furi_hal_crypto.c 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203
  1. #include <furi_hal_crypto.h>
  2. #include <furi_hal_bt.h>
  3. #include <furi_hal_random.h>
  4. #include <furi.h>
  5. #include <shci.h>
  6. #define TAG "FuriHalCrypto"
  7. CRYP_HandleTypeDef crypt;
  8. #define ENCLAVE_FACTORY_KEY_SLOTS 10
  9. #define ENCLAVE_SIGNATURE_SIZE 16
  10. static const uint8_t enclave_signature_iv[ENCLAVE_FACTORY_KEY_SLOTS][16] = {
  11. {0xac, 0x5d, 0x68, 0xb8, 0x79, 0x74, 0xfc, 0x7f, 0x45, 0x02, 0x82, 0xf1, 0x48, 0x7e, 0x75, 0x8a},
  12. {0x38, 0xe6, 0x6a, 0x90, 0x5e, 0x5b, 0x8a, 0xa6, 0x70, 0x30, 0x04, 0x72, 0xc2, 0x42, 0xea, 0xaf},
  13. {0x73, 0xd5, 0x8e, 0xfb, 0x0f, 0x4b, 0xa9, 0x79, 0x0f, 0xde, 0x0e, 0x53, 0x44, 0x7d, 0xaa, 0xfd},
  14. {0x3c, 0x9a, 0xf4, 0x43, 0x2b, 0xfe, 0xea, 0xae, 0x8c, 0xc6, 0xd1, 0x60, 0xd2, 0x96, 0x64, 0xa9},
  15. {0x10, 0xac, 0x7b, 0x63, 0x03, 0x7f, 0x43, 0x18, 0xec, 0x9d, 0x9c, 0xc4, 0x01, 0xdc, 0x35, 0xa7},
  16. {0x26, 0x21, 0x64, 0xe6, 0xd0, 0xf2, 0x47, 0x49, 0xdc, 0x36, 0xcd, 0x68, 0x0c, 0x91, 0x03, 0x44},
  17. {0x7a, 0xbd, 0xce, 0x9c, 0x24, 0x7a, 0x2a, 0xb1, 0x3c, 0x4f, 0x5a, 0x7d, 0x80, 0x3e, 0xfc, 0x0d},
  18. {0xcd, 0xdd, 0xd3, 0x02, 0x85, 0x65, 0x43, 0x83, 0xf9, 0xac, 0x75, 0x2f, 0x21, 0xef, 0x28, 0x6b},
  19. {0xab, 0x73, 0x70, 0xe8, 0xe2, 0x56, 0x0f, 0x58, 0xab, 0x29, 0xa5, 0xb1, 0x13, 0x47, 0x5e, 0xe8},
  20. {0x4f, 0x3c, 0x43, 0x77, 0xde, 0xed, 0x79, 0xa1, 0x8d, 0x4c, 0x1f, 0xfd, 0xdb, 0x96, 0x87, 0x2e},
  21. };
  22. static const uint8_t enclave_signature_input[ENCLAVE_FACTORY_KEY_SLOTS][ENCLAVE_SIGNATURE_SIZE] = {
  23. {0x9f, 0x5c, 0xb1, 0x43, 0x17, 0x53, 0x18, 0x8c, 0x66, 0x3d, 0x39, 0x45, 0x90, 0x13, 0xa9, 0xde},
  24. {0xc5, 0x98, 0xe9, 0x17, 0xb8, 0x97, 0x9e, 0x03, 0x33, 0x14, 0x13, 0x8f, 0xce, 0x74, 0x0d, 0x54},
  25. {0x34, 0xba, 0x99, 0x59, 0x9f, 0x70, 0x67, 0xe9, 0x09, 0xee, 0x64, 0x0e, 0xb3, 0xba, 0xfb, 0x75},
  26. {0xdc, 0xfa, 0x6c, 0x9a, 0x6f, 0x0a, 0x3e, 0xdc, 0x42, 0xf6, 0xae, 0x0d, 0x3c, 0xf7, 0x83, 0xaf},
  27. {0xea, 0x2d, 0xe3, 0x1f, 0x02, 0x99, 0x1a, 0x7e, 0x6d, 0x93, 0x4c, 0xb5, 0x42, 0xf0, 0x7a, 0x9b},
  28. {0x53, 0x5e, 0x04, 0xa2, 0x49, 0xa0, 0x73, 0x49, 0x56, 0xb0, 0x88, 0x8c, 0x12, 0xa0, 0xe4, 0x18},
  29. {0x7d, 0xa7, 0xc5, 0x21, 0x7f, 0x12, 0x95, 0xdd, 0x4d, 0x77, 0x01, 0xfa, 0x71, 0x88, 0x2b, 0x7f},
  30. {0xdc, 0x9b, 0xc5, 0xa7, 0x6b, 0x84, 0x5c, 0x37, 0x7c, 0xec, 0x05, 0xa1, 0x9f, 0x91, 0x17, 0x3b},
  31. {0xea, 0xcf, 0xd9, 0x9b, 0x86, 0xcd, 0x2b, 0x43, 0x54, 0x45, 0x82, 0xc6, 0xfe, 0x73, 0x1a, 0x1a},
  32. {0x77, 0xb8, 0x1b, 0x90, 0xb4, 0xb7, 0x32, 0x76, 0x8f, 0x8a, 0x57, 0x06, 0xc7, 0xdd, 0x08, 0x90},
  33. };
  34. static const uint8_t enclave_signature_expected[ENCLAVE_FACTORY_KEY_SLOTS][ENCLAVE_SIGNATURE_SIZE] = {
  35. {0xe9, 0x9a, 0xce, 0xe9, 0x4d, 0xe1, 0x7f, 0x55, 0xcb, 0x8a, 0xbf, 0xf2, 0x4d, 0x98, 0x27, 0x67},
  36. {0x34, 0x27, 0xa7, 0xea, 0xa8, 0x98, 0x66, 0x9b, 0xed, 0x43, 0xd3, 0x93, 0xb5, 0xa2, 0x87, 0x8e},
  37. {0x6c, 0xf3, 0x01, 0x78, 0x53, 0x1b, 0x11, 0x32, 0xf0, 0x27, 0x2f, 0xe3, 0x7d, 0xa6, 0xe2, 0xfd},
  38. {0xdf, 0x7f, 0x37, 0x65, 0x2f, 0xdb, 0x7c, 0xcf, 0x5b, 0xb6, 0xe4, 0x9c, 0x63, 0xc5, 0x0f, 0xe0},
  39. {0x9b, 0x5c, 0xee, 0x44, 0x0e, 0xd1, 0xcb, 0x5f, 0x28, 0x9f, 0x12, 0x17, 0x59, 0x64, 0x40, 0xbb},
  40. {0x94, 0xc2, 0x09, 0x98, 0x62, 0xa7, 0x2b, 0x93, 0xed, 0x36, 0x1f, 0x10, 0xbc, 0x26, 0xbd, 0x41},
  41. {0x4d, 0xb2, 0x2b, 0xc5, 0x96, 0x47, 0x61, 0xf4, 0x16, 0xe0, 0x81, 0xc3, 0x8e, 0xb9, 0x9c, 0x9b},
  42. {0xc3, 0x6b, 0x83, 0x55, 0x90, 0x38, 0x0f, 0xea, 0xd1, 0x65, 0xbf, 0x32, 0x4f, 0x8e, 0x62, 0x5b},
  43. {0x8d, 0x5e, 0x27, 0xbc, 0x14, 0x4f, 0x08, 0xa8, 0x2b, 0x14, 0x89, 0x5e, 0xdf, 0x77, 0x04, 0x31},
  44. {0xc9, 0xf7, 0x03, 0xf1, 0x6c, 0x65, 0xad, 0x49, 0x74, 0xbe, 0x00, 0x54, 0xfd, 0xa6, 0x9c, 0x32},
  45. };
  46. void furi_hal_crypto_init() {
  47. FURI_LOG_I(TAG, "Init OK");
  48. }
  49. static bool furi_hal_crypto_generate_unique_keys(uint8_t start_slot, uint8_t end_slot) {
  50. FuriHalCryptoKey key;
  51. uint8_t key_data[32];
  52. FURI_LOG_I(TAG, "Generating keys %u..%u", start_slot, end_slot);
  53. for(uint8_t slot = start_slot; slot <= end_slot; slot++) {
  54. key.type = FuriHalCryptoKeyTypeSimple;
  55. key.size = FuriHalCryptoKeySize256;
  56. key.data = key_data;
  57. furi_hal_random_fill_buf(key_data, 32);
  58. if(!furi_hal_crypto_store_add_key(&key, &slot)) {
  59. FURI_LOG_E(TAG, "Error writing key to slot %u", slot);
  60. return false;
  61. }
  62. }
  63. return true;
  64. }
  65. bool furi_hal_crypto_verify_key(uint8_t key_slot) {
  66. uint8_t keys_nb = 0;
  67. uint8_t valid_keys_nb = 0;
  68. uint8_t last_valid_slot = ENCLAVE_FACTORY_KEY_SLOTS;
  69. uint8_t empty_iv[16];
  70. furi_hal_crypto_verify_enclave(&keys_nb, &valid_keys_nb);
  71. if(key_slot <= ENCLAVE_FACTORY_KEY_SLOTS) { // It's a factory key
  72. if(key_slot > keys_nb) return false;
  73. } else { // Unique key
  74. if(keys_nb < ENCLAVE_FACTORY_KEY_SLOTS) // Some factory keys are missing
  75. return false;
  76. for(uint8_t i = key_slot; i > ENCLAVE_FACTORY_KEY_SLOTS; i--) {
  77. if(furi_hal_crypto_store_load_key(i, empty_iv)) {
  78. last_valid_slot = i;
  79. furi_hal_crypto_store_unload_key(i);
  80. break;
  81. }
  82. }
  83. if(last_valid_slot == key_slot)
  84. return true;
  85. else // Generate missing unique keys
  86. return furi_hal_crypto_generate_unique_keys(last_valid_slot + 1, key_slot);
  87. }
  88. return true;
  89. }
  90. bool furi_hal_crypto_verify_enclave(uint8_t* keys_nb, uint8_t* valid_keys_nb) {
  91. furi_assert(keys_nb);
  92. furi_assert(valid_keys_nb);
  93. uint8_t keys = 0;
  94. uint8_t keys_valid = 0;
  95. uint8_t buffer[ENCLAVE_SIGNATURE_SIZE];
  96. for(size_t key_slot = 0; key_slot < ENCLAVE_FACTORY_KEY_SLOTS; key_slot++) {
  97. if(furi_hal_crypto_store_load_key(key_slot + 1, enclave_signature_iv[key_slot])) {
  98. keys++;
  99. if(furi_hal_crypto_encrypt(
  100. enclave_signature_input[key_slot], buffer, ENCLAVE_SIGNATURE_SIZE)) {
  101. keys_valid +=
  102. memcmp(buffer, enclave_signature_expected[key_slot], ENCLAVE_SIGNATURE_SIZE) ==
  103. 0;
  104. }
  105. furi_hal_crypto_store_unload_key(key_slot + 1);
  106. }
  107. }
  108. *keys_nb = keys;
  109. *valid_keys_nb = keys_valid;
  110. if(*valid_keys_nb == ENCLAVE_FACTORY_KEY_SLOTS)
  111. return true;
  112. else
  113. return false;
  114. }
  115. bool furi_hal_crypto_store_add_key(FuriHalCryptoKey* key, uint8_t* slot) {
  116. furi_assert(key);
  117. furi_assert(slot);
  118. if(!furi_hal_bt_is_alive()) {
  119. return false;
  120. }
  121. SHCI_C2_FUS_StoreUsrKey_Cmd_Param_t pParam;
  122. size_t key_data_size = 0;
  123. if(key->type == FuriHalCryptoKeyTypeMaster) {
  124. pParam.KeyType = KEYTYPE_MASTER;
  125. } else if(key->type == FuriHalCryptoKeyTypeSimple) {
  126. pParam.KeyType = KEYTYPE_SIMPLE;
  127. } else if(key->type == FuriHalCryptoKeyTypeEncrypted) {
  128. pParam.KeyType = KEYTYPE_ENCRYPTED;
  129. key_data_size += 12;
  130. } else {
  131. furi_crash("Incorrect key type");
  132. }
  133. if(key->size == FuriHalCryptoKeySize128) {
  134. pParam.KeySize = KEYSIZE_16;
  135. key_data_size += 16;
  136. } else if(key->size == FuriHalCryptoKeySize256) {
  137. pParam.KeySize = KEYSIZE_32;
  138. key_data_size += 32;
  139. } else {
  140. furi_crash("Incorrect key size");
  141. }
  142. memcpy(pParam.KeyData, key->data, key_data_size);
  143. return SHCI_C2_FUS_StoreUsrKey(&pParam, slot) == SHCI_Success;
  144. }
  145. bool furi_hal_crypto_store_load_key(uint8_t slot, const uint8_t* iv) {
  146. furi_assert(slot > 0 && slot <= 100);
  147. if(!furi_hal_bt_is_alive()) {
  148. return false;
  149. }
  150. crypt.Instance = AES1;
  151. crypt.Init.DataType = CRYP_DATATYPE_32B;
  152. crypt.Init.KeySize = CRYP_KEYSIZE_256B;
  153. crypt.Init.Algorithm = CRYP_AES_CBC;
  154. crypt.Init.pInitVect = (uint32_t*)iv;
  155. crypt.Init.KeyIVConfigSkip = CRYP_KEYIVCONFIG_ONCE;
  156. crypt.Init.pKey = NULL;
  157. furi_check(HAL_CRYP_Init(&crypt) == HAL_OK);
  158. if(SHCI_C2_FUS_LoadUsrKey(slot) == SHCI_Success) {
  159. return true;
  160. } else {
  161. furi_check(HAL_CRYP_DeInit(&crypt) == HAL_OK);
  162. return false;
  163. }
  164. }
  165. bool furi_hal_crypto_store_unload_key(uint8_t slot) {
  166. if(!furi_hal_bt_is_alive()) {
  167. return false;
  168. }
  169. furi_check(HAL_CRYP_DeInit(&crypt) == HAL_OK);
  170. return SHCI_C2_FUS_UnloadUsrKey(slot) == SHCI_Success;
  171. }
  172. bool furi_hal_crypto_encrypt(const uint8_t* input, uint8_t* output, size_t size) {
  173. return HAL_CRYP_Encrypt(&crypt, (uint32_t*)input, size / 4, (uint32_t*)output, 1000) == HAL_OK;
  174. }
  175. bool furi_hal_crypto_decrypt(const uint8_t* input, uint8_t* output, size_t size) {
  176. return HAL_CRYP_Decrypt(&crypt, (uint32_t*)input, size / 4, (uint32_t*)output, 1000) == HAL_OK;
  177. }