|
| 1 | +// Copyright 2020 Contributors to the Parsec project. |
| 2 | +// SPDX-License-Identifier: Apache-2.0 |
| 3 | +//! Trusted Service provider |
| 4 | +//! |
| 5 | +//! This provider is backed by a crypto Trusted Service deployed in TrustZone |
| 6 | +use crate::key_info_managers::ManageKeyInfo; |
| 7 | +use crate::providers::Provide; |
| 8 | +use context::Context; |
| 9 | +use derivative::Derivative; |
| 10 | +use parsec_interface::operations::list_providers::ProviderInfo; |
| 11 | +use parsec_interface::operations::psa_key_attributes::{Attributes, Id}; |
| 12 | +use parsec_interface::requests::{Opcode, ProviderID, Result}; |
| 13 | +use psa_crypto::types::key; |
| 14 | +use std::collections::HashMap; |
| 15 | +use std::collections::HashSet; |
| 16 | +use std::sync::{atomic::AtomicU32, Arc, RwLock}; |
| 17 | +use uuid::Uuid; |
| 18 | + |
| 19 | +mod context; |
| 20 | + |
| 21 | +const SUPPORTED_OPCODES: [Opcode; 0] = []; |
| 22 | + |
| 23 | +/// Trusted Service provider structure |
| 24 | +/// |
| 25 | +/// Currently the provider only supports volatile keys due to limitations in the stack |
| 26 | +/// underneath us. Therefore none of the key information is persisted, being kept instead |
| 27 | +/// in a map for fast access. |
| 28 | +#[derive(Derivative)] |
| 29 | +#[derivative(Debug)] |
| 30 | +pub struct Provider { |
| 31 | + context: Context, |
| 32 | + // When calling write on a reference of key_info_store, a type |
| 33 | + // std::sync::RwLockWriteGuard<dyn ManageKeyInfo + Send + Sync> is returned. We need to use the |
| 34 | + // dereference operator (*) to access the inner type dyn ManageKeyInfo + Send + Sync and then |
| 35 | + // reference it to match with the method prototypes. |
| 36 | + #[derivative(Debug = "ignore")] |
| 37 | + key_info_store: Arc<RwLock<dyn ManageKeyInfo + Send + Sync>>, |
| 38 | + key_attr_map: HashMap<String, (Id, Attributes)>, |
| 39 | + |
| 40 | + // Holds the highest ID of all keys (including destroyed keys). New keys will receive an ID of |
| 41 | + // id_counter + 1. Once id_counter reaches the highest allowed ID, no more keys can be created. |
| 42 | + id_counter: AtomicU32, |
| 43 | +} |
| 44 | + |
| 45 | +impl Provider { |
| 46 | + /// Creates and initialise a new instance of Provider. |
| 47 | + fn new( |
| 48 | + key_info_store: Arc<RwLock<dyn ManageKeyInfo + Send + Sync>>, |
| 49 | + ) -> anyhow::Result<Provider> { |
| 50 | + let ts_provider = Provider { |
| 51 | + key_info_store, |
| 52 | + context: Context::connect()?, |
| 53 | + key_attr_map: HashMap::new(), |
| 54 | + id_counter: AtomicU32::new(key::PSA_KEY_ID_USER_MIN), |
| 55 | + }; |
| 56 | + Ok(ts_provider) |
| 57 | + } |
| 58 | +} |
| 59 | + |
| 60 | +impl Provide for Provider { |
| 61 | + fn describe(&self) -> Result<(ProviderInfo, HashSet<Opcode>)> { |
| 62 | + Ok((ProviderInfo { |
| 63 | + // Assigned UUID for this provider: 1c1139dc-ad7c-47dc-ad6b-db6fdb466552 |
| 64 | + uuid: Uuid::parse_str("1c1139dc-ad7c-47dc-ad6b-db6fdb466552")?, |
| 65 | + description: String::from("Provider exposing functionality provided by the Crypto Trusted Service running in a Trusted Execution Environment"), |
| 66 | + vendor: String::from("Arm"), |
| 67 | + version_maj: 0, |
| 68 | + version_min: 1, |
| 69 | + version_rev: 0, |
| 70 | + id: ProviderID::TrustedService, |
| 71 | + }, SUPPORTED_OPCODES.iter().copied().collect())) |
| 72 | + } |
| 73 | +} |
| 74 | + |
| 75 | +/// Trusted Service provider builder |
| 76 | +#[derive(Default, Derivative)] |
| 77 | +#[derivative(Debug)] |
| 78 | +pub struct ProviderBuilder { |
| 79 | + #[derivative(Debug = "ignore")] |
| 80 | + key_info_store: Option<Arc<RwLock<dyn ManageKeyInfo + Send + Sync>>>, |
| 81 | +} |
| 82 | + |
| 83 | +impl ProviderBuilder { |
| 84 | + /// Create a new provider builder |
| 85 | + pub fn new() -> ProviderBuilder { |
| 86 | + ProviderBuilder { |
| 87 | + key_info_store: None, |
| 88 | + } |
| 89 | + } |
| 90 | + |
| 91 | + /// Add a KeyInfo manager |
| 92 | + pub fn with_key_info_store( |
| 93 | + mut self, |
| 94 | + key_info_store: Arc<RwLock<dyn ManageKeyInfo + Send + Sync>>, |
| 95 | + ) -> ProviderBuilder { |
| 96 | + self.key_info_store = Some(key_info_store); |
| 97 | + |
| 98 | + self |
| 99 | + } |
| 100 | + |
| 101 | + /// Build into a TrustedService |
| 102 | + pub fn build(self) -> anyhow::Result<Provider> { |
| 103 | + Provider::new(self.key_info_store.ok_or_else(|| { |
| 104 | + std::io::Error::new(std::io::ErrorKind::InvalidData, "missing key info store") |
| 105 | + })?) |
| 106 | + } |
| 107 | +} |
0 commit comments