- made establishpacechannel output independant from any byte order conversion.
little endian handling is done by the ccid-part. - pacelib exports PACE-functionality. git-svn-id: https://vsmartcard.svn.sourceforge.net/svnroot/vsmartcard@223 96b47cad-a561-4643-ad3b-153ac7d7599c
This commit is contained in:
117
ccid/src/pace/pace.h
Normal file
117
ccid/src/pace/pace.h
Normal file
@@ -0,0 +1,117 @@
|
||||
/*
|
||||
* Copyright (C) 2010 Frank Morgner
|
||||
*
|
||||
* This file is part of ccid.
|
||||
*
|
||||
* ccid is free software: you can redistribute it and/or modify it under the
|
||||
* terms of the GNU General Public License as published by the Free Software
|
||||
* Foundation, either version 3 of the License, or (at your option) any later
|
||||
* version.
|
||||
*
|
||||
* ccid is distributed in the hope that it will be useful, but WITHOUT ANY
|
||||
* WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
|
||||
* FOR A PARTICULAR PURPOSE. See the GNU General Public License for more
|
||||
* details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License along with
|
||||
* ccid. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
#ifndef _CCID_PACE_H
|
||||
#define _CCID_PACE_H
|
||||
|
||||
#include <pace/pace_lib.h>
|
||||
#include <pace/sm.h>
|
||||
#include <opensc/opensc.h>
|
||||
#include <openssl/bn.h>
|
||||
#include <openssl/pace.h>
|
||||
|
||||
#ifdef __cplusplus
|
||||
extern "C" {
|
||||
#endif
|
||||
|
||||
#define PACE_BITMAP_PACE 0x40
|
||||
#define PACE_BITMAP_EID 0x20
|
||||
#define PACE_BITMAP_ESIGN 0x10
|
||||
|
||||
//#define PACE_MRZ 0x01
|
||||
//#define PACE_CAN 0x02
|
||||
//#define PACE_PIN 0x03
|
||||
//#define PACE_PUK 0x04
|
||||
|
||||
#define FID_EF_CARDACCESS 0x011C
|
||||
|
||||
#define MAX_EF_CARDACCESS 2048
|
||||
#define MAX_PIN_LEN 6
|
||||
#define MIN_PIN_LEN 6
|
||||
#define MAX_MRZ_LEN 128
|
||||
|
||||
int increment_ssc(struct pace_sm_ctx *psmctx);
|
||||
int decrement_ssc(struct pace_sm_ctx *psmctx);
|
||||
int reset_ssc(struct pace_sm_ctx *psmctx);
|
||||
|
||||
const char *pace_secret_name(enum s_type pin_id);
|
||||
|
||||
int pace_sm_encrypt(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
const u8 *data, size_t datalen, u8 **enc);
|
||||
int pace_sm_decrypt(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
const u8 *enc, size_t enclen, u8 **data);
|
||||
int pace_sm_authenticate(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
const u8 *data, size_t datalen, u8 **outdata);
|
||||
int pace_sm_verify_authentication(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
const u8 *mac, size_t maclen,
|
||||
const u8 *macdata, size_t macdatalen);
|
||||
int pace_sm_pre_transmit(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
sc_apdu_t *apdu);
|
||||
int pace_sm_post_transmit(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
sc_apdu_t *sm_apdu);
|
||||
|
||||
|
||||
struct establish_pace_channel_input {
|
||||
unsigned char pin_id;
|
||||
|
||||
size_t chat_length;
|
||||
const unsigned char *chat;
|
||||
|
||||
size_t pin_length;
|
||||
const unsigned char *pin;
|
||||
|
||||
size_t certificate_description_length;
|
||||
const unsigned char *certificate_description;
|
||||
};
|
||||
|
||||
struct establish_pace_channel_output {
|
||||
unsigned char mse_set_at_sw1;
|
||||
unsigned char mse_set_at_sw2;
|
||||
|
||||
size_t ef_cardaccess_length;
|
||||
unsigned char *ef_cardaccess;
|
||||
|
||||
size_t recent_car_length;
|
||||
unsigned char *recent_car;
|
||||
|
||||
size_t previous_car_length;
|
||||
unsigned char *previous_car;
|
||||
|
||||
size_t id_icc_length;
|
||||
unsigned char *id_icc;
|
||||
};
|
||||
|
||||
int GetReadersPACECapabilities(u8 *bitmap);
|
||||
|
||||
int EstablishPACEChannel(const struct sm_ctx *oldpacectx, sc_card_t *card,
|
||||
struct establish_pace_channel_input pace_input,
|
||||
struct establish_pace_channel_output *pace_output,
|
||||
struct sm_ctx *sctx);
|
||||
|
||||
int pace_reset_retry_counter(struct sm_ctx *ctx, sc_card_t *card,
|
||||
enum s_type pin_id, int ask_for_secret,
|
||||
const char *new, size_t new_len);
|
||||
#define pace_unblock_pin(ctx, card) \
|
||||
pace_reset_retry_counter(ctx, card, PACE_PIN, 0, NULL, 0)
|
||||
#define pace_change_pin(ctx, card, newp, newplen) \
|
||||
pace_reset_retry_counter(ctx, card, PACE_PIN, 1, newp, newplen)
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
#endif
|
||||
#endif
|
||||
44
ccid/src/pace/pace_lib.h
Normal file
44
ccid/src/pace/pace_lib.h
Normal file
@@ -0,0 +1,44 @@
|
||||
/*
|
||||
* Copyright (C) 2010 Frank Morgner
|
||||
*
|
||||
* This file is part of ccid.
|
||||
*
|
||||
* ccid is free software: you can redistribute it and/or modify it under the
|
||||
* terms of the GNU General Public License as published by the Free Software
|
||||
* Foundation, either version 3 of the License, or (at your option) any later
|
||||
* version.
|
||||
*
|
||||
* ccid is distributed in the hope that it will be useful, but WITHOUT ANY
|
||||
* WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
|
||||
* FOR A PARTICULAR PURPOSE. See the GNU General Public License for more
|
||||
* details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License along with
|
||||
* ccid. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
#ifndef _CCID_PACE_LIB_H
|
||||
#define _CCID_PACE_LIB_H
|
||||
|
||||
#include <openssl/pace.h>
|
||||
|
||||
#ifdef __cplusplus
|
||||
extern "C" {
|
||||
#endif
|
||||
|
||||
struct pace_sm_ctx {
|
||||
BIGNUM *ssc;
|
||||
const BUF_MEM *key_mac;
|
||||
const BUF_MEM *key_enc;
|
||||
PACE_CTX *ctx;
|
||||
};
|
||||
|
||||
|
||||
struct pace_sm_ctx * pace_sm_ctx_create(const BUF_MEM *key_mac,
|
||||
const BUF_MEM *key_enc, PACE_CTX *ctx);
|
||||
void pace_sm_ctx_free(struct pace_sm_ctx *ctx);
|
||||
void pace_sm_ctx_clear_free(struct pace_sm_ctx *ctx);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
#endif
|
||||
#endif
|
||||
38
ccid/src/pace/scutil.h
Normal file
38
ccid/src/pace/scutil.h
Normal file
@@ -0,0 +1,38 @@
|
||||
/*
|
||||
* Copyright (C) 2010 Frank Morgner
|
||||
*
|
||||
* This file is part of ccid.
|
||||
*
|
||||
* ccid is free software: you can redistribute it and/or modify it under the
|
||||
* terms of the GNU General Public License as published by the Free Software
|
||||
* Foundation, either version 3 of the License, or (at your option) any later
|
||||
* version.
|
||||
*
|
||||
* ccid is distributed in the hope that it will be useful, but WITHOUT ANY
|
||||
* WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
|
||||
* FOR A PARTICULAR PURPOSE. See the GNU General Public License for more
|
||||
* details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License along with
|
||||
* ccid. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
#ifndef _CCID_SCUTIL_H
|
||||
#define _CCID_SCUTIL_H
|
||||
|
||||
#include <opensc/opensc.h>
|
||||
|
||||
int initialize(int reader_id, const char *cdriver, int verbose,
|
||||
sc_context_t **ctx, sc_reader_t **reader);
|
||||
|
||||
int build_apdu(sc_context_t *ctx, const u8 *buf, size_t len, sc_apdu_t *apdu);
|
||||
|
||||
#define bin_print(file, label, data, len) \
|
||||
_bin_log(NULL, 0, NULL, 0, NULL, label, data, len, file)
|
||||
#define bin_log(ctx, label, data, len) \
|
||||
_bin_log(ctx, SC_LOG_TYPE_DEBUG, __FILE__, __LINE__, __FUNCTION__, label, data, len, NULL)
|
||||
void _bin_log(sc_context_t *ctx, int type, const char *file, int line,
|
||||
const char *func, const char *label, const u8 *data, size_t len,
|
||||
FILE *f);
|
||||
|
||||
#endif
|
||||
|
||||
66
ccid/src/pace/sm.h
Normal file
66
ccid/src/pace/sm.h
Normal file
@@ -0,0 +1,66 @@
|
||||
/*
|
||||
* Copyright (C) 2010 Frank Morgner
|
||||
*
|
||||
* This file is part of ccid.
|
||||
*
|
||||
* ccid is free software: you can redistribute it and/or modify it under the
|
||||
* terms of the GNU General Public License as published by the Free Software
|
||||
* Foundation, either version 3 of the License, or (at your option) any later
|
||||
* version.
|
||||
*
|
||||
* ccid is distributed in the hope that it will be useful, but WITHOUT ANY
|
||||
* WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
|
||||
* FOR A PARTICULAR PURPOSE. See the GNU General Public License for more
|
||||
* details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License along with
|
||||
* ccid. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
#ifndef _CCID_SM_H
|
||||
#define _CCID_SM_H
|
||||
|
||||
#include <opensc/opensc.h>
|
||||
|
||||
#ifdef __cplusplus
|
||||
extern "C" {
|
||||
#endif
|
||||
|
||||
#define SM_ISO_PADDING 0x01
|
||||
#define SM_NO_PADDING 0x02
|
||||
|
||||
struct sm_ctx {
|
||||
unsigned char active;
|
||||
|
||||
u8 padding_indicator;
|
||||
size_t block_length;
|
||||
|
||||
void *authentication_ctx;
|
||||
int (*authenticate)(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
const u8 *data, size_t datalen, u8 **outdata);
|
||||
int (*verify_authentication)(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
const u8 *mac, size_t maclen,
|
||||
const u8 *macdata, size_t macdatalen);
|
||||
|
||||
void *cipher_ctx;
|
||||
int (*encrypt)(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
const u8 *data, size_t datalen, u8 **enc);
|
||||
int (*decrypt)(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
const u8 *enc, size_t enclen, u8 **data);
|
||||
|
||||
int (*pre_transmit)(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
sc_apdu_t *apdu);
|
||||
int (*post_transmit)(sc_card_t *card, const struct sm_ctx *ctx,
|
||||
sc_apdu_t *sm_apdu);
|
||||
};
|
||||
|
||||
int sm_transmit_apdu(const struct sm_ctx *sctx, sc_card_t *card,
|
||||
sc_apdu_t *apdu);
|
||||
|
||||
int add_iso_pad(const u8 *data, size_t datalen, int block_size, u8 **padded);
|
||||
int add_padding(const struct sm_ctx *ctx, const u8 *data, size_t datalen,
|
||||
u8 **padded);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
#endif
|
||||
#endif
|
||||
Reference in New Issue
Block a user