Telematics SDK - API Reference
v1.51.0
|
Data Structures | |
class | telux::sec::ICryptoParam |
class | telux::sec::ICryptoManager |
ICryptoManager provides key management and crypto operation support. It uses trusted hardware bound crypto. All keys generated are bound to the device cryptographically. More... | |
class | telux::sec::CryptoParamBuilder |
class | telux::sec::SecurityFactory |
SecurityFactory allows creation of CryptoManager. More... | |
Typedefs | |
using | telux::sec::CryptoOperationTypes = int32_t |
using | telux::sec::BlockModeTypes = int32_t |
using | telux::sec::PaddingTypes = int32_t |
using | telux::sec::DigestTypes = int32_t |
using | telux::sec::AlgorithmTypes = int32_t |
using | telux::sec::CurveTypes = int32_t |
class telux::sec::ICryptoParam |
Specifies how a crypto operation should be performed. An instance of this must be created only thorough CryptoParamBuilder.
Public Member Functions | |
virtual | ~ICryptoParam () |
|
virtual |
class telux::sec::ICryptoManager |
ICryptoManager provides key management and crypto operation support. It uses trusted hardware bound crypto. All keys generated are bound to the device cryptographically.
Public Member Functions | |
virtual telux::common::ErrorCode | generateKey (std::shared_ptr< ICryptoParam > cryptoParam, std::vector< uint8_t > &keyBlob)=0 |
virtual telux::common::ErrorCode | importKey (std::shared_ptr< ICryptoParam > cryptoParam, telux::sec::KeyFormat keyFmt, std::vector< uint8_t > const &keyData, std::vector< uint8_t > &keyBlob)=0 |
virtual telux::common::ErrorCode | exportKey (telux::sec::KeyFormat keyFmt, std::vector< uint8_t > const &keyBlob, std::vector< uint8_t > &keyData)=0 |
virtual telux::common::ErrorCode | upgradeKey (std::shared_ptr< ICryptoParam > cryptoParam, std::vector< uint8_t > const &oldKeyBlob, std::vector< uint8_t > &newKeyBlob)=0 |
virtual telux::common::ErrorCode | signData (std::shared_ptr< ICryptoParam > cryptoParam, std::vector< uint8_t > const &keyBlob, std::vector< uint8_t > const &plainText, std::vector< uint8_t > &signature)=0 |
virtual telux::common::ErrorCode | verifyData (std::shared_ptr< ICryptoParam > cryptoParam, std::vector< uint8_t > const &keyBlob, std::vector< uint8_t > const &plainText, std::vector< uint8_t > const &signature)=0 |
virtual telux::common::ErrorCode | encryptData (std::shared_ptr< ICryptoParam > cryptoParam, std::vector< uint8_t > const &keyBlob, std::vector< uint8_t > const &plainText, std::vector< uint8_t > &encryptedText)=0 |
virtual telux::common::ErrorCode | decryptData (std::shared_ptr< ICryptoParam > cryptoParam, std::vector< uint8_t > const &keyBlob, std::vector< uint8_t > const &encryptedText, std::vector< uint8_t > &decryptedText)=0 |
virtual | ~ICryptoManager () |
|
virtual |
Destructor of ICryptoManager. Performs cleanup as applicable.
|
pure virtual |
Generates key and provides it in the form of corresponding key blob. The key's secret is encrypted in this key blob.
[in] | cryptoParam | Specifications of the key |
[out] | keyBlob | Key blob representing the key |
|
pure virtual |
Creates key blob from the given key data.
[in] | cryptoParam | Specifications of the key |
[in] | keyFmt | KeyFormat Format in which key should be imported |
[in] | keyData | Key's data in specific format to be imported |
[out] | keyBlob | Key blob Key blob created from the given key data |
|
pure virtual |
Generates equivalent key data from the given key blob.
[in] | keyFmt | KeyFormat Format in which key should be exported |
[in] | keyBlob | Key blob representing the key to be exported |
[out] | keyData | Key's data generated from the given key blob |
|
pure virtual |
Upgrade the given key if it has expired for example due to system software upgrade.
[in] | cryptoParam | Input parameters specifically unique data should be set if it was used when creating the key originally. |
[in] | oldKeyBlob | Key blob representing key to be upgraded |
[out] | newKeyBlob | Key blob representing upgraded key |
|
pure virtual |
Generates signature to verify integrity of the given data.
[in] | cryptoParam | Input parameters to signature generator algorithm |
[in] | keyBlob | Key blob to sign given data |
[in] | plainText | Data to be signed |
[out] | signature | Signature generated for the given data |
|
pure virtual |
Verifies integrity of the given data through its signature.
[in] | cryptoParam | Input parameters to signature validator algorithm |
[in] | keyBlob | Key blob to verify this data |
[in] | plainText | Data to be verified |
[in] | signature | Signature of the data |
|
pure virtual |
Encrypts data as per the given inputs to the encryption algorithm.
[in] | cryptoParam | Input parameters to encryption algorithm |
[in] | keyBlob | Key blob to be used for encryption |
[in] | plainText | Data to be encrypted |
[out] | encryptedText | Encrypted data |
|
pure virtual |
Decrypts data as per the given inputs to the decryption algorithm.
[in] | cryptoParam | Input parameters to decryption algorithm |
[in] | keyBlob | Key blob to be used for decryption |
[in] | encryptedText | Encrypted data to be decrypted |
[out] | decryptedText | Decrypted data |
class telux::sec::CryptoParamBuilder |
CryptoParamBuilder helps to setup input parameters for a given crypto operation.
Public Member Functions | |
CryptoParamBuilder () | |
CryptoParamBuilder | setAlgorithm (AlgorithmTypes algorithm) |
CryptoParamBuilder | setCryptoOperation (CryptoOperationTypes operation) |
CryptoParamBuilder | setDigest (DigestTypes digest) |
CryptoParamBuilder | setPadding (PaddingTypes padding) |
CryptoParamBuilder | setKeySize (int32_t keySize) |
CryptoParamBuilder | setMinimumMacLength (int32_t minMacLength) |
CryptoParamBuilder | setMacLength (int32_t macLength) |
CryptoParamBuilder | setBlockMode (BlockModeTypes blockMode) |
CryptoParamBuilder | setCurve (int32_t curve) |
CryptoParamBuilder | setCallerNonce (bool callerNonce) |
CryptoParamBuilder | setPublicExponent (uint64_t publicExponent) |
CryptoParamBuilder | setInitVector (std::vector< uint8_t > initVector) |
CryptoParamBuilder | setUniqueData (std::vector< uint8_t > uniqueData) |
std::shared_ptr< ICryptoParam > | build (void) |
telux::sec::CryptoParamBuilder::CryptoParamBuilder | ( | ) |
Allocates an instance of CryptoParamBuilder.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setAlgorithm | ( | AlgorithmTypes | algorithm | ) |
When generating the keys, specifies with which algorithm these keys will be used. For crypto operation, specifies the algorithm to use. Use telux::sec::Algorithm enumeration to define this.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setCryptoOperation | ( | CryptoOperationTypes | operation | ) |
When generating the keys, specifies crypto operation(s) for which the key will be used. For crypto operation, specifies operation itself (encryption/decryption/ signing/verification). Use telux::sec::CryptoOperation enumeration to define this. Multiple operation values can be OR'ed.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setDigest | ( | DigestTypes | digest | ) |
When generating the keys, specifies the digest algorithm(s) that may be used with the key to perform signing and verification operations using RSA, ECDSA and HMAC keys For crypto operation, specifies exact digest algorithm to be used. Use telux::sec::Digest enumeration to define this. Multiple values can be OR'ed.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setPadding | ( | PaddingTypes | padding | ) |
When generating the keys, specifies the padding modes that may be used with the RSA and AES key. For crypto operation, specifies exact padding to be used. Use telux::sec::Padding enumeration to define this. Multiple padding values can be OR'ed.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setKeySize | ( | int32_t | keySize | ) |
When generating the keys, specifies size in bits, of the key, measured in the regular way for the key's algorithm. For RSA keys, specifies the size of the public modulus. For AES keys, specifies length of the secret key material. For HMAC key, it specifies the key size in bits. For EC, it is used to select the EC group.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setMinimumMacLength | ( | int32_t | minMacLength | ) |
When generating the keys, specifies minimum length of the MAC in bits that can be requested or verified with this key for HMAC keys and AES keys that support GCM mode.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setMacLength | ( | int32_t | macLength | ) |
For crypto operation, specifies requested length of a MAC or GCM (which is guaranteed to be no less then minimum length of the MAC/GCM used when generating the key.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setBlockMode | ( | BlockModeTypes | blockMode | ) |
When generating the keys, specifies block cipher mode(s) with which this key can be used. For crypto operation, specifies exact block mode to be used. Use telux::sec::BlockMode enumeration to define this. Multiple block mode values can be OR'ed.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setCurve | ( | int32_t | curve | ) |
When generating the keys using EC algorithm, only key size, only curve or both key size and curve can be specified. If only key size is specified, appropriate NIST curve is selected automatically. If only curve is specified, given curve is used. If both are specified then given curve is used and also key size is validated.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setCallerNonce | ( | bool | callerNonce | ) |
When generating the AES key, set this to true. And when performing AES crypto operations define initialization vector using iv field in this structure.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setPublicExponent | ( | uint64_t | publicExponent | ) |
When generating the RSA key, specifies the value of the public exponent for an RSA key pair (necessary for all RSA keys).
CryptoParamBuilder telux::sec::CryptoParamBuilder::setInitVector | ( | std::vector< uint8_t > | initVector | ) |
When performing AES crypto operations, specifies initialization vector to be used.
CryptoParamBuilder telux::sec::CryptoParamBuilder::setUniqueData | ( | std::vector< uint8_t > | uniqueData | ) |
When generating or importing a key, an arbitrary value can be supplied through this method. In all subsequent use of the key, this value must be supplied again. The data given is bound to the key cryptographically. This data ties the key to the caller.
std::shared_ptr<ICryptoParam> telux::sec::CryptoParamBuilder::build | ( | void | ) |
Finally creates an instance of ICryptoParam based on the setter methods invoked on the builder. After building the builder's state is resetted.
class telux::sec::SecurityFactory |
SecurityFactory allows creation of CryptoManager.
Public Member Functions | |
virtual std::shared_ptr< ICryptoManager > | getCryptoManager (telux::common::ErrorCode &ec)=0 |
Static Public Member Functions | |
static SecurityFactory & | getInstance () |
|
static |
Gets the SecurityFactory instance.
|
pure virtual |
Provides instance of CryptoManager through which key management and cryptographic operations can be performed.
using telux::sec::CryptoOperationTypes = typedef int32_t |
This is a list of operation types consisting of entries from CryptoOperation. Multiple values can be OR'ed together. e.g. (CRYPTO_OP_ENCRYPT | CRYPTO_OP_DECRYPT).
using telux::sec::BlockModeTypes = typedef int32_t |
This is a list of block mode types consisting of entries from BlockMode. Multiple values can be OR'ed together. e.g. (BLOCK_MODE_ECB | BLOCK_MODE_CBC).
using telux::sec::PaddingTypes = typedef int32_t |
This is a list of padding types to use consisting of entries from Padding. Multiple values can be OR'ed together. e.g. (PADDING_PKCS7 | PADDING_RSA_PSS).
using telux::sec::DigestTypes = typedef int32_t |
This is a list of digest types to use consisting of entries from Digest. Multiple values can be OR'ed together. e.g. (DIGEST_SHA_2_256 | DIGEST_SHA_2_512).
using telux::sec::AlgorithmTypes = typedef int32_t |
This is one of the entry from Algorithm to specify algorithm to use.
using telux::sec::CurveTypes = typedef int32_t |
This is one of the entry from Curve to specify curve to use.
Specifies the operation for which the key can be used. A key can be used for multiple type of operations.
enum telux::sec::Padding |
Padding modes that may be applied to plain text for encryption operations. Only cryptographically-appropriate pairs are specified here.
enum telux::sec::Digest |
Specifies the digest algorithms that may be used with the key to perform signing and verification operations using RSA, ECDSA and HMAC keys. The digest used during signing/verification must match with the digest associated with the key when key was generated.
Algorithm for signing, verification, encryption and decryption operations.
enum telux::sec::Curve |