1 /* Microsoft Reference Implementation for TPM 2.0
2 *
3 * The copyright in this software is being made available under the BSD License,
4 * included below. This software may be subject to other third party and
5 * contributor rights, including patent rights, and no such rights are granted
6 * under this license.
7 *
8 * Copyright (c) Microsoft Corporation
9 *
10 * All rights reserved.
11 *
12 * BSD License
13 *
14 * Redistribution and use in source and binary forms, with or without modification,
15 * are permitted provided that the following conditions are met:
16 *
17 * Redistributions of source code must retain the above copyright notice, this list
18 * of conditions and the following disclaimer.
19 *
20 * Redistributions in binary form must reproduce the above copyright notice, this
21 * list of conditions and the following disclaimer in the documentation and/or
22 * other materials provided with the distribution.
23 *
24 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ""AS IS""
25 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
26 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
27 * DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR
28 * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
29 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
30 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON
31 * ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
32 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
33 * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
34 */
35 #include "Tpm.h"
36 #include "MAC_fp.h"
37
38 #if CC_MAC // Conditional expansion of this file
39
40 /*(See part 3 specification)
41 // Compute MAC on a data buffer
42 */
43 // Return Type: TPM_RC
44 // TPM_RC_ATTRIBUTES key referenced by 'handle' is a restricted key
45 // TPM_RC_KEY 'handle' does not reference a signing key
46 // TPM_RC_TYPE key referenced by 'handle' is not an HMAC key
47 // TPM_RC_VALUE 'hashAlg' is not compatible with the hash algorithm
48 // of the scheme of the object referenced by 'handle'
49 TPM_RC
TPM2_MAC(MAC_In * in,MAC_Out * out)50 TPM2_MAC(
51 MAC_In *in, // IN: input parameter list
52 MAC_Out *out // OUT: output parameter list
53 )
54 {
55 OBJECT *keyObject;
56 HMAC_STATE state;
57 TPMT_PUBLIC *publicArea;
58 TPM_RC result;
59
60 // Input Validation
61 // Get MAC key object and public area pointers
62 keyObject = HandleToObject(in->handle);
63 publicArea = &keyObject->publicArea;
64
65 // If the key is not able to do a MAC, indicate that the handle selects an
66 // object that can't do a MAC
67 result = CryptSelectMac(publicArea, &in->inScheme);
68 if(result == TPM_RCS_TYPE)
69 return TPM_RCS_TYPE + RC_MAC_handle;
70 // If there is another error type, indicate that the scheme and key are not
71 // compatible
72 if(result != TPM_RC_SUCCESS)
73 return RcSafeAddToResult(result, RC_MAC_inScheme);
74 // Make sure that the key is not restricted
75 if(IS_ATTRIBUTE(publicArea->objectAttributes, TPMA_OBJECT, restricted))
76 return TPM_RCS_ATTRIBUTES + RC_MAC_handle;
77 // and that it is a signing key
78 if(!IS_ATTRIBUTE(publicArea->objectAttributes, TPMA_OBJECT, sign))
79 return TPM_RCS_KEY + RC_MAC_handle;
80 // Command Output
81 out->outMAC.t.size = CryptMacStart(&state, &publicArea->parameters,
82 in->inScheme,
83 &keyObject->sensitive.sensitive.any.b);
84 // If the mac can't start, treat it as a fatal error
85 if(out->outMAC.t.size == 0)
86 return TPM_RC_FAILURE;
87 CryptDigestUpdate2B(&state.hashState, &in->buffer.b);
88 // If the MAC result is not what was expected, it is a fatal error
89 if(CryptHmacEnd2B(&state, &out->outMAC.b) != out->outMAC.t.size)
90 return TPM_RC_FAILURE;
91 return TPM_RC_SUCCESS;
92 }
93
94 #endif // CC_MAC