Merge "Fix Rsa-Oaep operation begin on T+GSI build" into main am: 51bf3fd503 am: 5f753cfcbf
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2650396 Change-Id: I24c386730c05fdcc698ab760644aa5b331e34b85 Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
@@ -18,6 +18,7 @@ package android.security.keystore2;
|
|||||||
|
|
||||||
import android.annotation.NonNull;
|
import android.annotation.NonNull;
|
||||||
import android.annotation.Nullable;
|
import android.annotation.Nullable;
|
||||||
|
import android.content.pm.PackageManager;
|
||||||
import android.hardware.security.keymint.KeyParameter;
|
import android.hardware.security.keymint.KeyParameter;
|
||||||
import android.security.keymaster.KeymasterDefs;
|
import android.security.keymaster.KeymasterDefs;
|
||||||
import android.security.keystore.KeyProperties;
|
import android.security.keystore.KeyProperties;
|
||||||
@@ -299,6 +300,12 @@ abstract class AndroidKeyStoreRSACipherSpi extends AndroidKeyStoreCipherSpiBase
|
|||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private static boolean hasKeyMintV2() {
|
||||||
|
PackageManager pm = android.app.AppGlobals.getInitialApplication().getPackageManager();
|
||||||
|
return pm.hasSystemFeature(PackageManager.FEATURE_HARDWARE_KEYSTORE, 200)
|
||||||
|
&& !pm.hasSystemFeature(PackageManager.FEATURE_HARDWARE_KEYSTORE, 300);
|
||||||
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
protected final void addAlgorithmSpecificParametersToBegin(
|
protected final void addAlgorithmSpecificParametersToBegin(
|
||||||
@NonNull List<KeyParameter> parameters, Authorization[] keyCharacteristics) {
|
@NonNull List<KeyParameter> parameters, Authorization[] keyCharacteristics) {
|
||||||
@@ -307,11 +314,12 @@ abstract class AndroidKeyStoreRSACipherSpi extends AndroidKeyStoreCipherSpiBase
|
|||||||
KeymasterDefs.KM_TAG_DIGEST, mKeymasterDigest
|
KeymasterDefs.KM_TAG_DIGEST, mKeymasterDigest
|
||||||
));
|
));
|
||||||
// Only add the KM_TAG_RSA_OAEP_MGF_DIGEST tag to begin() if the MGF Digest is
|
// Only add the KM_TAG_RSA_OAEP_MGF_DIGEST tag to begin() if the MGF Digest is
|
||||||
// present in the key properties. Keys generated prior to Android 14 did not have
|
// present in the key properties or KeyMint version is 200. Keys generated prior to
|
||||||
// this tag (Keystore didn't add it) so specifying any MGF digest tag would cause
|
// Android 14 did not have this tag (Keystore didn't add it) and hence not present in
|
||||||
// a begin() operation (on an Android 14 device) to fail (with a key that was generated
|
// imported key as well, so specifying any MGF digest tag would cause a begin()
|
||||||
// on Android 13 or below).
|
// operation (on an Android 14 device) to fail (with a key that was generated on
|
||||||
if (isMgfDigestTagPresentInKeyProperties(keyCharacteristics)) {
|
// Android 13 or below).
|
||||||
|
if (isMgfDigestTagPresentInKeyProperties(keyCharacteristics) || hasKeyMintV2()) {
|
||||||
parameters.add(KeyStore2ParameterUtils.makeEnum(
|
parameters.add(KeyStore2ParameterUtils.makeEnum(
|
||||||
KeymasterDefs.KM_TAG_RSA_OAEP_MGF_DIGEST, mKeymasterMgf1Digest
|
KeymasterDefs.KM_TAG_RSA_OAEP_MGF_DIGEST, mKeymasterMgf1Digest
|
||||||
));
|
));
|
||||||
|
|||||||
Reference in New Issue
Block a user