1189251Ssam/* 2189251Ssam * hostapd / EAP-SIM database/authenticator gateway 3252726Srpaulo * Copyright (c) 2005-2008, 2012, Jouni Malinen <j@w1.fi> 4189251Ssam * 5252726Srpaulo * This software may be distributed under the terms of the BSD license. 6252726Srpaulo * See README for more details. 7189251Ssam */ 8189251Ssam 9189251Ssam#ifndef EAP_SIM_DB_H 10189251Ssam#define EAP_SIM_DB_H 11189251Ssam 12189251Ssam#include "eap_common/eap_sim_common.h" 13189251Ssam 14189251Ssam/* Identity prefixes */ 15189251Ssam#define EAP_SIM_PERMANENT_PREFIX '1' 16189251Ssam#define EAP_SIM_PSEUDONYM_PREFIX '3' 17189251Ssam#define EAP_SIM_REAUTH_ID_PREFIX '5' 18189251Ssam#define EAP_AKA_PERMANENT_PREFIX '0' 19189251Ssam#define EAP_AKA_PSEUDONYM_PREFIX '2' 20189251Ssam#define EAP_AKA_REAUTH_ID_PREFIX '4' 21252726Srpaulo#define EAP_AKA_PRIME_PERMANENT_PREFIX '6' 22252726Srpaulo#define EAP_AKA_PRIME_PSEUDONYM_PREFIX '7' 23252726Srpaulo#define EAP_AKA_PRIME_REAUTH_ID_PREFIX '8' 24189251Ssam 25252726Srpauloenum eap_sim_db_method { 26252726Srpaulo EAP_SIM_DB_SIM, 27252726Srpaulo EAP_SIM_DB_AKA, 28252726Srpaulo EAP_SIM_DB_AKA_PRIME 29252726Srpaulo}; 30189251Ssam 31252726Srpaulostruct eap_sim_db_data; 32252726Srpaulo 33252726Srpaulostruct eap_sim_db_data * 34337817Scyeap_sim_db_init(const char *config, unsigned int db_timeout, 35252726Srpaulo void (*get_complete_cb)(void *ctx, void *session_ctx), 36252726Srpaulo void *ctx); 37252726Srpaulo 38189251Ssamvoid eap_sim_db_deinit(void *priv); 39189251Ssam 40252726Srpauloint eap_sim_db_get_gsm_triplets(struct eap_sim_db_data *data, 41252726Srpaulo const char *username, int max_chal, 42189251Ssam u8 *_rand, u8 *kc, u8 *sres, 43189251Ssam void *cb_session_ctx); 44189251Ssam 45189251Ssam#define EAP_SIM_DB_FAILURE -1 46189251Ssam#define EAP_SIM_DB_PENDING -2 47189251Ssam 48252726Srpaulochar * eap_sim_db_get_next_pseudonym(struct eap_sim_db_data *data, 49252726Srpaulo enum eap_sim_db_method method); 50189251Ssam 51252726Srpaulochar * eap_sim_db_get_next_reauth_id(struct eap_sim_db_data *data, 52252726Srpaulo enum eap_sim_db_method method); 53189251Ssam 54252726Srpauloint eap_sim_db_add_pseudonym(struct eap_sim_db_data *data, 55252726Srpaulo const char *permanent, char *pseudonym); 56189251Ssam 57252726Srpauloint eap_sim_db_add_reauth(struct eap_sim_db_data *data, const char *permanent, 58252726Srpaulo char *reauth_id, u16 counter, const u8 *mk); 59252726Srpauloint eap_sim_db_add_reauth_prime(struct eap_sim_db_data *data, 60252726Srpaulo const char *permanent, 61252726Srpaulo char *reauth_id, u16 counter, const u8 *k_encr, 62252726Srpaulo const u8 *k_aut, const u8 *k_re); 63189251Ssam 64252726Srpauloconst char * eap_sim_db_get_permanent(struct eap_sim_db_data *data, 65252726Srpaulo const char *pseudonym); 66189251Ssam 67189251Ssamstruct eap_sim_reauth { 68189251Ssam struct eap_sim_reauth *next; 69252726Srpaulo char *permanent; /* Permanent username */ 70252726Srpaulo char *reauth_id; /* Fast re-authentication username */ 71189251Ssam u16 counter; 72189251Ssam u8 mk[EAP_SIM_MK_LEN]; 73189251Ssam u8 k_encr[EAP_SIM_K_ENCR_LEN]; 74189251Ssam u8 k_aut[EAP_AKA_PRIME_K_AUT_LEN]; 75189251Ssam u8 k_re[EAP_AKA_PRIME_K_RE_LEN]; 76189251Ssam}; 77189251Ssam 78189251Ssamstruct eap_sim_reauth * 79252726Srpauloeap_sim_db_get_reauth_entry(struct eap_sim_db_data *data, 80252726Srpaulo const char *reauth_id); 81189251Ssam 82252726Srpaulovoid eap_sim_db_remove_reauth(struct eap_sim_db_data *data, 83252726Srpaulo struct eap_sim_reauth *reauth); 84189251Ssam 85252726Srpauloint eap_sim_db_get_aka_auth(struct eap_sim_db_data *data, const char *username, 86252726Srpaulo u8 *_rand, u8 *autn, u8 *ik, u8 *ck, 87252726Srpaulo u8 *res, size_t *res_len, void *cb_session_ctx); 88189251Ssam 89252726Srpauloint eap_sim_db_resynchronize(struct eap_sim_db_data *data, 90252726Srpaulo const char *username, const u8 *auts, 91189251Ssam const u8 *_rand); 92189251Ssam 93252726Srpaulochar * sim_get_username(const u8 *identity, size_t identity_len); 94252726Srpaulo 95189251Ssam#endif /* EAP_SIM_DB_H */ 96