Refactoring to tpm_tss_quote_info object
[strongswan.git] / src / libtpmtss / tpm_tss.h
1 /*
2 * Copyright (C) 2016 Andreas Steffen
3 * HSR Hochschule fuer Technik Rapperswil
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 /**
17 * @defgroup tpm_tss tpm_tss
18 * @{ @ingroup libtpmtss
19 */
20
21 #ifndef TPM_TSS_H_
22 #define TPM_TSS_H_
23
24 #include "tpm_tss_quote_info.h"
25
26 #include <library.h>
27 #include <crypto/hashers/hasher.h>
28
29 typedef enum tpm_version_t tpm_version_t;
30 typedef struct tpm_tss_t tpm_tss_t;
31
32 /**
33 * TPM Versions
34 */
35 enum tpm_version_t {
36 TPM_VERSION_ANY,
37 TPM_VERSION_1_2,
38 TPM_VERSION_2_0,
39 };
40
41 /**
42 * TPM access via TSS public interface
43 */
44 struct tpm_tss_t {
45
46 /**
47 * Get TPM version supported by TSS
48 *
49 * @return TPM version
50 */
51 tpm_version_t (*get_version)(tpm_tss_t *this);
52
53 /**
54 * Get TPM version info (TPM 1.2 only)
55 *
56 * @return TPM version info struct
57 */
58 chunk_t (*get_version_info)(tpm_tss_t *this);
59
60 /**
61 * Generate AIK key pair bound to TPM (TPM 1.2 only)
62 *
63 * @param ca_modulus RSA modulus of CA public key
64 * @param aik_blob AIK private key blob
65 * @param aik_pubkey AIK public key
66 * @return TRUE if AIK key generation succeeded
67 */
68 bool (*generate_aik)(tpm_tss_t *this, chunk_t ca_modulus,
69 chunk_t *aik_blob, chunk_t *aik_pubkey,
70 chunk_t *identity_req);
71
72 /**
73 * Get public key from TPM using its object handle (TPM 2.0 only)
74 *
75 * @param handle key object handle
76 * @return public key in PKCS#1 format
77 */
78 chunk_t (*get_public)(tpm_tss_t *this, uint32_t handle);
79
80 /**
81 * Retrieve the current value of a PCR register in a given PCR bank
82 *
83 * @param pcr_num PCR number
84 * @param pcr_value PCR value returned
85 * @param alg hash algorithm, selects PCR bank (TPM 2.0 only)
86 * @return TRUE if PCR value retrieval succeeded
87 */
88 bool (*read_pcr)(tpm_tss_t *this, uint32_t pcr_num, chunk_t *pcr_value,
89 hash_algorithm_t alg);
90
91 /**
92 * Extend a PCR register in a given PCR bank with a hash value
93 *
94 * @param pcr_num PCR number
95 * @param pcr_value extended PCR value returned
96 * @param hash data to be extended into the PCR
97 * @param alg hash algorithm, selects PCR bank (TPM 2.0 only)
98 * @return TRUE if PCR extension succeeded
99 */
100 bool (*extend_pcr)(tpm_tss_t *this, uint32_t pcr_num, chunk_t *pcr_value,
101 chunk_t data, hash_algorithm_t alg);
102
103 /**
104 * Do a quote signature over a selection of PCR registers
105 *
106 * @param aik_handle object handle of AIK to be used for quote signature
107 * @param pcr_sel selection of PCR registers
108 * @param alg hash algorithm to be used for quote signature
109 * @param data additional data to be hashed into the quote
110 * @param quote_mode define current and legacy TPM quote modes
111 * @param quote_info returns various info covered by quote signature
112 * @param quote_sig returns quote signature
113 * @return TRUE if quote signature succeeded
114 */
115 bool (*quote)(tpm_tss_t *this, uint32_t aik_handle, uint32_t pcr_sel,
116 hash_algorithm_t alg, chunk_t data,
117 tpm_quote_mode_t *quote_mode,
118 tpm_tss_quote_info_t **quote_info, chunk_t *quote_sig);
119
120 /**
121 * Destroy a tpm_tss_t.
122 */
123 void (*destroy)(tpm_tss_t *this);
124 };
125
126 /**
127 * Create a tpm_tss instance.
128 *
129 * @param version TPM version that must be supported by TSS
130 */
131 tpm_tss_t *tpm_tss_probe(tpm_version_t version);
132
133 #endif /** TPM_TSS_H_ @}*/