4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/** @file
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync The runtime cryptographic protocol.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Only limited crypto primitives (SHA-256 and RSA) are provided for runtime
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync authenticated variable service.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncCopyright (c) 2010 - 2012, Intel Corporation. All rights reserved.<BR>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncThis program and the accompanying materials
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncare licensed and made available under the terms and conditions of the BSD License
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncwhich accompanies this distribution. The full text of the license may be found at
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynchttp://opensource.org/licenses/bsd-license.php
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncTHE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncWITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync**/
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#ifndef __EFI_RUNTIME_CRYPT_PROTOCOL_H__
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#define __EFI_RUNTIME_CRYPT_PROTOCOL_H__
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#include <Library/BaseCryptLib.h>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync///
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/// Runtime Cryptographic Protocol GUID.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync///
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#define EFI_RUNTIME_CRYPT_PROTOCOL_GUID \
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync { \
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync 0xe1475e0c, 0x1746, 0x4802, { 0x86, 0x2e, 0x1, 0x1c, 0x2c, 0x2d, 0x9d, 0x86 } \
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/**
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Retrieves the size, in bytes, of the context buffer required for SHA-256 operations.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @return The size, in bytes, of the context buffer required for SHA-256 operations.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync**/
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynctypedef
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncUINTN
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync(EFIAPI *EFI_RUNTIME_CRYPT_SHA256_GET_CONTEXT_SIZE) (
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync VOID
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync );
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/**
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Initializes user-supplied memory pointed by Sha256Context as SHA-256 hash context for
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync subsequent use.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If Sha256Context is NULL, then return FALSE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in, out] Sha256Context Pointer to SHA-256 Context being initialized.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @retval TRUE SHA-256 context initialization succeeded.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @retval FALSE SHA-256 context initialization failed.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync**/
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynctypedef
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncBOOLEAN
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync(EFIAPI *EFI_RUNTIME_CRYPT_SHA256_INIT) (
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN OUT VOID *Sha256Context
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync );
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/**
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Performs SHA-256 digest on a data buffer of the specified length. This function can
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync be called multiple times to compute the digest of long or discontinuous data streams.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If Sha256Context is NULL, then return FALSE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in, out] Sha256Context Pointer to the SHA-256 context.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] Data Pointer to the buffer containing the data to be hashed.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] DataLength Length of Data buffer in bytes.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @retval TRUE SHA-256 data digest succeeded.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @retval FALSE Invalid SHA-256 context. After Sha256Final function has been called, the
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync SHA-256 context cannot be reused.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync**/
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynctypedef
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncBOOLEAN
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync(EFIAPI *EFI_RUNTIME_CRYPT_SHA256_UPDATE) (
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN OUT VOID *Sha256Context,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN CONST VOID *Data,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN UINTN DataLength
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync );
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/**
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Completes SHA-256 hash computation and retrieves the digest value into the specified
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync memory. After this function has been called, the SHA-256 context cannot be used again.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If Sha256Context is NULL, then return FALSE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If HashValue is NULL, then return FALSE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in, out] Sha256Context Pointer to SHA-256 context
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[out] HashValue Pointer to a buffer that receives the SHA-256 digest
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync value (32 bytes).
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @retval TRUE SHA-256 digest computation succeeded.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @retval FALSE SHA-256 digest computation failed.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync**/
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynctypedef
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncBOOLEAN
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync(EFIAPI *EFI_RUNTIME_CRYPT_SHA256_FINAL) (
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN OUT VOID *Sha256Context,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync OUT UINT8 *HashValue
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync );
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/**
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Allocates and Initializes one RSA Context for subsequent use.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @return Pointer to the RSA Context that has been initialized.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If the allocations fails, RsaNew() returns NULL.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync**/
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynctypedef
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncVOID *
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync(EFIAPI *EFI_RUNTIME_CRYPT_RSA_NEW) (
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync VOID
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync );
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/**
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Release the specified RSA Context.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] RsaContext Pointer to the RSA context to be released.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync**/
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynctypedef
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncVOID
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync(EFIAPI *EFI_RUNTIME_CRYPT_RSA_FREE) (
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN VOID *RsaContext
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync );
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/**
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Sets the tag-designated RSA key component into the established RSA context from
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync the user-specified nonnegative integer (octet string format represented in RSA
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync PKCS#1).
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If RsaContext is NULL, then return FALSE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in, out] RsaContext Pointer to RSA context being set.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] KeyTag Tag of RSA key component being set.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] BigNumber Pointer to octet integer buffer.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] BnLength Length of big number buffer in bytes.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @return TRUE RSA key component was set successfully.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @return FALSE Invalid RSA key component tag.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync**/
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynctypedef
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncBOOLEAN
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync(EFIAPI *EFI_RUNTIME_CRYPT_RSA_SET_KEY) (
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN OUT VOID *RsaContext,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN RSA_KEY_TAG KeyTag,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN CONST UINT8 *BigNumber,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN UINTN BnLength
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync );
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/**
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Verifies the RSA-SSA signature with EMSA-PKCS1-v1_5 encoding scheme defined in
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync RSA PKCS#1.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If RsaContext is NULL, then return FALSE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If MessageHash is NULL, then return FALSE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If Signature is NULL, then return FALSE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If HashLength is not equal to the size of MD5, SHA-1 or SHA-256 digest, then return FALSE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] RsaContext Pointer to RSA context for signature verification.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] MessageHash Pointer to octet message hash to be checked.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] HashLength Length of the message hash in bytes.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] Signature Pointer to RSA PKCS1-v1_5 signature to be verified.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @param[in] SigLength Length of signature in bytes.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @return TRUE Valid signature encoded in PKCS1-v1_5.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync @return FALSE Invalid signature or invalid RSA context.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync**/
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynctypedef
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncBOOLEAN
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync(EFIAPI *EFI_RUNTIME_CRYPT_RSA_PKCS1_VERIFY) (
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN VOID *RsaContext,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN CONST UINT8 *MessageHash,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN UINTN HashLength,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN UINT8 *Signature,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IN UINTN SigLength
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync );
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync///
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/// Runtime Cryptographic Protocol Structure.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync///
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynctypedef struct {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync EFI_RUNTIME_CRYPT_SHA256_GET_CONTEXT_SIZE Sha256GetContextSize;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync EFI_RUNTIME_CRYPT_SHA256_INIT Sha256Init;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync EFI_RUNTIME_CRYPT_SHA256_UPDATE Sha256Update;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync EFI_RUNTIME_CRYPT_SHA256_FINAL Sha256Final;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync EFI_RUNTIME_CRYPT_RSA_NEW RsaNew;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync EFI_RUNTIME_CRYPT_RSA_FREE RsaFree;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync EFI_RUNTIME_CRYPT_RSA_SET_KEY RsaSetKey;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync EFI_RUNTIME_CRYPT_RSA_PKCS1_VERIFY RsaPkcs1Verify;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync} EFI_RUNTIME_CRYPT_PROTOCOL;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncextern EFI_GUID gEfiRuntimeCryptProtocolGuid;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#endif