blob: 6418957c24656e86fde80062aec7e730a1fac635 [file] [log] [blame]
Damien Miller8ce82962002-05-22 14:24:01 +10001// $Id: Ssh.java,v 1.3 2002/05/22 04:24:02 djm Exp $
Damien Miller69e00a12001-09-15 20:58:46 +10002//
3// Ssh.java
4// SSH / smartcard integration project, smartcard side
5//
6// Tomoko Fukuzawa, created, Feb., 2000
7//
8// Naomaru Itoi, modified, Apr., 2000
9//
10
11// copyright 2000
12// the regents of the university of michigan
13// all rights reserved
14//
15// permission is granted to use, copy, create derivative works
16// and redistribute this software and such derivative works
17// for any purpose, so long as the name of the university of
18// michigan is not used in any advertising or publicity
19// pertaining to the use or distribution of this software
20// without specific, written prior authorization. if the
21// above copyright notice or any other identification of the
22// university of michigan is included in any copy of any
23// portion of this software, then the disclaimer below must
24// also be included.
25//
26// this software is provided as is, without representation
27// from the university of michigan as to its fitness for any
28// purpose, and without warranty by the university of
29// michigan of any kind, either express or implied, including
30// without limitation the implied warranties of
31// merchantability and fitness for a particular purpose. the
32// regents of the university of michigan shall not be liable
33// for any damages, including special, indirect, incidental, or
34// consequential damages, with respect to any claim arising
35// out of or in connection with the use of the software, even
36// if it has been or is hereafter advised of the possibility of
37// such damages.
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000038
39import javacard.framework.*;
40import javacardx.framework.*;
41import javacardx.crypto.*;
42
43public class Ssh extends javacard.framework.Applet
Damien Miller69e00a12001-09-15 20:58:46 +100044{
Damien Miller8ce82962002-05-22 14:24:01 +100045 // Change this when the applet changes; hi byte is major, low byte is minor
46 static final short applet_version = (short)0x0102;
47
Damien Miller69e00a12001-09-15 20:58:46 +100048 /* constants declaration */
49 // code of CLA byte in the command APDU header
50 static final byte Ssh_CLA =(byte)0x05;
51
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000052 // codes of INS byte in the command APDU header
Damien Miller69e00a12001-09-15 20:58:46 +100053 static final byte DECRYPT = (byte) 0x10;
54 static final byte GET_KEYLENGTH = (byte) 0x20;
55 static final byte GET_PUBKEY = (byte) 0x30;
Damien Miller8ce82962002-05-22 14:24:01 +100056 static final byte GET_VERSION = (byte) 0x32;
Damien Miller69e00a12001-09-15 20:58:46 +100057 static final byte GET_RESPONSE = (byte) 0xc0;
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000058
Damien Miller69e00a12001-09-15 20:58:46 +100059 static final short keysize = 1024;
Damien Miller8ce82962002-05-22 14:24:01 +100060 static final short root_fid = (short)0x3f00;
61 static final short privkey_fid = (short)0x0012;
62 static final short pubkey_fid = (short)(('s'<<8)|'h');
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000063
Damien Miller8ce82962002-05-22 14:24:01 +100064 /* instance variables declaration */
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000065 AsymKey rsakey;
66 CyberflexFile file;
67 CyberflexOS os;
Damien Miller69e00a12001-09-15 20:58:46 +100068
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000069 private Ssh()
70 {
71 file = new CyberflexFile();
72 os = new CyberflexOS();
Damien Miller69e00a12001-09-15 20:58:46 +100073
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000074 rsakey = new RSA_CRT_PrivateKey (keysize);
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000075
76 if ( ! rsakey.isSupportedLength (keysize) )
77 ISOException.throwIt (ISO.SW_WRONG_LENGTH);
78
Damien Miller69e00a12001-09-15 20:58:46 +100079 register();
80 } // end of the constructor
81
82 public boolean select() {
83 if (!rsakey.isInitialized())
84 rsakey.setKeyInstance ((short)0xc8, (short)0x10);
85
86 return true;
87 }
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000088
89 public static void install(APDU apdu)
90 {
Damien Miller69e00a12001-09-15 20:58:46 +100091 new Ssh(); // create a Ssh applet instance (card)
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000092 } // end of install method
93
Damien Miller69e00a12001-09-15 20:58:46 +100094 public static void main(String args[]) {
95 ISOException.throwIt((short) 0x9000);
96 }
97
Ben Lindstrom3133dbb2001-07-04 05:35:00 +000098 public void process(APDU apdu)
Damien Miller69e00a12001-09-15 20:58:46 +100099 {
100 // APDU object carries a byte array (buffer) to
101 // transfer incoming and outgoing APDU header
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000102 // and data bytes between card and CAD
Damien Miller8ce82962002-05-22 14:24:01 +1000103 byte buffer[] = apdu.getBuffer();
104 short size, st;
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000105
106 // verify that if the applet can accept this
Damien Miller69e00a12001-09-15 20:58:46 +1000107 // APDU message
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000108 // NI: change suggested by Wayne Dyksen, Purdue
109 if (buffer[ISO.OFFSET_INS] == ISO.INS_SELECT)
110 ISOException.throwIt(ISO.SW_NO_ERROR);
Damien Miller69e00a12001-09-15 20:58:46 +1000111
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000112 switch (buffer[ISO.OFFSET_INS]) {
113 case DECRYPT:
114 if (buffer[ISO.OFFSET_CLA] != Ssh_CLA)
115 ISOException.throwIt(ISO.SW_CLA_NOT_SUPPORTED);
116 //decrypt (apdu);
Damien Miller8ce82962002-05-22 14:24:01 +1000117 size = (short) (buffer[ISO.OFFSET_LC] & 0x00FF);
Damien Miller69e00a12001-09-15 20:58:46 +1000118
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000119 if (apdu.setIncomingAndReceive() != size)
120 ISOException.throwIt (ISO.SW_WRONG_LENGTH);
Damien Miller69e00a12001-09-15 20:58:46 +1000121
Damien Miller8ce82962002-05-22 14:24:01 +1000122 // check access; depends on bit 2 (x/a)
123 file.selectFile(root_fid);
124 file.selectFile(privkey_fid);
125 st = os.checkAccess(ACL.EXECUTE);
126 if (st != ST.ACCESS_CLEARED) {
127 CyberflexAPDU.prepareSW1SW2(st);
128 ISOException.throwIt(CyberflexAPDU.getSW1SW2());
129 }
130
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000131 rsakey.cryptoUpdate (buffer, (short) ISO.OFFSET_CDATA, size,
132 buffer, (short) ISO.OFFSET_CDATA);
Damien Miller69e00a12001-09-15 20:58:46 +1000133
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000134 apdu.setOutgoingAndSend ((short) ISO.OFFSET_CDATA, size);
Damien Miller8ce82962002-05-22 14:24:01 +1000135 break;
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000136 case GET_PUBKEY:
Damien Miller8ce82962002-05-22 14:24:01 +1000137 file.selectFile(root_fid); // select root
138 file.selectFile(pubkey_fid); // select public key file
139 size = (short)(file.getFileSize() - 16);
140 st = os.readBinaryFile(buffer, (short)0, (short)0, size);
141 if (st == ST.SUCCESS)
142 apdu.setOutgoingAndSend((short)0, size);
143 else {
144 CyberflexAPDU.prepareSW1SW2(st);
145 ISOException.throwIt(CyberflexAPDU.getSW1SW2());
146 }
147 break;
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000148 case GET_KEYLENGTH:
Damien Miller8ce82962002-05-22 14:24:01 +1000149 Util.setShort(buffer, (short)0, keysize);
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000150 apdu.setOutgoingAndSend ((short)0, (short)2);
Damien Miller8ce82962002-05-22 14:24:01 +1000151 break;
152 case GET_VERSION:
153 Util.setShort(buffer, (short)0, applet_version);
154 apdu.setOutgoingAndSend ((short)0, (short)2);
155 break;
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000156 case GET_RESPONSE:
Damien Miller8ce82962002-05-22 14:24:01 +1000157 break;
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000158 default:
Damien Miller69e00a12001-09-15 20:58:46 +1000159 ISOException.throwIt (ISO.SW_INS_NOT_SUPPORTED);
160 }
Ben Lindstrom3133dbb2001-07-04 05:35:00 +0000161
162 } // end of process method
163
Damien Miller69e00a12001-09-15 20:58:46 +1000164} // end of class Ssh