1 /* Microsoft Reference Implementation for TPM 2.0
2 *
3 * The copyright in this software is being made available under the BSD License,
4 * included below. This software may be subject to other third party and
5 * contributor rights, including patent rights, and no such rights are granted
6 * under this license.
7 *
8 * Copyright (c) Microsoft Corporation
9 *
10 * All rights reserved.
11 *
12 * BSD License
13 *
14 * Redistribution and use in source and binary forms, with or without modification,
15 * are permitted provided that the following conditions are met:
16 *
17 * Redistributions of source code must retain the above copyright notice, this list
18 * of conditions and the following disclaimer.
19 *
20 * Redistributions in binary form must reproduce the above copyright notice, this
21 * list of conditions and the following disclaimer in the documentation and/or
22 * other materials provided with the distribution.
23 *
24 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ""AS IS""
25 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
26 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
27 * DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR
28 * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
29 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
30 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON
31 * ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
32 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
33 * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
34 */
35 #include "Tpm.h"
36 #include "MakeCredential_fp.h"
37
38 #if CC_MakeCredential // Conditional expansion of this file
39
40 #include "Object_spt_fp.h"
41
42 /*(See part 3 specification)
43 // Make Credential with an object
44 */
45 // Return Type: TPM_RC
46 // TPM_RC_KEY 'handle' referenced an ECC key that has a unique
47 // field that is not a point on the curve of the key
48 // TPM_RC_SIZE 'credential' is larger than the digest size of
49 // Name algorithm of 'handle'
50 // TPM_RC_TYPE 'handle' does not reference an asymmetric
51 // decryption key
52 TPM_RC
TPM2_MakeCredential(MakeCredential_In * in,MakeCredential_Out * out)53 TPM2_MakeCredential(
54 MakeCredential_In *in, // IN: input parameter list
55 MakeCredential_Out *out // OUT: output parameter list
56 )
57 {
58 TPM_RC result = TPM_RC_SUCCESS;
59
60 OBJECT *object;
61 TPM2B_DATA data;
62
63 // Input Validation
64
65 // Get object pointer
66 object = HandleToObject(in->handle);
67
68 // input key must be an asymmetric, restricted decryption key
69 // NOTE: Needs to be restricted to have a symmetric value.
70 if(!CryptIsAsymAlgorithm(object->publicArea.type)
71 || !IS_ATTRIBUTE(object->publicArea.objectAttributes, TPMA_OBJECT, decrypt)
72 || !IS_ATTRIBUTE(object->publicArea.objectAttributes,
73 TPMA_OBJECT, restricted))
74 return TPM_RCS_TYPE + RC_MakeCredential_handle;
75
76 // The credential information may not be larger than the digest size used for
77 // the Name of the key associated with handle.
78 if(in->credential.t.size > CryptHashGetDigestSize(object->publicArea.nameAlg))
79 return TPM_RCS_SIZE + RC_MakeCredential_credential;
80
81 // Command Output
82
83 // Make encrypt key and its associated secret structure.
84 out->secret.t.size = sizeof(out->secret.t.secret);
85 result = CryptSecretEncrypt(object, IDENTITY_STRING, &data, &out->secret);
86 if(result != TPM_RC_SUCCESS)
87 return result;
88
89 // Prepare output credential data from secret
90 SecretToCredential(&in->credential, &in->objectName.b, &data.b,
91 object, &out->credentialBlob);
92
93 return TPM_RC_SUCCESS;
94 }
95
96 #endif // CC_MakeCredential