Skip to content

Commit

Permalink
set security level properly
Browse files Browse the repository at this point in the history
  • Loading branch information
5ec1cff committed Jul 28, 2024
1 parent 3ea1502 commit fca5bde
Show file tree
Hide file tree
Showing 2 changed files with 8 additions and 4 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -133,15 +133,15 @@ object KeystoreInterceptor : BinderInterceptor() {
keystore.linkToDeath(Killer, 0)
if (tee != null) {
Logger.i("register for TEE SecurityLevel $tee!")
val interceptor = SecurityLevelInterceptor(tee)
val interceptor = SecurityLevelInterceptor(tee, SecurityLevel.TRUSTED_ENVIRONMENT)
registerBinderInterceptor(bd, tee.asBinder(), interceptor)
teeInterceptor = interceptor
} else {
Logger.i("no TEE SecurityLevel found!")
}
if (strongBox != null) {
Logger.i("register for StrongBox SecurityLevel $tee!")
val interceptor = SecurityLevelInterceptor(strongBox)
val interceptor = SecurityLevelInterceptor(strongBox, SecurityLevel.STRONGBOX)
registerBinderInterceptor(bd, strongBox.asBinder(), interceptor)
strongBoxInterceptor = interceptor
} else {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,10 @@ import java.security.KeyPair
import java.security.cert.Certificate
import java.util.concurrent.ConcurrentHashMap

class SecurityLevelInterceptor(private val original: IKeystoreSecurityLevel) : BinderInterceptor() {
class SecurityLevelInterceptor(
private val original: IKeystoreSecurityLevel,
private val level: Int
) : BinderInterceptor() {
companion object {
private val generateKeyTransaction =
getTransactCode(IKeystoreSecurityLevel.Stub::class.java, "generateKey")
Expand Down Expand Up @@ -79,6 +82,7 @@ class SecurityLevelInterceptor(private val original: IKeystoreSecurityLevel) : B
): KeyEntryResponse {
val response = KeyEntryResponse()
val metadata = KeyMetadata()
metadata.keySecurityLevel = level
Utils.putCertificateChain(metadata, chain.toTypedArray<Certificate>())
val d = KeyDescriptor()
d.domain = descriptor.domain
Expand All @@ -91,7 +95,7 @@ class SecurityLevelInterceptor(private val original: IKeystoreSecurityLevel) : B
a.keyParameter = KeyParameter()
a.keyParameter.tag = Tag.PURPOSE
a.keyParameter.value = KeyParameterValue.keyPurpose(i)
a.securityLevel = SecurityLevel.TRUSTED_ENVIRONMENT
a.securityLevel = level
authorizations.add(a)
}
for (i in params.digest) {
Expand Down

0 comments on commit fca5bde

Please sign in to comment.