refactored PTS measurement algorithms
[strongswan.git] / src / libimcv / tcg / tcg_pts_attr_simple_evid_final.c
1 /*
2 * Copyright (C) 2011 Sansar Choinyambuu
3 * HSR Hochschule fuer Technik Rapperswil
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "tcg_pts_attr_simple_evid_final.h"
17
18 #include <pa_tnc/pa_tnc_msg.h>
19 #include <bio/bio_writer.h>
20 #include <bio/bio_reader.h>
21 #include <debug.h>
22
23 typedef struct private_tcg_pts_attr_simple_evid_final_t private_tcg_pts_attr_simple_evid_final_t;
24
25 /**
26 * Simple Evidence Final
27 * see section 3.15.2 of PTS Protocol: Binding to TNC IF-M Specification
28 *
29 * 1 2 3
30 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
31 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
32 * | Flags | Reserved | Optional Composite Hash Alg |
33 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
34 * | Optional TPM PCR Composite Length |
35 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
36 * ~ Optional TPM PCR Composite (Variable Length) ~
37 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
38 * | Optional TPM Quote Signature Length |
39 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
40 * ~ Optional TPM Quote Signature (Variable Length) ~
41 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
42 * ~ Optional Evidence Signature (Variable Length) ~
43 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
44 */
45
46 #define PTS_SIMPLE_EVID_FINAL_SIZE 4
47 #define PTS_SIMPLE_EVID_FINAL_RESERVED 0x00
48
49 /**
50 * Private data of an tcg_pts_attr_simple_evid_final_t object.
51 */
52 struct private_tcg_pts_attr_simple_evid_final_t {
53
54 /**
55 * Public members of tcg_pts_attr_simple_evid_final_t
56 */
57 tcg_pts_attr_simple_evid_final_t public;
58
59 /**
60 * Attribute vendor ID
61 */
62 pen_t vendor_id;
63
64 /**
65 * Attribute type
66 */
67 u_int32_t type;
68
69 /**
70 * Attribute value
71 */
72 chunk_t value;
73
74 /**
75 * Noskip flag
76 */
77 bool noskip_flag;
78
79 /**
80 * Set of flags for Simple Evidence Final
81 */
82 pts_simple_evid_final_flag_t flags;
83
84 /**
85 * Optional Composite Hash Algorithm
86 */
87 pts_meas_algorithms_t comp_hash_algorithm;
88
89 /**
90 * Optional TPM PCR Composite
91 */
92 chunk_t pcr_comp;
93
94 /**
95 * Optional TPM Quote Signature
96 */
97 chunk_t tpm_quote_sign;
98
99 /**
100 * Optional Evidence Signature
101 */
102 chunk_t evid_sign;
103
104 };
105
106 METHOD(pa_tnc_attr_t, get_vendor_id, pen_t,
107 private_tcg_pts_attr_simple_evid_final_t *this)
108 {
109 return this->vendor_id;
110 }
111
112 METHOD(pa_tnc_attr_t, get_type, u_int32_t,
113 private_tcg_pts_attr_simple_evid_final_t *this)
114 {
115 return this->type;
116 }
117
118 METHOD(pa_tnc_attr_t, get_value, chunk_t,
119 private_tcg_pts_attr_simple_evid_final_t *this)
120 {
121 return this->value;
122 }
123
124 METHOD(pa_tnc_attr_t, get_noskip_flag, bool,
125 private_tcg_pts_attr_simple_evid_final_t *this)
126 {
127 return this->noskip_flag;
128 }
129
130 METHOD(pa_tnc_attr_t, set_noskip_flag,void,
131 private_tcg_pts_attr_simple_evid_final_t *this, bool noskip)
132 {
133 this->noskip_flag = noskip;
134 }
135
136 METHOD(pa_tnc_attr_t, build, void,
137 private_tcg_pts_attr_simple_evid_final_t *this)
138 {
139 bio_writer_t *writer;
140 u_int8_t flags = 0;
141
142 writer = bio_writer_create(PTS_SIMPLE_EVID_FINAL_SIZE);
143
144 /* Determine the flags to set*/
145 if (this->flags & PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO)
146 {
147 flags += 64;
148 }
149 else if (this->flags & PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2)
150 {
151 flags += 128;
152 }
153 else if (this->flags & PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2_CAP_VER)
154 {
155 flags += 192;
156 }
157 if (this->flags & PTS_SIMPLE_EVID_FINAL_FLAG_EVID)
158 {
159 flags += 32;
160 }
161 writer->write_uint8 (writer, flags);
162 writer->write_uint8 (writer, PTS_SIMPLE_EVID_FINAL_RESERVED);
163 writer->write_uint16(writer, this->comp_hash_algorithm);
164
165 /* Optional fields */
166 if (this->pcr_comp.ptr && this->pcr_comp.len > 0)
167 {
168 writer->write_uint32 (writer, this->pcr_comp.len);
169 writer->write_data (writer, this->pcr_comp);
170 }
171 if (this->tpm_quote_sign.ptr && this->tpm_quote_sign.len > 0)
172 {
173 writer->write_uint32 (writer, this->tpm_quote_sign.len);
174 writer->write_data (writer, this->tpm_quote_sign);
175 }
176 if (this->evid_sign.ptr && this->evid_sign.len > 0)
177 {
178 writer->write_data (writer, this->evid_sign);
179 }
180
181 this->value = chunk_clone(writer->get_buf(writer));
182 writer->destroy(writer);
183 }
184
185 METHOD(pa_tnc_attr_t, process, status_t,
186 private_tcg_pts_attr_simple_evid_final_t *this, u_int32_t *offset)
187 {
188 bio_reader_t *reader;
189 u_int8_t flags;
190 u_int8_t reserved;
191 u_int16_t algorithm;
192
193 if (this->value.len < PTS_SIMPLE_EVID_FINAL_SIZE)
194 {
195 DBG1(DBG_TNC, "insufficient data for Simple Evidence Final");
196 *offset = 0;
197 return FAILED;
198 }
199 reader = bio_reader_create(this->value);
200
201 reader->read_uint8(reader, &flags);
202
203 /* Determine the flags to set*/
204 if (!((flags >> 7) & 1) && !((flags >> 6) & 1))
205 {
206 this->flags |= PTS_SIMPLE_EVID_FINAL_FLAG_NO;
207 }
208 else if (!((flags >> 7) & 1) && ((flags >> 6) & 1))
209 {
210 this->flags |= PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO;
211 }
212 else if (((flags >> 7) & 1) && !((flags >> 6) & 1))
213 {
214 this->flags |= PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2;
215 }
216 else if (((flags >> 7) & 1) && ((flags >> 6) & 1))
217 {
218 this->flags |= PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2_CAP_VER;
219 }
220 if ((flags >> 5) & 1)
221 {
222 this->flags |= PTS_SIMPLE_EVID_FINAL_FLAG_EVID;
223 }
224
225 reader->read_uint8(reader, &reserved);
226 reader->read_uint16(reader, &algorithm);
227 this->comp_hash_algorithm = algorithm;
228
229 /* Optional TPM PCR Composite field is included */
230 if (!(this->flags & PTS_SIMPLE_EVID_FINAL_FLAG_NO))
231 {
232 u_int32_t pcr_comp_len;
233 u_int32_t tpm_quote_sign_len;
234 reader->read_uint32(reader, &pcr_comp_len);
235 reader->read_data(reader, pcr_comp_len, &this->pcr_comp);
236 reader->read_uint32(reader, &tpm_quote_sign_len);
237 reader->read_data(reader, tpm_quote_sign_len, &this->tpm_quote_sign);
238 }
239
240 /* Optional Evidence Signature field is included */
241 if (this->flags & PTS_SIMPLE_EVID_FINAL_FLAG_EVID)
242 {
243 u_int32_t evid_sign_len = reader->remaining(reader);
244 reader->read_data(reader, evid_sign_len, &this->evid_sign);
245 }
246
247 reader->destroy(reader);
248 return SUCCESS;
249 }
250
251 METHOD(pa_tnc_attr_t, destroy, void,
252 private_tcg_pts_attr_simple_evid_final_t *this)
253 {
254 free(this->value.ptr);
255 free(this->pcr_comp.ptr);
256 free(this->tpm_quote_sign.ptr);
257 free(this->evid_sign.ptr);
258 free(this);
259 }
260
261 METHOD(tcg_pts_attr_simple_evid_final_t, get_flags, pts_simple_evid_final_flag_t,
262 private_tcg_pts_attr_simple_evid_final_t *this)
263 {
264 return this->flags;
265 }
266
267 METHOD(tcg_pts_attr_simple_evid_final_t, set_flags, void,
268 private_tcg_pts_attr_simple_evid_final_t *this, pts_simple_evid_final_flag_t flags)
269 {
270 this->flags = flags;
271 }
272
273 METHOD(tcg_pts_attr_simple_evid_final_t, get_comp_hash_algorithm, pts_meas_algorithms_t,
274 private_tcg_pts_attr_simple_evid_final_t *this)
275 {
276 return this->comp_hash_algorithm;
277 }
278
279 METHOD(tcg_pts_attr_simple_evid_final_t, set_comp_hash_algorithm, void,
280 private_tcg_pts_attr_simple_evid_final_t *this, pts_meas_algorithms_t comp_hash_algorithm)
281 {
282 this->comp_hash_algorithm = comp_hash_algorithm;
283 }
284
285 METHOD(tcg_pts_attr_simple_evid_final_t, get_comp_pcr_len, u_int32_t,
286 private_tcg_pts_attr_simple_evid_final_t *this)
287 {
288 if (this->pcr_comp.ptr && this->pcr_comp.len > 0)
289 {
290 return this->pcr_comp.len;
291 }
292 return 0;
293 }
294
295 METHOD(tcg_pts_attr_simple_evid_final_t, get_pcr_comp, chunk_t,
296 private_tcg_pts_attr_simple_evid_final_t *this)
297 {
298 return this->pcr_comp;
299 }
300
301 METHOD(tcg_pts_attr_simple_evid_final_t, set_pcr_comp, void,
302 private_tcg_pts_attr_simple_evid_final_t *this, chunk_t pcr_comp)
303 {
304 this->pcr_comp = pcr_comp;
305 }
306
307 METHOD(tcg_pts_attr_simple_evid_final_t, get_tpm_quote_sign_len, u_int32_t,
308 private_tcg_pts_attr_simple_evid_final_t *this)
309 {
310 if (this->tpm_quote_sign.ptr && this->tpm_quote_sign.len > 0)
311 {
312 return this->tpm_quote_sign.len;
313 }
314 return 0;
315 }
316
317 METHOD(tcg_pts_attr_simple_evid_final_t, get_tpm_quote_sign, chunk_t,
318 private_tcg_pts_attr_simple_evid_final_t *this)
319 {
320 return this->tpm_quote_sign;
321 }
322
323 METHOD(tcg_pts_attr_simple_evid_final_t, set_tpm_quote_sign, void,
324 private_tcg_pts_attr_simple_evid_final_t *this, chunk_t tpm_quote_sign)
325 {
326 this->tpm_quote_sign = tpm_quote_sign;
327 }
328
329 METHOD(tcg_pts_attr_simple_evid_final_t, get_evid_sign, chunk_t,
330 private_tcg_pts_attr_simple_evid_final_t *this)
331 {
332 return this->evid_sign;
333 }
334
335 METHOD(tcg_pts_attr_simple_evid_final_t, set_evid_sign, void,
336 private_tcg_pts_attr_simple_evid_final_t *this, chunk_t evid_sign)
337 {
338 this->evid_sign = evid_sign;
339 }
340
341 /**
342 * Described in header.
343 */
344 pa_tnc_attr_t *tcg_pts_attr_simple_evid_final_create(
345 pts_simple_evid_final_flag_t flags,
346 pts_meas_algorithms_t comp_hash_algorithm,
347 chunk_t pcr_comp,
348 chunk_t tpm_quote_sign,
349 chunk_t evid_sign)
350 {
351 private_tcg_pts_attr_simple_evid_final_t *this;
352
353 INIT(this,
354 .public = {
355 .pa_tnc_attribute = {
356 .get_vendor_id = _get_vendor_id,
357 .get_type = _get_type,
358 .get_value = _get_value,
359 .get_noskip_flag = _get_noskip_flag,
360 .set_noskip_flag = _set_noskip_flag,
361 .build = _build,
362 .process = _process,
363 .destroy = _destroy,
364 },
365 .get_flags= _get_flags,
366 .set_flags= _set_flags,
367 .get_comp_hash_algorithm = _get_comp_hash_algorithm,
368 .set_comp_hash_algorithm = _set_comp_hash_algorithm,
369 .get_comp_pcr_len = _get_comp_pcr_len,
370 .get_pcr_comp = _get_pcr_comp,
371 .set_pcr_comp = _set_pcr_comp,
372 .get_tpm_quote_sign_len = _get_tpm_quote_sign_len,
373 .get_tpm_quote_sign = _get_tpm_quote_sign,
374 .set_tpm_quote_sign = _set_tpm_quote_sign,
375 .get_evid_sign = _get_evid_sign,
376 .set_evid_sign = _set_evid_sign,
377 },
378 .vendor_id = PEN_TCG,
379 .type = TCG_PTS_SIMPLE_EVID_FINAL,
380 .flags = flags,
381 .comp_hash_algorithm = comp_hash_algorithm,
382 .pcr_comp = pcr_comp,
383 .tpm_quote_sign = tpm_quote_sign,
384 .evid_sign = evid_sign,
385 );
386
387 return &this->public.pa_tnc_attribute;
388 }
389
390
391 /**
392 * Described in header.
393 */
394 pa_tnc_attr_t *tcg_pts_attr_simple_evid_final_create_from_data(chunk_t data)
395 {
396 private_tcg_pts_attr_simple_evid_final_t *this;
397
398 INIT(this,
399 .public = {
400 .pa_tnc_attribute = {
401 .get_vendor_id = _get_vendor_id,
402 .get_type = _get_type,
403 .get_value = _get_value,
404 .get_noskip_flag = _get_noskip_flag,
405 .set_noskip_flag = _set_noskip_flag,
406 .build = _build,
407 .process = _process,
408 .destroy = _destroy,
409 },
410 .get_flags= _get_flags,
411 .set_flags= _set_flags,
412 .get_comp_hash_algorithm = _get_comp_hash_algorithm,
413 .set_comp_hash_algorithm = _set_comp_hash_algorithm,
414 .get_comp_pcr_len = _get_comp_pcr_len,
415 .get_pcr_comp = _get_pcr_comp,
416 .set_pcr_comp = _set_pcr_comp,
417 .get_tpm_quote_sign_len = _get_tpm_quote_sign_len,
418 .get_tpm_quote_sign = _get_tpm_quote_sign,
419 .set_tpm_quote_sign = _set_tpm_quote_sign,
420 .get_evid_sign = _get_evid_sign,
421 .set_evid_sign = _set_evid_sign,
422 },
423 .vendor_id = PEN_TCG,
424 .type = TCG_PTS_SIMPLE_EVID_FINAL,
425 .value = chunk_clone(data),
426 );
427
428 return &this->public.pa_tnc_attribute;
429 }