Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1448901
| From | "Winkler, Tomas" <tomas.winkler@intel.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | RE: [PATCH v5 0/8] Replay Protected Memory Block (RPMB) subsystem |
| Date | 2016-07-23 09:50 +0200 |
| Message-ID | <rXZR7-6c-1@gated-at.bofh.it> (permalink) |
| References | <rWnkS-2Af-19@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
> > Few storage technologies such is EMMC, UFS, and NVMe support RPMB > hardware partition with common protocol and frame layout. > The RPMB partition cannot be accessed via standard block layer, but by a set > of specific commands: WRITE, READ, GET_WRITE_COUNTER, and > PROGRAM_KEY. > Such a partition provides authenticated and replay protected access, hence > suitable as a secure storage. > > The RPMB layer aims to provide in-kernel API for Trusted Execution > Environment (TEE) devices that are capable to securely compute block frame > signature. In case a TEE device wish to store a replay protected data, it > creates an RPMB frame with requested data and computes HMAC of the > frame, then it requests the storage device via RPMB layer to store the data. > A TEE driver can claim the RPMB interface, for example, via > class_interface_register (). > The layer provides two APIs, for rpmb_req_cmd() for issuing one of RPMB > specific commands and rpmb_seq_cmd() for issuing of raw RPMB protocol > frames, which is close to emmc multi ioctl interface. > > A storage device registers its RPMB hardware (eMMC) partition or RPMB W- > LUN (UFS) with the RPMB layer providing an implementation for > rpmb_seq_cmd() handler. The interface enables sending sequence of RPMB > standard frames. > > A parallel user space API is provided via /dev/rpmbX character device with > two IOCTL commands. > Simplified one, RPMB_IOC_REQ_CMD, were read result cycles is performed > by the framework on behalf the user and second, RPMB_IOC_SEQ_CMD > where the whole RPMB sequence, including RESULT_READ is supplied by the > caller. > The latter is intended for easier adjusting of the applications that use > MMC_IOC_MULTI_CMD ioctl, such as > https://android.googlesource.com/trusty/app/storage/ > > There is a also sample tool under tools/rpmb/ directory that exercises these > interfaces and a simulation device that implements the device part. > > Tomas Winkler (8): > rpmb: add Replay Protected Memory Block (RPMB) subsystem > char: rpmb: add sysfs-class ABI documentation > char: rpmb: add device attributes > char: rpmb: provide a user space interface > char: rpmb: add RPMB simulation device > tools rpmb: add RPBM access tool > mmc: block: register RPMB partition with the RPMB subsystem > scsi: ufs: connect to RPMB subsystem > I've got few off line request for git access of this code, so here si the repo https://github.com/tomasbw/linux-mei.git branch rpmb. The branch is rebasing one over linux master branch Thanks and will appreciate any public review. Tomas
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
[PATCH v5 0/8] Replay Protected Memory Block (RPMB) subsystem Tomas Winkler <tomas.winkler@intel.com> - 2016-07-18 22:30 +0200
[PATCH v5 3/8] char: rpmb: add device attributes Tomas Winkler <tomas.winkler@intel.com> - 2016-07-18 22:30 +0200
[PATCH v5 4/8] char: rpmb: provide a user space interface Tomas Winkler <tomas.winkler@intel.com> - 2016-07-18 22:30 +0200
Re: [PATCH v5 4/8] char: rpmb: provide a user space interface Paul Gortmaker <paul.gortmaker@windriver.com> - 2016-07-19 00:20 +0200
RE: [PATCH v5 4/8] char: rpmb: provide a user space interface "Winkler, Tomas" <tomas.winkler@intel.com> - 2016-07-20 11:10 +0200
Re: [PATCH v5 4/8] char: rpmb: provide a user space interface Paul Gortmaker <paul.gortmaker@windriver.com> - 2016-07-20 16:30 +0200
[PATCH v5 5/8] char: rpmb: add RPMB simulation device Tomas Winkler <tomas.winkler@intel.com> - 2016-07-18 22:40 +0200
[PATCH v5 8/8] scsi: ufs: connect to RPMB subsystem Tomas Winkler <tomas.winkler@intel.com> - 2016-07-18 22:40 +0200
[PATCH v5 6/8] tools rpmb: add RPBM access tool Tomas Winkler <tomas.winkler@intel.com> - 2016-07-18 22:40 +0200
[PATCH v5 7/8] mmc: block: register RPMB partition with the RPMB subsystem Tomas Winkler <tomas.winkler@intel.com> - 2016-07-18 22:40 +0200
RE: [PATCH v5 0/8] Replay Protected Memory Block (RPMB) subsystem "Winkler, Tomas" <tomas.winkler@intel.com> - 2016-07-23 09:50 +0200
csiph-web