From: T Pratham <t-pratham@ti.com>
To: Herbert Xu <herbert@gondor.apana.org.au>,
"David S . Miller" <davem@davemloft.net>,
Rob Herring <robh@kernel.org>,
Krzysztof Kozlowski <krzk+dt@kernel.org>,
Conor Dooley <conor+dt@kernel.org>
Cc: T Pratham <t-pratham@ti.com>, <linux-crypto@vger.kernel.org>,
<devicetree@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
Kamlesh Gurudasani <kamlesh@ti.com>,
Manorit Chawdhry <m-chawdhry@ti.com>,
Vignesh Raghavendra <vigneshr@ti.com>,
Praneeth Bajjuri <praneeth@ti.com>,
Vishal Mahaveer <vishalm@ti.com>,
Kavitha Malarvizhi <k-malarvizhi@ti.com>
Subject: [PATCH v6 0/2] Add support for Texas Instruments DTHEv2 Crypto Engine
Date: Tue, 19 Aug 2025 11:42:43 +0530 [thread overview]
Message-ID: <20250819065844.3337101-1-t-pratham@ti.com> (raw)
Data Transform and Hashing Engine (DTHE) v2 is a new cryptography engine
introduced i TI AM62L SoC. DTHEv2 consists of multiple crypto IPs[1] (such
as AES Engine, hashing engine, TRNG, etc.) which can be used for
offloading cryptographic operations off of the CPU. The primary benefit
of DTHEv2 is enhanced side-channel attack resistance, with AES and PKE
engine being DPA and EMA resistant. These side-channel resistances are
the underlying requirement for various certifications like SESIP, PSA,
and IEC62443 (lvl 3+). Thus, DTHEv2 provides critical security benefits
for embedded systems that require protection against passive physical
attacks.
The AES Engine of DTHEv2 supports multiple AES modes (ECB, CBC, CTR,
CFB, f8), several protocols (GCM, CCM, XTS) and authentication modes
(CBC-MAC and f9). The hashing engine supports MD5, SHA1, and SHA2 (224,
256, 384, 512) algorithms along with HMAC. This patch series introduces
basic driver support for DTHEv2 engine, beginning with suporting AES-ECB
and AES-CBC algorithms. Other algorithms are planned to be added
gradually in phases after initial suppport is added.
The driver is tested using full kernel crypto selftests (CRYPTO_SELFTESTS)
which all pass successfully [2].
Signed-off-by: T Pratham <t-pratham@ti.com>
---
[1]: Section 14.6.3 (DMA Control Registers -> DMASS_DTHE)
Link: https://www.ti.com/lit/ug/sprujb4/sprujb4.pdf
[2]: DTHEv2 AES-ECB and AES-CBC kernel self-tests logs
Link: https://gist.github.com/Pratham-T/aaa499cf50d20310cb27266a645bfd60
Change log:
v6:
- Reworded the cover letter and commit messages to name DTHEv2 as a
crypto engine instead of crypto accelerator.
- Reworded the cover letter completely to emphasise more on the utility
of DTHEv2 as better resistance against physical attacks
- Reworded DTHEv2 description (help text) in KConfig
- Added dma_terminate_sync calls to ensure DMA requests are removed in
case when completion times-out.
- Some rearrangement of fields between dthe_tfm_ctx and dthe_aes_req_ctx
struct, so that per tfm members are correctly placed in tfm_ctx and per
request members are in req_ctx. Subsequently setkey, encrypt and
decrypt functions are also changed.
- Removed exit_tfm function which was useless and not required.
- Removed unnecessary zeroing of tfm_ctx object in init_tfm.
- Corrected return value in dthe_aes_run function.
- Reduced cra_priority of DTHEv2 algorithms.
v5:
- Simplified tfm ctx struct
- Set cra_reqsize instead of using crypto_skcipher_set_reqsize()
- Move setting sysconfig and irqenable registers to dthe_aes_run
v4:
- Corrected dt-bindings example indentation
- Simplified dt-bindings example, removing the node surrounding crypto
- Fixed typo in dthev2-common.h header guard
- Removed unused ctx field in dev_data struct
- Moved per-op data into request context
v3:
- Corrected dt-bindings reg length is too long error
- Converted AES driver code to use crypto_engine APIs for using
internal crypto queue instead of mutex.
- Removed calls to skcipher_request_complete in paths not returning
-EINPROGRESS before.
- Added missing KConfig import, which was accidentally removed in v2.
v2:
- Corrected dt-bindings syntax errors and other review comments in v1.
- Completely changed driver code structure, splitting code into
multiple files
Link to previous versions:
v5: https://lore.kernel.org/all/20250603124217.957116-1-t-pratham@ti.com/
v4: https://lore.kernel.org/all/20250508101723.846210-2-t-pratham@ti.com/
v3: https://lore.kernel.org/all/20250502121253.456974-2-t-pratham@ti.com/
v2: https://lore.kernel.org/all/20250411091321.2925308-1-t-pratham@ti.com/
v1: https://lore.kernel.org/all/20250206-dthe-v2-aes-v1-0-1e86cf683928@ti.com/
---
T Pratham (2):
dt-bindings: crypto: Add binding for TI DTHE V2
crypto: ti: Add driver for DTHE V2 AES Engine (ECB, CBC)
.../bindings/crypto/ti,am62l-dthev2.yaml | 50 +++
MAINTAINERS | 7 +
drivers/crypto/Kconfig | 1 +
drivers/crypto/Makefile | 1 +
drivers/crypto/ti/Kconfig | 14 +
drivers/crypto/ti/Makefile | 3 +
drivers/crypto/ti/dthev2-aes.c | 411 ++++++++++++++++++
drivers/crypto/ti/dthev2-common.c | 220 ++++++++++
drivers/crypto/ti/dthev2-common.h | 101 +++++
9 files changed, 808 insertions(+)
create mode 100644 Documentation/devicetree/bindings/crypto/ti,am62l-dthev2.yaml
create mode 100644 drivers/crypto/ti/Kconfig
create mode 100644 drivers/crypto/ti/Makefile
create mode 100644 drivers/crypto/ti/dthev2-aes.c
create mode 100644 drivers/crypto/ti/dthev2-common.c
create mode 100644 drivers/crypto/ti/dthev2-common.h
--
2.43.0
next reply other threads:[~2025-08-19 6:59 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-08-19 6:12 T Pratham [this message]
2025-08-19 6:12 ` [PATCH v6 1/2] dt-bindings: crypto: Add binding for TI DTHE V2 T Pratham
2025-08-20 7:43 ` Krzysztof Kozlowski
2025-08-20 8:52 ` T Pratham
2025-08-19 6:12 ` [PATCH v6 2/2] crypto: ti: Add driver for DTHE V2 AES Engine (ECB, CBC) T Pratham
2025-08-19 9:56 ` Ovidiu Panait
2025-08-20 8:58 ` T Pratham
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250819065844.3337101-1-t-pratham@ti.com \
--to=t-pratham@ti.com \
--cc=conor+dt@kernel.org \
--cc=davem@davemloft.net \
--cc=devicetree@vger.kernel.org \
--cc=herbert@gondor.apana.org.au \
--cc=k-malarvizhi@ti.com \
--cc=kamlesh@ti.com \
--cc=krzk+dt@kernel.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=m-chawdhry@ti.com \
--cc=praneeth@ti.com \
--cc=robh@kernel.org \
--cc=vigneshr@ti.com \
--cc=vishalm@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).