ndn::security::tpm::BackEndOsx Class Reference

The back-end implementation of TPM based on macOS Keychain Services. More...

#include <back-end-osx.hpp>

+ Inheritance diagram for ndn::security::tpm::BackEndOsx:
+ Collaboration diagram for ndn::security::tpm::BackEndOsx:

Classes

class  Error
 

Public Member Functions

 BackEndOsx (const std::string &location="")
 Create TPM backed based on macOS KeyChain service. More...
 
 ~BackEndOsx () override
 
unique_ptr< KeyHandlecreateKey (const Name &identity, const KeyParams &params)
 Create key for identity according to params. More...
 
void deleteKey (const Name &keyName)
 Delete a key with name keyName. More...
 
ConstBufferPtr exportKey (const Name &keyName, const char *pw, size_t pwLen)
 
unique_ptr< KeyHandlegetKeyHandle (const Name &keyName) const
 
bool hasKey (const Name &keyName) const
 
void importKey (const Name &keyName, const uint8_t *pkcs8, size_t pkcs8Len, const char *pw, size_t pwLen)
 Import a private key in encrypted PKCS #8 format. More...
 
bool isTerminalMode () const final
 Check if TPM is in terminal mode. More...
 
bool isTpmLocked () const final
 
void setTerminalMode (bool isTerminal) const final
 Set the terminal mode of TPM. More...
 
bool unlockTpm (const char *pw, size_t pwLen) const final
 Unlock TPM. More...
 

Static Public Member Functions

static ConstBufferPtr decrypt (const KeyRefOsx &key, const uint8_t *cipherText, size_t cipherSize)
 
static ConstBufferPtr derivePublicKey (const KeyRefOsx &key)
 
static const std::string & getScheme ()
 
static ConstBufferPtr sign (const KeyRefOsx &key, DigestAlgorithm digestAlgorithm, const uint8_t *buf, size_t size)
 Sign buf with key using digestAlgorithm. More...
 

Static Protected Member Functions

static void setKeyName (KeyHandle &keyHandle, const Name &identity, const KeyParams &params)
 Set the key name in keyHandle according to identity and params. More...
 

Detailed Description

The back-end implementation of TPM based on macOS Keychain Services.

Definition at line 39 of file back-end-osx.hpp.

Constructor & Destructor Documentation

ndn::security::tpm::BackEndOsx::BackEndOsx ( const std::string &  location = "")
explicit

Create TPM backed based on macOS KeyChain service.

Parameters
locationNot used (required by the TPM-registration interface)

Definition at line 131 of file back-end-osx.cpp.

ndn::security::tpm::BackEndOsx::~BackEndOsx ( )
overridedefault

Member Function Documentation

unique_ptr< KeyHandle > ndn::security::tpm::BackEnd::createKey ( const Name identity,
const KeyParams params 
)
inherited

Create key for identity according to params.

The key name is set in the returned KeyHandle.

Returns
The handle of the created key.
Exceptions
Tpm::Errorparams are invalid
Errorthe key cannot be created

Definition at line 51 of file back-end.cpp.

ConstBufferPtr ndn::security::tpm::BackEndOsx::decrypt ( const KeyRefOsx key,
const uint8_t *  cipherText,
size_t  cipherSize 
)
static

Definition at line 248 of file back-end-osx.cpp.

void ndn::security::tpm::BackEnd::deleteKey ( const Name keyName)
inherited

Delete a key with name keyName.

Continuing to use existing KeyHandles on a deleted key results in undefined behavior.

Exceptions
Errorif the deletion fails.

Definition at line 86 of file back-end.cpp.

ConstBufferPtr ndn::security::tpm::BackEndOsx::derivePublicKey ( const KeyRefOsx key)
static

Definition at line 281 of file back-end-osx.cpp.

ConstBufferPtr ndn::security::tpm::BackEnd::exportKey ( const Name keyName,
const char *  pw,
size_t  pwLen 
)
inherited
Returns
A private key with name keyName in encrypted PKCS #8 format using password pw
Exceptions
Errorthe key does not exist
Errorthe key cannot be exported, e.g., insufficient privilege

Definition at line 92 of file back-end.cpp.

unique_ptr< KeyHandle > ndn::security::tpm::BackEnd::getKeyHandle ( const Name keyName) const
inherited
Returns
The handle of a key with name keyName, or nullptr if the key does not exist.

Calling getKeyHandle multiple times with the same keyName will return different KeyHandle objects that all refer to the same key.

Definition at line 45 of file back-end.cpp.

const std::string & ndn::security::tpm::BackEndOsx::getScheme ( )
static

Definition at line 146 of file back-end-osx.cpp.

bool ndn::security::tpm::BackEnd::hasKey ( const Name keyName) const
inherited
Returns
True if a key with name keyName exists in TPM.

Definition at line 39 of file back-end.cpp.

void ndn::security::tpm::BackEnd::importKey ( const Name keyName,
const uint8_t *  pkcs8,
size_t  pkcs8Len,
const char *  pw,
size_t  pwLen 
)
inherited

Import a private key in encrypted PKCS #8 format.

Parameters
keyNameThe name of imported private key
pkcs8Pointer to the key in encrypted PKCS #8 format
pkcs8LenThe size of the key in encrypted PKCS #8 format
pwThe password to decrypt the private key
pwLenThe length of the password
Exceptions
Errorimport failed

Definition at line 101 of file back-end.cpp.

bool ndn::security::tpm::BackEndOsx::isTerminalMode ( ) const
finalvirtual

Check if TPM is in terminal mode.

Default implementation always returns true.

Reimplemented from ndn::security::tpm::BackEnd.

Definition at line 153 of file back-end-osx.cpp.

bool ndn::security::tpm::BackEndOsx::isTpmLocked ( ) const
finalvirtual
Returns
True if TPM is locked, otherwise false

Default implementation always returns false.

Reimplemented from ndn::security::tpm::BackEnd.

Definition at line 166 of file back-end-osx.cpp.

void ndn::security::tpm::BackEnd::setKeyName ( KeyHandle keyHandle,
const Name identity,
const KeyParams params 
)
staticprotectedinherited

Set the key name in keyHandle according to identity and params.

Definition at line 110 of file back-end.cpp.

void ndn::security::tpm::BackEndOsx::setTerminalMode ( bool  isTerminal) const
finalvirtual

Set the terminal mode of TPM.

In terminal mode, TPM will not ask user permission from GUI.

Default implementation does nothing.

Reimplemented from ndn::security::tpm::BackEnd.

Definition at line 159 of file back-end-osx.cpp.

ConstBufferPtr ndn::security::tpm::BackEndOsx::sign ( const KeyRefOsx key,
DigestAlgorithm  digestAlgorithm,
const uint8_t *  buf,
size_t  size 
)
static

Sign buf with key using digestAlgorithm.

Definition at line 197 of file back-end-osx.cpp.

bool ndn::security::tpm::BackEndOsx::unlockTpm ( const char *  pw,
size_t  pwLen 
) const
finalvirtual

Unlock TPM.

Parameters
pwThe password to unlock TPM
pwLenThe password size.

Default implementation always returns !isTpmLocked()

Reimplemented from ndn::security::tpm::BackEnd.

Definition at line 178 of file back-end-osx.cpp.