2002-05-22 04:24:01 +00:00
|
|
|
// $Id: Ssh.java,v 1.3 2002/05/22 04:24:02 djm Exp $
|
2001-09-15 10:58:46 +00:00
|
|
|
//
|
|
|
|
// Ssh.java
|
|
|
|
// SSH / smartcard integration project, smartcard side
|
|
|
|
//
|
|
|
|
// Tomoko Fukuzawa, created, Feb., 2000
|
|
|
|
//
|
|
|
|
// Naomaru Itoi, modified, Apr., 2000
|
|
|
|
//
|
|
|
|
|
|
|
|
// copyright 2000
|
|
|
|
// the regents of the university of michigan
|
|
|
|
// all rights reserved
|
|
|
|
//
|
|
|
|
// permission is granted to use, copy, create derivative works
|
|
|
|
// and redistribute this software and such derivative works
|
|
|
|
// for any purpose, so long as the name of the university of
|
|
|
|
// michigan is not used in any advertising or publicity
|
|
|
|
// pertaining to the use or distribution of this software
|
|
|
|
// without specific, written prior authorization. if the
|
|
|
|
// above copyright notice or any other identification of the
|
|
|
|
// university of michigan is included in any copy of any
|
|
|
|
// portion of this software, then the disclaimer below must
|
|
|
|
// also be included.
|
|
|
|
//
|
|
|
|
// this software is provided as is, without representation
|
|
|
|
// from the university of michigan as to its fitness for any
|
|
|
|
// purpose, and without warranty by the university of
|
|
|
|
// michigan of any kind, either express or implied, including
|
|
|
|
// without limitation the implied warranties of
|
|
|
|
// merchantability and fitness for a particular purpose. the
|
|
|
|
// regents of the university of michigan shall not be liable
|
|
|
|
// for any damages, including special, indirect, incidental, or
|
|
|
|
// consequential damages, with respect to any claim arising
|
|
|
|
// out of or in connection with the use of the software, even
|
|
|
|
// if it has been or is hereafter advised of the possibility of
|
|
|
|
// such damages.
|
2001-07-04 05:35:00 +00:00
|
|
|
|
|
|
|
import javacard.framework.*;
|
|
|
|
import javacardx.framework.*;
|
|
|
|
import javacardx.crypto.*;
|
|
|
|
|
|
|
|
public class Ssh extends javacard.framework.Applet
|
2001-09-15 10:58:46 +00:00
|
|
|
{
|
2002-05-22 04:24:01 +00:00
|
|
|
// Change this when the applet changes; hi byte is major, low byte is minor
|
|
|
|
static final short applet_version = (short)0x0102;
|
|
|
|
|
2001-09-15 10:58:46 +00:00
|
|
|
/* constants declaration */
|
|
|
|
// code of CLA byte in the command APDU header
|
|
|
|
static final byte Ssh_CLA =(byte)0x05;
|
|
|
|
|
2001-07-04 05:35:00 +00:00
|
|
|
// codes of INS byte in the command APDU header
|
2001-09-15 10:58:46 +00:00
|
|
|
static final byte DECRYPT = (byte) 0x10;
|
|
|
|
static final byte GET_KEYLENGTH = (byte) 0x20;
|
|
|
|
static final byte GET_PUBKEY = (byte) 0x30;
|
2002-05-22 04:24:01 +00:00
|
|
|
static final byte GET_VERSION = (byte) 0x32;
|
2001-09-15 10:58:46 +00:00
|
|
|
static final byte GET_RESPONSE = (byte) 0xc0;
|
2001-07-04 05:35:00 +00:00
|
|
|
|
2001-09-15 10:58:46 +00:00
|
|
|
static final short keysize = 1024;
|
2002-05-22 04:24:01 +00:00
|
|
|
static final short root_fid = (short)0x3f00;
|
|
|
|
static final short privkey_fid = (short)0x0012;
|
|
|
|
static final short pubkey_fid = (short)(('s'<<8)|'h');
|
2001-07-04 05:35:00 +00:00
|
|
|
|
2002-05-22 04:24:01 +00:00
|
|
|
/* instance variables declaration */
|
2001-07-04 05:35:00 +00:00
|
|
|
AsymKey rsakey;
|
|
|
|
CyberflexFile file;
|
|
|
|
CyberflexOS os;
|
2001-09-15 10:58:46 +00:00
|
|
|
|
2001-07-04 05:35:00 +00:00
|
|
|
private Ssh()
|
|
|
|
{
|
|
|
|
file = new CyberflexFile();
|
|
|
|
os = new CyberflexOS();
|
2001-09-15 10:58:46 +00:00
|
|
|
|
2001-07-04 05:35:00 +00:00
|
|
|
rsakey = new RSA_CRT_PrivateKey (keysize);
|
|
|
|
|
|
|
|
if ( ! rsakey.isSupportedLength (keysize) )
|
|
|
|
ISOException.throwIt (ISO.SW_WRONG_LENGTH);
|
|
|
|
|
2001-09-15 10:58:46 +00:00
|
|
|
register();
|
|
|
|
} // end of the constructor
|
|
|
|
|
|
|
|
public boolean select() {
|
|
|
|
if (!rsakey.isInitialized())
|
|
|
|
rsakey.setKeyInstance ((short)0xc8, (short)0x10);
|
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
2001-07-04 05:35:00 +00:00
|
|
|
|
|
|
|
public static void install(APDU apdu)
|
|
|
|
{
|
2001-09-15 10:58:46 +00:00
|
|
|
new Ssh(); // create a Ssh applet instance (card)
|
2001-07-04 05:35:00 +00:00
|
|
|
} // end of install method
|
|
|
|
|
2001-09-15 10:58:46 +00:00
|
|
|
public static void main(String args[]) {
|
|
|
|
ISOException.throwIt((short) 0x9000);
|
|
|
|
}
|
|
|
|
|
2001-07-04 05:35:00 +00:00
|
|
|
public void process(APDU apdu)
|
2001-09-15 10:58:46 +00:00
|
|
|
{
|
|
|
|
// APDU object carries a byte array (buffer) to
|
|
|
|
// transfer incoming and outgoing APDU header
|
2001-07-04 05:35:00 +00:00
|
|
|
// and data bytes between card and CAD
|
2002-05-22 04:24:01 +00:00
|
|
|
byte buffer[] = apdu.getBuffer();
|
|
|
|
short size, st;
|
2001-07-04 05:35:00 +00:00
|
|
|
|
|
|
|
// verify that if the applet can accept this
|
2001-09-15 10:58:46 +00:00
|
|
|
// APDU message
|
2001-07-04 05:35:00 +00:00
|
|
|
// NI: change suggested by Wayne Dyksen, Purdue
|
|
|
|
if (buffer[ISO.OFFSET_INS] == ISO.INS_SELECT)
|
|
|
|
ISOException.throwIt(ISO.SW_NO_ERROR);
|
2001-09-15 10:58:46 +00:00
|
|
|
|
2001-07-04 05:35:00 +00:00
|
|
|
switch (buffer[ISO.OFFSET_INS]) {
|
|
|
|
case DECRYPT:
|
|
|
|
if (buffer[ISO.OFFSET_CLA] != Ssh_CLA)
|
|
|
|
ISOException.throwIt(ISO.SW_CLA_NOT_SUPPORTED);
|
|
|
|
//decrypt (apdu);
|
2002-05-22 04:24:01 +00:00
|
|
|
size = (short) (buffer[ISO.OFFSET_LC] & 0x00FF);
|
2001-09-15 10:58:46 +00:00
|
|
|
|
2001-07-04 05:35:00 +00:00
|
|
|
if (apdu.setIncomingAndReceive() != size)
|
|
|
|
ISOException.throwIt (ISO.SW_WRONG_LENGTH);
|
2001-09-15 10:58:46 +00:00
|
|
|
|
2002-05-22 04:24:01 +00:00
|
|
|
// check access; depends on bit 2 (x/a)
|
|
|
|
file.selectFile(root_fid);
|
|
|
|
file.selectFile(privkey_fid);
|
|
|
|
st = os.checkAccess(ACL.EXECUTE);
|
|
|
|
if (st != ST.ACCESS_CLEARED) {
|
|
|
|
CyberflexAPDU.prepareSW1SW2(st);
|
|
|
|
ISOException.throwIt(CyberflexAPDU.getSW1SW2());
|
|
|
|
}
|
|
|
|
|
2001-07-04 05:35:00 +00:00
|
|
|
rsakey.cryptoUpdate (buffer, (short) ISO.OFFSET_CDATA, size,
|
|
|
|
buffer, (short) ISO.OFFSET_CDATA);
|
2001-09-15 10:58:46 +00:00
|
|
|
|
2001-07-04 05:35:00 +00:00
|
|
|
apdu.setOutgoingAndSend ((short) ISO.OFFSET_CDATA, size);
|
2002-05-22 04:24:01 +00:00
|
|
|
break;
|
2001-07-04 05:35:00 +00:00
|
|
|
case GET_PUBKEY:
|
2002-05-22 04:24:01 +00:00
|
|
|
file.selectFile(root_fid); // select root
|
|
|
|
file.selectFile(pubkey_fid); // select public key file
|
|
|
|
size = (short)(file.getFileSize() - 16);
|
|
|
|
st = os.readBinaryFile(buffer, (short)0, (short)0, size);
|
|
|
|
if (st == ST.SUCCESS)
|
|
|
|
apdu.setOutgoingAndSend((short)0, size);
|
|
|
|
else {
|
|
|
|
CyberflexAPDU.prepareSW1SW2(st);
|
|
|
|
ISOException.throwIt(CyberflexAPDU.getSW1SW2());
|
|
|
|
}
|
|
|
|
break;
|
2001-07-04 05:35:00 +00:00
|
|
|
case GET_KEYLENGTH:
|
2002-05-22 04:24:01 +00:00
|
|
|
Util.setShort(buffer, (short)0, keysize);
|
|
|
|
apdu.setOutgoingAndSend ((short)0, (short)2);
|
|
|
|
break;
|
|
|
|
case GET_VERSION:
|
|
|
|
Util.setShort(buffer, (short)0, applet_version);
|
2001-07-04 05:35:00 +00:00
|
|
|
apdu.setOutgoingAndSend ((short)0, (short)2);
|
2002-05-22 04:24:01 +00:00
|
|
|
break;
|
2001-07-04 05:35:00 +00:00
|
|
|
case GET_RESPONSE:
|
2002-05-22 04:24:01 +00:00
|
|
|
break;
|
2001-07-04 05:35:00 +00:00
|
|
|
default:
|
2001-09-15 10:58:46 +00:00
|
|
|
ISOException.throwIt (ISO.SW_INS_NOT_SUPPORTED);
|
|
|
|
}
|
2001-07-04 05:35:00 +00:00
|
|
|
|
|
|
|
} // end of process method
|
|
|
|
|
2001-09-15 10:58:46 +00:00
|
|
|
} // end of class Ssh
|