1// SPDX-License-Identifier: GPL-2.0-only
2/*
3 * Copyright (C) 2021 sigma star gmbh
4 */
5
6#include <crypto/aead.h>
7#include <crypto/aes.h>
8#include <crypto/algapi.h>
9#include <crypto/gcm.h>
10#include <crypto/skcipher.h>
11#include <keys/trusted-type.h>
12#include <linux/key-type.h>
13#include <linux/module.h>
14#include <linux/printk.h>
15#include <linux/random.h>
16#include <linux/scatterlist.h>
17#include <soc/fsl/dcp.h>
18
19#define DCP_BLOB_VERSION 1
20#define DCP_BLOB_AUTHLEN 16
21
22/**
23 * DOC: dcp blob format
24 *
25 * The Data Co-Processor (DCP) provides hardware-bound AES keys using its
26 * AES encryption engine only. It does not provide direct key sealing/unsealing.
27 * To make DCP hardware encryption keys usable as trust source, we define
28 * our own custom format that uses a hardware-bound key to secure the sealing
29 * key stored in the key blob.
30 *
31 * Whenever a new trusted key using DCP is generated, we generate a random 128-bit
32 * blob encryption key (BEK) and 128-bit nonce. The BEK and nonce are used to
33 * encrypt the trusted key payload using AES-128-GCM.
34 *
35 * The BEK itself is encrypted using the hardware-bound key using the DCP's AES
36 * encryption engine with AES-128-ECB. The encrypted BEK, generated nonce,
37 * BEK-encrypted payload and authentication tag make up the blob format together
38 * with a version number, payload length and authentication tag.
39 */
40
41/**
42 * struct dcp_blob_fmt - DCP BLOB format.
43 *
44 * @fmt_version: Format version, currently being %1.
45 * @blob_key: Random AES 128 key which is used to encrypt @payload,
46 *            @blob_key itself is encrypted with OTP or UNIQUE device key in
47 *            AES-128-ECB mode by DCP.
48 * @nonce: Random nonce used for @payload encryption.
49 * @payload_len: Length of the plain text @payload.
50 * @payload: The payload itself, encrypted using AES-128-GCM and @blob_key,
51 *           GCM auth tag of size DCP_BLOB_AUTHLEN is attached at the end of it.
52 *
53 * The total size of a DCP BLOB is sizeof(struct dcp_blob_fmt) + @payload_len +
54 * DCP_BLOB_AUTHLEN.
55 */
56struct dcp_blob_fmt {
57	__u8 fmt_version;
58	__u8 blob_key[AES_KEYSIZE_128];
59	__u8 nonce[AES_KEYSIZE_128];
60	__le32 payload_len;
61	__u8 payload[];
62} __packed;
63
64static bool use_otp_key;
65module_param_named(dcp_use_otp_key, use_otp_key, bool, 0);
66MODULE_PARM_DESC(dcp_use_otp_key, "Use OTP instead of UNIQUE key for sealing");
67
68static bool skip_zk_test;
69module_param_named(dcp_skip_zk_test, skip_zk_test, bool, 0);
70MODULE_PARM_DESC(dcp_skip_zk_test, "Don't test whether device keys are zero'ed");
71
72static unsigned int calc_blob_len(unsigned int payload_len)
73{
74	return sizeof(struct dcp_blob_fmt) + payload_len + DCP_BLOB_AUTHLEN;
75}
76
77static int do_dcp_crypto(u8 *in, u8 *out, bool do_encrypt)
78{
79	struct skcipher_request *req = NULL;
80	struct scatterlist src_sg, dst_sg;
81	struct crypto_skcipher *tfm;
82	u8 paes_key[DCP_PAES_KEYSIZE];
83	DECLARE_CRYPTO_WAIT(wait);
84	int res = 0;
85
86	if (use_otp_key)
87		paes_key[0] = DCP_PAES_KEY_OTP;
88	else
89		paes_key[0] = DCP_PAES_KEY_UNIQUE;
90
91	tfm = crypto_alloc_skcipher("ecb-paes-dcp", CRYPTO_ALG_INTERNAL,
92				    CRYPTO_ALG_INTERNAL);
93	if (IS_ERR(tfm)) {
94		res = PTR_ERR(tfm);
95		tfm = NULL;
96		goto out;
97	}
98
99	req = skcipher_request_alloc(tfm, GFP_NOFS);
100	if (!req) {
101		res = -ENOMEM;
102		goto out;
103	}
104
105	skcipher_request_set_callback(req, CRYPTO_TFM_REQ_MAY_BACKLOG |
106				      CRYPTO_TFM_REQ_MAY_SLEEP,
107				      crypto_req_done, &wait);
108	res = crypto_skcipher_setkey(tfm, paes_key, sizeof(paes_key));
109	if (res < 0)
110		goto out;
111
112	sg_init_one(&src_sg, in, AES_KEYSIZE_128);
113	sg_init_one(&dst_sg, out, AES_KEYSIZE_128);
114	skcipher_request_set_crypt(req, &src_sg, &dst_sg, AES_KEYSIZE_128,
115				   NULL);
116
117	if (do_encrypt)
118		res = crypto_wait_req(crypto_skcipher_encrypt(req), &wait);
119	else
120		res = crypto_wait_req(crypto_skcipher_decrypt(req), &wait);
121
122out:
123	skcipher_request_free(req);
124	crypto_free_skcipher(tfm);
125
126	return res;
127}
128
129static int do_aead_crypto(u8 *in, u8 *out, size_t len, u8 *key, u8 *nonce,
130			  bool do_encrypt)
131{
132	struct aead_request *aead_req = NULL;
133	struct scatterlist src_sg, dst_sg;
134	struct crypto_aead *aead;
135	int ret;
136
137	aead = crypto_alloc_aead("gcm(aes)", 0, CRYPTO_ALG_ASYNC);
138	if (IS_ERR(aead)) {
139		ret = PTR_ERR(aead);
140		goto out;
141	}
142
143	ret = crypto_aead_setauthsize(aead, DCP_BLOB_AUTHLEN);
144	if (ret < 0) {
145		pr_err("Can't set crypto auth tag len: %d\n", ret);
146		goto free_aead;
147	}
148
149	aead_req = aead_request_alloc(aead, GFP_KERNEL);
150	if (!aead_req) {
151		ret = -ENOMEM;
152		goto free_aead;
153	}
154
155	sg_init_one(&src_sg, in, len);
156	if (do_encrypt) {
157		/*
158		 * If we encrypt our buffer has extra space for the auth tag.
159		 */
160		sg_init_one(&dst_sg, out, len + DCP_BLOB_AUTHLEN);
161	} else {
162		sg_init_one(&dst_sg, out, len);
163	}
164
165	aead_request_set_crypt(aead_req, &src_sg, &dst_sg, len, nonce);
166	aead_request_set_callback(aead_req, CRYPTO_TFM_REQ_MAY_SLEEP, NULL,
167				  NULL);
168	aead_request_set_ad(aead_req, 0);
169
170	if (crypto_aead_setkey(aead, key, AES_KEYSIZE_128)) {
171		pr_err("Can't set crypto AEAD key\n");
172		ret = -EINVAL;
173		goto free_req;
174	}
175
176	if (do_encrypt)
177		ret = crypto_aead_encrypt(aead_req);
178	else
179		ret = crypto_aead_decrypt(aead_req);
180
181free_req:
182	aead_request_free(aead_req);
183free_aead:
184	crypto_free_aead(aead);
185out:
186	return ret;
187}
188
189static int decrypt_blob_key(u8 *key)
190{
191	return do_dcp_crypto(key, key, false);
192}
193
194static int encrypt_blob_key(u8 *key)
195{
196	return do_dcp_crypto(key, key, true);
197}
198
199static int trusted_dcp_seal(struct trusted_key_payload *p, char *datablob)
200{
201	struct dcp_blob_fmt *b = (struct dcp_blob_fmt *)p->blob;
202	int blen, ret;
203
204	blen = calc_blob_len(p->key_len);
205	if (blen > MAX_BLOB_SIZE)
206		return -E2BIG;
207
208	b->fmt_version = DCP_BLOB_VERSION;
209	get_random_bytes(b->nonce, AES_KEYSIZE_128);
210	get_random_bytes(b->blob_key, AES_KEYSIZE_128);
211
212	ret = do_aead_crypto(p->key, b->payload, p->key_len, b->blob_key,
213			     b->nonce, true);
214	if (ret) {
215		pr_err("Unable to encrypt blob payload: %i\n", ret);
216		return ret;
217	}
218
219	ret = encrypt_blob_key(b->blob_key);
220	if (ret) {
221		pr_err("Unable to encrypt blob key: %i\n", ret);
222		return ret;
223	}
224
225	b->payload_len = get_unaligned_le32(&p->key_len);
226	p->blob_len = blen;
227	return 0;
228}
229
230static int trusted_dcp_unseal(struct trusted_key_payload *p, char *datablob)
231{
232	struct dcp_blob_fmt *b = (struct dcp_blob_fmt *)p->blob;
233	int blen, ret;
234
235	if (b->fmt_version != DCP_BLOB_VERSION) {
236		pr_err("DCP blob has bad version: %i, expected %i\n",
237		       b->fmt_version, DCP_BLOB_VERSION);
238		ret = -EINVAL;
239		goto out;
240	}
241
242	p->key_len = le32_to_cpu(b->payload_len);
243	blen = calc_blob_len(p->key_len);
244	if (blen != p->blob_len) {
245		pr_err("DCP blob has bad length: %i != %i\n", blen,
246		       p->blob_len);
247		ret = -EINVAL;
248		goto out;
249	}
250
251	ret = decrypt_blob_key(b->blob_key);
252	if (ret) {
253		pr_err("Unable to decrypt blob key: %i\n", ret);
254		goto out;
255	}
256
257	ret = do_aead_crypto(b->payload, p->key, p->key_len + DCP_BLOB_AUTHLEN,
258			     b->blob_key, b->nonce, false);
259	if (ret) {
260		pr_err("Unwrap of DCP payload failed: %i\n", ret);
261		goto out;
262	}
263
264	ret = 0;
265out:
266	return ret;
267}
268
269static int test_for_zero_key(void)
270{
271	/*
272	 * Encrypting a plaintext of all 0x55 bytes will yield
273	 * this ciphertext in case the DCP test key is used.
274	 */
275	static const u8 bad[] = {0x9a, 0xda, 0xe0, 0x54, 0xf6, 0x3d, 0xfa, 0xff,
276				 0x5e, 0xa1, 0x8e, 0x45, 0xed, 0xf6, 0xea, 0x6f};
277	void *buf = NULL;
278	int ret = 0;
279
280	if (skip_zk_test)
281		goto out;
282
283	buf = kmalloc(AES_BLOCK_SIZE, GFP_KERNEL);
284	if (!buf) {
285		ret = -ENOMEM;
286		goto out;
287	}
288
289	memset(buf, 0x55, AES_BLOCK_SIZE);
290
291	ret = do_dcp_crypto(buf, buf, true);
292	if (ret)
293		goto out;
294
295	if (memcmp(buf, bad, AES_BLOCK_SIZE) == 0) {
296		pr_warn("Device neither in secure nor trusted mode!\n");
297		ret = -EINVAL;
298	}
299out:
300	kfree(buf);
301	return ret;
302}
303
304static int trusted_dcp_init(void)
305{
306	int ret;
307
308	if (use_otp_key)
309		pr_info("Using DCP OTP key\n");
310
311	ret = test_for_zero_key();
312	if (ret) {
313		pr_warn("Test for zero'ed keys failed: %i\n", ret);
314
315		return -EINVAL;
316	}
317
318	return register_key_type(&key_type_trusted);
319}
320
321static void trusted_dcp_exit(void)
322{
323	unregister_key_type(&key_type_trusted);
324}
325
326struct trusted_key_ops dcp_trusted_key_ops = {
327	.exit = trusted_dcp_exit,
328	.init = trusted_dcp_init,
329	.seal = trusted_dcp_seal,
330	.unseal = trusted_dcp_unseal,
331	.migratable = 0,
332};
333