2018-07-28 06:55:23 +03:00
|
|
|
// Copyright 2018 yuzu emulator team
|
|
|
|
// Licensed under GPLv2 or any later version
|
|
|
|
// Refer to the license.txt file included.
|
|
|
|
|
|
|
|
#pragma once
|
2018-07-29 04:39:42 +03:00
|
|
|
|
2018-07-28 06:55:23 +03:00
|
|
|
#include <array>
|
2018-09-24 04:04:13 +03:00
|
|
|
#include <map>
|
2018-10-30 07:03:25 +03:00
|
|
|
#include <optional>
|
2018-08-04 23:35:35 +03:00
|
|
|
#include <string>
|
2018-10-30 07:03:25 +03:00
|
|
|
|
2019-05-26 20:01:42 +03:00
|
|
|
#include <variant>
|
2018-07-28 21:28:14 +03:00
|
|
|
#include <fmt/format.h>
|
2019-04-16 16:12:04 +03:00
|
|
|
#include "common/common_funcs.h"
|
2018-07-28 06:55:23 +03:00
|
|
|
#include "common/common_types.h"
|
2018-09-29 18:48:51 +03:00
|
|
|
#include "core/crypto/partition_data_manager.h"
|
2018-09-24 04:04:13 +03:00
|
|
|
#include "core/file_sys/vfs_types.h"
|
|
|
|
|
2020-08-15 15:33:16 +03:00
|
|
|
namespace Common::FS {
|
2018-09-24 04:04:13 +03:00
|
|
|
class IOFile;
|
|
|
|
}
|
2018-09-04 04:58:19 +03:00
|
|
|
|
|
|
|
namespace Loader {
|
|
|
|
enum class ResultStatus : u16;
|
|
|
|
}
|
2018-07-28 06:55:23 +03:00
|
|
|
|
2018-07-29 04:39:42 +03:00
|
|
|
namespace Core::Crypto {
|
2018-07-28 06:55:23 +03:00
|
|
|
|
2018-08-25 18:48:23 +03:00
|
|
|
constexpr u64 TICKET_FILE_TITLEKEY_OFFSET = 0x180;
|
|
|
|
|
2018-07-29 04:39:42 +03:00
|
|
|
using Key128 = std::array<u8, 0x10>;
|
|
|
|
using Key256 = std::array<u8, 0x20>;
|
|
|
|
using SHA256Hash = std::array<u8, 0x20>;
|
2019-04-16 16:12:04 +03:00
|
|
|
|
|
|
|
enum class SignatureType {
|
|
|
|
RSA_4096_SHA1 = 0x10000,
|
|
|
|
RSA_2048_SHA1 = 0x10001,
|
|
|
|
ECDSA_SHA1 = 0x10002,
|
|
|
|
RSA_4096_SHA256 = 0x10003,
|
|
|
|
RSA_2048_SHA256 = 0x10004,
|
|
|
|
ECDSA_SHA256 = 0x10005,
|
|
|
|
};
|
|
|
|
|
|
|
|
u64 GetSignatureTypeDataSize(SignatureType type);
|
|
|
|
u64 GetSignatureTypePaddingSize(SignatureType type);
|
|
|
|
|
|
|
|
enum class TitleKeyType : u8 {
|
|
|
|
Common = 0,
|
|
|
|
Personalized = 1,
|
|
|
|
};
|
|
|
|
|
|
|
|
struct TicketData {
|
|
|
|
std::array<u8, 0x40> issuer;
|
|
|
|
union {
|
|
|
|
std::array<u8, 0x100> title_key_block;
|
|
|
|
|
|
|
|
struct {
|
|
|
|
Key128 title_key_common;
|
|
|
|
std::array<u8, 0xF0> title_key_common_pad;
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
INSERT_PADDING_BYTES(0x1);
|
|
|
|
TitleKeyType type;
|
|
|
|
INSERT_PADDING_BYTES(0x3);
|
|
|
|
u8 revision;
|
|
|
|
INSERT_PADDING_BYTES(0xA);
|
|
|
|
u64 ticket_id;
|
|
|
|
u64 device_id;
|
|
|
|
std::array<u8, 0x10> rights_id;
|
|
|
|
u32 account_id;
|
|
|
|
INSERT_PADDING_BYTES(0x14C);
|
|
|
|
};
|
|
|
|
static_assert(sizeof(TicketData) == 0x2C0, "TicketData has incorrect size.");
|
|
|
|
|
2019-05-26 20:01:42 +03:00
|
|
|
struct RSA4096Ticket {
|
2019-04-16 16:12:04 +03:00
|
|
|
SignatureType sig_type;
|
2019-05-26 20:01:42 +03:00
|
|
|
std::array<u8, 0x200> sig_data;
|
|
|
|
INSERT_PADDING_BYTES(0x3C);
|
|
|
|
TicketData data;
|
|
|
|
};
|
2019-04-16 16:12:04 +03:00
|
|
|
|
2019-05-26 20:01:42 +03:00
|
|
|
struct RSA2048Ticket {
|
|
|
|
SignatureType sig_type;
|
|
|
|
std::array<u8, 0x100> sig_data;
|
|
|
|
INSERT_PADDING_BYTES(0x3C);
|
|
|
|
TicketData data;
|
|
|
|
};
|
2019-04-16 16:12:04 +03:00
|
|
|
|
2019-05-26 20:01:42 +03:00
|
|
|
struct ECDSATicket {
|
|
|
|
SignatureType sig_type;
|
|
|
|
std::array<u8, 0x3C> sig_data;
|
|
|
|
INSERT_PADDING_BYTES(0x40);
|
|
|
|
TicketData data;
|
|
|
|
};
|
|
|
|
|
|
|
|
struct Ticket {
|
|
|
|
std::variant<RSA4096Ticket, RSA2048Ticket, ECDSATicket> data;
|
2019-04-16 16:12:04 +03:00
|
|
|
|
2019-05-26 20:01:42 +03:00
|
|
|
SignatureType GetSignatureType() const;
|
2019-04-16 16:12:04 +03:00
|
|
|
TicketData& GetData();
|
|
|
|
const TicketData& GetData() const;
|
|
|
|
u64 GetSize() const;
|
|
|
|
|
2019-05-26 20:01:42 +03:00
|
|
|
static Ticket SynthesizeCommon(Key128 title_key, const std::array<u8, 0x10>& rights_id);
|
2019-04-16 16:12:04 +03:00
|
|
|
};
|
2018-07-28 06:55:23 +03:00
|
|
|
|
|
|
|
static_assert(sizeof(Key128) == 16, "Key128 must be 128 bytes big.");
|
2018-09-24 04:04:13 +03:00
|
|
|
static_assert(sizeof(Key256) == 32, "Key256 must be 256 bytes big.");
|
|
|
|
|
|
|
|
template <size_t bit_size, size_t byte_size = (bit_size >> 3)>
|
|
|
|
struct RSAKeyPair {
|
|
|
|
std::array<u8, byte_size> encryption_key;
|
|
|
|
std::array<u8, byte_size> decryption_key;
|
|
|
|
std::array<u8, byte_size> modulus;
|
|
|
|
std::array<u8, 4> exponent;
|
|
|
|
};
|
2018-07-28 06:55:23 +03:00
|
|
|
|
2019-04-10 17:21:44 +03:00
|
|
|
template <size_t bit_size, size_t byte_size>
|
|
|
|
bool operator==(const RSAKeyPair<bit_size, byte_size>& lhs,
|
|
|
|
const RSAKeyPair<bit_size, byte_size>& rhs) {
|
|
|
|
return std::tie(lhs.encryption_key, lhs.decryption_key, lhs.modulus, lhs.exponent) ==
|
|
|
|
std::tie(rhs.encryption_key, rhs.decryption_key, rhs.modulus, rhs.exponent);
|
|
|
|
}
|
|
|
|
|
2019-05-26 20:01:42 +03:00
|
|
|
template <size_t bit_size, size_t byte_size>
|
|
|
|
bool operator!=(const RSAKeyPair<bit_size, byte_size>& lhs,
|
|
|
|
const RSAKeyPair<bit_size, byte_size>& rhs) {
|
|
|
|
return !(lhs == rhs);
|
|
|
|
}
|
|
|
|
|
2018-09-24 03:37:27 +03:00
|
|
|
enum class KeyCategory : u8 {
|
|
|
|
Standard,
|
|
|
|
Title,
|
|
|
|
Console,
|
|
|
|
};
|
|
|
|
|
2018-07-28 06:55:23 +03:00
|
|
|
enum class S256KeyType : u64 {
|
2018-09-24 03:56:02 +03:00
|
|
|
SDKey, // f1=SDKeyType
|
|
|
|
Header, //
|
|
|
|
SDKeySource, // f1=SDKeyType
|
|
|
|
HeaderSource, //
|
2018-07-28 06:55:23 +03:00
|
|
|
};
|
|
|
|
|
|
|
|
enum class S128KeyType : u64 {
|
2018-07-29 04:39:42 +03:00
|
|
|
Master, // f1=crypto revision
|
|
|
|
Package1, // f1=crypto revision
|
|
|
|
Package2, // f1=crypto revision
|
|
|
|
Titlekek, // f1=crypto revision
|
|
|
|
ETicketRSAKek, //
|
|
|
|
KeyArea, // f1=crypto revision f2=type {app, ocean, system}
|
|
|
|
SDSeed, //
|
|
|
|
Titlekey, // f1=rights id LSB f2=rights id MSB
|
2018-08-17 00:12:05 +03:00
|
|
|
Source, // f1=source type, f2= sub id
|
2018-09-24 03:56:02 +03:00
|
|
|
Keyblob, // f1=crypto revision
|
|
|
|
KeyblobMAC, // f1=crypto revision
|
|
|
|
TSEC, //
|
|
|
|
SecureBoot, //
|
|
|
|
BIS, // f1=partition (0-3), f2=type {crypt, tweak}
|
|
|
|
HeaderKek, //
|
|
|
|
SDKek, //
|
|
|
|
RSAKek, //
|
2018-07-28 06:55:23 +03:00
|
|
|
};
|
|
|
|
|
|
|
|
enum class KeyAreaKeyType : u8 {
|
|
|
|
Application,
|
|
|
|
Ocean,
|
|
|
|
System,
|
|
|
|
};
|
|
|
|
|
2018-08-17 00:12:05 +03:00
|
|
|
enum class SourceKeyType : u8 {
|
2018-09-24 03:31:00 +03:00
|
|
|
SDKek, //
|
|
|
|
AESKekGeneration, //
|
|
|
|
AESKeyGeneration, //
|
2018-09-24 03:56:02 +03:00
|
|
|
RSAOaepKekGeneration, //
|
|
|
|
Master, //
|
|
|
|
Keyblob, // f2=crypto revision
|
|
|
|
KeyAreaKey, // f2=KeyAreaKeyType
|
|
|
|
Titlekek, //
|
|
|
|
Package2, //
|
|
|
|
HeaderKek, //
|
|
|
|
KeyblobMAC, //
|
|
|
|
ETicketKek, //
|
|
|
|
ETicketKekek, //
|
2018-08-17 00:12:05 +03:00
|
|
|
};
|
|
|
|
|
|
|
|
enum class SDKeyType : u8 {
|
|
|
|
Save,
|
|
|
|
NCA,
|
|
|
|
};
|
|
|
|
|
2018-09-24 03:56:02 +03:00
|
|
|
enum class BISKeyType : u8 {
|
|
|
|
Crypto,
|
|
|
|
Tweak,
|
|
|
|
};
|
|
|
|
|
|
|
|
enum class RSAKekType : u8 {
|
|
|
|
Mask0,
|
|
|
|
Seed3,
|
|
|
|
};
|
|
|
|
|
2018-07-28 06:55:23 +03:00
|
|
|
template <typename KeyType>
|
|
|
|
struct KeyIndex {
|
|
|
|
KeyType type;
|
|
|
|
u64 field1;
|
|
|
|
u64 field2;
|
|
|
|
|
2018-07-29 04:39:42 +03:00
|
|
|
std::string DebugInfo() const {
|
2018-07-28 06:55:23 +03:00
|
|
|
u8 key_size = 16;
|
2018-07-30 02:00:09 +03:00
|
|
|
if constexpr (std::is_same_v<KeyType, S256KeyType>)
|
2018-07-28 06:55:23 +03:00
|
|
|
key_size = 32;
|
|
|
|
return fmt::format("key_size={:02X}, key={:02X}, field1={:016X}, field2={:016X}", key_size,
|
|
|
|
static_cast<u8>(type), field1, field2);
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
2018-08-17 00:10:01 +03:00
|
|
|
// boost flat_map requires operator< for O(log(n)) lookups.
|
2018-07-29 04:39:42 +03:00
|
|
|
template <typename KeyType>
|
2018-08-17 00:10:01 +03:00
|
|
|
bool operator<(const KeyIndex<KeyType>& lhs, const KeyIndex<KeyType>& rhs) {
|
2018-08-19 04:16:20 +03:00
|
|
|
return std::tie(lhs.type, lhs.field1, lhs.field2) < std::tie(rhs.type, rhs.field1, rhs.field2);
|
2018-07-29 04:39:42 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
class KeyManager {
|
|
|
|
public:
|
2020-07-01 07:28:49 +03:00
|
|
|
static KeyManager& Instance() {
|
2020-05-20 22:28:16 +03:00
|
|
|
static KeyManager instance;
|
|
|
|
return instance;
|
|
|
|
}
|
|
|
|
|
2020-07-01 07:21:29 +03:00
|
|
|
KeyManager(const KeyManager&) = delete;
|
|
|
|
KeyManager& operator=(const KeyManager&) = delete;
|
2018-07-28 06:55:23 +03:00
|
|
|
|
2020-07-01 07:24:35 +03:00
|
|
|
KeyManager(KeyManager&&) = delete;
|
|
|
|
KeyManager& operator=(KeyManager&&) = delete;
|
|
|
|
|
2018-07-29 04:39:42 +03:00
|
|
|
bool HasKey(S128KeyType id, u64 field1 = 0, u64 field2 = 0) const;
|
|
|
|
bool HasKey(S256KeyType id, u64 field1 = 0, u64 field2 = 0) const;
|
2018-07-28 06:55:23 +03:00
|
|
|
|
2018-07-29 04:39:42 +03:00
|
|
|
Key128 GetKey(S128KeyType id, u64 field1 = 0, u64 field2 = 0) const;
|
|
|
|
Key256 GetKey(S256KeyType id, u64 field1 = 0, u64 field2 = 0) const;
|
2018-07-28 06:55:23 +03:00
|
|
|
|
2018-09-24 03:57:20 +03:00
|
|
|
Key256 GetBISKey(u8 partition_id) const;
|
|
|
|
|
2018-07-28 06:55:23 +03:00
|
|
|
void SetKey(S128KeyType id, Key128 key, u64 field1 = 0, u64 field2 = 0);
|
|
|
|
void SetKey(S256KeyType id, Key256 key, u64 field1 = 0, u64 field2 = 0);
|
|
|
|
|
2018-07-30 19:46:23 +03:00
|
|
|
static bool KeyFileExists(bool title);
|
|
|
|
|
2019-04-16 16:12:04 +03:00
|
|
|
// Call before using the sd seed to attempt to derive it if it dosen't exist. Needs system
|
|
|
|
// save 8*43 and the private file to exist.
|
2018-08-17 00:12:05 +03:00
|
|
|
void DeriveSDSeedLazy();
|
|
|
|
|
2018-09-29 18:48:51 +03:00
|
|
|
bool BaseDeriveNecessary() const;
|
2018-09-24 04:03:00 +03:00
|
|
|
void DeriveBase();
|
2018-09-29 18:48:51 +03:00
|
|
|
void DeriveETicket(PartitionDataManager& data);
|
2019-04-10 17:22:04 +03:00
|
|
|
void PopulateTickets();
|
2019-04-17 18:29:21 +03:00
|
|
|
void SynthesizeTickets();
|
2018-09-24 04:04:13 +03:00
|
|
|
|
2018-09-29 18:48:51 +03:00
|
|
|
void PopulateFromPartitionData(PartitionDataManager& data);
|
2018-09-24 04:05:01 +03:00
|
|
|
|
2019-04-16 16:12:04 +03:00
|
|
|
const std::map<u128, Ticket>& GetCommonTickets() const;
|
|
|
|
const std::map<u128, Ticket>& GetPersonalizedTickets() const;
|
2019-04-10 17:22:04 +03:00
|
|
|
|
2019-04-16 16:12:04 +03:00
|
|
|
bool AddTicketCommon(Ticket raw);
|
|
|
|
bool AddTicketPersonalized(Ticket raw);
|
2019-04-10 17:22:04 +03:00
|
|
|
|
2018-07-28 06:55:23 +03:00
|
|
|
private:
|
2020-05-20 22:28:16 +03:00
|
|
|
KeyManager();
|
|
|
|
|
2018-09-24 04:03:00 +03:00
|
|
|
std::map<KeyIndex<S128KeyType>, Key128> s128_keys;
|
|
|
|
std::map<KeyIndex<S256KeyType>, Key256> s256_keys;
|
|
|
|
|
2019-04-10 17:22:04 +03:00
|
|
|
// Map from rights ID to ticket
|
2019-04-16 16:12:04 +03:00
|
|
|
std::map<u128, Ticket> common_tickets;
|
|
|
|
std::map<u128, Ticket> personal_tickets;
|
2019-04-10 17:22:04 +03:00
|
|
|
|
2018-09-24 03:51:44 +03:00
|
|
|
std::array<std::array<u8, 0xB0>, 0x20> encrypted_keyblobs{};
|
|
|
|
std::array<std::array<u8, 0x90>, 0x20> keyblobs{};
|
2019-04-10 17:22:04 +03:00
|
|
|
std::array<u8, 576> eticket_extended_kek{};
|
2018-07-28 06:55:23 +03:00
|
|
|
|
2018-07-29 04:39:42 +03:00
|
|
|
bool dev_mode;
|
2018-08-04 23:35:35 +03:00
|
|
|
void LoadFromFile(const std::string& filename, bool is_title_keys);
|
|
|
|
void AttemptLoadKeyFile(const std::string& dir1, const std::string& dir2,
|
|
|
|
const std::string& filename, bool title);
|
2018-09-24 04:03:00 +03:00
|
|
|
template <size_t Size>
|
|
|
|
void WriteKeyToFile(KeyCategory category, std::string_view keyname,
|
|
|
|
const std::array<u8, Size>& key);
|
|
|
|
|
2018-10-13 16:13:19 +03:00
|
|
|
void DeriveGeneralPurposeKeys(std::size_t crypto_revision);
|
2018-09-29 18:48:51 +03:00
|
|
|
|
2019-05-26 20:01:42 +03:00
|
|
|
RSAKeyPair<2048> GetETicketRSAKey() const;
|
2019-04-10 17:22:04 +03:00
|
|
|
|
2018-09-24 04:03:00 +03:00
|
|
|
void SetKeyWrapped(S128KeyType id, Key128 key, u64 field1 = 0, u64 field2 = 0);
|
|
|
|
void SetKeyWrapped(S256KeyType id, Key256 key, u64 field1 = 0, u64 field2 = 0);
|
2018-07-28 06:55:23 +03:00
|
|
|
};
|
2018-08-17 00:12:05 +03:00
|
|
|
|
|
|
|
Key128 GenerateKeyEncryptionKey(Key128 source, Key128 master, Key128 kek_seed, Key128 key_seed);
|
2018-09-29 18:48:51 +03:00
|
|
|
Key128 DeriveKeyblobKey(const Key128& sbk, const Key128& tsec, Key128 source);
|
|
|
|
Key128 DeriveKeyblobMACKey(const Key128& keyblob_key, const Key128& mac_source);
|
|
|
|
Key128 DeriveMasterKey(const std::array<u8, 0x90>& keyblob, const Key128& master_source);
|
|
|
|
std::array<u8, 0x90> DecryptKeyblob(const std::array<u8, 0xB0>& encrypted_keyblob,
|
|
|
|
const Key128& key);
|
2018-09-24 03:51:44 +03:00
|
|
|
|
2018-10-30 07:03:25 +03:00
|
|
|
std::optional<Key128> DeriveSDSeed();
|
2018-09-24 04:04:13 +03:00
|
|
|
Loader::ResultStatus DeriveSDKeys(std::array<Key256, 2>& sd_keys, KeyManager& keys);
|
|
|
|
|
2020-08-15 15:33:16 +03:00
|
|
|
std::vector<Ticket> GetTicketblob(const Common::FS::IOFile& ticket_save);
|
2018-09-24 04:04:13 +03:00
|
|
|
|
2019-04-16 16:12:04 +03:00
|
|
|
// Returns a pair of {rights_id, titlekey}. Fails if the ticket has no certificate authority
|
|
|
|
// (offset 0x140-0x144 is zero)
|
|
|
|
std::optional<std::pair<Key128, Key128>> ParseTicket(const Ticket& ticket,
|
2018-10-30 07:03:25 +03:00
|
|
|
const RSAKeyPair<2048>& eticket_extended_key);
|
2018-08-17 00:12:05 +03:00
|
|
|
|
2018-07-29 04:39:42 +03:00
|
|
|
} // namespace Core::Crypto
|