platform_info_facility.cpp 5.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144
  1. /*
  2. * Copyright (C) 2011-2016 Intel Corporation. All rights reserved.
  3. *
  4. * Redistribution and use in source and binary forms, with or without
  5. * modification, are permitted provided that the following conditions
  6. * are met:
  7. *
  8. * * Redistributions of source code must retain the above copyright
  9. * notice, this list of conditions and the following disclaimer.
  10. * * Redistributions in binary form must reproduce the above copyright
  11. * notice, this list of conditions and the following disclaimer in
  12. * the documentation and/or other materials provided with the
  13. * distribution.
  14. * * Neither the name of Intel Corporation nor the names of its
  15. * contributors may be used to endorse or promote products derived
  16. * from this software without specific prior written permission.
  17. *
  18. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
  19. * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
  20. * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
  21. * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
  22. * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  23. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
  24. * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
  25. * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
  26. * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
  27. * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
  28. * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  29. *
  30. */
  31. #include "platform_info_logic.h"
  32. #include "byte_order.h"
  33. #include <assert.h>
  34. #include "sgx_profile.h"
  35. ae_error_t PlatformInfoLogic::get_sgx_epid_group_flags(const platform_info_blob_wrapper_t* p_platform_info_blob, uint8_t* pflags)
  36. {
  37. ae_error_t retval = AE_SUCCESS;
  38. if (NULL != pflags && NULL != p_platform_info_blob && p_platform_info_blob->valid_info_blob) {
  39. *pflags = p_platform_info_blob->platform_info_blob.sgx_epid_group_flags;
  40. }
  41. else {
  42. retval = AE_INVALID_PARAMETER;
  43. }
  44. return retval;
  45. }
  46. ae_error_t PlatformInfoLogic::get_sgx_tcb_evaluation_flags(const platform_info_blob_wrapper_t* p_platform_info_blob, uint16_t* pflags)
  47. {
  48. ae_error_t retval = AE_SUCCESS;
  49. if (NULL != pflags && NULL != p_platform_info_blob && p_platform_info_blob->valid_info_blob) {
  50. const uint16_t* p = reinterpret_cast<const uint16_t*>(p_platform_info_blob->platform_info_blob.sgx_tcb_evaluation_flags);
  51. *pflags = lv_ntohs(*p);
  52. }
  53. else {
  54. retval = AE_INVALID_PARAMETER;
  55. }
  56. return retval;
  57. }
  58. bool PlatformInfoLogic::sgx_gid_out_of_date(const platform_info_blob_wrapper_t* p_platform_info_blob)
  59. {
  60. uint8_t flags = 0;
  61. bool retVal = false;
  62. ae_error_t getflagsError = get_sgx_epid_group_flags(p_platform_info_blob, &flags);
  63. if (AE_SUCCESS == getflagsError) {
  64. retVal = (0 != (QE_EPID_GROUP_OUT_OF_DATE & flags));
  65. }
  66. SGX_DBGPRINT_ONE_STRING_TWO_INTS_CREATE_SESSION(__FUNCTION__" returning ", retVal, retVal);
  67. return retVal;
  68. }
  69. bool PlatformInfoLogic::performance_rekey_available(const platform_info_blob_wrapper_t* p_platform_info_blob)
  70. {
  71. //
  72. // return whether platform info blob says PR is available
  73. // the group associated with PR that's returned corresponds to the group
  74. // that we'll be in **after** executing PR
  75. //
  76. bool retVal = false;
  77. uint8_t flags;
  78. ae_error_t getflagsError = get_sgx_epid_group_flags(p_platform_info_blob, &flags);
  79. if (AE_SUCCESS == getflagsError) {
  80. retVal = static_cast<bool>(flags & PERF_REKEY_FOR_QE_EPID_GROUP_AVAILABLE);
  81. }
  82. SGX_DBGPRINT_ONE_STRING_TWO_INTS_CREATE_SESSION(__FUNCTION__" returning ", retVal, retVal);
  83. return retVal;
  84. }
  85. bool PlatformInfoLogic::qe_svn_out_of_date(const platform_info_blob_wrapper_t* p_platform_info_blob)
  86. {
  87. uint16_t flags = 0;
  88. bool retVal = true;
  89. ae_error_t getflagsError = get_sgx_tcb_evaluation_flags(p_platform_info_blob, &flags);
  90. if (AE_SUCCESS == getflagsError) {
  91. retVal = (0 != (QUOTE_ISVSVN_QE_OUT_OF_DATE & flags));
  92. }
  93. SGX_DBGPRINT_ONE_STRING_TWO_INTS_CREATE_SESSION(__FUNCTION__" returning ", retVal, retVal);
  94. return retVal;
  95. }
  96. bool PlatformInfoLogic::pce_svn_out_of_date(const platform_info_blob_wrapper_t* p_platform_info_blob)
  97. {
  98. uint16_t flags = 0;
  99. bool retVal = true;
  100. ae_error_t getflagsError = get_sgx_tcb_evaluation_flags(p_platform_info_blob, &flags);
  101. if (AE_SUCCESS == getflagsError) {
  102. retVal = (0 != (QUOTE_ISVSVN_PCE_OUT_OF_DATE & flags));
  103. }
  104. SGX_DBGPRINT_ONE_STRING_TWO_INTS_CREATE_SESSION(__FUNCTION__" returning ", retVal, retVal);
  105. return retVal;
  106. }
  107. bool PlatformInfoLogic::cpu_svn_out_of_date(const platform_info_blob_wrapper_t* p_platform_info_blob)
  108. {
  109. uint16_t flags = 0;
  110. bool retVal = false;
  111. ae_error_t getflagsError = get_sgx_tcb_evaluation_flags(p_platform_info_blob, &flags);
  112. if (AE_SUCCESS == getflagsError) {
  113. retVal = (0 != (QUOTE_CPUSVN_OUT_OF_DATE & flags));
  114. }
  115. SGX_DBGPRINT_ONE_STRING_TWO_INTS_CREATE_SESSION(__FUNCTION__" returning ", retVal, retVal);
  116. return retVal;
  117. }
  118. ae_error_t PlatformInfoLogic::need_epid_provisioning(const platform_info_blob_wrapper_t* p_platform_info_blob)
  119. {
  120. ae_error_t status = AESM_NEP_DONT_NEED_EPID_PROVISIONING;
  121. if (sgx_gid_out_of_date(p_platform_info_blob) &&
  122. !qe_svn_out_of_date(p_platform_info_blob) &&
  123. !cpu_svn_out_of_date(p_platform_info_blob) &&
  124. !pce_svn_out_of_date(p_platform_info_blob))
  125. {
  126. status = AESM_NEP_DONT_NEED_UPDATE_PVEQE; // don't need update, but need epid provisioning
  127. }
  128. else if (!sgx_gid_out_of_date(p_platform_info_blob) && performance_rekey_available(p_platform_info_blob))
  129. {
  130. status = AESM_NEP_PERFORMANCE_REKEY;
  131. }
  132. SGX_DBGPRINT_ONE_STRING_TWO_INTS_CREATE_SESSION(__FUNCTION__" returning ", status, status);
  133. return status;
  134. }