1/* 2 * Copyright (C) 2016 The Android Open Source Project 3 * 4 * Licensed under the Apache License, Version 2.0 (the "License"); 5 * you may not use this file except in compliance with the License. 6 * You may obtain a copy of the License at 7 * 8 * http://www.apache.org/licenses/LICENSE-2.0 9 * 10 * Unless required by applicable law or agreed to in writing, software 11 * distributed under the License is distributed on an "AS IS" BASIS, 12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 * See the License for the specific language governing permissions and 14 * limitations under the License. 15 */ 16 17#ifndef ANDROID_VOLD_KEYSTORAGE_H 18#define ANDROID_VOLD_KEYSTORAGE_H 19 20#include <string> 21 22namespace android { 23namespace vold { 24 25// Represents the information needed to decrypt a disk encryption key. 26// If "token" is nonempty, it is passed in as a required Gatekeeper auth token. 27// If "token" and "secret" are nonempty, "secret" is appended to the application-specific 28// binary needed to unlock. 29// If only "secret" is nonempty, it is used to decrypt in a non-Keymaster process. 30class KeyAuthentication { 31 public: 32 KeyAuthentication(std::string t, std::string s) : token{t}, secret{s} {}; 33 34 bool usesKeymaster() const { return !token.empty() || secret.empty(); }; 35 36 const std::string token; 37 const std::string secret; 38}; 39 40extern const KeyAuthentication kEmptyAuthentication; 41 42// Create a directory at the named path, and store "key" in it, 43// in such a way that it can only be retrieved via Keymaster and 44// can be securely deleted. 45// It's safe to move/rename the directory after creation. 46bool storeKey(const std::string& dir, const KeyAuthentication& auth, const std::string& key); 47 48// Retrieve the key from the named directory. 49bool retrieveKey(const std::string& dir, const KeyAuthentication& auth, std::string* key); 50 51// Securely destroy the key stored in the named directory and delete the directory. 52bool destroyKey(const std::string& dir); 53 54bool runSecdiscardSingle(const std::string& file); 55} // namespace vold 56} // namespace android 57 58#endif 59