tpm.hpp
Go to the documentation of this file.
1 /* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
2 /*
3  * Copyright (c) 2013-2024 Regents of the University of California.
4  *
5  * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
6  *
7  * ndn-cxx library is free software: you can redistribute it and/or modify it under the
8  * terms of the GNU Lesser General Public License as published by the Free Software
9  * Foundation, either version 3 of the License, or (at your option) any later version.
10  *
11  * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
12  * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13  * PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
14  *
15  * You should have received copies of the GNU General Public License and GNU Lesser
16  * General Public License along with ndn-cxx, e.g., in COPYING.md file. If not, see
17  * <http://www.gnu.org/licenses/>.
18  *
19  * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
20  */
21 
22 #ifndef NDN_CXX_SECURITY_TPM_TPM_HPP
23 #define NDN_CXX_SECURITY_TPM_TPM_HPP
24 
25 #include "ndn-cxx/name.hpp"
28 
29 #include <unordered_map>
30 #include <boost/logic/tribool.hpp>
31 
32 namespace ndn::security {
33 
34 namespace transform {
35 class PrivateKey;
36 } // namespace transform
37 
38 class KeyChain;
39 
40 namespace tpm {
41 
42 class BackEnd;
43 
62 class Tpm : noncopyable
63 {
64 public:
65  class Error : public std::runtime_error
66  {
67  public:
68  using std::runtime_error::runtime_error;
69  };
70 
71  ~Tpm();
72 
76  const std::string&
77  getTpmLocator() const
78  {
79  return m_locator;
80  }
81 
88  bool
89  hasKey(const Name& keyName) const;
90 
98  getPublicKey(const Name& keyName) const;
99 
107  sign(const InputBuffers& bufs, const Name& keyName, DigestAlgorithm digestAlgorithm) const;
108 
117  [[nodiscard]] boost::logic::tribool
118  verify(const InputBuffers& bufs, span<const uint8_t> sig, const Name& keyName,
119  DigestAlgorithm digestAlgorithm) const;
120 
127  decrypt(span<const uint8_t> buf, const Name& keyName) const;
128 
129 public: // Management
134  [[deprecated]]
135  bool
136  isTerminalMode() const;
137 
144  [[deprecated]]
145  void
146  setTerminalMode(bool isTerminal) const;
147 
152  [[deprecated]]
153  bool
154  isTpmLocked() const;
155 
163  [[deprecated]]
164  [[nodiscard]] bool
165  unlockTpm(const char* password, size_t passwordLength) const;
166 
167 NDN_CXX_PUBLIC_WITH_TESTS_ELSE_PRIVATE: // operations accessible only by KeyChain
174  Tpm(const std::string& locator, unique_ptr<BackEnd> impl);
175 
186  Name
187  createKey(const Name& identityName, const KeyParams& params);
188 
192  void
193  deleteKey(const Name& keyName);
194 
208  exportPrivateKey(const Name& keyName, const char* pw, size_t pwLen) const;
209 
222  void
223  importPrivateKey(const Name& keyName, span<const uint8_t> pkcs8, const char* pw, size_t pwLen);
224 
228  void
229  importPrivateKey(const Name& keyName, shared_ptr<transform::PrivateKey> key);
230 
236  void
237  clearKeyCache()
238  {
239  m_keys.clear();
240  }
241 
242 private:
248  const KeyHandle*
249  findKey(const Name& keyName) const;
250 
251 private:
252  const std::string m_locator;
253  const unique_ptr<BackEnd> m_backEnd;
254 
255  mutable std::unordered_map<Name, unique_ptr<KeyHandle>> m_keys;
256 
257  friend KeyChain;
258 };
259 
260 } // namespace tpm
261 
262 using tpm::Tpm;
263 
264 } // namespace ndn::security
265 
266 #endif // NDN_CXX_SECURITY_TPM_TPM_HPP
Base class for key parameters.
Definition: key-params.hpp:36
Represents an absolute name.
Definition: name.hpp:45
The main interface for signing key management.
Definition: key-chain.hpp:87
TPM front-end class.
Definition: tpm.hpp:63
bool unlockTpm(const char *password, size_t passwordLength) const
Unlock the TPM.
Definition: tpm.cpp:116
void setTerminalMode(bool isTerminal) const
Set the terminal mode of the TPM.
Definition: tpm.cpp:104
ConstBufferPtr getPublicKey(const Name &keyName) const
Definition: tpm.cpp:63
ConstBufferPtr decrypt(span< const uint8_t > buf, const Name &keyName) const
Decrypt blob using the key with name keyName.
Definition: tpm.cpp:88
boost::logic::tribool verify(const InputBuffers &bufs, span< const uint8_t > sig, const Name &keyName, DigestAlgorithm digestAlgorithm) const
Verify discontiguous ranges using the key with name keyName and using the digest digestAlgorithm.
Definition: tpm.cpp:77
ConstBufferPtr sign(const InputBuffers &bufs, const Name &keyName, DigestAlgorithm digestAlgorithm) const
Sign discontiguous ranges using the key with name keyName and using the digest digestAlgorithm.
Definition: tpm.cpp:70
const std::string & getTpmLocator() const
Return the TPM Locator.
Definition: tpm.hpp:77
bool isTerminalMode() const
Check if the TPM is in terminal mode.
Definition: tpm.cpp:98
bool hasKey(const Name &keyName) const
Check if a private key exists.
Definition: tpm.cpp:39
bool isTpmLocked() const
Definition: tpm.cpp:110
Abstraction of a private key in crypto transformations.
Definition: private-key.hpp:39
#define NDN_CXX_PUBLIC_WITH_TESTS_ELSE_PRIVATE
Definition: common.hpp:49
Contains the ndn-cxx security framework.
std::shared_ptr< const Buffer > ConstBufferPtr
Definition: buffer.hpp:140
InputBuffers bufs
span< const uint8_t > sig