Replaced with boolean variable for PCR info included and Evidence Signature included...
[strongswan.git] / src / libpts / tcg / tcg_pts_attr_simple_evid_final.c
1 /*
2 * Copyright (C) 2011 Sansar Choinyambuu
3 * HSR Hochschule fuer Technik Rapperswil
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "tcg_pts_attr_simple_evid_final.h"
17
18 #include <pa_tnc/pa_tnc_msg.h>
19 #include <bio/bio_writer.h>
20 #include <bio/bio_reader.h>
21 #include <debug.h>
22
23 typedef struct private_tcg_pts_attr_simple_evid_final_t private_tcg_pts_attr_simple_evid_final_t;
24
25 /**
26 * Simple Evidence Final
27 * see section 3.15.2 of PTS Protocol: Binding to TNC IF-M Specification
28 *
29 * 1 2 3
30 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
31 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
32 * | Flags | Reserved | Optional Composite Hash Alg |
33 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
34 * | Optional TPM PCR Composite Length |
35 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
36 * ~ Optional TPM PCR Composite (Variable Length) ~
37 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
38 * | Optional TPM Quote Signature Length |
39 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
40 * ~ Optional TPM Quote Signature (Variable Length) ~
41 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
42 * ~ Optional Evidence Signature (Variable Length) ~
43 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
44 */
45
46 #define PTS_SIMPLE_EVID_FINAL_SIZE 2
47 #define PTS_SIMPLE_EVID_FINAL_RESERVED 0x00
48
49 /**
50 * Private data of an tcg_pts_attr_simple_evid_final_t object.
51 */
52 struct private_tcg_pts_attr_simple_evid_final_t {
53
54 /**
55 * Public members of tcg_pts_attr_simple_evid_final_t
56 */
57 tcg_pts_attr_simple_evid_final_t public;
58
59 /**
60 * Attribute vendor ID
61 */
62 pen_t vendor_id;
63
64 /**
65 * Attribute type
66 */
67 u_int32_t type;
68
69 /**
70 * Attribute value
71 */
72 chunk_t value;
73
74 /**
75 * Noskip flag
76 */
77 bool noskip_flag;
78
79 /**
80 * Is Evidence Signature included
81 */
82 bool evid_sign_included;
83
84 /**
85 * Set of flags for Simple Evidence Final
86 */
87 pts_simple_evid_final_flag_t flags;
88
89 /**
90 * Optional Composite Hash Algorithm
91 */
92 pts_meas_algorithms_t comp_hash_algorithm;
93
94 /**
95 * Optional TPM PCR Composite
96 */
97 chunk_t pcr_comp;
98
99 /**
100 * Optional TPM Quote Signature
101 */
102 chunk_t tpm_quote_sign;
103
104 /**
105 * Optional Evidence Signature
106 */
107 chunk_t evid_sign;
108
109 };
110
111 METHOD(pa_tnc_attr_t, get_vendor_id, pen_t,
112 private_tcg_pts_attr_simple_evid_final_t *this)
113 {
114 return this->vendor_id;
115 }
116
117 METHOD(pa_tnc_attr_t, get_type, u_int32_t,
118 private_tcg_pts_attr_simple_evid_final_t *this)
119 {
120 return this->type;
121 }
122
123 METHOD(pa_tnc_attr_t, get_value, chunk_t,
124 private_tcg_pts_attr_simple_evid_final_t *this)
125 {
126 return this->value;
127 }
128
129 METHOD(pa_tnc_attr_t, get_noskip_flag, bool,
130 private_tcg_pts_attr_simple_evid_final_t *this)
131 {
132 return this->noskip_flag;
133 }
134
135 METHOD(pa_tnc_attr_t, set_noskip_flag,void,
136 private_tcg_pts_attr_simple_evid_final_t *this, bool noskip)
137 {
138 this->noskip_flag = noskip;
139 }
140
141 METHOD(pa_tnc_attr_t, build, void,
142 private_tcg_pts_attr_simple_evid_final_t *this)
143 {
144 bio_writer_t *writer;
145 u_int8_t flags = 0;
146
147 writer = bio_writer_create(PTS_SIMPLE_EVID_FINAL_SIZE);
148
149 /* Determine the flags to set*/
150 if (this->flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO)
151 {
152 flags += 64;
153 }
154 else if (this->flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2)
155 {
156 flags += 128;
157 }
158 else if (this->flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2_CAP_VER)
159 {
160 flags += 192;
161 }
162 if (this->evid_sign_included)
163 {
164 flags += 32;
165 }
166
167 writer->write_uint8 (writer, flags);
168 writer->write_uint8 (writer, PTS_SIMPLE_EVID_FINAL_RESERVED);
169
170 /* Optional fields */
171 if (this->comp_hash_algorithm)
172 {
173 writer->write_uint16(writer, this->comp_hash_algorithm);
174 }
175 if (this->pcr_comp.ptr && this->pcr_comp.len > 0)
176 {
177 writer->write_uint32 (writer, this->pcr_comp.len);
178 writer->write_data (writer, this->pcr_comp);
179 }
180 if (this->tpm_quote_sign.ptr && this->tpm_quote_sign.len > 0)
181 {
182 writer->write_uint32 (writer, this->tpm_quote_sign.len);
183 writer->write_data (writer, this->tpm_quote_sign);
184 }
185 if (this->evid_sign.ptr && this->evid_sign.len > 0)
186 {
187 writer->write_data (writer, this->evid_sign);
188 }
189
190 this->value = chunk_clone(writer->get_buf(writer));
191 writer->destroy(writer);
192 }
193
194 METHOD(pa_tnc_attr_t, process, status_t,
195 private_tcg_pts_attr_simple_evid_final_t *this, u_int32_t *offset)
196 {
197 bio_reader_t *reader;
198 u_int8_t flags;
199 u_int8_t reserved;
200 //u_int16_t algorithm;
201
202 if (this->value.len < PTS_SIMPLE_EVID_FINAL_SIZE)
203 {
204 DBG1(DBG_TNC, "insufficient data for Simple Evidence Final");
205 *offset = 0;
206 return FAILED;
207 }
208 reader = bio_reader_create(this->value);
209
210 reader->read_uint8(reader, &flags);
211
212 /* Determine the flags to set*/
213 if (!((flags >> 7) & 1) && !((flags >> 6) & 1))
214 {
215 this->flags = PTS_SIMPLE_EVID_FINAL_FLAG_NO;
216 }
217 else if (!((flags >> 7) & 1) && ((flags >> 6) & 1))
218 {
219 this->flags = PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO;
220 }
221 else if (((flags >> 7) & 1) && !((flags >> 6) & 1))
222 {
223 this->flags = PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2;
224 }
225 else if (((flags >> 7) & 1) && ((flags >> 6) & 1))
226 {
227 this->flags = PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2_CAP_VER;
228 }
229 if ((flags >> 5) & 1)
230 {
231 this->evid_sign_included = TRUE;
232 }
233
234 reader->read_uint8(reader, &reserved);
235
236 /* Optional Composite Hash Algorithm and TPM PCR Composite field is included */
237 if (this->flags != PTS_SIMPLE_EVID_FINAL_FLAG_NO)
238 {
239 u_int32_t pcr_comp_len;
240 u_int32_t tpm_quote_sign_len;
241
242 /** TODO: Ignoring Hashing algorithm field
243 * There is no flag defined which indicates the precense of it
244 * reader->read_uint16(reader, &algorithm);
245 * this->comp_hash_algorithm = algorithm;
246 */
247 reader->read_uint32(reader, &pcr_comp_len);
248 reader->read_data(reader, pcr_comp_len, &this->pcr_comp);
249 this->pcr_comp = chunk_clone(this->pcr_comp);
250 reader->read_uint32(reader, &tpm_quote_sign_len);
251 reader->read_data(reader, tpm_quote_sign_len, &this->tpm_quote_sign);
252 this->tpm_quote_sign = chunk_clone(this->tpm_quote_sign);
253 }
254
255 /* Optional Evidence Signature field is included */
256 if (this->evid_sign_included)
257 {
258 u_int32_t evid_sign_len = reader->remaining(reader);
259 reader->read_data(reader, evid_sign_len, &this->evid_sign);
260 this->evid_sign = chunk_clone(this->evid_sign);
261 }
262
263 reader->destroy(reader);
264 return SUCCESS;
265 }
266
267 METHOD(pa_tnc_attr_t, destroy, void,
268 private_tcg_pts_attr_simple_evid_final_t *this)
269 {
270 free(this->value.ptr);
271 free(this->pcr_comp.ptr);
272 free(this->tpm_quote_sign.ptr);
273 free(this->evid_sign.ptr);
274 free(this);
275 }
276
277 METHOD(tcg_pts_attr_simple_evid_final_t, is_evid_sign_included, bool,
278 private_tcg_pts_attr_simple_evid_final_t *this)
279 {
280 return this->evid_sign_included;
281 }
282
283 METHOD(tcg_pts_attr_simple_evid_final_t, get_flags, pts_simple_evid_final_flag_t,
284 private_tcg_pts_attr_simple_evid_final_t *this)
285 {
286 return this->flags;
287 }
288
289 METHOD(tcg_pts_attr_simple_evid_final_t, get_comp_hash_algorithm, pts_meas_algorithms_t,
290 private_tcg_pts_attr_simple_evid_final_t *this)
291 {
292 return this->comp_hash_algorithm;
293 }
294
295 METHOD(tcg_pts_attr_simple_evid_final_t, get_pcr_comp, chunk_t,
296 private_tcg_pts_attr_simple_evid_final_t *this)
297 {
298 return this->pcr_comp;
299 }
300
301 METHOD(tcg_pts_attr_simple_evid_final_t, get_tpm_quote_sign, chunk_t,
302 private_tcg_pts_attr_simple_evid_final_t *this)
303 {
304 return this->tpm_quote_sign;
305 }
306
307 METHOD(tcg_pts_attr_simple_evid_final_t, get_evid_sign, chunk_t,
308 private_tcg_pts_attr_simple_evid_final_t *this)
309 {
310 return this->evid_sign;
311 }
312
313 /**
314 * Described in header.
315 */
316 pa_tnc_attr_t *tcg_pts_attr_simple_evid_final_create(
317 bool evid_sign_included,
318 pts_simple_evid_final_flag_t flags,
319 pts_meas_algorithms_t comp_hash_algorithm,
320 chunk_t pcr_comp,
321 chunk_t tpm_quote_sign,
322 chunk_t evid_sign)
323 {
324 private_tcg_pts_attr_simple_evid_final_t *this;
325
326 INIT(this,
327 .public = {
328 .pa_tnc_attribute = {
329 .get_vendor_id = _get_vendor_id,
330 .get_type = _get_type,
331 .get_value = _get_value,
332 .get_noskip_flag = _get_noskip_flag,
333 .set_noskip_flag = _set_noskip_flag,
334 .build = _build,
335 .process = _process,
336 .destroy = _destroy,
337 },
338 .is_evid_sign_included = _is_evid_sign_included,
339 .get_flags = _get_flags,
340 .get_comp_hash_algorithm = _get_comp_hash_algorithm,
341 .get_pcr_comp = _get_pcr_comp,
342 .get_tpm_quote_sign = _get_tpm_quote_sign,
343 .get_evid_sign = _get_evid_sign,
344 },
345 .vendor_id = PEN_TCG,
346 .type = TCG_PTS_SIMPLE_EVID_FINAL,
347 .evid_sign_included = evid_sign_included,
348 .flags = flags,
349 .comp_hash_algorithm = comp_hash_algorithm,
350 .pcr_comp = chunk_clone(pcr_comp),
351 .tpm_quote_sign = chunk_clone(tpm_quote_sign),
352 .evid_sign = chunk_clone(evid_sign),
353 );
354
355 return &this->public.pa_tnc_attribute;
356 }
357
358
359 /**
360 * Described in header.
361 */
362 pa_tnc_attr_t *tcg_pts_attr_simple_evid_final_create_from_data(chunk_t data)
363 {
364 private_tcg_pts_attr_simple_evid_final_t *this;
365
366 INIT(this,
367 .public = {
368 .pa_tnc_attribute = {
369 .get_vendor_id = _get_vendor_id,
370 .get_type = _get_type,
371 .get_value = _get_value,
372 .get_noskip_flag = _get_noskip_flag,
373 .set_noskip_flag = _set_noskip_flag,
374 .build = _build,
375 .process = _process,
376 .destroy = _destroy,
377 },
378 .is_evid_sign_included = _is_evid_sign_included,
379 .get_flags= _get_flags,
380 .get_comp_hash_algorithm = _get_comp_hash_algorithm,
381 .get_pcr_comp = _get_pcr_comp,
382 .get_tpm_quote_sign = _get_tpm_quote_sign,
383 .get_evid_sign = _get_evid_sign,
384 },
385 .vendor_id = PEN_TCG,
386 .type = TCG_PTS_SIMPLE_EVID_FINAL,
387 .value = chunk_clone(data),
388 );
389
390 return &this->public.pa_tnc_attribute;
391 }