summaryrefslogtreecommitdiffstats
path: root/content/child/webcrypto/shared_crypto.h
blob: 3be2612df5aff27c0917bbd9b6f1cceda062df2a (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
// Copyright 2014 The Chromium Authors. All rights reserved.
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.

#ifndef CONTENT_CHILD_WEBCRYPTO_SHARED_CRYPTO_H_
#define CONTENT_CHILD_WEBCRYPTO_SHARED_CRYPTO_H_

#include <vector>

#include "base/basictypes.h"
#include "base/compiler_specific.h"
#include "base/memory/scoped_ptr.h"
#include "content/common/content_export.h"
#include "third_party/WebKit/public/platform/WebArrayBuffer.h"
#include "third_party/WebKit/public/platform/WebCrypto.h"
#include "third_party/WebKit/public/platform/WebCryptoAlgorithmParams.h"

namespace content {

namespace webcrypto {

class CryptoData;
class Status;

// Do one-time initialization. It is safe to call this multiple times.
CONTENT_EXPORT void Init();

// The functions exported by shared_crypto.h provide a common entry point for
// synchronous crypto operations.
//
// Here is how the layer cake looks.
//
//              Blink
//                |
//  ==============|==========================
//                |
//             content
//                |
//                |
//                v
//          WebCryptoImpl     (Implements the blink::WebCrypto interface for
//                |            asynchronous completions; posts tasks to
//                |            the webcrypto worker pool to fulfill the request
//                             using the synchronous methods of shared_crypto.h)
//                |
//                |      [shared_crypto_unittest.cc]
//                |           /
//                |          /   (The blink::WebCrypto interface is not
//                |         /     testable from the chromium side because
//                |        /      the result object is not mockable.
//                |       /       Tests are done on shared_crypto instead.
//                V      v
//        [shared_crypto.h]   (Exposes synchronous functions in the
//                |            webcrypto:: namespace. This does
//                |            common validations, infers default
//                |            parameters, and casts the algorithm
//                |            parameters to the right types)
//                |
//                V
//       [platform_crypto.h]  (Exposes functions in the webcrypto::platform
//                |            namespace)
//                |
//                |
//                V
//  [platform_crypto_{nss|openssl}.cc]  (Implements using the platform crypto
//                                       library)
//
// The shared_crypto.h functions are responsible for:
//
//  * Validating the key usages
//  * Inferring default parameters when not specified
//  * Validating key exportability
//  * Validating algorithm with key.algorithm
//  * Converting the Blink key to a more specific platform::{PublicKey,
//    PrivateKey, SymKey} and making sure it was the right type.
//  * Validating alogorithm specific parameters (for instance, was the iv for
//    AES-CBC 16 bytes).
//  * Parse a JWK

CONTENT_EXPORT Status Encrypt(const blink::WebCryptoAlgorithm& algorithm,
                              const blink::WebCryptoKey& key,
                              const CryptoData& data,
                              std::vector<uint8>* buffer);

CONTENT_EXPORT Status Decrypt(const blink::WebCryptoAlgorithm& algorithm,
                              const blink::WebCryptoKey& key,
                              const CryptoData& data,
                              std::vector<uint8>* buffer);

CONTENT_EXPORT Status Digest(const blink::WebCryptoAlgorithm& algorithm,
                             const CryptoData& data,
                             std::vector<uint8>* buffer);

CONTENT_EXPORT scoped_ptr<blink::WebCryptoDigestor> CreateDigestor(
    blink::WebCryptoAlgorithmId algorithm);

CONTENT_EXPORT Status
    GenerateSecretKey(const blink::WebCryptoAlgorithm& algorithm,
                      bool extractable,
                      blink::WebCryptoKeyUsageMask usage_mask,
                      blink::WebCryptoKey* key);

CONTENT_EXPORT Status
    GenerateKeyPair(const blink::WebCryptoAlgorithm& algorithm,
                    bool extractable,
                    blink::WebCryptoKeyUsageMask usage_mask,
                    blink::WebCryptoKey* public_key,
                    blink::WebCryptoKey* private_key);

CONTENT_EXPORT Status ImportKey(blink::WebCryptoKeyFormat format,
                                const CryptoData& key_data,
                                const blink::WebCryptoAlgorithm& algorithm,
                                bool extractable,
                                blink::WebCryptoKeyUsageMask usage_mask,
                                blink::WebCryptoKey* key);

CONTENT_EXPORT Status ExportKey(blink::WebCryptoKeyFormat format,
                                const blink::WebCryptoKey& key,
                                std::vector<uint8>* buffer);

CONTENT_EXPORT Status Sign(const blink::WebCryptoAlgorithm& algorithm,
                           const blink::WebCryptoKey& key,
                           const CryptoData& data,
                           std::vector<uint8>* buffer);

CONTENT_EXPORT Status
    VerifySignature(const blink::WebCryptoAlgorithm& algorithm,
                    const blink::WebCryptoKey& key,
                    const CryptoData& signature,
                    const CryptoData& data,
                    bool* signature_match);

CONTENT_EXPORT Status
    WrapKey(blink::WebCryptoKeyFormat format,
            const blink::WebCryptoKey& wrapping_key,
            const blink::WebCryptoKey& key_to_wrap,
            const blink::WebCryptoAlgorithm& wrapping_algorithm,
            std::vector<uint8>* buffer);

CONTENT_EXPORT Status
    UnwrapKey(blink::WebCryptoKeyFormat format,
              const CryptoData& wrapped_key_data,
              const blink::WebCryptoKey& wrapping_key,
              const blink::WebCryptoAlgorithm& wrapping_algorithm,
              const blink::WebCryptoAlgorithm& algorithm,
              bool extractable,
              blink::WebCryptoKeyUsageMask usage_mask,
              blink::WebCryptoKey* key);

// Called on the target Blink thread.
CONTENT_EXPORT bool SerializeKeyForClone(const blink::WebCryptoKey& key,
                                         blink::WebVector<uint8>* key_data);

// Called on the target Blink thread.
CONTENT_EXPORT bool DeserializeKeyForClone(
    const blink::WebCryptoKeyAlgorithm& algorithm,
    blink::WebCryptoKeyType type,
    bool extractable,
    blink::WebCryptoKeyUsageMask usage_mask,
    const CryptoData& key_data,
    blink::WebCryptoKey* key);

}  // namespace webcrypto

}  // namespace content

#endif  // CONTENT_CHILD_WEBCRYPTO_SHARED_CRYPTO_H_