tpm.hpp
Go to the documentation of this file.
1 /* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
2 /*
3  * Copyright (c) 2013-2020 Regents of the University of California.
4  *
5  * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
6  *
7  * ndn-cxx library is free software: you can redistribute it and/or modify it under the
8  * terms of the GNU Lesser General Public License as published by the Free Software
9  * Foundation, either version 3 of the License, or (at your option) any later version.
10  *
11  * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
12  * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13  * PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
14  *
15  * You should have received copies of the GNU General Public License and GNU Lesser
16  * General Public License along with ndn-cxx, e.g., in COPYING.md file. If not, see
17  * <http://www.gnu.org/licenses/>.
18  *
19  * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
20  */
21 
22 #ifndef NDN_SECURITY_TPM_TPM_HPP
23 #define NDN_SECURITY_TPM_TPM_HPP
24 
25 #include "ndn-cxx/name.hpp"
28 
29 #include <unordered_map>
30 #include <boost/logic/tribool.hpp>
31 
32 namespace ndn {
33 namespace security {
34 
35 namespace transform {
36 class PrivateKey;
37 } // namespace transform
38 
39 inline namespace v2 {
40 class KeyChain;
41 } // inline namespace v2
42 
43 namespace tpm {
44 
45 class BackEnd;
46 
65 class Tpm : noncopyable
66 {
67 public:
68  class Error : public std::runtime_error
69  {
70  public:
71  using std::runtime_error::runtime_error;
72  };
73 
74  ~Tpm();
75 
76  std::string
77  getTpmLocator() const;
78 
85  bool
86  hasKey(const Name& keyName) const;
87 
95  getPublicKey(const Name& keyName) const;
96 
104  sign(const InputBuffers& bufs, const Name& keyName, DigestAlgorithm digestAlgorithm) const;
105 
112  sign(const uint8_t* buf, size_t size, const Name& keyName, DigestAlgorithm digestAlgorithm) const
113  {
114  return sign({{buf, size}}, keyName, digestAlgorithm);
115  }
116 
125  boost::logic::tribool
126  verify(const InputBuffers& bufs, const uint8_t* sig, size_t sigLen, const Name& keyName,
127  DigestAlgorithm digestAlgorithm) const;
128 
136  boost::logic::tribool
137  verify(const uint8_t* buf, size_t bufLen, const uint8_t* sig, size_t sigLen,
138  const Name& keyName, DigestAlgorithm digestAlgorithm) const
139  {
140  return verify({{buf, bufLen}}, sig, sigLen, keyName, digestAlgorithm);
141  }
142 
149  decrypt(const uint8_t* buf, size_t size, const Name& keyName) const;
150 
151 public: // Management
155  bool
156  isTerminalMode() const;
157 
163  void
164  setTerminalMode(bool isTerminal) const;
165 
169  bool
170  isTpmLocked() const;
171 
178  NDN_CXX_NODISCARD bool
179  unlockTpm(const char* password, size_t passwordLength) const;
180 
189  Tpm(const std::string& scheme, const std::string& location, unique_ptr<BackEnd> impl);
190 
201  Name
202  createKey(const Name& identityName, const KeyParams& params);
203 
207  void
208  deleteKey(const Name& keyName);
209 
222  exportPrivateKey(const Name& keyName, const char* pw, size_t pwLen) const;
223 
234  void
235  importPrivateKey(const Name& keyName, const uint8_t* pkcs8, size_t pkcs8Len,
236  const char* pw, size_t pwLen);
237 
241  void
242  importPrivateKey(const Name& keyName, shared_ptr<transform::PrivateKey> key);
243 
249  void
250  clearKeyCache()
251  {
252  m_keys.clear();
253  }
254 
255 private:
261  const KeyHandle*
262  findKey(const Name& keyName) const;
263 
264 private:
265  std::string m_scheme;
266  std::string m_location;
267 
268  mutable std::unordered_map<Name, unique_ptr<KeyHandle>> m_keys;
269 
270  const unique_ptr<BackEnd> m_backEnd;
271 
272  friend class v2::KeyChain;
273 };
274 
275 } // namespace tpm
276 
277 using tpm::Tpm;
278 
279 } // namespace security
280 } // namespace ndn
281 
282 #endif // NDN_SECURITY_TPM_TPM_HPP
ConstBufferPtr sign(const uint8_t *buf, size_t size, const Name &keyName, DigestAlgorithm digestAlgorithm) const
Sign blob using the key with name keyName and using the digest digestAlgorithm.
Definition: tpm.hpp:112
Definition: data.cpp:26
The interface of signing key management.
Definition: key-chain.hpp:45
Abstraction of TPM key handle.
Definition: key-handle.hpp:37
TPM front-end class.
Definition: tpm.hpp:65
size_t sigLen
boost::logic::tribool verify(const uint8_t *buf, size_t bufLen, const uint8_t *sig, size_t sigLen, const Name &keyName, DigestAlgorithm digestAlgorithm) const
Verify blob using the key with name keyName and using the digest digestAlgorithm. ...
Definition: tpm.hpp:137
#define NDN_CXX_NODISCARD
Definition: backports.hpp:68
const uint8_t * sig
#define NDN_CXX_PUBLIC_WITH_TESTS_ELSE_PRIVATE
Definition: common.hpp:48
Abstraction of private key in crypto transformation.
Definition: private-key.hpp:38
Represents an absolute name.
Definition: name.hpp:44
Base class for key parameters.
Definition: key-params.hpp:35
InputBuffers bufs
shared_ptr< const Buffer > ConstBufferPtr
Definition: buffer.hpp:126