tpm2: introduce TPM_CCE_PolicyFidoSigned command

This patch implements TPM_CCE_PolicyFidoSigned command support as in
the design document, http://go/h1-for-fido.
Policy Digest is extended by

SHA256(TPM_CCE_PolicyFidoSigned || authenticatorDataDescr ||
  authenticatorData[authenticatorDataDescr] || signing key name),
  where
  TPM_CCE_PolicyFidoSigned is 0x2008001,
  authenticatorDataDescr is an array of (offset, size) tuples,
  authenticatorData is a signature generated by FIDO security key,
  and signing key name is an object name of the signing key.

The auth parameter shall be the signature for authenticatorData and
nonce only, that is,
  auth = sign(AuthenticatorData || hash(session nonce)).

This patch increases the flash usage by 1020 bytes.

BUG=b:140527213
TEST=ran 'trunks_client --regression_test' with trunks, built from
crrev.com/c/1907759, which adds PolicyFidoSigned test case.

Change-Id: I94ba184d206db6c5301bbe930f47a7486ab0ab80
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/third_party/tpm2/+/1892419
Tested-by: Namyoon Woo <namyoon@chromium.org>
Reviewed-by: Andrey Pronin <apronin@chromium.org>
Commit-Queue: Namyoon Woo <namyoon@chromium.org>
11 files changed
tree: 4b0eaae00da0418755628097981bf4013f92a3a6
  1. fuzz/
  2. generator/
  3. .gitignore
  4. _TPM_Hash_Data.c
  5. _TPM_Hash_Data_fp.h
  6. _TPM_Hash_End.c
  7. _TPM_Hash_End_fp.h
  8. _TPM_Hash_Start.c
  9. _TPM_Hash_Start_fp.h
  10. _TPM_Init.c
  11. _TPM_Init_fp.h
  12. ActivateCredential.c
  13. ActivateCredential_fp.h
  14. AlgorithmCap.c
  15. AlgorithmCap_fp.h
  16. Attest_spt.c
  17. Attest_spt_fp.h
  18. BaseTypes.h
  19. Bits.c
  20. bits.h
  21. Bits_fp.h
  22. bool.h
  23. Cancel.c
  24. Capabilities.h
  25. Certify.c
  26. Certify_fp.h
  27. CertifyCreation.c
  28. CertifyCreation_fp.h
  29. ChangeEPS.c
  30. ChangeEPS_fp.h
  31. ChangePPS.c
  32. ChangePPS_fp.h
  33. Clear.c
  34. Clear_fp.h
  35. ClearControl.c
  36. ClearControl_fp.h
  37. Clock.c
  38. ClockRateAdjust.c
  39. ClockRateAdjust_fp.h
  40. ClockSet.c
  41. ClockSet_fp.h
  42. CommandAttributeData.c
  43. CommandAudit.c
  44. CommandAudit_fp.h
  45. CommandCodeAttributes.c
  46. CommandCodeAttributes_fp.h
  47. CommandDispatcher.c
  48. CommandDispatcher_fp.h
  49. Commands_fp.h
  50. COMMIT-QUEUE.ini
  51. Commit.c
  52. Commit_fp.h
  53. Context_spt.c
  54. Context_spt_fp.h
  55. ContextLoad.c
  56. ContextLoad_fp.h
  57. ContextSave.c
  58. ContextSave_fp.h
  59. CpriCryptPri.c
  60. CpriCryptPri_fp.h
  61. CpriDataEcc.c
  62. CpriDataEcc.h
  63. CpriECC.c
  64. CpriECC_fp.h
  65. CpriHash.c
  66. CpriHash_fp.h
  67. CpriHashData.c
  68. CpriMisc.c
  69. CpriMisc_fp.h
  70. CpriRNG.c
  71. CpriRNG_fp.h
  72. CpriRSA.c
  73. CpriRSA_fp.h
  74. CpriSym.c
  75. CpriSym_fp.h
  76. Create.c
  77. Create_fp.h
  78. CreatePrimary.c
  79. CreatePrimary_fp.h
  80. CryptoEngine.h
  81. CryptSelfTest.c
  82. CryptSelfTest_fp.h
  83. CryptUtil.c
  84. CryptUtil_fp.h
  85. DA.c
  86. DA_fp.h
  87. DictionaryAttackLockReset.c
  88. DictionaryAttackLockReset_fp.h
  89. DictionaryAttackParameters.c
  90. DictionaryAttackParameters_fp.h
  91. DRTM.c
  92. Duplicate.c
  93. Duplicate_fp.h
  94. EC_Ephemeral.c
  95. EC_Ephemeral_fp.h
  96. ECC_Parameters.c
  97. ECC_Parameters_fp.h
  98. ECDH_KeyGen.c
  99. ECDH_KeyGen_fp.h
  100. ECDH_ZGen.c
  101. ECDH_ZGen_fp.h
  102. EncryptDecrypt.c
  103. EncryptDecrypt_fp.h
  104. Entity.c
  105. Entity_fp.h
  106. Entropy.c
  107. EventSequenceComplete.c
  108. EventSequenceComplete_fp.h
  109. EvictControl.c
  110. EvictControl_fp.h
  111. ExecCommand.c
  112. ExecCommand_fp.h
  113. FieldUpgradeData.c
  114. FieldUpgradeData_fp.h
  115. FieldUpgradeStart.c
  116. FieldUpgradeStart_fp.h
  117. FirmwareRead.c
  118. FirmwareRead_fp.h
  119. FlushContext.c
  120. FlushContext_fp.h
  121. GetCapability.c
  122. GetCapability_fp.h
  123. GetCommandAuditDigest.c
  124. GetCommandAuditDigest_fp.h
  125. GetCommandCodeString.c
  126. GetCommandCodeString_fp.h
  127. GetRandom.c
  128. GetRandom_fp.h
  129. GetSessionAuditDigest.c
  130. GetSessionAuditDigest_fp.h
  131. GetTestResult.c
  132. GetTestResult_fp.h
  133. GetTime.c
  134. GetTime_fp.h
  135. Global.c
  136. Global.h
  137. Handle.c
  138. Handle_fp.h
  139. HandleProcess.c
  140. HandleProcess_fp.h
  141. Hash.c
  142. Hash_fp.h
  143. HashSequenceStart.c
  144. HashSequenceStart_fp.h
  145. Hierarchy.c
  146. Hierarchy_fp.h
  147. HierarchyChangeAuth.c
  148. HierarchyChangeAuth_fp.h
  149. HierarchyControl.c
  150. HierarchyControl_fp.h
  151. HMAC.c
  152. HMAC_fp.h
  153. HMAC_Start.c
  154. HMAC_Start_fp.h
  155. Implementation.h
  156. Import.c
  157. Import_fp.h
  158. IncrementalSelfTest.c
  159. IncrementalSelfTest_fp.h
  160. InternalRoutines.h
  161. libtpm2.pc.in
  162. LICENSE
  163. Load.c
  164. Load_fp.h
  165. LoadExternal.c
  166. LoadExternal_fp.h
  167. Locality.c
  168. Locality_fp.h
  169. LocalityPlat.c
  170. MakeCredential.c
  171. MakeCredential_fp.h
  172. Makefile
  173. Manufacture.c
  174. Manufacture_fp.h
  175. Marshal_ActivateCredential.c
  176. Marshal_Certify.c
  177. Marshal_CertifyCreation.c
  178. Marshal_ChangeEPS.c
  179. Marshal_ChangePPS.c
  180. Marshal_Clear.c
  181. Marshal_ClearControl.c
  182. Marshal_ClockRateAdjust.c
  183. Marshal_ClockSet.c
  184. Marshal_Commit.c
  185. Marshal_ContextLoad.c
  186. Marshal_ContextSave.c
  187. Marshal_Create.c
  188. Marshal_CreatePrimary.c
  189. Marshal_DictionaryAttackLockReset.c
  190. Marshal_DictionaryAttackParameters.c
  191. Marshal_Duplicate.c
  192. Marshal_EC_Ephemeral.c
  193. Marshal_ECC_Parameters.c
  194. Marshal_ECDH_KeyGen.c
  195. Marshal_ECDH_ZGen.c
  196. Marshal_EncryptDecrypt.c
  197. Marshal_EventSequenceComplete.c
  198. Marshal_EvictControl.c
  199. Marshal_FieldUpgradeData.c
  200. Marshal_FieldUpgradeStart.c
  201. Marshal_FirmwareRead.c
  202. Marshal_FlushContext.c
  203. marshal_fp.h
  204. Marshal_GetCapability.c
  205. Marshal_GetCommandAuditDigest.c
  206. Marshal_GetRandom.c
  207. Marshal_GetSessionAuditDigest.c
  208. Marshal_GetTestResult.c
  209. Marshal_GetTime.c
  210. Marshal_Hash.c
  211. Marshal_HashSequenceStart.c
  212. Marshal_HierarchyChangeAuth.c
  213. Marshal_HierarchyControl.c
  214. Marshal_HMAC.c
  215. Marshal_HMAC_Start.c
  216. Marshal_Import.c
  217. Marshal_IncrementalSelfTest.c
  218. Marshal_Load.c
  219. Marshal_LoadExternal.c
  220. Marshal_MakeCredential.c
  221. Marshal_NV_Certify.c
  222. Marshal_NV_ChangeAuth.c
  223. Marshal_NV_DefineSpace.c
  224. Marshal_NV_Extend.c
  225. Marshal_NV_GlobalWriteLock.c
  226. Marshal_NV_Increment.c
  227. Marshal_NV_Read.c
  228. Marshal_NV_ReadLock.c
  229. Marshal_NV_ReadPublic.c
  230. Marshal_NV_SetBits.c
  231. Marshal_NV_UndefineSpace.c
  232. Marshal_NV_UndefineSpaceSpecial.c
  233. Marshal_NV_Write.c
  234. Marshal_NV_WriteLock.c
  235. Marshal_ObjectChangeAuth.c
  236. Marshal_PCR_Allocate.c
  237. Marshal_PCR_Event.c
  238. Marshal_PCR_Extend.c
  239. Marshal_PCR_Read.c
  240. Marshal_PCR_Reset.c
  241. Marshal_PCR_SetAuthPolicy.c
  242. Marshal_PCR_SetAuthValue.c
  243. Marshal_PolicyAuthorize.c
  244. Marshal_PolicyAuthValue.c
  245. Marshal_PolicyCommandCode.c
  246. Marshal_PolicyCounterTimer.c
  247. Marshal_PolicyCpHash.c
  248. Marshal_PolicyDuplicationSelect.c
  249. Marshal_PolicyFidoSigned.c
  250. Marshal_PolicyGetDigest.c
  251. Marshal_PolicyLocality.c
  252. Marshal_PolicyNameHash.c
  253. Marshal_PolicyNV.c
  254. Marshal_PolicyNvWritten.c
  255. Marshal_PolicyOR.c
  256. Marshal_PolicyPassword.c
  257. Marshal_PolicyPCR.c
  258. Marshal_PolicyPhysicalPresence.c
  259. Marshal_PolicyRestart.c
  260. Marshal_PolicySecret.c
  261. Marshal_PolicySigned.c
  262. Marshal_PolicyTicket.c
  263. Marshal_PP_Commands.c
  264. Marshal_Quote.c
  265. Marshal_ReadClock.c
  266. Marshal_ReadPublic.c
  267. Marshal_Rewrap.c
  268. Marshal_RSA_Decrypt.c
  269. Marshal_RSA_Encrypt.c
  270. Marshal_SelfTest.c
  271. Marshal_SequenceComplete.c
  272. Marshal_SequenceUpdate.c
  273. Marshal_SetAlgorithmSet.c
  274. Marshal_SetCommandCodeAuditStatus.c
  275. Marshal_SetPrimaryPolicy.c
  276. Marshal_Shutdown.c
  277. Marshal_Sign.c
  278. Marshal_StartAuthSession.c
  279. Marshal_Startup.c
  280. Marshal_StirRandom.c
  281. marshal_test.c
  282. Marshal_TestParms.c
  283. Marshal_Unseal.c
  284. Marshal_VerifySignature.c
  285. Marshal_ZGen_2Phase.c
  286. MathFunctions.c
  287. MathFunctions_fp.h
  288. MemoryLib.c
  289. MemoryLib_fp.h
  290. NV.c
  291. NV_Certify.c
  292. NV_Certify_fp.h
  293. NV_ChangeAuth.c
  294. NV_ChangeAuth_fp.h
  295. NV_DefineSpace.c
  296. NV_DefineSpace_fp.h
  297. NV_Extend.c
  298. NV_Extend_fp.h
  299. NV_fp.h
  300. NV_GlobalWriteLock.c
  301. NV_GlobalWriteLock_fp.h
  302. NV_Increment.c
  303. NV_Increment_fp.h
  304. NV_Read.c
  305. NV_Read_fp.h
  306. NV_ReadLock.c
  307. NV_ReadLock_fp.h
  308. NV_ReadPublic.c
  309. NV_ReadPublic_fp.h
  310. NV_SetBits.c
  311. NV_SetBits_fp.h
  312. NV_spt.c
  313. NV_spt_fp.h
  314. NV_UndefineSpace.c
  315. NV_UndefineSpace_fp.h
  316. NV_UndefineSpaceSpecial.c
  317. NV_UndefineSpaceSpecial_fp.h
  318. NV_Write.c
  319. NV_Write_fp.h
  320. NV_WriteLock.c
  321. NV_WriteLock_fp.h
  322. NVMem.c
  323. Object.c
  324. Object_fp.h
  325. Object_spt.c
  326. Object_spt_fp.h
  327. ObjectChangeAuth.c
  328. ObjectChangeAuth_fp.h
  329. OsslCryptoEngine.h
  330. OWNERS
  331. parsep3
  332. parsep4
  333. PCR.c
  334. PCR_Allocate.c
  335. PCR_Allocate_fp.h
  336. PCR_Event.c
  337. PCR_Event_fp.h
  338. PCR_Extend.c
  339. PCR_Extend_fp.h
  340. PCR_fp.h
  341. PCR_Read.c
  342. PCR_Read_fp.h
  343. PCR_Reset.c
  344. PCR_Reset_fp.h
  345. PCR_SetAuthPolicy.c
  346. PCR_SetAuthPolicy_fp.h
  347. PCR_SetAuthValue.c
  348. PCR_SetAuthValue_fp.h
  349. Platform.h
  350. PlatformData.c
  351. PlatformData.h
  352. Policy_spt.c
  353. Policy_spt_fp.h
  354. PolicyAuthorize.c
  355. PolicyAuthorize_fp.h
  356. PolicyAuthValue.c
  357. PolicyAuthValue_fp.h
  358. PolicyCommandCode.c
  359. PolicyCommandCode_fp.h
  360. PolicyCounterTimer.c
  361. PolicyCounterTimer_fp.h
  362. PolicyCpHash.c
  363. PolicyCpHash_fp.h
  364. PolicyDuplicationSelect.c
  365. PolicyDuplicationSelect_fp.h
  366. PolicyFidoSigned.c
  367. PolicyFidoSigned_fp.h
  368. PolicyGetDigest.c
  369. PolicyGetDigest_fp.h
  370. PolicyLocality.c
  371. PolicyLocality_fp.h
  372. PolicyNameHash.c
  373. PolicyNameHash_fp.h
  374. PolicyNV.c
  375. PolicyNV_fp.h
  376. PolicyNvWritten.c
  377. PolicyNvWritten_fp.h
  378. PolicyOR.c
  379. PolicyOR_fp.h
  380. PolicyPassword.c
  381. PolicyPassword_fp.h
  382. PolicyPCR.c
  383. PolicyPCR_fp.h
  384. PolicyPhysicalPresence.c
  385. PolicyPhysicalPresence_fp.h
  386. PolicyRestart.c
  387. PolicyRestart_fp.h
  388. PolicySecret.c
  389. PolicySecret_fp.h
  390. PolicySigned.c
  391. PolicySigned_fp.h
  392. PolicyTicket.c
  393. PolicyTicket_fp.h
  394. Power.c
  395. Power_fp.h
  396. PowerPlat.c
  397. PP.c
  398. PP_Commands.c
  399. PP_Commands_fp.h
  400. PP_fp.h
  401. PPPlat.c
  402. PRESUBMIT.cfg
  403. PropertyCap.c
  404. PropertyCap_fp.h
  405. Quote.c
  406. Quote_fp.h
  407. ReadClock.c
  408. ReadClock_fp.h
  409. README
  410. ReadPublic.c
  411. ReadPublic_fp.h
  412. Rewrap.c
  413. Rewrap_fp.h
  414. RSA_Decrypt.c
  415. RSA_Decrypt_fp.h
  416. RSA_Encrypt.c
  417. RSA_Encrypt_fp.h
  418. RSAData.c
  419. RSAKeySieve.c
  420. RSAKeySieve.h
  421. RSAKeySieve_fp.h
  422. SelfTest.c
  423. SelfTest_fp.h
  424. SequenceComplete.c
  425. SequenceComplete_fp.h
  426. SequenceUpdate.c
  427. SequenceUpdate_fp.h
  428. Session.c
  429. Session_fp.h
  430. SessionProcess.c
  431. SessionProcess_fp.h
  432. SetAlgorithmSet.c
  433. SetAlgorithmSet_fp.h
  434. SetCommandCodeAuditStatus.c
  435. SetCommandCodeAuditStatus_fp.h
  436. SetPrimaryPolicy.c
  437. SetPrimaryPolicy_fp.h
  438. Shutdown.c
  439. Shutdown_fp.h
  440. Sign.c
  441. Sign_fp.h
  442. StartAuthSession.c
  443. StartAuthSession_fp.h
  444. Startup.c
  445. Startup_fp.h
  446. StirRandom.c
  447. StirRandom_fp.h
  448. stubs_ecc.c
  449. stubs_hash.c
  450. stubs_sym.c
  451. swap.h
  452. TcpServer.c
  453. TestParms.c
  454. TestParms_fp.h
  455. thirdparty_preinstall.sh
  456. Ticket.c
  457. Ticket_fp.h
  458. Time.c
  459. Time_fp.h
  460. Tpm.h
  461. tpm_generated.c
  462. tpm_generated.h
  463. TPM_Types.h
  464. tpm_types.h
  465. TPMB.h
  466. TpmBuildSwitches.h
  467. TPMCmdp.c
  468. TPMCmds.c
  469. TpmError.h
  470. TpmFail.c
  471. TpmFail_fp.h
  472. TpmTcpProtocol.h
  473. Unique.c
  474. Unique_fp.h
  475. Unseal.c
  476. Unseal_fp.h
  477. VendorString.h
  478. VerifySignature.c
  479. VerifySignature_fp.h
  480. ZGen_2Phase.c
  481. ZGen_2Phase_fp.h