vitasdk
Documentation of the vitasdk

Exports for Kernel. More...

Functions

int ksceSblAuthMgrClearDmac5Key (int slot_id, int zero)
 Clear a DMAC5 key slot.
 
int ksceSblAuthMgrSetDmac5Key (const void *key, SceSize keylen, int slot_id, int key_id)
 Set a DMAC5 key slot.
 
int ksceSblAuthMgrAuthHeader (int handle, const void *self_header_addr, SceSize self_header_size, SceAuthInfo *auth_info)
 Authenticate a SELF header.
 
int ksceSblAuthMgrClose (int handle)
 Close a SELF authentication session.
 
int ksceSblAuthMgrCompareSwVersion (int version)
 Check whether a software version is supported.
 
int ksceSblAuthMgrDecBindData (void *klicensee, SceSize klicensee_len, const void *request, SceSize request_len, int zero)
 Decrypt NPDRM bind data in place using a read-only request.
 
int ksceSblAuthMgrGetEKc (void *data, SceSize size, int key_id)
 Process NPDRM EKc key material in place.
 
int ksceSblAuthMgrLoadBlock (int handle, void *buffer, SceSize buffer_size)
 Authenticate and decrypt a SELF segment block in place.
 
int ksceSblAuthMgrOpen (int *handle)
 Open a SELF authentication session.
 
int ksceSblAuthMgrSetupAuthSegment (int handle, int segment_index)
 Select and initialize a SELF segment for authentication.
 
int ksceSblAuthMgrVerifySpfsoCtx (SceSblSpsfoContext *ctx)
 Verify a signed SPSFO context.
 

Detailed Description

Exports for Kernel.


Using this library in your project

Include the header file in your project:


Link the library to the executable:

SceSblAuthMgrForKernel_stub SceSblAuthMgrForDriver_stub



Function Documentation

◆ ksceSblAuthMgrClearDmac5Key()

int ksceSblAuthMgrClearDmac5Key ( int  slot_id,
int  zero 
)

Clear a DMAC5 key slot.

AuthMgr does not validate slot_id before forwarding it to secure command

  1. SceSblSsMgr manages slots 12 through 23, but no FW 3.60 module that imports this function calls it directly.
Parameters
[in]slot_idDMAC5 key slot identifier.
[in]zeroMust be 0; forwarded in the secure command.
Returns
0 on success, 0x800F0516 when zero is not 0, or a negative synchronization or secure-module error.

◆ ksceSblAuthMgrSetDmac5Key()

int ksceSblAuthMgrSetDmac5Key ( const void *  key,
SceSize  keylen,
int  slot_id,
int  key_id 
)

Set a DMAC5 key slot.

FW 3.60 does not validate slot_id before forwarding it to secure command

  1. SceSblSsMgr allocates slots 12 through 23.
Parameters
[in]keyNon-NULL pointer to the key data.
[in]keylenKey size, either 0x10 or 0x20 bytes.
[in]slot_idDMAC5 key slot identifier.
[in]key_idKey identifier: 0, 0x10000, 0x10001, 0x20000, or 0x20001.
Returns
0 on success, 0x800F0516 for an invalid pointer, key size, or key identifier, or a negative synchronization or secure-module error.

◆ ksceSblAuthMgrAuthHeader()

int ksceSblAuthMgrAuthHeader ( int  handle,
const void *  self_header_addr,
SceSize  self_header_size,
SceAuthInfo *  auth_info 
)

Authenticate a SELF header.

Call this function after ksceSblAuthMgrOpen. The complete SceAuthInfo context is sent to secure command 1. On success, only SceAuthInfo::response is copied back from the secure-module response.

When the system license state is uninitialized, expired, or reports a backup-battery failure, FW 3.60 sets the four-bit field at bits 8 through 11 of SceAuthInfo::self_type to 1 before authentication. For media types 13 and 14, the verified SPSFO system version is written to ::SceSelfAuthInfo::program_sceversion in the response SELF authorization information; other media types receive zero in that field.

When the upper 12 bits of the authenticated program-authority ID equal 0x2F0, a registered Utoken override can replace the response program-authority ID, capability, attribute, and first 0x10 bytes of the shared secret. The no-override error 0x800F1A02 is ignored; other negative Utoken errors are returned.

Parameters
[in]handleAuthentication session handle. Must be 1.
[in]self_header_addrNon-NULL address of the mapped SELF header.
[in]self_header_sizeSize of the mapped SELF header in bytes.
[in,out]auth_infoNon-NULL pointer to the SELF authentication context.
Returns
0 on success, 0x800F0509 for an invalid handle, 0x800F0516 for an invalid pointer, or a negative address-translation, Utoken, or secure-module error.

◆ ksceSblAuthMgrClose()

int ksceSblAuthMgrClose ( int  handle)

Close a SELF authentication session.

This releases the single session acquired by ksceSblAuthMgrOpen and the suspend lock held while the session is open. FW 3.60 clears the internal session only when stopping the secure module succeeds, but it does not return a secure module stop error to the caller.

Parameters
[in]handleAuthentication session handle. Must be 1.
Returns
0 on success, 0x800F0509 for an invalid handle, or a negative mutex or semaphore error.

◆ ksceSblAuthMgrCompareSwVersion()

int ksceSblAuthMgrCompareSwVersion ( int  version)

Check whether a software version is supported.

SceKernelModulemgr applies this check to the authenticated software version of a game process image after loading it.

Parameters
[in]versionSoftware-version bit pattern. The value -1 is always accepted. Otherwise, the low 12 bits are cleared and the unsigned result must not exceed 0x03600000 on FW 3.60.
Returns
0 when accepted, otherwise 0x800F0537.

◆ ksceSblAuthMgrDecBindData()

int ksceSblAuthMgrDecBindData ( void *  klicensee,
SceSize  klicensee_len,
const void *  request,
SceSize  request_len,
int  zero 
)

Decrypt NPDRM bind data in place using a read-only request.

Both buffers must be physically contiguous and 0x40-byte aligned. NpDrm calls this with a 0x10-byte output and a 0x90-byte request assembled from a 0x20-byte bind seed followed by a 0x70-byte RIF header.

Parameters
[in,out]klicenseeNon-NULL output buffer.
[in]klicensee_lenOutput size, from 0 through 0x1000 bytes and a multiple of 0x10.
[in]requestNon-NULL read-only request buffer.
[in]request_lenRequest size, from 0x10 through 0x1000 bytes and a multiple of 0x10.
[in]zeroMust be 0.
Returns
0 on success, 0x800F0516 for invalid pointers, alignment, sizes, or zero, or a negative address-translation, synchronization, or secure-module error.

◆ ksceSblAuthMgrGetEKc()

int ksceSblAuthMgrGetEKc ( void *  data,
SceSize  size,
int  key_id 
)

Process NPDRM EKc key material in place.

The secure module may return a different number of bytes than supplied. AuthMgr rejects counts above 0x100; otherwise, it copies the reported number of bytes back to data. NpDrm uses key identifier 0 to process its 0xC0-byte encrypted key-material table.

Parameters
[in,out]dataNon-NULL input/output buffer.
[in]sizeInput size, from 0x10 through 0x100 bytes and a multiple of 0x10.
[in]key_idKey identifier, from 0 through 2.
Returns
0 on success, 0x800F0516 for an invalid pointer, size, key identifier, or secure-module output size, or a negative synchronization or secure-module error.

◆ ksceSblAuthMgrLoadBlock()

int ksceSblAuthMgrLoadBlock ( int  handle,
void *  buffer,
SceSize  buffer_size 
)

Authenticate and decrypt a SELF segment block in place.

The input and output use the same list of physical address ranges. Cache maintenance is rounded up to 0x40 bytes. SceKernelModulemgr submits stream chunks of up to 0x10000 bytes.

Parameters
[in]handleAuthentication session handle. Must be 1.
[in,out]bufferNon-NULL, 0x20-byte-aligned block buffer.
[in]buffer_sizeNonzero block size in bytes.
Returns
0 on success, 0x800F0509 for an invalid handle, 0x800F0516 for an invalid buffer, size, or alignment, or a negative address-translation or secure-module error.

◆ ksceSblAuthMgrOpen()

int ksceSblAuthMgrOpen ( int *  handle)

Open a SELF authentication session.

FW 3.60 supports one session for the whole system. A successful call starts the Auth secure module, writes handle 1 to handle, and holds a suspend lock until the matching ksceSblAuthMgrClose call.

Parameters
[out]handleNon-NULL pointer that receives handle 1.
Returns
0 on success, 0x800F0501 when a session is already open, 0x800F0516 for an invalid pointer or internal session state, or a negative synchronization or secure-module scheduler error.

◆ ksceSblAuthMgrSetupAuthSegment()

int ksceSblAuthMgrSetupAuthSegment ( int  handle,
int  segment_index 
)

Select and initialize a SELF segment for authentication.

The segment index is forwarded unchanged to secure command 2. SceKernelModulemgr treats return value 1 as an uncompressed segment and every other nonnegative value as a deflate-compressed segment.

Parameters
[in]handleAuthentication session handle. Must be 1.
[in]segment_indexSELF segment index.
Returns
The secure-module segment mode, 0x800F0509 for an invalid handle, or another negative secure-module error.

◆ ksceSblAuthMgrVerifySpfsoCtx()

int ksceSblAuthMgrVerifySpfsoCtx ( SceSblSpsfoContext *  ctx)

Verify a signed SPSFO context.

The mapped file is passed to secure command 8. After successful secure verification, FW 3.60 checks the embedded signed-header offset and saves a copy of the 0x200-byte header in AuthMgr for later SELF authentication.

Parameters
[in,out]ctxNon-NULL pointer to the SPSFO mapping. Its memory-block base must be non-NULL and 0x20-byte aligned, and its exact file size must not exceed 0x8000 bytes.
Returns
0 on success, 0x800F0516 for an invalid context, base, or size, 0x800F0524 for an invalid signed-header range after verification, or a negative address-translation, synchronization, or secure-module error.