2013-09-18 07:31:18 +02:00
|
|
|
/** @file
|
|
|
|
Implement TPM2 DictionaryAttack related command.
|
|
|
|
|
2016-01-11 06:18:32 +01:00
|
|
|
Copyright (c) 2013 - 2016, Intel Corporation. All rights reserved. <BR>
|
2019-04-04 01:06:56 +02:00
|
|
|
SPDX-License-Identifier: BSD-2-Clause-Patent
|
2013-09-18 07:31:18 +02:00
|
|
|
|
|
|
|
**/
|
|
|
|
|
|
|
|
#include <IndustryStandard/UefiTcgPlatform.h>
|
|
|
|
#include <Library/Tpm2CommandLib.h>
|
|
|
|
#include <Library/Tpm2DeviceLib.h>
|
|
|
|
#include <Library/BaseMemoryLib.h>
|
|
|
|
#include <Library/BaseLib.h>
|
|
|
|
#include <Library/DebugLib.h>
|
|
|
|
|
|
|
|
#pragma pack(1)
|
|
|
|
|
|
|
|
typedef struct {
|
2021-12-05 23:54:12 +01:00
|
|
|
TPM2_COMMAND_HEADER Header;
|
|
|
|
TPMI_RH_LOCKOUT LockHandle;
|
|
|
|
UINT32 AuthSessionSize;
|
|
|
|
TPMS_AUTH_COMMAND AuthSession;
|
2013-09-18 07:31:18 +02:00
|
|
|
} TPM2_DICTIONARY_ATTACK_LOCK_RESET_COMMAND;
|
|
|
|
|
|
|
|
typedef struct {
|
2021-12-05 23:54:12 +01:00
|
|
|
TPM2_RESPONSE_HEADER Header;
|
|
|
|
UINT32 AuthSessionSize;
|
|
|
|
TPMS_AUTH_RESPONSE AuthSession;
|
2013-09-18 07:31:18 +02:00
|
|
|
} TPM2_DICTIONARY_ATTACK_LOCK_RESET_RESPONSE;
|
|
|
|
|
|
|
|
typedef struct {
|
2021-12-05 23:54:12 +01:00
|
|
|
TPM2_COMMAND_HEADER Header;
|
|
|
|
TPMI_RH_LOCKOUT LockHandle;
|
|
|
|
UINT32 AuthSessionSize;
|
|
|
|
TPMS_AUTH_COMMAND AuthSession;
|
|
|
|
UINT32 NewMaxTries;
|
|
|
|
UINT32 NewRecoveryTime;
|
|
|
|
UINT32 LockoutRecovery;
|
2013-09-18 07:31:18 +02:00
|
|
|
} TPM2_DICTIONARY_ATTACK_PARAMETERS_COMMAND;
|
|
|
|
|
|
|
|
typedef struct {
|
2021-12-05 23:54:12 +01:00
|
|
|
TPM2_RESPONSE_HEADER Header;
|
|
|
|
UINT32 AuthSessionSize;
|
|
|
|
TPMS_AUTH_RESPONSE AuthSession;
|
2013-09-18 07:31:18 +02:00
|
|
|
} TPM2_DICTIONARY_ATTACK_PARAMETERS_RESPONSE;
|
|
|
|
|
|
|
|
#pragma pack()
|
|
|
|
|
|
|
|
/**
|
|
|
|
This command cancels the effect of a TPM lockout due to a number of successive authorization failures.
|
|
|
|
If this command is properly authorized, the lockout counter is set to zero.
|
|
|
|
|
|
|
|
@param[in] LockHandle TPM_RH_LOCKOUT
|
|
|
|
@param[in] AuthSession Auth Session context
|
|
|
|
|
|
|
|
@retval EFI_SUCCESS Operation completed successfully.
|
|
|
|
@retval EFI_DEVICE_ERROR Unexpected device behavior.
|
|
|
|
**/
|
|
|
|
EFI_STATUS
|
|
|
|
EFIAPI
|
|
|
|
Tpm2DictionaryAttackLockReset (
|
2021-12-05 23:54:12 +01:00
|
|
|
IN TPMI_RH_LOCKOUT LockHandle,
|
|
|
|
IN TPMS_AUTH_COMMAND *AuthSession
|
2013-09-18 07:31:18 +02:00
|
|
|
)
|
|
|
|
{
|
2021-12-05 23:54:12 +01:00
|
|
|
EFI_STATUS Status;
|
|
|
|
TPM2_DICTIONARY_ATTACK_LOCK_RESET_COMMAND SendBuffer;
|
|
|
|
TPM2_DICTIONARY_ATTACK_LOCK_RESET_RESPONSE RecvBuffer;
|
|
|
|
UINT32 SendBufferSize;
|
|
|
|
UINT32 RecvBufferSize;
|
|
|
|
UINT8 *Buffer;
|
|
|
|
UINT32 SessionInfoSize;
|
2013-09-18 07:31:18 +02:00
|
|
|
|
|
|
|
//
|
|
|
|
// Construct command
|
|
|
|
//
|
2021-12-05 23:54:12 +01:00
|
|
|
SendBuffer.Header.tag = SwapBytes16 (TPM_ST_SESSIONS);
|
|
|
|
SendBuffer.Header.commandCode = SwapBytes32 (TPM_CC_DictionaryAttackLockReset);
|
2013-09-18 07:31:18 +02:00
|
|
|
|
|
|
|
SendBuffer.LockHandle = SwapBytes32 (LockHandle);
|
|
|
|
|
|
|
|
//
|
|
|
|
// Add in Auth session
|
|
|
|
//
|
|
|
|
Buffer = (UINT8 *)&SendBuffer.AuthSession;
|
|
|
|
|
|
|
|
// sessionInfoSize
|
2021-12-05 23:54:12 +01:00
|
|
|
SessionInfoSize = CopyAuthSessionCommand (AuthSession, Buffer);
|
|
|
|
Buffer += SessionInfoSize;
|
|
|
|
SendBuffer.AuthSessionSize = SwapBytes32 (SessionInfoSize);
|
2013-09-18 07:31:18 +02:00
|
|
|
|
2021-12-05 23:54:12 +01:00
|
|
|
SendBufferSize = (UINT32)((UINTN)Buffer - (UINTN)&SendBuffer);
|
2013-09-18 07:31:18 +02:00
|
|
|
SendBuffer.Header.paramSize = SwapBytes32 (SendBufferSize);
|
|
|
|
|
|
|
|
//
|
|
|
|
// send Tpm command
|
|
|
|
//
|
|
|
|
RecvBufferSize = sizeof (RecvBuffer);
|
2021-12-05 23:54:12 +01:00
|
|
|
Status = Tpm2SubmitCommand (SendBufferSize, (UINT8 *)&SendBuffer, &RecvBufferSize, (UINT8 *)&RecvBuffer);
|
2013-09-18 07:31:18 +02:00
|
|
|
if (EFI_ERROR (Status)) {
|
2016-01-11 06:18:32 +01:00
|
|
|
goto Done;
|
2013-09-18 07:31:18 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
if (RecvBufferSize < sizeof (TPM2_RESPONSE_HEADER)) {
|
2021-11-17 04:21:36 +01:00
|
|
|
DEBUG ((DEBUG_ERROR, "Tpm2DictionaryAttackLockReset - RecvBufferSize Error - %x\n", RecvBufferSize));
|
2016-01-11 06:18:32 +01:00
|
|
|
Status = EFI_DEVICE_ERROR;
|
|
|
|
goto Done;
|
2013-09-18 07:31:18 +02:00
|
|
|
}
|
2021-12-05 23:54:12 +01:00
|
|
|
|
|
|
|
if (SwapBytes32 (RecvBuffer.Header.responseCode) != TPM_RC_SUCCESS) {
|
|
|
|
DEBUG ((DEBUG_ERROR, "Tpm2DictionaryAttackLockReset - responseCode - %x\n", SwapBytes32 (RecvBuffer.Header.responseCode)));
|
2016-01-11 06:18:32 +01:00
|
|
|
Status = EFI_DEVICE_ERROR;
|
|
|
|
goto Done;
|
2013-09-18 07:31:18 +02:00
|
|
|
}
|
|
|
|
|
2016-01-11 06:18:32 +01:00
|
|
|
Done:
|
|
|
|
//
|
|
|
|
// Clear AuthSession Content
|
|
|
|
//
|
2021-12-05 23:54:12 +01:00
|
|
|
ZeroMem (&SendBuffer, sizeof (SendBuffer));
|
|
|
|
ZeroMem (&RecvBuffer, sizeof (RecvBuffer));
|
2016-01-11 06:18:32 +01:00
|
|
|
return Status;
|
2013-09-18 07:31:18 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
This command cancels the effect of a TPM lockout due to a number of successive authorization failures.
|
|
|
|
If this command is properly authorized, the lockout counter is set to zero.
|
|
|
|
|
|
|
|
@param[in] LockHandle TPM_RH_LOCKOUT
|
|
|
|
@param[in] AuthSession Auth Session context
|
|
|
|
@param[in] NewMaxTries Count of authorization failures before the lockout is imposed
|
|
|
|
@param[in] NewRecoveryTime Time in seconds before the authorization failure count is automatically decremented
|
|
|
|
@param[in] LockoutRecovery Time in seconds after a lockoutAuth failure before use of lockoutAuth is allowed
|
|
|
|
|
|
|
|
@retval EFI_SUCCESS Operation completed successfully.
|
|
|
|
@retval EFI_DEVICE_ERROR Unexpected device behavior.
|
|
|
|
**/
|
|
|
|
EFI_STATUS
|
|
|
|
EFIAPI
|
|
|
|
Tpm2DictionaryAttackParameters (
|
2021-12-05 23:54:12 +01:00
|
|
|
IN TPMI_RH_LOCKOUT LockHandle,
|
|
|
|
IN TPMS_AUTH_COMMAND *AuthSession,
|
|
|
|
IN UINT32 NewMaxTries,
|
|
|
|
IN UINT32 NewRecoveryTime,
|
|
|
|
IN UINT32 LockoutRecovery
|
2013-09-18 07:31:18 +02:00
|
|
|
)
|
|
|
|
{
|
2021-12-05 23:54:12 +01:00
|
|
|
EFI_STATUS Status;
|
|
|
|
TPM2_DICTIONARY_ATTACK_PARAMETERS_COMMAND SendBuffer;
|
|
|
|
TPM2_DICTIONARY_ATTACK_PARAMETERS_RESPONSE RecvBuffer;
|
|
|
|
UINT32 SendBufferSize;
|
|
|
|
UINT32 RecvBufferSize;
|
|
|
|
UINT8 *Buffer;
|
|
|
|
UINT32 SessionInfoSize;
|
2013-09-18 07:31:18 +02:00
|
|
|
|
|
|
|
//
|
|
|
|
// Construct command
|
|
|
|
//
|
2021-12-05 23:54:12 +01:00
|
|
|
SendBuffer.Header.tag = SwapBytes16 (TPM_ST_SESSIONS);
|
|
|
|
SendBuffer.Header.commandCode = SwapBytes32 (TPM_CC_DictionaryAttackParameters);
|
2013-09-18 07:31:18 +02:00
|
|
|
|
|
|
|
SendBuffer.LockHandle = SwapBytes32 (LockHandle);
|
|
|
|
|
|
|
|
//
|
|
|
|
// Add in Auth session
|
|
|
|
//
|
|
|
|
Buffer = (UINT8 *)&SendBuffer.AuthSession;
|
|
|
|
|
|
|
|
// sessionInfoSize
|
2021-12-05 23:54:12 +01:00
|
|
|
SessionInfoSize = CopyAuthSessionCommand (AuthSession, Buffer);
|
|
|
|
Buffer += SessionInfoSize;
|
|
|
|
SendBuffer.AuthSessionSize = SwapBytes32 (SessionInfoSize);
|
2013-09-18 07:31:18 +02:00
|
|
|
|
|
|
|
//
|
|
|
|
// Real data
|
|
|
|
//
|
2021-12-05 23:54:12 +01:00
|
|
|
WriteUnaligned32 ((UINT32 *)Buffer, SwapBytes32 (NewMaxTries));
|
|
|
|
Buffer += sizeof (UINT32);
|
|
|
|
WriteUnaligned32 ((UINT32 *)Buffer, SwapBytes32 (NewRecoveryTime));
|
|
|
|
Buffer += sizeof (UINT32);
|
|
|
|
WriteUnaligned32 ((UINT32 *)Buffer, SwapBytes32 (LockoutRecovery));
|
|
|
|
Buffer += sizeof (UINT32);
|
2013-09-18 07:31:18 +02:00
|
|
|
|
2021-12-05 23:54:12 +01:00
|
|
|
SendBufferSize = (UINT32)((UINTN)Buffer - (UINTN)&SendBuffer);
|
2013-09-18 07:31:18 +02:00
|
|
|
SendBuffer.Header.paramSize = SwapBytes32 (SendBufferSize);
|
|
|
|
|
|
|
|
//
|
|
|
|
// send Tpm command
|
|
|
|
//
|
|
|
|
RecvBufferSize = sizeof (RecvBuffer);
|
2021-12-05 23:54:12 +01:00
|
|
|
Status = Tpm2SubmitCommand (SendBufferSize, (UINT8 *)&SendBuffer, &RecvBufferSize, (UINT8 *)&RecvBuffer);
|
2013-09-18 07:31:18 +02:00
|
|
|
if (EFI_ERROR (Status)) {
|
2016-01-11 06:18:32 +01:00
|
|
|
goto Done;
|
2013-09-18 07:31:18 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
if (RecvBufferSize < sizeof (TPM2_RESPONSE_HEADER)) {
|
2021-11-17 04:21:36 +01:00
|
|
|
DEBUG ((DEBUG_ERROR, "Tpm2DictionaryAttackParameters - RecvBufferSize Error - %x\n", RecvBufferSize));
|
2016-01-11 06:18:32 +01:00
|
|
|
Status = EFI_DEVICE_ERROR;
|
|
|
|
goto Done;
|
2013-09-18 07:31:18 +02:00
|
|
|
}
|
2021-12-05 23:54:12 +01:00
|
|
|
|
|
|
|
if (SwapBytes32 (RecvBuffer.Header.responseCode) != TPM_RC_SUCCESS) {
|
|
|
|
DEBUG ((DEBUG_ERROR, "Tpm2DictionaryAttackParameters - responseCode - %x\n", SwapBytes32 (RecvBuffer.Header.responseCode)));
|
2016-01-11 06:18:32 +01:00
|
|
|
Status = EFI_DEVICE_ERROR;
|
|
|
|
goto Done;
|
2013-09-18 07:31:18 +02:00
|
|
|
}
|
|
|
|
|
2016-01-11 06:18:32 +01:00
|
|
|
Done:
|
|
|
|
//
|
|
|
|
// Clear AuthSession Content
|
|
|
|
//
|
2021-12-05 23:54:12 +01:00
|
|
|
ZeroMem (&SendBufferSize, sizeof (SendBufferSize));
|
|
|
|
ZeroMem (&RecvBuffer, sizeof (RecvBuffer));
|
2016-01-11 06:18:32 +01:00
|
|
|
return Status;
|
2013-09-18 07:31:18 +02:00
|
|
|
}
|