C/C++ API
HSM Dinamo
Loading...
Looking for...
No entries found
tokenization.c

Example of tokenization with the SVault module using token generation and secret recovery.

See Note on examples.
#include <string.h>
#include <stdlib.h>
#include <stdio.h>
#include <dinamo.h> /* header do Dinamo */
#define HOST_ADDR "127.0.0.1"
#define USER_ID "master"
#define USER_PWD "12345678"
int main()
{
int nRet = 0;
struct AUTH_PWD authPwd;
HSESSIONCTX hSession = NULL;
//Chave simétrica utilizada para proteção dos dados
#define PROTECTION_KEY_NAME "aes256"
char szMK[] = PROTECTION_KEY_NAME;
BYTE pbTokenBlob[D_SVAULT_TOKEN_BLOB_LEN] = {0};
DWORD dwTokenBlobLen = sizeof(pbTokenBlob);
char szToken[D_SVAULT_MAX_TL + 1] = {0};
char szSecret[D_SVAULT_MAX_TL + 1] = {0};
DWORD dwSecretLen = sizeof(szSecret);
char szMask[D_SVAULT_MAX_TL + 1] = {0};
//Inicializa as bibliotecas do Dinamo
nRet = DInitialize(0);
if (nRet) {
printf("Function failure: DInitialize \nError code: %d\n", nRet);
goto clean;
}
printf("Libraries initialized.\n");
//Inicializa a estrutura para conexão com o HSM
strncpy(authPwd. szAddr, HOST_ADDR, sizeof(authPwd.szAddr));
authPwd. nPort = DEFAULT_PORT;
strncpy(authPwd. szUserId, USER_ID, sizeof(authPwd.szUserId));
strncpy(authPwd. szPassword, USER_PWD, sizeof(authPwd.szPassword));
nRet = DOpenSession(&hSession, SS_USER_PWD,(BYTE *)&authPwd, sizeof(authPwd), ENCRYPTED_CONN);
if (nRet) {
printf("Function failure: DOpenSession \nError code: %d\n", nRet);
goto clean;
}
printf("Session with Dinamo established.\n");
/*
Generates the master key.
This key is generated only once and must be persisted in the HSM for
use with all the tokens generated by it.
*/
nRet = DGenerateKey(hSession, szMK, ALG_AES_256, 0, NULL);
/*
Tokenizes a CPF.
*/
{
SVAULT_GEN_TOKEN stTokenInfo = { D_SVAULT_F_MASK_SECRET,
"26122200468",
PROTECTION_KEY_NAME};
nRet = DSVaultGenToken(hSession,
0,
(BYTE *)&stTokenInfo,
pbTokenBlob,
&dwTokenBlobLen,
szToken,
0);
if (nRet)
{
printf("Function failure: DSVaultGenToken \nError code: %d\n", nRet);
goto clean;
}
printf("Token (CPF) generated successfully.\"%s\".\n", szToken);
/*
Get the secret back.
*/
nRet = DSVaultGetData(hSession,
PROTECTION_KEY_NAME,
NULL,
pbTokenBlob,
dwTokenBlobLen,
szSecret,
&dwSecretLen,
0);
if (nRet) {
printf("Function failed: DSVaultGetData (CPF) \nError code: %d\n", nRet);
goto clean;
}
printf("Secret (CPF) retrieved successfully.\"%s\".\n", szSecret);
/*
Recover the masked secret.
*/
#define CPF_MASK "***\0\0\0***"
memcpy(szMask, CPF_MASK, sizeof(CPF_MASK));
dwSecretLen = sizeof(szSecret);
nRet = DSVaultGetData(hSession,
PROTECTION_KEY_NAME,
szMask,
pbTokenBlob,
dwTokenBlobLen,
szSecret,
&dwSecretLen,
0);
if (nRet)
{
printf("Function failed: DSVaultGetData (CPF) \nError code: %d\n", nRet);
goto clean;
}
printf("Secret (CPF) retrieved successfully.\"%s\".\n", szSecret);
}
/*
Tokensizes a string.
*/
{
"This is a test",
PROTECTION_KEY_NAME};
dwTokenBlobLen = sizeof(pbTokenBlob);
nRet = DSVaultGenToken(hSession,
0,
(BYTE *)&stTokenInfoString,
pbTokenBlob,
&dwTokenBlobLen,
szToken,
0);
if (nRet)
{
printf("Function failure: DSVaultGenToken (string) \nError code: %d\n", nRet);
goto clean;
}
printf("Token (string) generated successfully.\"%s\".\n", szToken);
/*
Get the secret back.
*/
dwSecretLen = sizeof(szSecret);
nRet = DSVaultGetData(hSession,
PROTECTION_KEY_NAME,
NULL,
pbTokenBlob,
dwTokenBlobLen,
szSecret,
&dwSecretLen,
0);
if (nRet)
{
printf("Function failed: DSVaultGetData (string) \nError code: %d\n", nRet);
goto clean;
}
#ifdef _WIN32
SetConsoleOutputCP(CP_UTF8);
#endif
printf("Secret (string) retrieved successfully. \"%s\".\n", szSecret);
/*
Recover the masked secret.
*/
memset(szMask, 0, sizeof(szMask));
#define TEXT_MASK "*******\0\0\0"
memcpy(szMask, TEXT_MASK, sizeof(TEXT_MASK));
dwSecretLen = sizeof(szSecret);
nRet = DSVaultGetData(hSession,
PROTECTION_KEY_NAME,
szMask,
pbTokenBlob,
dwTokenBlobLen,
szSecret,
&dwSecretLen,
0);
if (nRet)
{
printf("Function failed: DSVaultGetData (string) \nError code: %d\n", nRet);
goto clean;
}
printf("Secret (string) retrieved successfully. \"%s\".\n", szSecret);
}
clean:
if (hSession) {
DCloseSession(&hSession, 0);
printf("Session closed.\n");
}
printf("Libraries finished.\n");
return nRet;
}
HSM Application Programming Interface (API) Dinamo.
#define D_SVAULT_TOKEN_BLOB_LEN
Definition dinamo.h:2112
void * HSESSIONCTX
Definition dinamo.h:68
#define DEFAULT_PORT
Definition dinamo.h:1948
#define ALG_AES_256
Definition dinamo.h:1028
#define D_SVAULT_GET_OP_SECRET
Definition dinamo.h:2116
#define D_SVAULT_MAX_TL
Definition dinamo.h:2093
#define D_SVAULT_CKS_NULL
Definition dinamo.h:2100
unsigned char BYTE
Definition dinamo.h:45
#define D_SVAULT_F_MASK_SECRET
Definition dinamo.h:2098
#define D_SVAULT_BASE62
Definition dinamo.h:2110
#define D_SVAULT_T_TKR2
Definition dinamo.h:2095
unsigned int DWORD
Definition dinamo.h:46
#define ENCRYPTED_CONN
Definition dinamo.h:585
#define SS_USER_PWD
Definition dinamo.h:576
#define D_SVAULT_BASE10
Definition dinamo.h:2106
#define D_SVAULT_CKS_CPF
Definition dinamo.h:2101
int AAP_API DGenerateKey(HSESSIONCTX hSession, char *szKeyId, int nAlgId, DWORD dwFlags, HKEYCTX *phKey)
int AAP_API DOpenSession(HSESSIONCTX *phSession, DWORD dwParam, BYTE *pbData, DWORD dwDataLen, DWORD dwFlags)
int AAP_API DCloseSession(HSESSIONCTX *phSession, DWORD dwFlags)
int AAP_API DInitialize(DWORD dwReserved)
int AAP_API DFinalize()
int AAP_API DSVaultGetData(HSESSIONCTX hSession, DWORD dwOp, const char *szMK, const char *szMask, BYTE *pbTokenBlob, DWORD dwTokenBlobLen, char *szData, DWORD *pdwDataLen, DWORD dwReserved)
int AAP_API DSVaultGenToken(HSESSIONCTX hSession, DWORD dwOp, BYTE *pbInData, BYTE *pbTokenBlob, DWORD *pdwTokenBlobLen, char *szToken, DWORD dwReserved)
Definition dinamo.h:3089
int nPort
Definition dinamo.h:3091
char szUserId[MAX_USR_LEN]
Definition dinamo.h:3092
char szAddr[MAX_ADDR_LEN]
Definition dinamo.h:3090
char szPassword[MAX_USR_PWD]
Definition dinamo.h:3093
Definition dinamo.h:2243