| OLD | NEW |
| (Empty) |
| 1 // Copyright 2014 The Chromium Authors. All rights reserved. | |
| 2 // Use of this source code is governed by a BSD-style license that can be | |
| 3 // found in the LICENSE file. | |
| 4 | |
| 5 #ifndef CONTENT_CHILD_WEBCRYPTO_WEBCRYPTO_UTIL_H_ | |
| 6 #define CONTENT_CHILD_WEBCRYPTO_WEBCRYPTO_UTIL_H_ | |
| 7 | |
| 8 #include <stdint.h> | |
| 9 #include <string> | |
| 10 | |
| 11 #include "base/values.h" | |
| 12 #include "content/common/content_export.h" | |
| 13 #include "third_party/WebKit/public/platform/WebCryptoAlgorithm.h" | |
| 14 #include "third_party/WebKit/public/platform/WebCryptoKey.h" | |
| 15 | |
| 16 namespace content { | |
| 17 | |
| 18 namespace webcrypto { | |
| 19 | |
| 20 class Status; | |
| 21 | |
| 22 // Creates a WebCryptoAlgorithm without any parameters. | |
| 23 CONTENT_EXPORT blink::WebCryptoAlgorithm CreateAlgorithm( | |
| 24 blink::WebCryptoAlgorithmId id); | |
| 25 | |
| 26 // Creates an HMAC import algorithm whose inner hash algorithm is determined by | |
| 27 // the specified algorithm ID. It is an error to call this method with a hash | |
| 28 // algorithm that is not SHA*. | |
| 29 CONTENT_EXPORT blink::WebCryptoAlgorithm CreateHmacImportAlgorithm( | |
| 30 blink::WebCryptoAlgorithmId hash_id, | |
| 31 unsigned int length_bits); | |
| 32 | |
| 33 // Same as above but without specifying a length. | |
| 34 CONTENT_EXPORT blink::WebCryptoAlgorithm CreateHmacImportAlgorithmNoLength( | |
| 35 blink::WebCryptoAlgorithmId hash_id); | |
| 36 | |
| 37 // Creates an import algorithm for RSA algorithms that take a hash. | |
| 38 // It is an error to call this with a hash_id that is not a SHA*. | |
| 39 CONTENT_EXPORT blink::WebCryptoAlgorithm CreateRsaHashedImportAlgorithm( | |
| 40 blink::WebCryptoAlgorithmId id, | |
| 41 blink::WebCryptoAlgorithmId hash_id); | |
| 42 | |
| 43 // Creates an import algorithm for EC keys. | |
| 44 CONTENT_EXPORT blink::WebCryptoAlgorithm CreateEcImportAlgorithm( | |
| 45 blink::WebCryptoAlgorithmId id, | |
| 46 blink::WebCryptoNamedCurve named_curve); | |
| 47 | |
| 48 // Returns true if the set bits in b make up a subset of the set bits in a. | |
| 49 bool ContainsKeyUsages(blink::WebCryptoKeyUsageMask a, | |
| 50 blink::WebCryptoKeyUsageMask b); | |
| 51 | |
| 52 bool KeyUsageAllows(const blink::WebCryptoKey& key, | |
| 53 const blink::WebCryptoKeyUsage usage); | |
| 54 | |
| 55 Status GetAesGcmTagLengthInBits(const blink::WebCryptoAesGcmParams* params, | |
| 56 unsigned int* tag_length_bits); | |
| 57 | |
| 58 Status GetAesKeyGenLengthInBits(const blink::WebCryptoAesKeyGenParams* params, | |
| 59 unsigned int* keylen_bits); | |
| 60 | |
| 61 Status GetHmacKeyGenLengthInBits(const blink::WebCryptoHmacKeyGenParams* params, | |
| 62 unsigned int* keylen_bits); | |
| 63 | |
| 64 // Gets the requested key length in bits for an HMAC import operation. | |
| 65 Status GetHmacImportKeyLengthBits( | |
| 66 const blink::WebCryptoHmacImportParams* params, | |
| 67 unsigned int key_data_byte_length, | |
| 68 unsigned int* keylen_bits); | |
| 69 | |
| 70 Status VerifyAesKeyLengthForImport(unsigned int keylen_bytes); | |
| 71 | |
| 72 Status CheckKeyCreationUsages(blink::WebCryptoKeyUsageMask all_possible_usages, | |
| 73 blink::WebCryptoKeyUsageMask actual_usages, | |
| 74 bool allow_empty_usages); | |
| 75 | |
| 76 // Extracts the public exponent and modulus length from the Blink parameters. | |
| 77 // On success it is guaranteed that: | |
| 78 // * public_exponent is either 3 or 65537 | |
| 79 // * modulus_length_bits is a multiple of 8 | |
| 80 // * modulus_length is >= 256 | |
| 81 // * modulus_length is <= 16K | |
| 82 Status GetRsaKeyGenParameters( | |
| 83 const blink::WebCryptoRsaHashedKeyGenParams* params, | |
| 84 unsigned int* public_exponent, | |
| 85 unsigned int* modulus_length_bits); | |
| 86 | |
| 87 // Verifies that |usages| is valid when importing a key of the given format. | |
| 88 Status VerifyUsagesBeforeImportAsymmetricKey( | |
| 89 blink::WebCryptoKeyFormat format, | |
| 90 blink::WebCryptoKeyUsageMask all_public_key_usages, | |
| 91 blink::WebCryptoKeyUsageMask all_private_key_usages, | |
| 92 blink::WebCryptoKeyUsageMask usages); | |
| 93 | |
| 94 // Truncates an octet string to a particular bit length. This is accomplished by | |
| 95 // resizing to the closest byte length, and then zero-ing the unused | |
| 96 // least-significant bits of the final byte. | |
| 97 // | |
| 98 // It is an error to call this function with a bit length that is larger than | |
| 99 // that of |bytes|. | |
| 100 // | |
| 101 // TODO(eroman): This operation is not yet defined by the WebCrypto spec, | |
| 102 // however this is a reasonable interpretation: | |
| 103 // https://www.w3.org/Bugs/Public/show_bug.cgi?id=27402 | |
| 104 void TruncateToBitLength(size_t length_bits, std::vector<uint8_t>* bytes); | |
| 105 | |
| 106 // Rounds a bit count (up) to the nearest byte count. | |
| 107 // | |
| 108 // This is mathematically equivalent to (x + 7) / 8, however has no | |
| 109 // possibility of integer overflow. | |
| 110 template <typename T> | |
| 111 T NumBitsToBytes(T x) { | |
| 112 return (x / 8) + (7 + (x % 8)) / 8; | |
| 113 } | |
| 114 | |
| 115 // The "get key length" operation for AES keys. | |
| 116 Status GetAesKeyLength(const blink::WebCryptoAlgorithm& key_length_algorithm, | |
| 117 bool* has_length_bits, | |
| 118 unsigned int* length_bits); | |
| 119 | |
| 120 // The "get key length" operation for HMAC keys. | |
| 121 Status GetHmacKeyLength(const blink::WebCryptoAlgorithm& key_length_algorithm, | |
| 122 bool* has_length_bits, | |
| 123 unsigned int* length_bits); | |
| 124 | |
| 125 // Splits the combined usages given to GenerateKey() into the respective usages | |
| 126 // for the public key and private key. Returns an error if the usages are | |
| 127 // invalid. | |
| 128 Status GetUsagesForGenerateAsymmetricKey( | |
| 129 blink::WebCryptoKeyUsageMask combined_usages, | |
| 130 blink::WebCryptoKeyUsageMask all_public_usages, | |
| 131 blink::WebCryptoKeyUsageMask all_private_usages, | |
| 132 blink::WebCryptoKeyUsageMask* public_usages, | |
| 133 blink::WebCryptoKeyUsageMask* private_usages); | |
| 134 | |
| 135 } // namespace webcrypto | |
| 136 | |
| 137 } // namespace content | |
| 138 | |
| 139 #endif // CONTENT_CHILD_WEBCRYPTO_WEBCRYPTO_UTIL_H_ | |
| OLD | NEW |