Commit Graph

68 Commits

Author SHA1 Message Date
Seth Moore
c78e369c4c Fix incorrect SID matching for bio prompts
The default value for canUnlockViaBiometrics, which determines if we
are able to show a bio prompt, is true. However, if there are 0
biometric authenticator IDs, then it's impossible for the user to
satisfy a bio prompt. In this case, we should set canUnlockViaBiometrics
to false.

The loop that is normally expected to invert canUnlockViaBiometrics was
never run in the case of 0 bio authenticator ids, so we mistakenly
let the crypto init operation succeed when we should have blocked it.

Bug: 188864794
Test: Manual, using sample app that displays a biometric prompt.
Change-Id: Ib95b0564aa098157718b8d4a45b11baa69dad71b
2021-12-01 14:59:24 -08:00
Treehugger Robot
70e7dd44b4 Merge changes Ic6e60752,I2b8b7e74
* changes:
  Test for contract between AndroidKeyStoreKey hash and equals.
  Keystore 2.0 SPI: Fix contract between equals and hashCode 2
2021-10-08 15:31:03 +00:00
Janis Danisevskis
5fe5f2def0 Test for contract between AndroidKeyStoreKey hash and equals.
Test: atest KeystoreTests
Bug: 196118021

Merged-In: Ic6e60752faa986debe3d325f54242cffaa03b336
Change-Id: Ic6e60752faa986debe3d325f54242cffaa03b336
2021-10-07 16:39:39 -07:00
Janis Danisevskis
e36fe6bf46 Keystore 2.0 SPI: Fix contract between equals and hashCode 2
This fixes the contract between equals and hashCode in
AndroidKeystorePublicKey. The previous fix made only a reference
comparisson between certificate blobs. In this patch java.util.Arrays is
used to compare and compute the hash of the array.

Bug: 196118021
Test: See following CL.
Change-Id: I2b8b7e740fb377de39fd21f763e15cb00024b2fc
2021-10-07 16:24:46 -07:00
Janis Danisevskis
4ff6274fa7 Keystore 2.0 SPI: Fix NullPointerException in setKeyEntry.
Fix a NullPointerException when trying to insert SecretKey that already
exists.

Bug: 202146009
Test: atest android.keystore.cts.AndroidKeyStoreTest#testKeyStore_SetKeyEntry_ReplacedWithSameGeneratedSecretKey
Change-Id: If3a4bd6677ab3173c5c1a7c921ba567b7981662b
2021-10-07 08:24:42 -07:00
Seth Moore
11cce949b6 Fix key alias string comparison
The code was doing a reference compare, not object value comparison,
resulting in failures in the KeyStore setEntry API.

Test: CtsKeystoreTestCases:android.keystore.cts.AndroidKeyStoreTest
Fixes: 197138784
Change-Id: I2c5e47283eed5694951869e9ea3853364ddef9d1
2021-08-19 12:44:08 -07:00
Janis Danisevskis
7bdc12d5f3 Keystore 2.0 SPI: Fix contract between equals and hashCode
This fixes the contract between equals and hashCode in
AndroidKeystoreKey and AndroidKeystorePublicKey.

Bug: 196118021
Test: N/A
Change-Id: I3f7e6d72d53c7051c13daeb5aa6ce1abf4eb0cc5
2021-08-12 12:29:02 -07:00
Janis Danisevskis
f5985b0838 Keystore 2.0 SPI: Add EC_CURVE tag on key generation.
The KeyMint spec requires the specification of the EC_CURVE tag when
generating an EC key. This patch adds the correct curve tag parameter to
the parameter list.

Test: CtsVerifier Protected confirmation test.
Bug: 192908276
Merged-In: I2e7dd4868abda85d244e73592ff12d688f5c21fc
Change-Id: I2e7dd4868abda85d244e73592ff12d688f5c21fc
2021-07-08 10:00:22 -07:00
Max Bires
5023e1fb96 Merge "Fixing the race condition in GenerateRkpKey" 2021-07-01 14:20:37 +00:00
Victor Chang
507a653a6e Update the java doc of AndroidKeyStoreProvider#getKeyStoreOperationHandle to support Signature object
Test: m droid
Change-Id: Ie65dcfe96f3bb00cc9af4d49e4e1d1f57bde438a
2021-06-16 15:57:44 +01:00
Max Bires
5e43390b9b Fixing the race condition in GenerateRkpKey
This file was written on the assumption that bindService was
synchronous, which it isn't. This change adds a CountDownLatch to force
the class to wait for the binding to finish. If the relevant key
generation service is not present on the system, then this
functionality will just silently be skipped over.

Bug: 190222116
Test: atest RemoteProvisionerUnitTests
Change-Id: Ie34997a08aa743642c66a20c4b756cd47bff4af1
Merged-In: Ie34997a08aa743642c66a20c4b756cd47bff4af1
2021-06-13 21:50:36 +00:00
Max Bires
b2a11d35e5 Revert "Fixing the race condition in GenerateRkpKey"
This reverts commit 0f62195535.

Reason for revert: Breaks non-RKP systems

Bug: 190222116
Change-Id: I7e31a3045caa7b8bb0e34c8d1e266c104a627324
Merged-In: I7e31a3045caa7b8bb0e34c8d1e266c104a627324
2021-06-09 20:21:41 +00:00
Max Bires
0f62195535 Fixing the race condition in GenerateRkpKey
This file was written on the assumption that bindService was
synchronous, which it isn't. This change adds a CountDownLatch to force
the class to wait for the binding to finish.

Bug: 190222116
Test: atest RemoteProvisionerUnitTests
Change-Id: I917a61da612f21f9a0f783bea5d24270d4e1db42
Merged-In: I917a61da612f21f9a0f783bea5d24270d4e1db42
2021-06-07 18:30:51 +00:00
Joshua Duong
3b2decbb34 Merge "Use keymasterSwEnforcedUserAuthenticators if keymasterHwEnforcedUserAuthenticators is zero." 2021-05-13 20:16:08 +00:00
Janis Danisevskis
738e422b00 Keystore 2.0 SPI: Fix NPE in getUniqueAliases.
getUniqueAliases may return a null if an error occurred. This would lead
to a NPE in engineAliases.

This patch makes getUniqueAliases return an empty HashSet instead.

Test: atest KeystoreTests

Change-Id: I387d90ea851a8b9c18bb2b20d1a0bfc1ab76c99f
2021-05-12 17:29:26 -07:00
Joshua Duong
299345bb8e Use keymasterSwEnforcedUserAuthenticators if keymasterHwEnforcedUserAuthenticators is zero.
Bug: 186562600

Test: atest android.appsecurity.cts.AuthBoundKeyTest#useInvalidatedAuthBoundKey
Change-Id: I52a9c04b3e000416fb141d90d8d1f034348499de
2021-05-12 08:30:05 -07:00
Treehugger Robot
06df6d84eb Merge "Keystore 2.0 SPI: Fix engineDoFinal with null input." 2021-04-23 17:53:34 +00:00
Janis Danisevskis
70cf430ede Keystore 2.0 SPI: Fix engineDoFinal with null input.
AndroidKeyStoreCipherSpiBase.engineDoFinal may get called with a null
input argument. In the case where we forward the operation to the
default provider doFinal() needs to be called instead of
doFinal(byte[], int, int).

Bug: 183913233
Test: atest android.keystore.cts.CipherTest#testEncryptsAndDecryptsUsingCipherStreams
Change-Id: Ia3afaf281be7c8e5493ac8e4155a7aa02d1d37f0
2021-04-22 14:55:45 +00:00
Nikita Iashchenko
1bc8a1f886 Remove usage of Math.randomLongInternal
As a part of internal libcore API cleanup some of the functions
previously exposed are getting removed from public surface.
Math#randomLongInternal is a wrapper around java.util.Random and has no
specific implications so its usages are get refactored.

Bug: 154796679
Test: m droid
Change-Id: I29e0e9307fbaf9c1ac018b83014efb2d3dd74479
2021-04-21 14:10:43 +00:00
Janis Danisevskis
464e6c415f Keystore 2.0 SPI: Make getAttestationIds return an empty array.
getAttestationIds shall return an empty array instead of null.

Bug: 184026478
Test: N/A
Change-Id: I6c6233fa50a83cf7d6354d2783525704a3b39d0d
2021-04-07 14:38:57 -07:00
Janis Danisevskis
a6dcf091f5 Keystore 2.0: Remove Keystore 1.0 SPI with all remaining references
Bug: 171305684
Test: CtsKeystoreTestCases
Change-Id: I337515dadc9e45b909bff058d4e13371b4fa843c
2021-04-01 17:06:41 -07:00
Max Bires
e7f48b9926 Merge "Adding AIDL and functions for talking to RemoteProvisioner" 2021-03-25 00:03:09 +00:00
Max Bires
7fd458dc44 Adding AIDL and functions for talking to RemoteProvisioner
This change adds an AIDL interface which the RemoteProvisioner app
implements that allows the keystore SPI to inform the app when an
attestation key may have been used, and when the underlying attestation
key pool is totally empty. The former is a non-blocking call, and the
latter blocks until completion.

Since the latter involves network, there are timeouts involved on the
app side to ensure that the blocking call doesn't hang indefinitely if
there's no network.

Test: atest CtsKeystoreTestCases && atest RemoteProvisionerUnitTests

Change-Id: Ie49e37659c96ce5c1626d1b99a4a7ccc62028156
2021-03-24 01:13:10 -07:00
Janis Danisevskis
68570cc5a7 Keystore 2.0: Add @IntDef for Keystore namespaces.
Bug: 182914789
Test: N/A
Change-Id: Ibdfd2a4a37d7200317ef449ef857f34401625237
2021-03-22 17:43:32 -07:00
Janis Danisevskis
8758b2ceaf Keystore 2.0: Fix infinit recursion.
Fix endless recursion when Cipher is initialized with
AndroidKeyStorePrivateKey.

Fixes: 183167349
Test: atest android.keystore.cts.AndroidKeyStoreTest#testKeyStore_Encrypting_RSA_NONE_NOPADDING
Change-Id: I5b4166fb1a4e298072f7156ba61a64966e86dc53
2021-03-19 08:09:34 +00:00
Treehugger Robot
be1b1d5550 Merge "Keystore 2.0: Fix diagnosing invalid key in CipherSpiBase." 2021-03-18 23:46:37 +00:00
Janis Danisevskis
0b66a19bdd Keystore 2.0: No longer install the legacy provider.
The legacy provider is obsolete now that all calling code has
been fixed.

Bug: 183100147
Bug: 183093711
Bug: 171305684
Test: N/A
Merged-In: I0d71d3c9cdd586a508827eb26120c872cb8643ea
Change-Id: I0d71d3c9cdd586a508827eb26120c872cb8643ea
2021-03-18 20:24:39 +00:00
Janis Danisevskis
0b858aef63 Keystore 2.0: Fix diagnosing invalid key in CipherSpiBase.
Bug: 183101158
Test: atest CtsLibcoreTestCases:com.android.org.conscrypt.javax.crypto.CipherBasicsTest#testAeadEncryption

Merged-In: Idc9c7dc2614a47818227a06fe76078f72c0c1f57
Change-Id: Idc9c7dc2614a47818227a06fe76078f72c0c1f57
2021-03-18 19:41:56 +00:00
Janis Danisevskis
274a93e953 Keystore 2.0: Fix TODOs in public doc comments.
Bug: 174580379
Test: N/A
Change-Id: If893c408156b2481a22730de22f1a7ba391d88eb
2021-03-10 11:22:22 -08:00
Janis Danisevskis
051d7668f7 Keystore 2.0: Silence common error on operation abort.
Test: N/A
Change-Id: I7c85ae881165bc77d836624bfe20251b971d4479
2021-03-04 15:48:12 -08:00
Dmitry Dementyev
16491e1316 Migrate recoverablekeystore to KeyStore V2.
Test: manual
Bug: 171305545
Change-Id: Id415be48cab6852df155b5b2dbaf941ef54cd5a4
2021-02-25 16:42:15 -08:00
Janis Danisevskis
0cdf262ee5 Keystore 2.0: Remove attestKey from KeyChain.
KeyChain supports device id attestation through KeyGenParameterSpec now.
No need to call attest key individually. Also calling attest key
individually is no longer supported by Keystore 2.0 and KeyMint.

Also isBoundKeyAlgorithm returns true.

Test: atest FrameworksServicesTests:DevicePolicyManagerTest
Bug: 171305387
Merged-In: I759fe245b48fe435153fded2c74c9ae99634c146
Change-Id: I759fe245b48fe435153fded2c74c9ae99634c146
2021-02-23 14:41:49 -08:00
Janis Danisevskis
fa1a21957c Keystore 2.0: Fix correct handling of Uid/Namespace
AndroidKeyStoreKeyPairGeneratorSpi used the Uid as namespace which is
wrong, and ParcelableKeyGenParameterSpec inadvertently used the Uid as
namespace specifier during conversion.

Bug: 160623310
Test: com.android.keychain.tests.BasicKeyChainServiceTest#testGenerateKeyPairErrorsOnBadUid
Change-Id: I84b4c69c639e42922449e00a3708cef89b82f63e
2021-02-22 12:55:35 -08:00
Shawn Willden
bffded442a Add support for app-generated attestation keys.
This allows apps to request that AndroidKeyStore generate attestation
keys that can be used to sign attestations of other keys that the app
generates or imports.

Bug: 163606833
Test: atest CtsKeystoreTests
Change-Id: I943a6922271cbe909cb3a9d67021663b5646aa70
2021-02-17 06:46:13 -07:00
Janis Danisevskis
3faed136d5 Merge "Adding device ID attestation to KeyGenParameterSpec" 2021-02-11 20:03:01 +00:00
Janis Danisevskis
b660e617df Merge "Keystore 2.0 SPI: Fix various CTS failures." 2021-02-09 16:41:10 +00:00
Janis Danisevskis
14a82f7983 Merge "Keystore 2.0 SPI: Add CERTIFICATE_* tags." 2021-02-08 16:52:16 +00:00
Max Bires
84cd6f2257 Adding device ID attestation to KeyGenParameterSpec
Now that attestation and generation of keys occurs in the same step, the
device ID attestation parameters need to be passed into the
KeyPairGeneratorSpi. This change shifts functionality that was
previously in AttestationUtils into KeyGenParameterSpec and the
keystore2 KeyPairGeneratorSpi. The API changes should be gated to
Platform APIs and hidden from less privileged components.

Test: atest cts/tests/tests/keystore/src/android/keystore/cts/KeyGenParameterSpecTest.java
Bug: 177369988
Change-Id: Iafbc1661583bdf61da644b2c0838b9024018ee82
2021-02-07 16:44:53 -08:00
Janis Danisevskis
19cd93f603 Keystore 2.0 SPI: Fix various CTS failures.
* Add missing purpose to HMAC operations.
* Pass correct key descriptor to wrapped key import.
* Corrected error message on Import wrapped key failure due to missing
  wrapping key.
* Do not bail out on missing attestation challenge when device
  properties are requested.
* Fix AndroidKeyStoreKey.equals(). It is sufficient to compare the
  unique key ID.

Test: Keystore CTS tests.
Change-Id: Id3b93b18486e3a818ae8e91be6344294ec592e68
2021-02-07 16:42:24 -08:00
Janis Danisevskis
b6a9ed2f65 Keystore 2.0: Fix getKey returns null on key not found.
Test: CTS test.
Change-Id: I2a1edcf275da02cf005b6600450d152530eceaa9
2021-02-05 09:50:34 -08:00
Qi Wu
cca3d81204 Add limited use keys related API into Keystore 2.0 SPI.
Bug: b/174140443
Test: atest CtsKeystoreTestCases

The new CTS tests for this feature is introduced in aosp/1556464

Change-Id: I9620c4a3e5d2c10ed8a50d494e63eb2fb19dabef
Merged-In: I9620c4a3e5d2c10ed8a50d494e63eb2fb19dabef
2021-02-03 07:17:04 +00:00
Janis Danisevskis
05943c30a1 Keystore 2.0 SPI: Small fix to apease CTS test.
* The Keystore SPI needs to return null if getKeyEntry is called on a
  pure certificate entry.
* Also checked the wrong purpose.

Test: Keystore CTS tests.
Change-Id: Ib668447a9ff56fc4cea550f547c6cbfea3590cb3
2021-01-31 20:41:51 -08:00
Janis Danisevskis
f5c1e0433d Keystore 2.0 SPI: Add CERTIFICATE_* tags.
Certificate subject, serial, not before and not after information is now
passed to keystore/keymint for certificate generation.
Also makeDate accepts negative time values for dates predating Jan 1970
because the CTS tests likes to generate historic certificates.

Test: Keystore CTS tests.
Change-Id: I7ce664b010222298bda8049aad48f7db155a836d
2021-01-31 20:40:20 -08:00
Bram Bonné
b3c666454e ECDH SPI interface
Test: atest KeyAgreementTest
Bug: 171847641
Change-Id: I7cb0c713e3797bb738a6134c690824e762346d4f
2021-01-27 10:54:47 +01:00
Janis Danisevskis
a7303378bc Keystore 2 SPI: Fix KeyStorePublicKey getEncoded().
AndroidKeyStorePublicKey now returns the encoded key instead of the
encoded certificate.

Test: Keystore CTS tests.
Bug: 178456047
Change-Id: I2c9b44bd13c702545b33ed0fb4c7e802c13851f6
2021-01-26 08:14:00 -08:00
Janis Danisevskis
adeebe5e38 Keystore 2.0 SPI: Fix bug in chunked streamer.
The chunked streamer sent the chunk buffer prematurely leading to
oversized and garbage data sent to keystore.

Test: atest android.keystore.cts.SignatureTest#testSmallMsgKat
Change-Id: I84e40766b735f05b3fb7e0e692d26a25a0496649
2021-01-15 08:36:47 -08:00
Janis Danisevskis
2e494c0577 Keystore 2.0: Fix wrong exception returned on not authenticated.
Test: CtsVerifier fingerprint bound key test.
Change-Id: I0aa897455b88d7a709e4de6b515eef43bc15d053
2021-01-06 10:23:30 -08:00
Treehugger Robot
220d33ce2c Merge "Keystore 2.0 SPI: Switch to aidl union KeyParameters" 2020-12-21 18:10:58 +00:00
Janis Danisevskis
a80fd14256 Keystore 2.0 SPI: Public key operation workaround.
Test: Keystore cts tests.
Change-Id: I316fdb8beae018ac91c172dede735e6b0759368a
2020-12-18 11:15:27 -08:00
Janis Danisevskis
efaff8f604 Keystore 2.0 SPI: Bug fixes
* Correctly recover public key from certificate.
* KeyStore2ParameterUtils: iterate through set flags instead of unset
  flags.
* Return private key on Keystore.getKey() instead of public key.

Test: Keystore CTS tests
Change-Id: I99c1bd49ff5cf7a2d89b54559504e67b3def0cd3
2020-12-18 11:09:06 -08:00