keycard-go/lightwallet/actionsets/installer.go

275 lines
6.6 KiB
Go
Raw Normal View History

2018-10-24 11:42:00 +00:00
package actionsets
import (
"crypto/rand"
"errors"
"fmt"
2018-10-03 14:26:57 +00:00
"os"
2018-11-06 09:25:54 +00:00
"github.com/status-im/hardware-wallet-go/apdu"
"github.com/status-im/hardware-wallet-go/globalplatform"
"github.com/status-im/hardware-wallet-go/lightwallet"
"github.com/status-im/hardware-wallet-go/lightwallet/actions"
)
var (
cardManagerAID = []byte{0xa0, 0x00, 0x00, 0x01, 0x51, 0x00, 0x00, 0x00}
testKey = []byte{0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47, 0x48, 0x49, 0x4a, 0x4b, 0x4c, 0x4d, 0x4e, 0x4f}
pkgAID = []byte{0x53, 0x74, 0x61, 0x74, 0x75, 0x73, 0x57, 0x61, 0x6C, 0x6C, 0x65, 0x74}
// applet and instance aid
walletAID = []byte{0x53, 0x74, 0x61, 0x74, 0x75, 0x73, 0x57, 0x61, 0x6C, 0x6C, 0x65, 0x74, 0x41, 0x70, 0x70}
ndefAppletAID = []byte{0x53, 0x74, 0x61, 0x74, 0x75, 0x73, 0x57, 0x61, 0x6C, 0x6C, 0x65, 0x74, 0x4E, 0x46, 0x43}
ndefInstanceAID = []byte{0xD2, 0x76, 0x00, 0x00, 0x85, 0x01, 0x01}
2018-11-06 17:38:13 +00:00
errAppletNotInstalled = errors.New("applet not installed")
errCardNotInitialized = errors.New("card not initialized")
errCardAlreadyInitialized = errors.New("card already initialized")
)
2018-10-05 14:40:32 +00:00
// Installer defines a struct with methods to install an applet to a smartcard.
type Installer struct {
c globalplatform.Channel
}
2018-10-05 14:40:32 +00:00
// NewInstaller returns a new Installer that communicates to Transmitter t.
func NewInstaller(t globalplatform.Transmitter) *Installer {
return &Installer{
c: globalplatform.NewNormalChannel(t),
}
}
2018-10-05 14:40:32 +00:00
// Install installs the applet from the specified capFile.
2018-10-22 17:33:53 +00:00
func (i *Installer) Install(capFile *os.File, overwriteApplet bool) error {
2018-11-06 11:54:11 +00:00
info, err := actions.Select(i.c, walletAID)
if err != nil {
2018-10-22 17:33:53 +00:00
return err
}
2018-11-06 11:54:11 +00:00
if info.Installed && !overwriteApplet {
return errors.New("applet already installed")
2018-10-04 14:06:55 +00:00
}
2018-11-06 11:54:11 +00:00
err = i.initGPSecureChannel(cardManagerAID)
if err != nil {
return err
2018-10-04 14:06:55 +00:00
}
err = i.deleteAID(ndefInstanceAID, walletAID, pkgAID)
if err != nil {
2018-10-22 17:33:53 +00:00
return err
}
2018-10-19 11:45:35 +00:00
err = i.installApplets(capFile)
if err != nil {
2018-10-22 17:33:53 +00:00
return err
}
2018-10-22 17:33:53 +00:00
return err
}
2018-10-24 11:42:00 +00:00
func (i *Installer) Init() (*lightwallet.Secrets, error) {
secrets, err := lightwallet.NewSecrets()
2018-10-22 17:33:53 +00:00
if err != nil {
return nil, err
}
info, err := actions.Select(i.c, walletAID)
2018-10-24 16:16:14 +00:00
if err != nil {
return nil, err
}
if !info.Installed {
2018-11-06 17:38:13 +00:00
return nil, errAppletNotInstalled
}
if info.Initialized {
2018-11-06 17:38:13 +00:00
return nil, errCardAlreadyInitialized
}
err = actions.Init(i.c, info.PublicKey, secrets, walletAID)
2018-10-22 17:33:53 +00:00
if err != nil {
return nil, err
}
return secrets, nil
}
2018-10-24 16:16:14 +00:00
func (i *Installer) Pair(pairingPass, pin string) (*lightwallet.PairingInfo, error) {
_, err := actions.SelectInitialized(i.c, walletAID)
if err != nil {
return nil, err
}
return actions.Pair(i.c, pairingPass, pin)
}
2018-11-06 17:38:13 +00:00
// Info returns a lightwallet.ApplicationInfo struct with info about the card.
2018-11-06 11:54:11 +00:00
func (i *Installer) Info() (*lightwallet.ApplicationInfo, error) {
return actions.Select(i.c, walletAID)
}
2018-11-06 17:38:13 +00:00
// Status returns
2018-11-07 13:39:58 +00:00
func (i *Installer) Status(index uint8, key []byte) (*lightwallet.ApplicationStatus, error) {
2018-11-06 17:38:13 +00:00
info, err := actions.Select(i.c, walletAID)
if err != nil {
2018-11-07 13:39:58 +00:00
return nil, err
2018-11-06 17:38:13 +00:00
}
if !info.Installed {
2018-11-07 13:39:58 +00:00
return nil, errAppletNotInstalled
2018-11-06 17:38:13 +00:00
}
if !info.Initialized {
2018-11-07 13:39:58 +00:00
return nil, errCardNotInitialized
2018-11-06 17:38:13 +00:00
}
sc, err := actions.OpenSecureChannel(i.c, info, index, key)
if err != nil {
2018-11-07 13:39:58 +00:00
return nil, err
2018-11-06 17:38:13 +00:00
}
2018-11-07 13:39:58 +00:00
return actions.GetStatusApplication(sc)
2018-11-06 17:38:13 +00:00
}
2018-10-05 14:40:32 +00:00
// Delete deletes the applet and related package from the card.
func (i *Installer) Delete() error {
2018-10-24 16:16:14 +00:00
err := i.initGPSecureChannel(cardManagerAID)
if err != nil {
return err
}
return i.deleteAID(ndefInstanceAID, walletAID, pkgAID)
}
2018-10-24 16:16:14 +00:00
func (i *Installer) initGPSecureChannel(sdaid []byte) error {
// select card manager
err := i.selectAID(sdaid)
if err != nil {
return err
}
// initialize update
session, err := i.initializeUpdate()
if err != nil {
return err
}
i.c = globalplatform.NewSecureChannel(session, i.c)
// external authenticate
return i.externalAuthenticate(session)
}
func (i *Installer) selectAID(aid []byte) error {
sel := globalplatform.NewCommandSelect(cardManagerAID)
_, err := i.send("select", sel)
return err
}
func (i *Installer) initializeUpdate() (*globalplatform.Session, error) {
hostChallenge, err := generateHostChallenge()
if err != nil {
2018-10-04 10:10:19 +00:00
return nil, err
}
init := globalplatform.NewCommandInitializeUpdate(hostChallenge)
resp, err := i.send("initialize update", init)
if err != nil {
2018-10-04 10:10:19 +00:00
return nil, err
}
// verify cryptogram and initialize session keys
keys := globalplatform.NewKeyProvider(testKey, testKey)
session, err := globalplatform.NewSession(keys, resp, hostChallenge)
return session, err
}
func (i *Installer) externalAuthenticate(session *globalplatform.Session) error {
encKey := session.KeyProvider().Enc()
extAuth, err := globalplatform.NewCommandExternalAuthenticate(encKey, session.CardChallenge(), session.HostChallenge())
if err != nil {
return err
}
_, err = i.send("external authenticate", extAuth)
return err
}
func (i *Installer) deleteAID(aids ...[]byte) error {
for _, aid := range aids {
del := globalplatform.NewCommandDelete(aid)
_, err := i.send("delete", del, globalplatform.SwOK, globalplatform.SwReferencedDataNotFound)
if err != nil {
return err
}
}
return nil
}
2018-10-19 11:45:35 +00:00
func (i *Installer) installApplets(capFile *os.File) error {
2018-10-03 14:26:57 +00:00
// install for load
preLoad := globalplatform.NewCommandInstallForLoad(pkgAID, cardManagerAID)
_, err := i.send("install for load", preLoad)
2018-10-03 14:26:57 +00:00
if err != nil {
2018-10-19 11:45:35 +00:00
return err
2018-10-03 14:26:57 +00:00
}
// load
load, err := globalplatform.NewLoadCommandStream(capFile)
if err != nil {
2018-10-19 11:45:35 +00:00
return err
2018-10-03 14:26:57 +00:00
}
for load.Next() {
cmd := load.GetCommand()
2018-10-19 11:45:35 +00:00
_, err = i.send(fmt.Sprintf("load %d of 36", load.Index()), cmd)
2018-10-03 14:26:57 +00:00
if err != nil {
2018-10-19 11:45:35 +00:00
return err
2018-10-03 14:26:57 +00:00
}
}
2018-10-19 11:45:35 +00:00
installNdef := globalplatform.NewCommandInstallForInstall(pkgAID, ndefAppletAID, ndefInstanceAID, []byte{})
_, err = i.send("install for install (ndef)", installNdef)
2018-10-04 10:10:19 +00:00
if err != nil {
2018-10-19 11:45:35 +00:00
return err
2018-10-04 10:10:19 +00:00
}
2018-10-19 11:45:35 +00:00
installWallet := globalplatform.NewCommandInstallForInstall(pkgAID, walletAID, walletAID, []byte{})
_, err = i.send("install for install (wallet)", installWallet)
2018-10-04 10:10:19 +00:00
2018-10-19 11:45:35 +00:00
return err
}
func (i *Installer) send(description string, cmd *apdu.Command, allowedResponses ...uint16) (*apdu.Response, error) {
2018-10-05 09:35:56 +00:00
logger.Debug("sending apdu command", "name", description)
resp, err := i.c.Send(cmd)
if err != nil {
return nil, err
}
if len(allowedResponses) == 0 {
allowedResponses = []uint16{apdu.SwOK}
}
for _, code := range allowedResponses {
if code == resp.Sw {
return resp, nil
}
}
2018-10-05 14:40:32 +00:00
err = fmt.Errorf("unexpected response from command %s: %x", description, resp.Sw)
return nil, err
}
func generateHostChallenge() ([]byte, error) {
c := make([]byte, 8)
_, err := rand.Read(c)
return c, err
}