Merge "Keystore: Attestation fix in AOSP builds" am: ecb4b6d158 am: c17512848d

Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2237500

Change-Id: Ie6d9e023e5d6caac694f91ace381697f54ddf8ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Eran Messeri
2023-01-31 17:41:10 +00:00
committed by Automerger Merge Worker
3 changed files with 46 additions and 3 deletions

View File

@@ -1696,7 +1696,10 @@ package android.os {
public class Build { public class Build {
method public static boolean is64BitAbi(String); method public static boolean is64BitAbi(String);
method public static boolean isDebuggable(); method public static boolean isDebuggable();
field @Nullable public static final String BRAND_FOR_ATTESTATION;
field public static final boolean IS_EMULATOR; field public static final boolean IS_EMULATOR;
field @Nullable public static final String MODEL_FOR_ATTESTATION;
field @Nullable public static final String PRODUCT_FOR_ATTESTATION;
} }
public static class Build.VERSION { public static class Build.VERSION {

View File

@@ -61,6 +61,17 @@ public class Build {
/** The name of the overall product. */ /** The name of the overall product. */
public static final String PRODUCT = getString("ro.product.name"); public static final String PRODUCT = getString("ro.product.name");
/**
* The product name for attestation. In non-default builds (like the AOSP build) the value of
* the 'PRODUCT' system property may be different to the one provisioned to KeyMint,
* and Keymint attestation would still attest to the product name, it's running on.
* @hide
*/
@Nullable
@TestApi
public static final String PRODUCT_FOR_ATTESTATION =
getString("ro.product.name_for_attestation");
/** The name of the industrial design. */ /** The name of the industrial design. */
public static final String DEVICE = getString("ro.product.device"); public static final String DEVICE = getString("ro.product.device");
@@ -89,9 +100,31 @@ public class Build {
/** The consumer-visible brand with which the product/hardware will be associated, if any. */ /** The consumer-visible brand with which the product/hardware will be associated, if any. */
public static final String BRAND = getString("ro.product.brand"); public static final String BRAND = getString("ro.product.brand");
/**
* The product brand for attestation. In non-default builds (like the AOSP build) the value of
* the 'BRAND' system property may be different to the one provisioned to KeyMint,
* and Keymint attestation would still attest to the product brand, it's running on.
* @hide
*/
@Nullable
@TestApi
public static final String BRAND_FOR_ATTESTATION =
getString("ro.product.brand_for_attestation");
/** The end-user-visible name for the end product. */ /** The end-user-visible name for the end product. */
public static final String MODEL = getString("ro.product.model"); public static final String MODEL = getString("ro.product.model");
/**
* The product model for attestation. In non-default builds (like the AOSP build) the value of
* the 'MODEL' system property may be different to the one provisioned to KeyMint,
* and Keymint attestation would still attest to the product model, it's running on.
* @hide
*/
@Nullable
@TestApi
public static final String MODEL_FOR_ATTESTATION =
getString("ro.product.model_for_attestation");
/** The manufacturer of the device's primary system-on-chip. */ /** The manufacturer of the device's primary system-on-chip. */
@NonNull @NonNull
public static final String SOC_MANUFACTURER = SocProperties.soc_manufacturer().orElse(UNKNOWN); public static final String SOC_MANUFACTURER = SocProperties.soc_manufacturer().orElse(UNKNOWN);

View File

@@ -801,25 +801,32 @@ public abstract class AndroidKeyStoreKeyPairGeneratorSpi extends KeyPairGenerato
)); ));
if (mSpec.isDevicePropertiesAttestationIncluded()) { if (mSpec.isDevicePropertiesAttestationIncluded()) {
final String platformReportedBrand = TextUtils.isEmpty(Build.BRAND_FOR_ATTESTATION)
? Build.BRAND : Build.BRAND_FOR_ATTESTATION;
params.add(KeyStore2ParameterUtils.makeBytes( params.add(KeyStore2ParameterUtils.makeBytes(
KeymasterDefs.KM_TAG_ATTESTATION_ID_BRAND, KeymasterDefs.KM_TAG_ATTESTATION_ID_BRAND,
Build.BRAND.getBytes(StandardCharsets.UTF_8) platformReportedBrand.getBytes(StandardCharsets.UTF_8)
)); ));
params.add(KeyStore2ParameterUtils.makeBytes( params.add(KeyStore2ParameterUtils.makeBytes(
KeymasterDefs.KM_TAG_ATTESTATION_ID_DEVICE, KeymasterDefs.KM_TAG_ATTESTATION_ID_DEVICE,
Build.DEVICE.getBytes(StandardCharsets.UTF_8) Build.DEVICE.getBytes(StandardCharsets.UTF_8)
)); ));
final String platformReportedProduct =
TextUtils.isEmpty(Build.PRODUCT_FOR_ATTESTATION) ? Build.PRODUCT :
Build.PRODUCT_FOR_ATTESTATION;
params.add(KeyStore2ParameterUtils.makeBytes( params.add(KeyStore2ParameterUtils.makeBytes(
KeymasterDefs.KM_TAG_ATTESTATION_ID_PRODUCT, KeymasterDefs.KM_TAG_ATTESTATION_ID_PRODUCT,
Build.PRODUCT.getBytes(StandardCharsets.UTF_8) platformReportedProduct.getBytes(StandardCharsets.UTF_8)
)); ));
params.add(KeyStore2ParameterUtils.makeBytes( params.add(KeyStore2ParameterUtils.makeBytes(
KeymasterDefs.KM_TAG_ATTESTATION_ID_MANUFACTURER, KeymasterDefs.KM_TAG_ATTESTATION_ID_MANUFACTURER,
Build.MANUFACTURER.getBytes(StandardCharsets.UTF_8) Build.MANUFACTURER.getBytes(StandardCharsets.UTF_8)
)); ));
final String platformReportedModel = TextUtils.isEmpty(Build.MODEL_FOR_ATTESTATION)
? Build.MODEL : Build.MODEL_FOR_ATTESTATION;
params.add(KeyStore2ParameterUtils.makeBytes( params.add(KeyStore2ParameterUtils.makeBytes(
KeymasterDefs.KM_TAG_ATTESTATION_ID_MODEL, KeymasterDefs.KM_TAG_ATTESTATION_ID_MODEL,
Build.MODEL.getBytes(StandardCharsets.UTF_8) platformReportedModel.getBytes(StandardCharsets.UTF_8)
)); ));
} }