mirror of
https://github.com/apache/nuttx.git
synced 2026-09-29 10:34:23 +00:00
The EdgeLock Enclave offers a key store the mailbox driver did not reach. A key generated in there is permitted one algorithm and one usage, and export can be withheld, so the private half has no command that returns it. Adds the session, key store and key management services, key generation, signing by handle, and the storage exchange that makes a key store outlive a boot. Storage runs the other way round from every other command: the enclave asks the host to write its key store down and to give it back, and those requests arrive while a command of this side's is still outstanding, so the reply tag is what tells them apart. Two things a port has to know and neither reference nor header says. Key store commands carry a trailing crc, the exclusive or of every word including the header, without which the enclave answers rating 0xb9. And a persistent key lifetime is a statement of intent: the strict flag on key generation is what writes the key to the store, and without it a store exported around the key comes back without it. Every mailbox wait is bounded. An enclave that stops answering must not take the calling thread with it, and a reply buffer is a kilobyte, which does not belong on the stack of whatever task asked for a signature. Tested on an i.MX93: a P-256 key generated in the enclave, signing a digest whose signature verifies against the returned public half on a host, and still doing so after the board has been powered off. Signed-off-by: Royyan Zahir <royzah@gmail.com> |
||
|---|---|---|
| .. | ||
| arm | ||
| arm64 | ||
| avr | ||
| ceva | ||
| dummy | ||
| hc | ||
| mips | ||
| misoc | ||
| or1k | ||
| renesas | ||
| risc-v | ||
| sim | ||
| sparc | ||
| tricore | ||
| x86 | ||
| x86_64 | ||
| xtensa | ||
| z16 | ||
| z80 | ||
| CMakeLists.txt | ||
| Kconfig | ||