On 9/1/26 10:52, Jamin Lin wrote:
This series depends on:

  1. [v4,0/4] Add ASPEED ACRY RSA model for the AST2600
     
https://patchwork.kernel.org/project/qemu-devel/cover/[email protected]/

This series adds ECDSA to the QEMU crypto akcipher framework and models the
ASPEED AST10x0 secure boot controller (SBC) ECDSA engine on top of it.

The crypto side adds ECDSA sign/verify for prime256v1 (NIST P-256) and
secp384r1 (NIST P-384) in both the gcrypt and nettle backends, using the raw
big-endian form (public key Qx || Qy, private key scalar d, signature r || s)
with a pre-computed digest as input.

Both the AST2600 and the AST1030/AST1060 have a Secure Boot Controller (SBC)
that supports RSA and ECDSA verification, but only the AST1030/AST1060 have an
ECDSA verify engine, so this series models ECDSA only. RSA verification is used
solely to verify the AST2600 SPL in ROM CODE, which ASPEED does not release,
so it is very unlikely to be used by end users.

v1:
  1. Add ECDSA akcipher support with gcrypt backend
  2. Add ECDSA akcipher support with nettle backend
  3. Add ECDSA sign/verify unit tests
  4. Support the ECDSA verify command for AST10x0
  5. Add ASPEED SBC ECDSA engine qtest

v2:
  1. Wrap the SEC SRAM in a container mapped at offset 0 so the device
     addresses it by relative offset (drop the "sram-base" property)
  2. Add a patch removing the obsolete unimplemented SBC mapping
  3. Add Qtest to ast1060-evb machine.
  4. Rename R_ECDSA_CMD to R_SEC_TRIGGER, since the register
     triggers both the RSA and ECDSA engines.

v3:
  1. fix typo
  2. Replace g_printerr with g_test_skip

v4:
   1. Reorder the patches to fix a QEMU startup failure at an intermediate 
commit.
   2. Add public key type validation for ECDSA verification.
   3. Add private key type validation for ECDSA signing.
   4. Remove sbc_unimplemented from AspeedSoCState
   5. Update the commit messages.

Jamin Lin (9):
   qapi/crypto: Add ECDSA algorithm and curve id
   crypto/akcipher: Support ECDSA sign/verify with gcrypt
   crypto/akcipher: Support ECDSA sign/verify with nettle
   tests/crypto: Add ECDSA sign/verify tests
   hw/arm/aspeed_ast10x0: Remove obsolete unimplemented SBC mapping
   hw/misc/aspeed_sbc: Increase register space to 0x1000
   hw/arm/aspeed_ast10x0: Wire SEC SRAM to the SBC model
   hw/misc/aspeed_sbc: Support the ECDSA verify command
   tests/qtest: Add ASPEED SBC ECDSA engine test

  qapi/crypto.json                  |  33 ++-
  include/hw/arm/aspeed_soc.h       |   1 -
  include/hw/misc/aspeed_sbc.h      |   6 +-
  hw/arm/aspeed_ast10x0.c           |  14 +-
  hw/misc/aspeed_sbc.c              | 158 +++++++++++++-
  tests/qtest/aspeed-sbc-test.c     | 194 +++++++++++++++++
  tests/unit/test-crypto-akcipher.c | 236 +++++++++++++++++++++
  crypto/akcipher-gcrypt.c.inc      | 340 +++++++++++++++++++++++++++++-
  crypto/akcipher-nettle.c.inc      | 272 ++++++++++++++++++++++++
  hw/misc/trace-events              |   2 +
  tests/qtest/meson.build           |   2 +
  11 files changed, 1242 insertions(+), 16 deletions(-)
  create mode 100644 tests/qtest/aspeed-sbc-test.c


Applied to

    https://github.com/legoater/qemu aspeed-next

Thanks,

C.


Reply via email to