key_manager.h 9.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318
  1. // Copyright 2018 yuzu emulator team
  2. // Licensed under GPLv2 or any later version
  3. // Refer to the license.txt file included.
  4. #pragma once
  5. #include <array>
  6. #include <filesystem>
  7. #include <map>
  8. #include <optional>
  9. #include <string>
  10. #include <variant>
  11. #include <fmt/format.h>
  12. #include "common/common_funcs.h"
  13. #include "common/common_types.h"
  14. #include "core/crypto/partition_data_manager.h"
  15. #include "core/file_sys/vfs_types.h"
  16. namespace Common::FS {
  17. class IOFile;
  18. }
  19. namespace FileSys {
  20. class ContentProvider;
  21. }
  22. namespace Loader {
  23. enum class ResultStatus : u16;
  24. }
  25. namespace Core::Crypto {
  26. constexpr u64 TICKET_FILE_TITLEKEY_OFFSET = 0x180;
  27. using Key128 = std::array<u8, 0x10>;
  28. using Key256 = std::array<u8, 0x20>;
  29. using SHA256Hash = std::array<u8, 0x20>;
  30. enum class SignatureType {
  31. RSA_4096_SHA1 = 0x10000,
  32. RSA_2048_SHA1 = 0x10001,
  33. ECDSA_SHA1 = 0x10002,
  34. RSA_4096_SHA256 = 0x10003,
  35. RSA_2048_SHA256 = 0x10004,
  36. ECDSA_SHA256 = 0x10005,
  37. };
  38. u64 GetSignatureTypeDataSize(SignatureType type);
  39. u64 GetSignatureTypePaddingSize(SignatureType type);
  40. enum class TitleKeyType : u8 {
  41. Common = 0,
  42. Personalized = 1,
  43. };
  44. struct TicketData {
  45. std::array<u8, 0x40> issuer;
  46. union {
  47. std::array<u8, 0x100> title_key_block;
  48. struct {
  49. Key128 title_key_common;
  50. std::array<u8, 0xF0> title_key_common_pad;
  51. };
  52. };
  53. INSERT_PADDING_BYTES(0x1);
  54. TitleKeyType type;
  55. INSERT_PADDING_BYTES(0x3);
  56. u8 revision;
  57. INSERT_PADDING_BYTES(0xA);
  58. u64 ticket_id;
  59. u64 device_id;
  60. std::array<u8, 0x10> rights_id;
  61. u32 account_id;
  62. INSERT_PADDING_BYTES(0x14C);
  63. };
  64. static_assert(sizeof(TicketData) == 0x2C0, "TicketData has incorrect size.");
  65. struct RSA4096Ticket {
  66. SignatureType sig_type;
  67. std::array<u8, 0x200> sig_data;
  68. INSERT_PADDING_BYTES(0x3C);
  69. TicketData data;
  70. };
  71. struct RSA2048Ticket {
  72. SignatureType sig_type;
  73. std::array<u8, 0x100> sig_data;
  74. INSERT_PADDING_BYTES(0x3C);
  75. TicketData data;
  76. };
  77. struct ECDSATicket {
  78. SignatureType sig_type;
  79. std::array<u8, 0x3C> sig_data;
  80. INSERT_PADDING_BYTES(0x40);
  81. TicketData data;
  82. };
  83. struct Ticket {
  84. std::variant<RSA4096Ticket, RSA2048Ticket, ECDSATicket> data;
  85. SignatureType GetSignatureType() const;
  86. TicketData& GetData();
  87. const TicketData& GetData() const;
  88. u64 GetSize() const;
  89. static Ticket SynthesizeCommon(Key128 title_key, const std::array<u8, 0x10>& rights_id);
  90. };
  91. static_assert(sizeof(Key128) == 16, "Key128 must be 128 bytes big.");
  92. static_assert(sizeof(Key256) == 32, "Key256 must be 256 bytes big.");
  93. template <size_t bit_size, size_t byte_size = (bit_size >> 3)>
  94. struct RSAKeyPair {
  95. std::array<u8, byte_size> encryption_key;
  96. std::array<u8, byte_size> decryption_key;
  97. std::array<u8, byte_size> modulus;
  98. std::array<u8, 4> exponent;
  99. };
  100. template <size_t bit_size, size_t byte_size>
  101. bool operator==(const RSAKeyPair<bit_size, byte_size>& lhs,
  102. const RSAKeyPair<bit_size, byte_size>& rhs) {
  103. return std::tie(lhs.encryption_key, lhs.decryption_key, lhs.modulus, lhs.exponent) ==
  104. std::tie(rhs.encryption_key, rhs.decryption_key, rhs.modulus, rhs.exponent);
  105. }
  106. template <size_t bit_size, size_t byte_size>
  107. bool operator!=(const RSAKeyPair<bit_size, byte_size>& lhs,
  108. const RSAKeyPair<bit_size, byte_size>& rhs) {
  109. return !(lhs == rhs);
  110. }
  111. enum class KeyCategory : u8 {
  112. Standard,
  113. Title,
  114. Console,
  115. };
  116. enum class S256KeyType : u64 {
  117. SDKey, // f1=SDKeyType
  118. Header, //
  119. SDKeySource, // f1=SDKeyType
  120. HeaderSource, //
  121. };
  122. enum class S128KeyType : u64 {
  123. Master, // f1=crypto revision
  124. Package1, // f1=crypto revision
  125. Package2, // f1=crypto revision
  126. Titlekek, // f1=crypto revision
  127. ETicketRSAKek, //
  128. KeyArea, // f1=crypto revision f2=type {app, ocean, system}
  129. SDSeed, //
  130. Titlekey, // f1=rights id LSB f2=rights id MSB
  131. Source, // f1=source type, f2= sub id
  132. Keyblob, // f1=crypto revision
  133. KeyblobMAC, // f1=crypto revision
  134. TSEC, //
  135. SecureBoot, //
  136. BIS, // f1=partition (0-3), f2=type {crypt, tweak}
  137. HeaderKek, //
  138. SDKek, //
  139. RSAKek, //
  140. };
  141. enum class KeyAreaKeyType : u8 {
  142. Application,
  143. Ocean,
  144. System,
  145. };
  146. enum class SourceKeyType : u8 {
  147. SDKek, //
  148. AESKekGeneration, //
  149. AESKeyGeneration, //
  150. RSAOaepKekGeneration, //
  151. Master, //
  152. Keyblob, // f2=crypto revision
  153. KeyAreaKey, // f2=KeyAreaKeyType
  154. Titlekek, //
  155. Package2, //
  156. HeaderKek, //
  157. KeyblobMAC, //
  158. ETicketKek, //
  159. ETicketKekek, //
  160. };
  161. enum class SDKeyType : u8 {
  162. Save,
  163. NCA,
  164. };
  165. enum class BISKeyType : u8 {
  166. Crypto,
  167. Tweak,
  168. };
  169. enum class RSAKekType : u8 {
  170. Mask0,
  171. Seed3,
  172. };
  173. template <typename KeyType>
  174. struct KeyIndex {
  175. KeyType type;
  176. u64 field1;
  177. u64 field2;
  178. std::string DebugInfo() const {
  179. u8 key_size = 16;
  180. if constexpr (std::is_same_v<KeyType, S256KeyType>)
  181. key_size = 32;
  182. return fmt::format("key_size={:02X}, key={:02X}, field1={:016X}, field2={:016X}", key_size,
  183. static_cast<u8>(type), field1, field2);
  184. }
  185. };
  186. // boost flat_map requires operator< for O(log(n)) lookups.
  187. template <typename KeyType>
  188. bool operator<(const KeyIndex<KeyType>& lhs, const KeyIndex<KeyType>& rhs) {
  189. return std::tie(lhs.type, lhs.field1, lhs.field2) < std::tie(rhs.type, rhs.field1, rhs.field2);
  190. }
  191. class KeyManager {
  192. public:
  193. static KeyManager& Instance() {
  194. static KeyManager instance;
  195. return instance;
  196. }
  197. KeyManager(const KeyManager&) = delete;
  198. KeyManager& operator=(const KeyManager&) = delete;
  199. KeyManager(KeyManager&&) = delete;
  200. KeyManager& operator=(KeyManager&&) = delete;
  201. bool HasKey(S128KeyType id, u64 field1 = 0, u64 field2 = 0) const;
  202. bool HasKey(S256KeyType id, u64 field1 = 0, u64 field2 = 0) const;
  203. Key128 GetKey(S128KeyType id, u64 field1 = 0, u64 field2 = 0) const;
  204. Key256 GetKey(S256KeyType id, u64 field1 = 0, u64 field2 = 0) const;
  205. Key256 GetBISKey(u8 partition_id) const;
  206. void SetKey(S128KeyType id, Key128 key, u64 field1 = 0, u64 field2 = 0);
  207. void SetKey(S256KeyType id, Key256 key, u64 field1 = 0, u64 field2 = 0);
  208. static bool KeyFileExists(bool title);
  209. // Call before using the sd seed to attempt to derive it if it dosen't exist. Needs system
  210. // save 8*43 and the private file to exist.
  211. void DeriveSDSeedLazy();
  212. bool BaseDeriveNecessary() const;
  213. void DeriveBase();
  214. void DeriveETicket(PartitionDataManager& data, const FileSys::ContentProvider& provider);
  215. void PopulateTickets();
  216. void SynthesizeTickets();
  217. void PopulateFromPartitionData(PartitionDataManager& data);
  218. const std::map<u128, Ticket>& GetCommonTickets() const;
  219. const std::map<u128, Ticket>& GetPersonalizedTickets() const;
  220. bool AddTicketCommon(Ticket raw);
  221. bool AddTicketPersonalized(Ticket raw);
  222. private:
  223. KeyManager();
  224. std::map<KeyIndex<S128KeyType>, Key128> s128_keys;
  225. std::map<KeyIndex<S256KeyType>, Key256> s256_keys;
  226. // Map from rights ID to ticket
  227. std::map<u128, Ticket> common_tickets;
  228. std::map<u128, Ticket> personal_tickets;
  229. std::array<std::array<u8, 0xB0>, 0x20> encrypted_keyblobs{};
  230. std::array<std::array<u8, 0x90>, 0x20> keyblobs{};
  231. std::array<u8, 576> eticket_extended_kek{};
  232. bool dev_mode;
  233. void LoadFromFile(const std::filesystem::path& file_path, bool is_title_keys);
  234. template <size_t Size>
  235. void WriteKeyToFile(KeyCategory category, std::string_view keyname,
  236. const std::array<u8, Size>& key);
  237. void DeriveGeneralPurposeKeys(std::size_t crypto_revision);
  238. RSAKeyPair<2048> GetETicketRSAKey() const;
  239. void SetKeyWrapped(S128KeyType id, Key128 key, u64 field1 = 0, u64 field2 = 0);
  240. void SetKeyWrapped(S256KeyType id, Key256 key, u64 field1 = 0, u64 field2 = 0);
  241. };
  242. Key128 GenerateKeyEncryptionKey(Key128 source, Key128 master, Key128 kek_seed, Key128 key_seed);
  243. Key128 DeriveKeyblobKey(const Key128& sbk, const Key128& tsec, Key128 source);
  244. Key128 DeriveKeyblobMACKey(const Key128& keyblob_key, const Key128& mac_source);
  245. Key128 DeriveMasterKey(const std::array<u8, 0x90>& keyblob, const Key128& master_source);
  246. std::array<u8, 0x90> DecryptKeyblob(const std::array<u8, 0xB0>& encrypted_keyblob,
  247. const Key128& key);
  248. std::optional<Key128> DeriveSDSeed();
  249. Loader::ResultStatus DeriveSDKeys(std::array<Key256, 2>& sd_keys, KeyManager& keys);
  250. std::vector<Ticket> GetTicketblob(const Common::FS::IOFile& ticket_save);
  251. // Returns a pair of {rights_id, titlekey}. Fails if the ticket has no certificate authority
  252. // (offset 0x140-0x144 is zero)
  253. std::optional<std::pair<Key128, Key128>> ParseTicket(const Ticket& ticket,
  254. const RSAKeyPair<2048>& eticket_extended_key);
  255. } // namespace Core::Crypto