Discussion of the implementations of VIRTIO specification
 help / color / mirror / Atom feed
* [PATCH v5 0/2] Add inline encryption support
@ 2026-09-29  4:21 Linlin Zhang
  2026-09-29  4:21 ` [PATCH v5 1/2] virtio-blk: Add the control virtqueue Linlin Zhang
  2026-09-29  4:21 ` [PATCH v5 2/2] virtio-blk: Add inline encryption support Linlin Zhang
  0 siblings, 2 replies; 3+ messages in thread
From: Linlin Zhang @ 2026-09-29  4:21 UTC (permalink / raw)
  To: virtio-dev, stefanha, ebiggers; +Cc: neeraj.soni

From: linlzhan <linlin.zhang@oss.qualcomm.com>

This series adds virtio-blk inline encryption support for devices backed
by storage hardware with an inline crypto engine.

The protocol exposes device capabilities such as keyslot count, maximum
DUN size, and supported key types. Encrypted requests identify a
provisioned keyslot and carry a 256-bit DUN. Key management and crypto
capability discovery use the block device control virtqueue.

The control virtqueue is defined as a generic framework so that its
buffer layout and queue placement are independent of any particular
control command. Inline encryption then builds on this framework with
explicit crypto command formats, capability validation, and keyslot
state semantics.

All key related operatios are handled in the control virtqueue, and
the crypto I/O request is handled in the request queue.

For background on inline encryption in UFS and eMMC storage, see:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/block/inline-encryption.rst

changes in v5
 - Change feature bit value of VIRTIO_BLK_F_CTRL_VQ and
   VIRTIO_BLK_F_INLINE_ENCRYPTION to 20 and 21 respectively

changes in v4
 - Add a control virtqueue specific subsection for virtio block
 - Move all control virtqueue request related to this new subsection
 - Add the precise semantics, error codes, etc for the new control
   virtqueue commands
 - Move 'MUST' to the normative section
 - Use c struct to describe control virtqueue request

changes in v3:
 - Add a control virtqueue
 - Move key program/evict/derive_sw_secret/generate/prepare/import to
   the control virtqueue
 - Add the driver and device requirements for the request in the control
   virtqueue
 - Extend DUN in crypto message to a fixed four-element array of 64-bit
   fields 

changes in v2:
 - Revmove virtualization-specific terminology
 - Move MUST sentence to the device/driver normative section
 - Add explicit rejection for CRYPTO request if IE feature bit
   isn't negociated
 - Modify the support list of crypto modes and the definition of
   the size of the crypto modes buffer
---

linlzhan (2):
  virtio-blk: Add the control virtqueue
  virtio-blk: Add inline encryption support

 device-types/blk/description.tex        | 619 +++++++++++++++++++++++-
 device-types/blk/device-conformance.tex |   1 +
 device-types/blk/driver-conformance.tex |   1 +
 3 files changed, 612 insertions(+), 9 deletions(-)

-- 
2.34.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-29  4:22 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-29  4:21 [PATCH v5 0/2] Add inline encryption support Linlin Zhang
2026-09-29  4:21 ` [PATCH v5 1/2] virtio-blk: Add the control virtqueue Linlin Zhang
2026-09-29  4:21 ` [PATCH v5 2/2] virtio-blk: Add inline encryption support Linlin Zhang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox