Skip to content
This repository was archived by the owner on May 24, 2026. It is now read-only.

Request to review and merge latest code changes - #7

Merged
divegeek merged 18 commits into
divegeek:masterfrom
cpathak:master
Jul 28, 2020
Merged

Request to review and merge latest code changes#7
divegeek merged 18 commits into
divegeek:masterfrom
cpathak:master

Conversation

@cpathak

Copy link
Copy Markdown
Contributor

The current code has most of the code. Following commands are not yet tested.

  • Import Wrapped Key
  • get Hmac Shared Parameters
  • Compute Hmac.
    Following commands will be added to the code in future pull requests.
  • attest key
  • destroy attested ids
    All other commands are functionally tested with jcard sim basic tests- more testing is on going.

cpathak added 18 commits March 27, 2020 17:07
- removed command related classes and combined them into KMKeymasterApplet class
- removed context class as it is no longer needed.
- changed the random number generation logic to use aes cbc with aes 128 bit key encryption as simulator does not support aes ecb and aes 256 bit key.
- changed exception throwing to use ISOException.throwit() to use runtime environment's instance.
Implemented transient memory based code.
- Some Code optimizations.
- ImportKey, GenerateKey and GetKeyCharacteristics functionality.
- GetKeyCharacteristics only tested on jcardSim.
Code changes to crypto provider.
New feature implemented but not tested.
Removed untested code from KeymasterApplet.
- Tested only with jcard sim.
- Basic testing with Begin, Update, Finish and Abort.
- Basic testing with Upgrade Key, Delete Key, DeleteAllKeys.
Tested Import Wrapped key with jcard sim.
Optimization is still necessary.
Also fixed vts related requirement for rsa decryption without padding. JCardSim automaticaly removes the leading zeros after decryption. VTS test fails due to this.
- Added AES GCM cipher for begin, update and finish operations.
- Also added some bugfixes.
Also added some bug fixes related to EC key import.
- Generates AES GCM nonce if none passed.
- Frees pending operations if ISOException occurs
Added RSA OAEP based SHA1 and SHA256 encrypt and decrypt functionality.
This uses SunJce as jacardsim does not support it.
This uses RSA private key decryption with no padding from jcard sim to sign the data. The padding for pkcs1 and padding none is done before the jcard sim api is called.
However there is no way to verify the signature using jcard sim as the public key encryption without padding allows only 255 bytes of input data.
Added AttestKey command and provision command functionality. Currently JCardSim tests pass whereas OracleSimulator tests fails as the command strings are not correct and also commands larger then 256 bytes are failing. This will be fixed in later releases.
Added functionality for destroyAttestationIds.
Added support for ECDSA related subject pub key info in attest key certificate.
Bug fix related importwrappedkey and hmac key sizes to pass VTS tests.
Added two more enum values for boot state.
- EC Keys support in X509 subject pub key info
- AES CTR support
- OAEP 256 for import wrapped key
- hmac key size from 64 to 512
@divegeek
divegeek merged commit 9c6b1fc into divegeek:masterJul 28, 2020
mdwivedi pushed a commit that referenced this pull request Dec 8, 2021
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@cpathak@divegeek