From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-15.8 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH,MAILING_LIST_MULTI, MENTIONS_GIT_HOSTING,SPF_HELO_NONE,SPF_PASS,USER_AGENT_GIT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9781AC4338F for ; Thu, 29 Jul 2021 16:47:32 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id EC25660F22 for ; Thu, 29 Jul 2021 16:47:31 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org EC25660F22 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 0D24282F2D; Thu, 29 Jul 2021 18:47:30 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="gxbF5njV"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 4E76D82F2D; Thu, 29 Jul 2021 18:47:28 +0200 (CEST) Received: from mail-oi1-x22b.google.com (mail-oi1-x22b.google.com [IPv6:2607:f8b0:4864:20::22b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id E47A282DC3 for ; Thu, 29 Jul 2021 18:47:24 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=mr.nuke.me@gmail.com Received: by mail-oi1-x22b.google.com with SMTP id u25so9218705oiv.5 for ; Thu, 29 Jul 2021 09:47:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=WaEy4GnPtIp37KuO36LhlhySHZE4wrzyii+62mO381g=; b=gxbF5njV7nBpotYaYiYSlpwRrBaQ1a2xigRxIzYNpGvu9YTcPe7Rq/yFiSXDBI86lc H+xp5jjzfB4IeSYWP42cNSFJYwUJ1o25r1metm9TkCmym9nmCC5Zb/MbGpngVbsiHJoW j0UgsWZqgndLPcXp+lTLdhc/sZDtEJtSkcHsRKAao5WBbtLEAqeZcfDIn4NXSjeB1UXy JlkJ0YcCIDNQcF0H9kkeJKGEHmbMp6XUvJFLZIUJ71D+I2Fu6Ygzq4/27urxMO+IZHRG dUxFwHRYwzykb+LaVmYg7z7kO9AXV6XC1H0vQxjRJuNeaClsL7IwWd+Xz3QoTNaA9wua MyFw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=WaEy4GnPtIp37KuO36LhlhySHZE4wrzyii+62mO381g=; b=X0xEYYCtc1byAo7a9RO7pyVzMxs5I7G7DQRaKcHN0YmVc76kZBzhUAIGm4G5mime5d yC3/y8eqTsb9wYDdkcdBQT63f5sudozL8X1lILAvzbSGsd3uHsqLw5MO2FSS+j7pg7M3 5ZAVB3cKm2fnDk84wbIWz2x3pcR8Q3UNCJdiLqhjw7asCWnfAMCyhQ+I1yn5GSb+cqPZ Y6BhMwLU181oJfyRRuoIqD/veXv8FRmVs9atyiUf0aHLiZDfbX/Q49cfxeVmkTVaiacU X0IT/DgdY0LzwMYc6U4vRLKVvgeTxUiCj8P0Py3lCsQcC9+HDhdmCjRyrKUUWxD1nIdT U+iQ== X-Gm-Message-State: AOAM531IaIwX4+Y5YjGGsux3UK+rYSRae3i1G23cKxyA4+eJbQZgJvH6 nUP7Su3krNYd+wREhahjLt3xp+U1dyg= X-Google-Smtp-Source: ABdhPJz22uwDzzI6/wuzc77Twx2rK1OoHvQRFJdeAbEJuZo7SGmlanVZdzkzySrrmLXIhBngspXHVQ== X-Received: by 2002:aca:1015:: with SMTP id 21mr10821920oiq.143.1627577243079; Thu, 29 Jul 2021 09:47:23 -0700 (PDT) Received: from nuclearis3.lan (c-98-195-139-126.hsd1.tx.comcast.net. [98.195.139.126]) by smtp.gmail.com with ESMTPSA id i12sm623273otr.56.2021.07.29.09.47.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 29 Jul 2021 09:47:22 -0700 (PDT) From: Alexandru Gagniuc To: u-boot@lists.denx.de, patrick.delaunay@foss.st.com Cc: Alexandru Gagniuc , sjg@chromium.org, etienne.carriere@linaro.org, patrice.chotard@foss.st.com Subject: [PATCH 0/5] Enable ECDSA FIT verification for stm32mp Date: Thu, 29 Jul 2021 11:47:14 -0500 Message-Id: <20210729164719.3490718-1-mr.nuke.me@gmail.com> X-Mailer: git-send-email 2.31.1 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean This series is based on the latest master, so no patch dependencies. Q: Will there be a software-only implementation of ECDSA ? A: That is the goal, so that we can have more extensive testing with the sandbox. I don not have the bandwidth to implement it. There has been an initial poer of software ecdsa here: https://github.com/timr11/u-boot/tree/ecdsa-vrf-1 Q: Can more code be shared with the RSA verification path? A: Probably yes. Mostly having to do with parsing the "/signature" node and "key-name-hint"s in the u-boot FDT. Although there isn't any copypasted RSA code, or code with substantial similarity. Changes since v5: - Fixed clang warning stemming from test/dm/ecdsa.c Changes since v4: - Use U_BOOT_CRYPTO_ALGO() to add ECDSA to .u_boot_list - No need to #define IMAGE_ENABLE_VERIFY_ECDSA - Use ut_asserteq(x, -ENODEV) instead of ut_assert(x == -ENODEV) Changes since v3: - Remove unused ecdsa_check_key() function Changes since v2: - Spell out "elliptic curve" in Kconfig (Although RSA isn't spelled out) Changes since v1: - Add test to make sure the UCLASS is enabled - Fix check against wrong sig_len in ecdsa_romapi.c - s/U_BOOT_DEVICE/U_BOOT_DRVINFO/ - Use "if(!ret)" instead of "if (ret == 0)" - Use uclass_first_device_err() instead of uclass_fi Alexandru Gagniuc (5): dm: crypto: Define UCLASS API for ECDSA signature verification lib: ecdsa: Implement UCLASS_ECDSA verification on target arm: stm32mp1: Implement ECDSA signature verification Kconfig: FIT_SIGNATURE should not select RSA_VERIFY test: dm: Add test for ECDSA UCLASS support arch/arm/mach-stm32mp/Kconfig | 9 ++ arch/arm/mach-stm32mp/Makefile | 1 + arch/arm/mach-stm32mp/ecdsa_romapi.c | 102 ++++++++++++++++++++ common/Kconfig.boot | 8 +- configs/sandbox_defconfig | 2 + include/crypto/ecdsa-uclass.h | 39 ++++++++ include/dm/uclass-id.h | 1 + lib/Kconfig | 1 + lib/Makefile | 1 + lib/ecdsa/Kconfig | 23 +++++ lib/ecdsa/Makefile | 1 + lib/ecdsa/ecdsa-verify.c | 134 +++++++++++++++++++++++++++ test/dm/Makefile | 1 + test/dm/ecdsa.c | 38 ++++++++ 14 files changed, 357 insertions(+), 4 deletions(-) create mode 100644 arch/arm/mach-stm32mp/ecdsa_romapi.c create mode 100644 include/crypto/ecdsa-uclass.h create mode 100644 lib/ecdsa/Kconfig create mode 100644 lib/ecdsa/Makefile create mode 100644 lib/ecdsa/ecdsa-verify.c create mode 100644 test/dm/ecdsa.c -- 2.31.1