_simaka_sql_card_t, destroy, void,
146 private_eap_simaka_sql_card_t *this)
147 {
148 free(this);
149 }
150
151 /**
152 * See header
153 */
154 eap_simaka_sql_card_t *eap_simaka_sql_card_create(database_t *db,
155 bool remove_used)
156 {
157 private_eap_simaka_sql_card_t *this;
158
159 INIT(this,
160 .public = {
161 .card = {
162 .get_triplet = _get_triplet,
163 .get_quintuplet = _get_quintuplet,
164 .resync = (void*)return_false,
165 .get_pseudonym = (void*)return_null,
166 .set_pseudonym = (void*)nop,
167 .get_reauth = (void*)return_null,
168 .set_reauth = (void*)nop,
169 },
170 .destroy = _destroy,
171 },
172 .db = db,
173 .remove_used = remove_used,
174 );
175
176 return &this->public;
177 }