From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-15.8 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_CR_TRAILER,INCLUDES_PATCH, MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,USER_AGENT_GIT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6A132C4338F for ; Thu, 29 Jul 2021 16:47:46 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 70D4A60EB2 for ; Thu, 29 Jul 2021 16:47:45 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 70D4A60EB2 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id B579182F24; Thu, 29 Jul 2021 18:47:38 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="AxVjcAlg"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 0F47282F2D; Thu, 29 Jul 2021 18:47:29 +0200 (CEST) Received: from mail-ot1-x336.google.com (mail-ot1-x336.google.com [IPv6:2607:f8b0:4864:20::336]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 17A9482F0C for ; Thu, 29 Jul 2021 18:47:26 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=mr.nuke.me@gmail.com Received: by mail-ot1-x336.google.com with SMTP id h63-20020a9d14450000b02904ce97efee36so6492312oth.7 for ; Thu, 29 Jul 2021 09:47:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=ddG9MP94Pa7dDKCZBDe5Z8rqx8WmV+QH3Ga/9zgAQmM=; b=AxVjcAlgrr/iUPAxy7eWJ4Z4bG5Qi0Iodach4drqHvve9GAWjLB55k1sLaobC5E8GY dObiciM6D3zNI+E4ON+7KQyrdSsMX+LvczB08732EBocUPEs/ZERJOqeap2W/3IMiKNo aCi2WgzRqJKNm12Me7zJNkp0PpsgWw2QEA+6miAocG9Qr+mriBOWgDgb+Gs0PkLNtze1 x7/6DOtlglXVls2cdnZbIM8u2+Wr7OQWs1DrIuMSBUT91GYHucrrFOicfe7VCtqVohXR bXQZL7hWwiNxdWARVeVYvVCHXBH91Bx0/wAkl2Y6MhGa/048yjfw2KO+fAZz2u1QjpSd 4U7Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=ddG9MP94Pa7dDKCZBDe5Z8rqx8WmV+QH3Ga/9zgAQmM=; b=Os8RkBS46xKkAJsgIzURJpakoxp3Ue1EIoiyy5ldgNRN2NjZgsGZUkB7MDeCI26cXC 50uUeZHN2k5l33+HDUd2sBB69CjN22JSydtuB34vFS3bVaCqpUQZ4dE3hCHbCrX2Tog6 8VM/lc+mzZWz1/jGBQxYf9OKViORoxYi3ZFSGqNRtbESG84gGJUTxm518TWQ8NT4mGz/ 1BzUe4+pfgVL52+i2rFoPdratRNvZ//ZD7sAmyQbjl9ZY1enNCt1W+yMgYmDaYvOZWb9 U1KWMIvNj2YYm9JPiVvk6CRTQH3OCcDhySlF0Pp9yFR3KelEV+Y/TeGl71xvXySomibu Sdvg== X-Gm-Message-State: AOAM533NUF2tnfkzo6yyAMUynPBNtdjXQn8nn7aANgUOD2EONH8X/WX3 EFahewk1/oNxioh3oCG3CSuNsZQewIQ= X-Google-Smtp-Source: ABdhPJx4QivCWF9619rmbdQqcD8GKe3ZbVeMtSTeBHNSGdHSN2TXBw1uXZpyQiYZzXBmc/o1UtXa0w== X-Received: by 2002:a05:6830:4188:: with SMTP id r8mr4114497otu.53.1627577244280; Thu, 29 Jul 2021 09:47:24 -0700 (PDT) Received: from nuclearis3.lan (c-98-195-139-126.hsd1.tx.comcast.net. [98.195.139.126]) by smtp.gmail.com with ESMTPSA id i12sm623273otr.56.2021.07.29.09.47.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 29 Jul 2021 09:47:23 -0700 (PDT) From: Alexandru Gagniuc To: u-boot@lists.denx.de, patrick.delaunay@foss.st.com Cc: Alexandru Gagniuc , sjg@chromium.org, etienne.carriere@linaro.org, patrice.chotard@foss.st.com Subject: [PATCH 1/5] dm: crypto: Define UCLASS API for ECDSA signature verification Date: Thu, 29 Jul 2021 11:47:15 -0500 Message-Id: <20210729164719.3490718-2-mr.nuke.me@gmail.com> X-Mailer: git-send-email 2.31.1 In-Reply-To: <20210729164719.3490718-1-mr.nuke.me@gmail.com> References: <20210729164719.3490718-1-mr.nuke.me@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean Define a UCLASS API for verifying ECDSA signatures. Unlike UCLASS_MOD_EXP, which focuses strictly on modular exponentiation, the ECDSA class focuses on verification. This is done so that it better aligns with mach-specific implementations, such as stm32mp. Signed-off-by: Alexandru Gagniuc --- include/crypto/ecdsa-uclass.h | 39 +++++++++++++++++++++++++++++++++++ include/dm/uclass-id.h | 1 + 2 files changed, 40 insertions(+) create mode 100644 include/crypto/ecdsa-uclass.h diff --git a/include/crypto/ecdsa-uclass.h b/include/crypto/ecdsa-uclass.h new file mode 100644 index 0000000000..189843820a --- /dev/null +++ b/include/crypto/ecdsa-uclass.h @@ -0,0 +1,39 @@ +/* SPDX-License-Identifier: GPL-2.0+ */ +/* + * Copyright (c) 2020, Alexandru Gagniuc + */ + +#include + +/** + * struct ecdsa_public_key - ECDSA public key properties + * + * The struct has pointers to the (x, y) curve coordinates to an ECDSA public + * key, as well as the name of the ECDSA curve. The size of the key is inferred + * from the 'curve_name' + */ +struct ecdsa_public_key { + const char *curve_name; /* Name of curve, e.g. "prime256v1" */ + const void *x; /* x coordinate of public key */ + const void *y; /* y coordinate of public key */ + unsigned int size_bits; /* key size in bits, derived from curve name */ +}; + +struct ecdsa_ops { + /** + * Verify signature of hash against given public key + * + * @dev: ECDSA Device + * @pubkey: ECDSA public key + * @hash: Hash of binary image + * @hash_len: Length of hash in bytes + * @signature: Signature in a raw (R, S) point pair + * @sig_len: Length of signature in bytes + * + * This function verifies that the 'signature' of the given 'hash' was + * signed by the private key corresponding to 'pubkey'. + */ + int (*verify)(struct udevice *dev, const struct ecdsa_public_key *pubkey, + const void *hash, size_t hash_len, + const void *signature, size_t sig_len); +}; diff --git a/include/dm/uclass-id.h b/include/dm/uclass-id.h index 9d474533ba..e7edd409f3 100644 --- a/include/dm/uclass-id.h +++ b/include/dm/uclass-id.h @@ -47,6 +47,7 @@ enum uclass_id { UCLASS_DSI_HOST, /* Display Serial Interface host */ UCLASS_DMA, /* Direct Memory Access */ UCLASS_DSA, /* Distributed (Ethernet) Switch Architecture */ + UCLASS_ECDSA, /* Elliptic curve cryptographic device */ UCLASS_EFI, /* EFI managed devices */ UCLASS_ETH, /* Ethernet device */ UCLASS_ETH_PHY, /* Ethernet PHY device */ -- 2.31.1