From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id B658FC25B6E for ; Tue, 24 Oct 2023 16:21:05 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:Message-ID:Date:Subject:Cc :To:From:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References: List-Owner; bh=WNro9hCJNQkyer0o2vi9YAaaUtPP3ZDP5YaG1JdGpxI=; b=WIZZ8tZ9AQ5dOQ 2qpRlrfYzxWLV8TdOYhx+Bit0YuCyBXkUtGgZNBEeZlQdeq2fwkHokj+Z1ufzNtshDaYWYCAr+4Rq f5uJhwvW8GyyLweI0m+F9Hjwjj9i+Aa3EOK0Nq3THjs3IG2BI9Irq5B5T/W+qc+YdUSMgWRmsPIcC F3x+QYdJ9ewoD+sTJXobpDnRygMgNYVXfy9OM9zHAXFTLqkZgMISf2dQqJJqRZnqycLRkRkrhzT4H FMkIuH49RusgvSPwK/FSfZOYhCe7CZx8RImGiVtVMieHAAyfC56eBrhK6derwXzuPunTmfMeJwg3f HvlE1cFMeAq5UsvUVfCg==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.96 #2 (Red Hat Linux)) id 1qvK92-00ARuI-1K; Tue, 24 Oct 2023 16:20:40 +0000 Received: from mail-ej1-x634.google.com ([2a00:1450:4864:20::634]) by bombadil.infradead.org with esmtps (Exim 4.96 #2 (Red Hat Linux)) id 1qvK8y-00ARsm-2C for linux-arm-kernel@lists.infradead.org; Tue, 24 Oct 2023 16:20:39 +0000 Received: by mail-ej1-x634.google.com with SMTP id a640c23a62f3a-99de884ad25so703322166b.3 for ; Tue, 24 Oct 2023 09:20:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sigma-star.at; s=google; t=1698164432; x=1698769232; darn=lists.infradead.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=TRO+xCDaQbDKnIXJCwBi3Y2yF65udPG/2rEKc0aYwBQ=; b=Mb6EJTrAydaP9rG+35EB5TKz/taMPFiBGabtWEtAhyBmsiIgdsUerkm88aLdgFYpZJ oow8C/Ni+qbbJq9aAHddXkCbwDy/G0rRnmNT3/Kuto++afpIHIRYcmcRh36ri2b08mh6 +4Cm2epin9fZKNEKP27poyTYUB36QSk8+jiRfNNCxvKNRJmU+BKRn61TCVNRMGqZprKf rc/fnKtPOmtMg8iPu95QWIdQp5JQPp4jviPtVSofUM5mHsWpUqn2JYEwXUpUi8vntauu l8uOFaOqKiRGd3/geeoSERXXzQXpw4ctWzRbl3iwF/nsWC0ODRFeTPjianleT+AU6AiR /AEw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1698164432; x=1698769232; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=TRO+xCDaQbDKnIXJCwBi3Y2yF65udPG/2rEKc0aYwBQ=; b=BIm/H5urVWYSi4KFjusV2M4tsQS9u6cZTnlougFijsP+A/onDvmhNF8EU3PbvoeDAB Poa+FDUS0R4XgOaAW18MQ9Dik9RJURY3UR5O+KkcmR2ZJTFoZGrQUAieLXyPsT/Q6TNg x/+wRlWjKuHjGd0lNt65K8drzMXgVlK4DMzqH8JlD4O4GZNd9hNpNXWHzfPRUGSaVlN/ L08aAnO7ve23v8hOdILgPRpuq9gnCVDtA/t98PNDTE9u9oH4YU7S3zVCYAQ8mI4hnPT3 YRPPzYW7Xj/CGMy4lou6zVdNig9DxHxTOlyAtRDCBrrITdasa40reG4bb/HngJ8eC9z0 nUaw== X-Gm-Message-State: AOJu0YydPIPd6Il3eAT2xk46bKSg/6sDDQDX6xLRQqkWUqIPWWnbOuFI ve5nE2zbIi2BsQB29Gh+ESnjnQ== X-Google-Smtp-Source: AGHT+IEIk3iJ6GCsHRYMeMdo8uw1QNTL6gntpg/5SaGUAZHqkqQekLyT81Tgpt8fo9diZdiabupYpQ== X-Received: by 2002:a17:907:c0d:b0:9be:8693:66bb with SMTP id ga13-20020a1709070c0d00b009be869366bbmr9625930ejc.59.1698164431055; Tue, 24 Oct 2023 09:20:31 -0700 (PDT) Received: from localhost (clnet-p106-198.ikbnet.co.at. [83.175.106.198]) by smtp.gmail.com with UTF8SMTPSA id cw11-20020a170906c78b00b009add084a00csm8489556ejb.36.2023.10.24.09.20.29 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 24 Oct 2023 09:20:30 -0700 (PDT) From: David Gstir To: Mimi Zohar , James Bottomley , Jarkko Sakkinen , Herbert Xu , "David S. Miller" Cc: David Gstir , Shawn Guo , Jonathan Corbet , Sascha Hauer , Pengutronix Kernel Team , Fabio Estevam , NXP Linux Team , Ahmad Fatoum , sigma star Kernel Team , David Howells , Li Yang , Paul Moore , James Morris , "Serge E. Hallyn" , "Paul E. McKenney" , Randy Dunlap , Catalin Marinas , "Rafael J. Wysocki" , Tejun Heo , "Steven Rostedt (Google)" , linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linux-crypto@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linuxppc-dev@lists.ozlabs.org, linux-security-module@vger.kernel.org Subject: [PATCH v4 0/5] DCP as trusted keys backend Date: Tue, 24 Oct 2023 18:20:14 +0200 Message-ID: <20231024162024.51260-1-david@sigma-star.at> X-Mailer: git-send-email 2.42.0 MIME-Version: 1.0 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20231024_092036_723720_2ACC7545 X-CRM114-Status: GOOD ( 20.49 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org This is a revival of the previous patch set submitted by Richard Weinberger: https://lore.kernel.org/linux-integrity/20210614201620.30451-1-richard@nod.at/ v3 is here: https://lore.kernel.org/keyrings/20230918141826.8139-1-david@sigma-star.at/ v3 -> v4: - Split changes on MAINTAINERS and documentation into dedicated patches - Use more concise wording in commit messages as suggested by Jarkko Sakkinen v2 -> v3: - Addressed review comments from Jarkko Sakkinen v1 -> v2: - Revive and rebase to latest version - Include review comments from Ahmad Fatoum The Data CoProcessor (DCP) is an IP core built into many NXP SoCs such as i.mx6ull. Similar to the CAAM engine used in more powerful SoCs, DCP can AES- encrypt/decrypt user data using a unique, never-disclosed, device-specific key. Unlike CAAM though, it cannot directly wrap and unwrap blobs in hardware. As DCP offers only the bare minimum feature set and a blob mechanism needs aid from software. A blob in this case is a piece of sensitive data (e.g. a key) that is encrypted and authenticated using the device-specific key so that unwrapping can only be done on the hardware where the blob was wrapped. This patch series adds a DCP based, trusted-key backend and is similar in spirit to the one by Ahmad Fatoum [0] that does the same for CAAM. It is of interest for similar use cases as the CAAM patch set, but for lower end devices, where CAAM is not available. Because constructing and parsing the blob has to happen in software, we needed to decide on a blob format and chose the following: struct dcp_blob_fmt { __u8 fmt_version; __u8 blob_key[AES_KEYSIZE_128]; __u8 nonce[AES_KEYSIZE_128]; __le32 payload_len; __u8 payload[]; } __packed; The `fmt_version` is currently 1. The encrypted key is stored in the payload area. It is AES-128-GCM encrypted using `blob_key` and `nonce`, GCM auth tag is attached at the end of the payload (`payload_len` does not include the size of the auth tag). The `blob_key` itself is encrypted in AES-128-ECB mode by DCP using the OTP or UNIQUE device key. A new `blob_key` and `nonce` are generated randomly, when sealing/exporting the DCP blob. This patchset was tested with dm-crypt on an i.MX6ULL board. [0] https://lore.kernel.org/keyrings/20220513145705.2080323-1-a.fatoum@pengutronix.de/ David Gstir (5): crypto: mxs-dcp: Add support for hardware-bound keys KEYS: trusted: Introduce NXP DCP-backed trusted keys MAINTAINERS: add entry for DCP-based trusted keys docs: document DCP-backed trusted keys kernel params docs: trusted-encrypted: add DCP as new trust source .../admin-guide/kernel-parameters.txt | 13 + .../security/keys/trusted-encrypted.rst | 85 +++++ MAINTAINERS | 9 + drivers/crypto/mxs-dcp.c | 104 +++++- include/keys/trusted_dcp.h | 11 + include/soc/fsl/dcp.h | 17 + security/keys/trusted-keys/Kconfig | 9 +- security/keys/trusted-keys/Makefile | 2 + security/keys/trusted-keys/trusted_core.c | 6 +- security/keys/trusted-keys/trusted_dcp.c | 311 ++++++++++++++++++ 10 files changed, 554 insertions(+), 13 deletions(-) create mode 100644 include/keys/trusted_dcp.h create mode 100644 include/soc/fsl/dcp.h create mode 100644 security/keys/trusted-keys/trusted_dcp.c -- 2.35.3 _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel