aboutsummaryrefslogtreecommitdiff
path: root/service_provider.c
blob: aaa58a154e2f67021ec4aebc5949c8b397b2fd4e (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
/* implementation of a basic service provider for use with the trusted
 * module */

#include <stdlib.h>

#include "crypto.h"
#include "service_provider.h"
#include "trusted_module.h"

struct file_version {
    hash_t kf; /* h(key, file_idx) */
    hash_t l; /* h(h(file contents), kf) */
    hash_t enc_key; /* XOR'd with h(kf, module secret) */

    struct tm_cert cert; /* VR certificate */
    hash_t cert_hmac;

    void *contents;
    size_t len;
};

struct file_record {
    int version;
    int counter;

    struct iomt_node *acl;
    int acl_nodes;

    struct tm_cert fr_cert; /* issued by module */
    hash_t fr_hmac;

    struct file_version *versions;
    int n_versions;
};

struct service_provider {
    struct trusted_module *tm;

    struct file_record *records;
    int n_records;

    struct iomt_node *mt; /* leaves of CDI-IOMT, value is counter */
    int mt_nodes;
};

struct service_provider *sp_new(const void *key, size_t keylen)
{
    struct service_provider *sp = calloc(1, sizeof(*sp));

    sp->tm = tm_new(key, keylen);

    /* everything else is already zeroed by calloc */
    return sp;
}

void sp_request(struct service_provider *sp, const struct user_request *req, hash_t hmac)
{

}