mirror of
https://github.com/torvalds/linux.git
synced 2024-12-10 21:21:54 +00:00
e9c5048c2d
The Cryptographic Acceleration and Assurance Module (CAAM) is an IP core built into many newer i.MX and QorIQ SoCs by NXP. The CAAM does crypto acceleration, hardware number generation and has a blob mechanism for encapsulation/decapsulation of sensitive material. This blob mechanism depends on a device specific random 256-bit One Time Programmable Master Key that is fused in each SoC at manufacturing time. This key is unreadable and can only be used by the CAAM for AES encryption/decryption of user data. This makes it a suitable backend (source) for kernel trusted keys. Previous commits generalized trusted keys to support multiple backends and added an API to access the CAAM blob mechanism. Based on these, provide the necessary glue to use the CAAM for trusted keys. Reviewed-by: David Gstir <david@sigma-star.at> Reviewed-by: Pankaj Gupta <pankaj.gupta@nxp.com> Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org> Tested-by: Tim Harvey <tharvey@gateworks.com> Tested-by: Matthias Schiffer <matthias.schiffer@ew.tq-group.com> Tested-by: Pankaj Gupta <pankaj.gupta@nxp.com> Tested-by: Michael Walle <michael@walle.cc> # on ls1028a (non-E and E) Tested-by: John Ernberg <john.ernberg@actia.se> # iMX8QXP Signed-off-by: Ahmad Fatoum <a.fatoum@pengutronix.de> Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
39 lines
1.0 KiB
Plaintext
39 lines
1.0 KiB
Plaintext
config TRUSTED_KEYS_TPM
|
|
bool "TPM-based trusted keys"
|
|
depends on TCG_TPM >= TRUSTED_KEYS
|
|
default y
|
|
select CRYPTO
|
|
select CRYPTO_HMAC
|
|
select CRYPTO_SHA1
|
|
select CRYPTO_HASH_INFO
|
|
select ASN1_ENCODER
|
|
select OID_REGISTRY
|
|
select ASN1
|
|
help
|
|
Enable use of the Trusted Platform Module (TPM) as trusted key
|
|
backend. Trusted keys are random number symmetric keys,
|
|
which will be generated and RSA-sealed by the TPM.
|
|
The TPM only unseals the keys, if the boot PCRs and other
|
|
criteria match.
|
|
|
|
config TRUSTED_KEYS_TEE
|
|
bool "TEE-based trusted keys"
|
|
depends on TEE >= TRUSTED_KEYS
|
|
default y
|
|
help
|
|
Enable use of the Trusted Execution Environment (TEE) as trusted
|
|
key backend.
|
|
|
|
config TRUSTED_KEYS_CAAM
|
|
bool "CAAM-based trusted keys"
|
|
depends on CRYPTO_DEV_FSL_CAAM_JR >= TRUSTED_KEYS
|
|
select CRYPTO_DEV_FSL_CAAM_BLOB_GEN
|
|
default y
|
|
help
|
|
Enable use of NXP's Cryptographic Accelerator and Assurance Module
|
|
(CAAM) as trusted key backend.
|
|
|
|
if !TRUSTED_KEYS_TPM && !TRUSTED_KEYS_TEE && !TRUSTED_KEYS_CAAM
|
|
comment "No trust source selected!"
|
|
endif
|