mirror of
				https://github.com/cuberite/polarssl.git
				synced 2025-11-04 04:32:24 -05:00 
			
		
		
		
	Merge pull request #3696 from jdurkop/psa-support-data-storage-3289
PSA: support arbitrary data storage from opaque drivers
This commit is contained in:
		
						commit
						8bf9097872
					
				@ -256,26 +256,60 @@ static psa_status_t get_expected_key_size( const psa_key_attributes_t *attribute
 | 
				
			|||||||
                                           size_t *expected_size )
 | 
					                                           size_t *expected_size )
 | 
				
			||||||
{
 | 
					{
 | 
				
			||||||
    size_t buffer_size = 0;
 | 
					    size_t buffer_size = 0;
 | 
				
			||||||
    if( PSA_KEY_LIFETIME_GET_LOCATION( attributes->core.lifetime ) == PSA_KEY_LOCATION_LOCAL_STORAGE )
 | 
					    psa_key_location_t location = PSA_KEY_LIFETIME_GET_LOCATION( attributes->core.lifetime );
 | 
				
			||||||
 | 
					    psa_key_type_t key_type = attributes->core.type;
 | 
				
			||||||
 | 
					    size_t key_bits = attributes->core.bits;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					    switch( location )
 | 
				
			||||||
    {
 | 
					    {
 | 
				
			||||||
        buffer_size = PSA_KEY_EXPORT_MAX_SIZE( attributes->core.type,
 | 
					        case PSA_KEY_LOCATION_LOCAL_STORAGE:
 | 
				
			||||||
                                               attributes->core.bits );
 | 
					            buffer_size = PSA_KEY_EXPORT_MAX_SIZE( key_type, key_bits );
 | 
				
			||||||
 | 
					
 | 
				
			||||||
            if( buffer_size == 0 )
 | 
					            if( buffer_size == 0 )
 | 
				
			||||||
                return( PSA_ERROR_NOT_SUPPORTED );
 | 
					                return( PSA_ERROR_NOT_SUPPORTED );
 | 
				
			||||||
 | 
					
 | 
				
			||||||
            *expected_size = buffer_size;
 | 
					            *expected_size = buffer_size;
 | 
				
			||||||
            return( PSA_SUCCESS );
 | 
					            return( PSA_SUCCESS );
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#if defined(PSA_CRYPTO_DRIVER_TEST)
 | 
				
			||||||
 | 
					        case PSA_CRYPTO_TEST_DRIVER_LIFETIME:
 | 
				
			||||||
 | 
					#ifdef TEST_DRIVER_KEY_CONTEXT_SIZE_FUNCTION
 | 
				
			||||||
 | 
					            *expected_size = test_size_function( key_type, key_bits );
 | 
				
			||||||
 | 
					            return( PSA_SUCCESS );
 | 
				
			||||||
 | 
					#else /* TEST_DRIVER_KEY_CONTEXT_SIZE_FUNCTION */
 | 
				
			||||||
 | 
					            if( PSA_KEY_TYPE_IS_KEY_PAIR( key_type ) )
 | 
				
			||||||
 | 
					            {
 | 
				
			||||||
 | 
					                int public_key_overhead = ( ( TEST_DRIVER_KEY_CONTEXT_STORE_PUBLIC_KEY == 1 ) ?
 | 
				
			||||||
 | 
					                                           PSA_KEY_EXPORT_MAX_SIZE( key_type, key_bits ) : 0 );
 | 
				
			||||||
 | 
					                *expected_size = TEST_DRIVER_KEY_CONTEXT_BASE_SIZE
 | 
				
			||||||
 | 
					                                 + TEST_DRIVER_KEY_CONTEXT_PUBLIC_KEY_SIZE
 | 
				
			||||||
 | 
					                                 + public_key_overhead;
 | 
				
			||||||
 | 
					            }
 | 
				
			||||||
 | 
					            else if( PSA_KEY_TYPE_IS_PUBLIC_KEY( attributes->core.type ) )
 | 
				
			||||||
 | 
					            {
 | 
				
			||||||
 | 
					                *expected_size = TEST_DRIVER_KEY_CONTEXT_BASE_SIZE
 | 
				
			||||||
 | 
					                                 + TEST_DRIVER_KEY_CONTEXT_PUBLIC_KEY_SIZE;
 | 
				
			||||||
 | 
					            }
 | 
				
			||||||
 | 
					            else if ( !PSA_KEY_TYPE_IS_KEY_PAIR( key_type ) &&
 | 
				
			||||||
 | 
					                      !PSA_KEY_TYPE_IS_PUBLIC_KEY ( attributes->core.type ) )
 | 
				
			||||||
 | 
					            {
 | 
				
			||||||
 | 
					                *expected_size = TEST_DRIVER_KEY_CONTEXT_BASE_SIZE
 | 
				
			||||||
 | 
					                                 + TEST_DRIVER_KEY_CONTEXT_SYMMETRIC_FACTOR
 | 
				
			||||||
 | 
					                                 * ( ( key_bits + 7 ) / 8 );
 | 
				
			||||||
            }
 | 
					            }
 | 
				
			||||||
            else
 | 
					            else
 | 
				
			||||||
            {
 | 
					            {
 | 
				
			||||||
        /* TBD: opaque driver support: need to calculate size through a
 | 
					                return( PSA_ERROR_NOT_SUPPORTED );
 | 
				
			||||||
         * driver-defined size function, since the size of an opaque (wrapped)
 | 
					            }
 | 
				
			||||||
         * key will be different for each implementation. */
 | 
					            return( PSA_SUCCESS );
 | 
				
			||||||
 | 
					#endif /* TEST_DRIVER_KEY_CONTEXT_SIZE_FUNCTION */
 | 
				
			||||||
 | 
					#endif /* PSA_CRYPTO_DRIVER_TEST */
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        default:
 | 
				
			||||||
            return( PSA_ERROR_NOT_SUPPORTED );
 | 
					            return( PSA_ERROR_NOT_SUPPORTED );
 | 
				
			||||||
    }
 | 
					    }
 | 
				
			||||||
}
 | 
					}
 | 
				
			||||||
#endif /* PSA_CRYPTO_DRIVER_PRESENT */
 | 
					#endif /* PSA_CRYPTO_ACCELERATOR_DRIVER_PRESENT */
 | 
				
			||||||
 | 
					
 | 
				
			||||||
psa_status_t psa_driver_wrapper_generate_key( const psa_key_attributes_t *attributes,
 | 
					psa_status_t psa_driver_wrapper_generate_key( const psa_key_attributes_t *attributes,
 | 
				
			||||||
                                              psa_key_slot_t *slot )
 | 
					                                              psa_key_slot_t *slot )
 | 
				
			||||||
 | 
				
			|||||||
							
								
								
									
										95
									
								
								tests/include/test/drivers/size.h
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										95
									
								
								tests/include/test/drivers/size.h
									
									
									
									
									
										Normal file
									
								
							@ -0,0 +1,95 @@
 | 
				
			|||||||
 | 
					/*
 | 
				
			||||||
 | 
					 * Test driver for context size functions
 | 
				
			||||||
 | 
					 */
 | 
				
			||||||
 | 
					/*  Copyright The Mbed TLS Contributors
 | 
				
			||||||
 | 
					 *  SPDX-License-Identifier: Apache-2.0
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 *  Licensed under the Apache License, Version 2.0 (the "License"); you may
 | 
				
			||||||
 | 
					 *  not use this file except in compliance with the License.
 | 
				
			||||||
 | 
					 *  You may obtain a copy of the License at
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 *  http://www.apache.org/licenses/LICENSE-2.0
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 *  Unless required by applicable law or agreed to in writing, software
 | 
				
			||||||
 | 
					 *  distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
 | 
				
			||||||
 | 
					 *  WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 | 
				
			||||||
 | 
					 *  See the License for the specific language governing permissions and
 | 
				
			||||||
 | 
					 *  limitations under the License.
 | 
				
			||||||
 | 
					 */
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#ifndef PSA_CRYPTO_TEST_DRIVERS_SIZE_H
 | 
				
			||||||
 | 
					#define PSA_CRYPTO_TEST_DRIVERS_SIZE_H
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#if !defined(MBEDTLS_CONFIG_FILE)
 | 
				
			||||||
 | 
					#include "mbedtls/config.h"
 | 
				
			||||||
 | 
					#else
 | 
				
			||||||
 | 
					#include MBEDTLS_CONFIG_FILE
 | 
				
			||||||
 | 
					#endif
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#if defined(PSA_CRYPTO_DRIVER_TEST)
 | 
				
			||||||
 | 
					#include <psa/crypto_driver_common.h>
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					typedef struct {
 | 
				
			||||||
 | 
					    unsigned int context;
 | 
				
			||||||
 | 
					} test_driver_key_context_t;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					/** \def TEST_DRIVER_KEY_CONTEXT_BASE_SIZE
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 * This macro returns the base size for the key context. It is the size of the
 | 
				
			||||||
 | 
					 * driver specific information stored in each key context.
 | 
				
			||||||
 | 
					 */
 | 
				
			||||||
 | 
					#define TEST_DRIVER_KEY_CONTEXT_BASE_SIZE          sizeof( test_driver_key_context_t )
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					/** \def TEST_DRIVER_KEY_CONTEXT_KEY_PAIR_SIZE
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 * Number of bytes included in every key context for a key pair.
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 * This pair size is for an ECC 256-bit private/public key pair.
 | 
				
			||||||
 | 
					 * Based on this value, the size of the private key can be derived by
 | 
				
			||||||
 | 
					 * subtracting the public key size below from this one.
 | 
				
			||||||
 | 
					 */
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#define TEST_DRIVER_KEY_CONTEXT_KEY_PAIR_SIZE      65
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					/** \def TEST_DRIVER_KEY_CONTEXT_PUBLIC_KEY_SIZE
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 * Number of bytes included in every key context for a public key.
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 * For ECC public keys, it needs 257 bits so 33 bytes.
 | 
				
			||||||
 | 
					 */
 | 
				
			||||||
 | 
					#define TEST_DRIVER_KEY_CONTEXT_PUBLIC_KEY_SIZE    33
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					/** \def TEST_DRIVER_KEY_CONTEXT_SYMMETRIC_FACTOR
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 * Every key context for a symmetric key includes this many times the key size.
 | 
				
			||||||
 | 
					 */
 | 
				
			||||||
 | 
					#define TEST_DRIVER_KEY_CONTEXT_SYMMETRIC_FACTOR   0
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					/** \def TEST_DRIVER_KEY_CONTEXT_STORE_PUBLIC_KEY
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 * If this is true for a key pair, the key context includes space for the public key.
 | 
				
			||||||
 | 
					 * If this is false, no additional space is added for the public key.
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 * For this instance, store the public key with the private one.
 | 
				
			||||||
 | 
					 */
 | 
				
			||||||
 | 
					#define TEST_DRIVER_KEY_CONTEXT_STORE_PUBLIC_KEY   1
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					/** \def TEST_DRIVER_KEY_CONTEXT_SIZE_FUNCTION
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 * If TEST_DRIVER_KEY_CONTEXT_SIZE_FUNCTION is defined, the test driver
 | 
				
			||||||
 | 
					 * provides a size_function entry point, otherwise, it does not.
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 * Some opaque drivers have the need to support a custom size for the storage
 | 
				
			||||||
 | 
					 * of key and context information. The size_function provides the ability to
 | 
				
			||||||
 | 
					 * provide that customization.
 | 
				
			||||||
 | 
					 */
 | 
				
			||||||
 | 
					//#define TEST_DRIVER_KEY_CONTEXT_SIZE_FUNCTION
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#ifdef TEST_DRIVER_KEY_CONTEXT_SIZE_FUNCTION
 | 
				
			||||||
 | 
					size_t test_size_function(
 | 
				
			||||||
 | 
					    const psa_key_type_t key_type,
 | 
				
			||||||
 | 
					    const size_t key_bits );
 | 
				
			||||||
 | 
					#endif /* TEST_DRIVER_KEY_CONTEXT_SIZE_FUNCTION */
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#endif /* PSA_CRYPTO_DRIVER_TEST */
 | 
				
			||||||
 | 
					#endif /* PSA_CRYPTO_TEST_DRIVERS_SIZE_H */
 | 
				
			||||||
@ -25,5 +25,6 @@
 | 
				
			|||||||
#include "test/drivers/signature.h"
 | 
					#include "test/drivers/signature.h"
 | 
				
			||||||
#include "test/drivers/keygen.h"
 | 
					#include "test/drivers/keygen.h"
 | 
				
			||||||
#include "test/drivers/cipher.h"
 | 
					#include "test/drivers/cipher.h"
 | 
				
			||||||
 | 
					#include "test/drivers/size.h"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
#endif /* PSA_CRYPTO_TEST_DRIVER_H */
 | 
					#endif /* PSA_CRYPTO_TEST_DRIVER_H */
 | 
				
			||||||
 | 
				
			|||||||
							
								
								
									
										42
									
								
								tests/src/drivers/size.c
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										42
									
								
								tests/src/drivers/size.c
									
									
									
									
									
										Normal file
									
								
							@ -0,0 +1,42 @@
 | 
				
			|||||||
 | 
					/*
 | 
				
			||||||
 | 
					 * Test driver for retrieving key context size.
 | 
				
			||||||
 | 
					 * Only used by opaque drivers.
 | 
				
			||||||
 | 
					 */
 | 
				
			||||||
 | 
					/*  Copyright The Mbed TLS Contributors
 | 
				
			||||||
 | 
					 *  SPDX-License-Identifier: Apache-2.0
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 *  Licensed under the Apache License, Version 2.0 (the "License"); you may
 | 
				
			||||||
 | 
					 *  not use this file except in compliance with the License.
 | 
				
			||||||
 | 
					 *  You may obtain a copy of the License at
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 *  http://www.apache.org/licenses/LICENSE-2.0
 | 
				
			||||||
 | 
					 *
 | 
				
			||||||
 | 
					 *  Unless required by applicable law or agreed to in writing, software
 | 
				
			||||||
 | 
					 *  distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
 | 
				
			||||||
 | 
					 *  WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 | 
				
			||||||
 | 
					 *  See the License for the specific language governing permissions and
 | 
				
			||||||
 | 
					 *  limitations under the License.
 | 
				
			||||||
 | 
					 */
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#if !defined(MBEDTLS_CONFIG_FILE)
 | 
				
			||||||
 | 
					#include "mbedtls/config.h"
 | 
				
			||||||
 | 
					#else
 | 
				
			||||||
 | 
					#include MBEDTLS_CONFIG_FILE
 | 
				
			||||||
 | 
					#endif
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#if defined(MBEDTLS_PSA_CRYPTO_DRIVERS) && defined(PSA_CRYPTO_DRIVER_TEST)
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#include "test/drivers/size.h"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#ifdef TEST_KEY_CONTEXT_SIZE_FUNCTION
 | 
				
			||||||
 | 
					size_t test_size_function(
 | 
				
			||||||
 | 
					    const psa_key_type_t key_type,
 | 
				
			||||||
 | 
					    const size_t key_bits )
 | 
				
			||||||
 | 
					{
 | 
				
			||||||
 | 
					    (void) key_type;
 | 
				
			||||||
 | 
					    (void) key_bits;
 | 
				
			||||||
 | 
					    return 0;
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 | 
					#endif /*TEST_KEY_CONTEXT_SIZE_FUNCTION */
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					#endif /* MBEDTLS_PSA_CRYPTO_DRIVERS && PSA_CRYPTO_DRIVER_TEST */
 | 
				
			||||||
@ -241,6 +241,7 @@
 | 
				
			|||||||
    <ClInclude Include="..\..\tests\include\test\drivers\cipher.h" />
 | 
					    <ClInclude Include="..\..\tests\include\test\drivers\cipher.h" />
 | 
				
			||||||
    <ClInclude Include="..\..\tests\include\test\drivers\keygen.h" />
 | 
					    <ClInclude Include="..\..\tests\include\test\drivers\keygen.h" />
 | 
				
			||||||
    <ClInclude Include="..\..\tests\include\test\drivers\signature.h" />
 | 
					    <ClInclude Include="..\..\tests\include\test\drivers\signature.h" />
 | 
				
			||||||
 | 
					    <ClInclude Include="..\..\tests\include\test\drivers\size.h" />
 | 
				
			||||||
    <ClInclude Include="..\..\tests\include\test\drivers\test_driver.h" />
 | 
					    <ClInclude Include="..\..\tests\include\test\drivers\test_driver.h" />
 | 
				
			||||||
    <ClInclude Include="..\..\library\common.h" />
 | 
					    <ClInclude Include="..\..\library\common.h" />
 | 
				
			||||||
    <ClInclude Include="..\..\library\psa_crypto_core.h" />
 | 
					    <ClInclude Include="..\..\library\psa_crypto_core.h" />
 | 
				
			||||||
 | 
				
			|||||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user