/*
* The MIT License
*
* Copyright 2014, 2015, 2016 Rui Martinho (rmartinho@gmail.com), António Braz (antoniocbraz@gmail.com)
*
* Permission is hereby granted, free of charge, to any person obtaining a copy
* of this software and associated documentation files (the "Software"), to deal
* in the Software without restriction, including without limitation the rights
* to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
* copies of the Software, and to permit persons to whom the Software is
* furnished to do so, subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in
* all copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
* THE SOFTWARE.
*/
package org.poreid.cc.ias;
import org.poreid.pcscforjava.Card;
import org.poreid.pcscforjava.CardChannel;
import org.poreid.pcscforjava.CardException;
import org.poreid.pcscforjava.CardTerminal;
import org.poreid.pcscforjava.CommandAPDU;
import org.poreid.pcscforjava.ResponseAPDU;
import java.io.ByteArrayOutputStream;
import java.net.Proxy;
import java.util.Date;
import java.util.Locale;
import org.poreid.DigestPrefixes;
import org.poreid.POReIDException;
import org.poreid.Pin;
import org.poreid.PkAlias;
import org.poreid.RSAPaddingSchemes;
import org.poreid.cc.CardSpecificReferences;
import org.poreid.cc.CitizenCard;
import org.poreid.common.Util;
import org.poreid.cc.CCConfig;
import org.poreid.dialogs.pindialogs.PinBlockedException;
import org.poreid.dialogs.pindialogs.PinEntryCancelledException;
import org.poreid.dialogs.pindialogs.PinTimeoutException;
/**
*
* @author POReID
*/
public final class IASCard extends CitizenCard {
private final Card card;
private final CardChannel channel;
public IASCard(Card card, CardTerminal terminal, Locale locale, boolean cachePreferences, Proxy proxy, Date date) {
super(new IASSpecificReferences(card, terminal, locale, cachePreferences, proxy, date));
this.card = card;
this.channel = card.getBasicChannel();
}
@Override
protected int selectFile(String fileId) throws POReIDException {
try {
ResponseAPDU responseApdu;
responseApdu = channel.transmit(new CommandAPDU(0x00, 0xA4, 0x03, 0x0C), true, true);
if (0x9000 != responseApdu.getSW()) {
throw new POReIDException("Código de estado não esperado: " + Integer.toHexString(responseApdu.getSW()));
}
responseApdu = channel.transmit(new CommandAPDU(0x00, 0xA4, 0x09, 0x00, Util.hexToBytes(fileId.substring(4))), true, true);
if (0x9000 != responseApdu.getSW()) {
throw new POReIDException("Código de estado não esperado: " + Integer.toHexString(responseApdu.getSW()));
}
return parseFCI(responseApdu.getData());
} catch (CardException ex) {
throw new POReIDException(ex);
}
}
private int parseFCI(byte[] fci) throws POReIDException {
int size = 0;
int index = 0;
if (fci != null && fci[index] == 0x6F && fci.length == fci[++index] + 2) {
search:
while (++index < fci.length) {
switch (fci[index]) {
case (byte) 0x80:
if (fci[++index]==2){
size = ((fci[++index] & 0xFF) << 8) | (fci[++index] & 0xFF);
} else {
throw new POReIDException("Formato do FCI (file control information) não esperado");
}
break search;
default:
index = fci[++index] + index;
break;
}
}
}
return size;
}
@Override
public final byte[] getChallenge() throws POReIDException {
try {
ResponseAPDU response = this.channel.transmit(new CommandAPDU(0x00, 0x84, 0x00, 0x00, 0x08), true, true);
if (response.getSW() != 0x9000) {
throw new POReIDException("Código de estado não esperado: " + response.getSW());
}
return response.getData();
} catch (CardException ex) {
throw new POReIDException(ex);
}
}
@Override
public byte[] sign(byte hash[], byte[] pinCode, String digestAlgo, PkAlias pkAlias, RSAPaddingSchemes... sch) throws PinTimeoutException, PinEntryCancelledException, PinBlockedException, POReIDException {
ResponseAPDU responseApdu;
RSAPaddingSchemes scheme = sch.length > 0 && null != sch[0] ? sch[0] : RSAPaddingSchemes.PKCS1;
try {
CardSpecificReferences csr = getCardSpecificReferences();
Pin iasPin = csr.getCryptoReferences(pkAlias);
DigestPrefixes digestPrefixes = csr.getDigestPrefix(digestAlgo);
if (null == digestPrefixes) {
throw new POReIDException("Algoritmo de resumo desconhecido - " + digestAlgo);
}
ByteArrayOutputStream baos = new ByteArrayOutputStream();
baos.write(digestPrefixes.getPrefix(), 0, digestPrefixes.getPrefix().length);
baos.write(hash, 0, hash.length);
if (!CCConfig.isExternalPinCachePermitted() && !isOTPPinChanging()) {
pinCode = null;
}
verifyPin(iasPin, pinCode);
setSecurityEnvironment(csr.getAlgorithmID(digestAlgo, scheme), iasPin.getKeyReference());
responseApdu = channel.transmit(new CommandAPDU(0x00, 0x88, 0x02, 0x00, baos.toByteArray()), true, true);
if (0x9000 != responseApdu.getSW()) {
throw new POReIDException("Erro durante a computação da assinatura digital: " + Integer.toHexString(responseApdu.getSW()));
}
return responseApdu.getData();
} catch (CardException | IllegalStateException ex) {
throw new POReIDException(ex);
}
}
private void setSecurityEnvironment(Byte algorithmID, byte keyReference) throws CardException, POReIDException {
ResponseAPDU responseApdu;
if (null == algorithmID){
throw new POReIDException("Algoritmo não suportado");
}
responseApdu = channel.transmit(new CommandAPDU(0x00, 0x22, 0x41, 0xA4, new byte[]{(byte) 0x95, (byte) 0x01, (byte) 0x40, (byte) 0x84, (byte) 0x01, keyReference, (byte) 0x80, (byte) 0x01, algorithmID}), true, true);
if (0x9000 != responseApdu.getSW()) {
throw new POReIDException("Código de estado não esperado: " + Integer.toHexString(responseApdu.getSW()));
}
}
@Override
protected byte[] getNFillModifyPinAPDU(Pin pin, byte[][] pins) {
byte[] apdu = getModifyPinAPDU(pin);
System.arraycopy(pins[1], 0, apdu, 5, pins[1].length);
return apdu;
}
@Override
protected byte[] getModifyPinAPDU(Pin pin) {
byte pad = pin.getPadChar();
return new byte[]{0x00, 0x24, 0x01, pin.getReference(), 0x08, pad, pad, pad, pad, pad, pad, pad, pad};
}
@Override
protected boolean verifyToModify() {
return true;
}
}