Zephyr API Documentation 4.5.0-rc1
A Scalable Open Source RTOS
Loading...
Searching...
No Matches
fido2_types.h
Go to the documentation of this file.
1/*
2 * Copyright (c) 2026 Siratul Islam <email@sirat.me>
3 *
4 * SPDX-License-Identifier: Apache-2.0
5 */
6
12
13#ifndef ZEPHYR_INCLUDE_AUTHENTICATION_FIDO2_FIDO2_TYPES_H_
14#define ZEPHYR_INCLUDE_AUTHENTICATION_FIDO2_FIDO2_TYPES_H_
15
16#include <stddef.h>
17#include <stdint.h>
18#include <stdbool.h>
19#include <zephyr/sys/util.h>
20
26
27#ifdef __cplusplus
28extern "C" {
29#endif
30
32#define FIDO2_CREDENTIAL_ID_MAX_SIZE 128
33
35#define FIDO2_RP_ID_MAX_LEN 128
36
38#define FIDO2_RP_NAME_MAX_LEN 64
39
41#define FIDO2_USER_NAME_MAX_LEN 64
42
44#define FIDO2_USER_DISPLAY_NAME_MAX_LEN 64
45
47#define FIDO2_USER_ID_MAX_SIZE 64
48
50#define FIDO2_AAGUID_SIZE 16
51
53#define FIDO2_SHA256_SIZE 32
54
56#define FIDO2_PIN_HASH_SIZE 16
57
59#define FIDO2_PIN_HASH_ENC_MAX_SIZE 32
60
62#define FIDO2_PIN_ENC_MAX_SIZE 80
63
65#define FIDO2_PIN_AUTH_SIZE_P1 16
66
68#define FIDO2_PIN_AUTH_SIZE_P2 32
69
71#define FIDO2_PIN_AUTH_MAX_SIZE 32
72
74#define FIDO2_PIN_PADDED_SIZE 64
75
77#define FIDO2_PIN_TOKEN_ENC_MAX_SIZE 48
78
80#define FIDO2_DISCOVERABLE_CRED_ID_SIZE 32
81
83#define FIDO2_NON_DISCOVERABLE_CRED_ID_SIZE 64
84
86#define FIDO2_AUTH_DATA_HEADER_SIZE 37
87
89#define FIDO2_ATTESTED_CRED_DATA_MAX_SIZE \
90 (FIDO2_AAGUID_SIZE + 2 + FIDO2_CREDENTIAL_ID_MAX_SIZE + FIDO2_COSE_KEY_MAX_SIZE)
91
93#define FIDO2_AUTH_DATA_MAX_SIZE (FIDO2_AUTH_DATA_HEADER_SIZE + FIDO2_ATTESTED_CRED_DATA_MAX_SIZE)
94
96#define FIDO2_MAX_EXTENSIONS 8
97
99#define FIDO2_MAX_VERSIONS 4
100
102#define FIDO2_P256_UNCOMPRESSED_KEY_SIZE 65
103
105#define FIDO2_P256_COORD_SIZE 32
106
108#define FIDO2_EC_POINT_UNCOMPRESSED 0x04
109
111#define FIDO2_ECDSA_SIG_MAX_SIZE 72
112
114#define FIDO2_EXT_HMAC_SECRET BIT(0)
116#define FIDO2_EXT_LARGE_BLOB_KEY BIT(1)
118#define FIDO2_EXT_CRED_BLOB BIT(2)
120#define FIDO2_EXT_THIRD_PARTY_PAY BIT(3)
121
123#define FIDO2_TRANSPORT_USB BIT(0)
125#define FIDO2_TRANSPORT_BLE BIT(1)
127#define FIDO2_TRANSPORT_NFC BIT(2)
128
130#define AUTH_DATA_FLAG_UP BIT(0)
132#define AUTH_DATA_FLAG_UV BIT(2)
134#define AUTH_DATA_FLAG_AT BIT(6)
136#define AUTH_DATA_FLAG_ED BIT(7)
137
140 FIDO2_OK = 0x00,
188};
189
201
211
219
253
300
301#ifdef __cplusplus
302}
303#endif
304
306
307#endif /* ZEPHYR_INCLUDE_AUTHENTICATION_FIDO2_FIDO2_TYPES_H_ */
@ FIDO2_ERR_OPERATION_PENDING
Operation pending.
Definition fido2_types.h:160
@ FIDO2_ERR_INVALID_OPTION
Option value invalid for this operation.
Definition fido2_types.h:166
@ FIDO2_ERR_PIN_BLOCKED
PIN blocked.
Definition fido2_types.h:172
@ FIDO2_ERR_REQUEST_TOO_LARGE
Request exceeds maxMsgSize.
Definition fido2_types.h:179
@ FIDO2_ERR_PROCESSING
Processing.
Definition fido2_types.h:157
@ FIDO2_ERR_CBOR_UNEXPECTED_TYPE
Unexpected CBOR type.
Definition fido2_types.h:149
@ FIDO2_ERR_INVALID_CHANNEL
Invalid channel.
Definition fido2_types.h:148
@ FIDO2_ERR_KEEPALIVE_CANCEL
Keepalive cancelled by platform.
Definition fido2_types.h:167
@ FIDO2_ERR_UNSUPPORTED_ALGORITHM
Unsupported algorithm.
Definition fido2_types.h:162
@ FIDO2_ERR_ACTION_TIMEOUT
Platform response timed out.
Definition fido2_types.h:180
@ FIDO2_ERR_NO_OPERATIONS
No operations pending.
Definition fido2_types.h:161
@ FIDO2_ERR_USER_ACTION_TIMEOUT
User action timed out.
Definition fido2_types.h:169
@ FIDO2_ERR_INTEGRITY_FAILURE
Authenticator integrity check failed.
Definition fido2_types.h:183
@ FIDO2_ERR_INVALID_CREDENTIAL
Invalid credential.
Definition fido2_types.h:158
@ FIDO2_ERR_OPERATION_DENIED
Operation denied.
Definition fido2_types.h:163
@ FIDO2_ERR_INVALID_SUBCOMMAND
Invalid subcommand for this command.
Definition fido2_types.h:184
@ FIDO2_ERR_PIN_AUTH_BLOCKED
PIN auth blocked.
Definition fido2_types.h:174
@ FIDO2_ERR_PUAT_REQUIRED
PIN/UV auth token required.
Definition fido2_types.h:176
@ FIDO2_ERR_CREDENTIAL_EXCLUDED
Credential in excludeList found.
Definition fido2_types.h:156
@ FIDO2_ERR_UV_INVALID
User verification failed.
Definition fido2_types.h:185
@ FIDO2_ERR_PIN_AUTH_INVALID
PIN auth verification failed.
Definition fido2_types.h:173
@ FIDO2_ERR_UNAUTHORIZED_PERMISSION
PIN/UV token missing permission.
Definition fido2_types.h:186
@ FIDO2_ERR_PIN_INVALID
Invalid PIN.
Definition fido2_types.h:171
@ FIDO2_ERR_NOT_ALLOWED
Operation not allowed.
Definition fido2_types.h:170
@ FIDO2_ERR_INVALID_SEQ
Invalid sequence number.
Definition fido2_types.h:144
@ FIDO2_ERR_PIN_POLICY_VIOLATION
PIN policy violation.
Definition fido2_types.h:177
@ FIDO2_ERR_USER_ACTION_PENDING
Waiting for user action.
Definition fido2_types.h:159
@ FIDO2_ERR_RESERVED
PIN/UV auth token expired.
Definition fido2_types.h:178
@ FIDO2_OK
Success.
Definition fido2_types.h:140
@ FIDO2_ERR_UP_REQUIRED
User presence required.
Definition fido2_types.h:181
@ FIDO2_ERR_UNSUPPORTED_OPTION
Unsupported option.
Definition fido2_types.h:165
@ FIDO2_ERR_INVALID_COMMAND
Invalid command.
Definition fido2_types.h:141
@ FIDO2_ERR_INVALID_PARAMETER
Invalid parameter.
Definition fido2_types.h:142
@ FIDO2_ERR_OTHER
Other unspecified error.
Definition fido2_types.h:187
@ FIDO2_ERR_PIN_NOT_SET
PIN not set.
Definition fido2_types.h:175
@ FIDO2_ERR_UNSUPPORTED_EXTENSION
Unsupported extension.
Definition fido2_types.h:153
@ FIDO2_ERR_CHANNEL_BUSY
Channel busy.
Definition fido2_types.h:146
@ FIDO2_ERR_INVALID_CBOR
Invalid CBOR encoding.
Definition fido2_types.h:150
@ FIDO2_ERR_KEY_STORE_FULL
Key store full.
Definition fido2_types.h:164
@ FIDO2_ERR_INVALID_LENGTH
Invalid message length.
Definition fido2_types.h:143
@ FIDO2_ERR_FP_DATABASE_FULL
Fingerprint database full.
Definition fido2_types.h:154
@ FIDO2_ERR_LOCK_REQUIRED
Command requires lock.
Definition fido2_types.h:147
@ FIDO2_ERR_MISSING_PARAMETER
Required parameter missing.
Definition fido2_types.h:151
@ FIDO2_ERR_UV_BLOCKED
User verification blocked.
Definition fido2_types.h:182
@ FIDO2_ERR_LIMIT_EXCEEDED
Limit exceeded.
Definition fido2_types.h:152
@ FIDO2_ERR_TIMEOUT
Request timed out.
Definition fido2_types.h:145
@ FIDO2_ERR_NO_CREDENTIALS
No credentials found.
Definition fido2_types.h:168
@ FIDO2_ERR_LARGE_BLOB_STORAGE_FULL
Large blob storage full.
Definition fido2_types.h:155
@ FIDO2_COSE_EDDSA
EdDSA.
Definition fido2_types.h:215
@ FIDO2_COSE_ECDHES_HKDF256
ECDH ES w/ HKDF.
Definition fido2_types.h:216
@ FIDO2_COSE_ES256
ECDSA w/ SHA-256.
Definition fido2_types.h:214
@ FIDO2_COSE_RS256
RSASSA-PKCS1-v1_5 w/ SHA-256.
Definition fido2_types.h:217
@ FIDO2_CRED_PROTECT_UV_OPTIONAL
UV optional; credential usable without verification.
Definition fido2_types.h:205
@ FIDO2_CRED_PROTECT_UV_OPTIONAL_WITH_LIST
UV optional; credential usable only with credential ID list.
Definition fido2_types.h:207
@ FIDO2_CRED_PROTECT_UV_REQUIRED
UV required; credential always requires user verification.
Definition fido2_types.h:209
@ FIDO2_CMD_GET_INFO
Get authenticator info.
Definition fido2_types.h:194
@ FIDO2_CMD_SELECTION
Authenticator selection.
Definition fido2_types.h:199
@ FIDO2_CMD_CREDENTIAL_MGMT
Credential management.
Definition fido2_types.h:198
@ FIDO2_CMD_GET_ASSERTION
Authenticate with a credential.
Definition fido2_types.h:193
@ FIDO2_CMD_CLIENT_PIN
Client PIN operations.
Definition fido2_types.h:195
@ FIDO2_CMD_RESET
Factory reset.
Definition fido2_types.h:196
@ FIDO2_CMD_MAKE_CREDENTIAL
Create a new credential.
Definition fido2_types.h:192
@ FIDO2_CMD_GET_NEXT_ASSERTION
Get next assertion.
Definition fido2_types.h:197
#define FIDO2_MAX_VERSIONS
Maximum number of supported versions.
Definition fido2_types.h:99
#define FIDO2_RP_ID_MAX_LEN
Maximum relying party ID length.
Definition fido2_types.h:35
#define FIDO2_USER_NAME_MAX_LEN
Maximum user name length.
Definition fido2_types.h:41
#define FIDO2_AAGUID_SIZE
AAGUID size in bytes.
Definition fido2_types.h:50
fido2_status
CTAP2 status codes.
Definition fido2_types.h:139
#define FIDO2_MAX_EXTENSIONS
Maximum number of supported extensions.
Definition fido2_types.h:96
#define FIDO2_CREDENTIAL_ID_MAX_SIZE
FIDO2 shared types.
Definition fido2_types.h:32
fido2_cose_alg
COSE algorithm identifiers.
Definition fido2_types.h:213
#define FIDO2_RP_NAME_MAX_LEN
Maximum relying party name length.
Definition fido2_types.h:38
#define FIDO2_USER_DISPLAY_NAME_MAX_LEN
Maximum user display name length.
Definition fido2_types.h:44
fido2_cred_protect
Credential protection levels.
Definition fido2_types.h:203
#define FIDO2_SHA256_SIZE
SHA-256 hash size.
Definition fido2_types.h:53
fido2_cmd
CTAP2 command codes.
Definition fido2_types.h:191
#define FIDO2_USER_ID_MAX_SIZE
Maximum user ID size in bytes.
Definition fido2_types.h:47
__UINT32_TYPE__ uint32_t
Definition stdint.h:90
__INT32_TYPE__ int32_t
Definition stdint.h:74
__UINT8_TYPE__ uint8_t
Definition stdint.h:88
__UINT16_TYPE__ uint16_t
Definition stdint.h:89
A stored FIDO2 credential.
Definition fido2_types.h:221
uint8_t user_id[64]
User handle.
Definition fido2_types.h:237
char rp_name[64]
Relying party display name.
Definition fido2_types.h:231
uint32_t sign_count
Signature counter.
Definition fido2_types.h:243
char user_display_name[64]
User display name.
Definition fido2_types.h:235
uint8_t cred_protect
Credential protection level.
Definition fido2_types.h:251
uint8_t rp_id_hash[32]
SHA-256 hash of the relying party ID.
Definition fido2_types.h:227
int32_t algorithm
COSE algorithm identifier.
Definition fido2_types.h:247
bool discoverable
Discoverable (resident) credential.
Definition fido2_types.h:249
uint32_t extensions
Credential extensions bitmask (e.g.
Definition fido2_types.h:245
uint32_t key_id
PSA Crypto key identifier for this credential.
Definition fido2_types.h:241
uint16_t id_len
Credential identifier length.
Definition fido2_types.h:225
char user_name[64]
User account name.
Definition fido2_types.h:233
uint16_t user_id_len
User handle length.
Definition fido2_types.h:239
char rp_id[128]
Relying party identifier.
Definition fido2_types.h:229
Device information returned by authenticatorGetInfo.
Definition fido2_types.h:257
uint8_t num_extensions
Number of supported extensions.
Definition fido2_types.h:265
bool client_pin
Client PIN supported.
Definition fido2_types.h:280
uint8_t min_pin_length
Current minimum PIN length.
Definition fido2_types.h:298
bool uv
Built-in user verification support.
Definition fido2_types.h:282
bool up
User presence support.
Definition fido2_types.h:281
uint8_t transports
Supported transports bitmask.
Definition fido2_types.h:275
const char * versions[4]
Supported protocol versions.
Definition fido2_types.h:259
const char * extensions[8]
Supported extensions.
Definition fido2_types.h:263
bool plat
Platform device.
Definition fido2_types.h:278
uint16_t max_credential_id_length
Maximum credential ID length.
Definition fido2_types.h:271
uint8_t pin_uv_auth_protocols[2]
Supported PIN/UV auth protocol versions.
Definition fido2_types.h:292
uint16_t max_credential_count
Maximum credential count.
Definition fido2_types.h:269
uint8_t pin_retries
Remaining PIN retry attempts.
Definition fido2_types.h:296
uint8_t num_pin_uv_auth_protocols
Number of supported PIN/UV auth protocols.
Definition fido2_types.h:294
bool always_uv
Authenticator always requires UV.
Definition fido2_types.h:286
bool pin_uv_auth_token
pinUvAuthToken support
Definition fido2_types.h:284
uint32_t firmware_version
Firmware version.
Definition fido2_types.h:290
uint8_t aaguid[16]
Authenticator Attestation GUID.
Definition fido2_types.h:267
bool make_cred_uv_not_rqd
makeCredUvNotRqd support
Definition fido2_types.h:285
bool no_mc_ga_permissions_with_client_pin
Only if clientPin present.
Definition fido2_types.h:287
bool rk
Resident key support.
Definition fido2_types.h:279
bool cred_mgmt
Credential management support.
Definition fido2_types.h:283
uint16_t max_msg_size
Maximum CBOR message size in bytes.
Definition fido2_types.h:273
uint8_t num_versions
Number of supported versions.
Definition fido2_types.h:261
struct fido2_device_info::@263367117337362161200252061145100352376301326151 options
CTAP 2.1 Options Map.
Misc utilities.