blob: ee37a20108541954e858f752353e1937eafd234a [file] [log] [blame]
Gilles Peskine961849f2018-11-30 18:54:54 +01001/*
2 * PSA crypto layer on top of Mbed TLS crypto
3 */
4/* Copyright (C) 2018, ARM Limited, All Rights Reserved
5 * SPDX-License-Identifier: Apache-2.0
6 *
7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
8 * not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
10 *
11 * http://www.apache.org/licenses/LICENSE-2.0
12 *
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
18 *
19 * This file is part of mbed TLS (https://tls.mbed.org)
20 */
21
22#ifndef PSA_CRYPTO_SLOT_MANAGEMENT_H
23#define PSA_CRYPTO_SLOT_MANAGEMENT_H
24
25/* Number of key slots (plus one because 0 is not used).
26 * The value is a compile-time constant for now, for simplicity. */
27#define PSA_KEY_SLOT_COUNT 32
28
Gilles Peskine66fb1262018-12-10 16:29:04 +010029/** Access a key slot at the given handle. */
30psa_status_t psa_get_key_slot( psa_key_handle_t handle,
31 psa_key_slot_t **p_slot );
32
33/** Initialize the key slot structures. */
34psa_status_t psa_initialize_key_slots( void );
35
36/** Delete all data from key slots in memory. This does not affect persistent
37 * storage. */
38void psa_wipe_all_key_slots( void );
39
Gilles Peskine961849f2018-11-30 18:54:54 +010040/** \defgroup core_slot_management Internal functions exposed by the core
41 * @{
42 */
43
Gilles Peskine961849f2018-11-30 18:54:54 +010044/** Wipe an a key slot and mark it as available.
45 *
46 * This does not affect persistent storage.
47 *
48 * \param handle The key slot number to release.
49 *
50 * \retval #PSA_SUCCESS
51 * \retval #PSA_ERROR_INVALID_ARGUMENT
52 * \retval #PSA_ERROR_TAMPERING_DETECTED
53 */
54psa_status_t psa_internal_release_key_slot( psa_key_handle_t handle );
55
56/** Declare a slot as persistent and load it from storage.
57 *
58 * This function may only be called immediately after a successful call
59 * to psa_internal_allocate_key_slot().
60 *
61 * \param handle A handle to a key slot freshly allocated with
62 * psa_internal_allocate_key_slot().
63 *
64 * \retval #PSA_SUCCESS
65 * The slot content was loaded successfully.
66 * \retval #PSA_ERROR_EMPTY_SLOT
67 * There is no content for this slot in persistent storage.
68 * \retval #PSA_ERROR_INVALID_HANDLE
69 * \retval #PSA_ERROR_INVALID_ARGUMENT
70 * \p id is not acceptable.
71 * \retval #PSA_ERROR_INSUFFICIENT_MEMORY
72 * \retval #PSA_ERROR_STORAGE_FAILURE
73 */
74psa_status_t psa_internal_make_key_persistent( psa_key_handle_t handle,
75 psa_key_id_t id );
76
77/**@}*/
78
79#endif /* PSA_CRYPTO_SLOT_MANAGEMENT_H */