On 9/1/26 10:52, Jamin Lin wrote:
> This series depends on:
>
> 1. [v4,0/4] Add ASPEED ACRY RSA model for the AST2600
> https://patchwork.kernel.org/project/qemu-devel/cover/20260901081531.898176-1-jamin_lin@aspeedtech.com/
>
> This series adds ECDSA to the QEMU crypto akcipher framework and models the
> ASPEED AST10x0 secure boot controller (SBC) ECDSA engine on top of it.
>
> The crypto side adds ECDSA sign/verify for prime256v1 (NIST P-256) and
> secp384r1 (NIST P-384) in both the gcrypt and nettle backends, using the raw
> big-endian form (public key Qx || Qy, private key scalar d, signature r || s)
> with a pre-computed digest as input.
>
> Both the AST2600 and the AST1030/AST1060 have a Secure Boot Controller (SBC)
> that supports RSA and ECDSA verification, but only the AST1030/AST1060 have an
> ECDSA verify engine, so this series models ECDSA only. RSA verification is used
> solely to verify the AST2600 SPL in ROM CODE, which ASPEED does not release,
> so it is very unlikely to be used by end users.
>
> v1:
> 1. Add ECDSA akcipher support with gcrypt backend
> 2. Add ECDSA akcipher support with nettle backend
> 3. Add ECDSA sign/verify unit tests
> 4. Support the ECDSA verify command for AST10x0
> 5. Add ASPEED SBC ECDSA engine qtest
>
> v2:
> 1. Wrap the SEC SRAM in a container mapped at offset 0 so the device
> addresses it by relative offset (drop the "sram-base" property)
> 2. Add a patch removing the obsolete unimplemented SBC mapping
> 3. Add Qtest to ast1060-evb machine.
> 4. Rename R_ECDSA_CMD to R_SEC_TRIGGER, since the register
> triggers both the RSA and ECDSA engines.
>
> v3:
> 1. fix typo
> 2. Replace g_printerr with g_test_skip
>
> v4:
> 1. Reorder the patches to fix a QEMU startup failure at an intermediate commit.
> 2. Add public key type validation for ECDSA verification.
> 3. Add private key type validation for ECDSA signing.
> 4. Remove sbc_unimplemented from AspeedSoCState
> 5. Update the commit messages.
>
> Jamin Lin (9):
> qapi/crypto: Add ECDSA algorithm and curve id
> crypto/akcipher: Support ECDSA sign/verify with gcrypt
> crypto/akcipher: Support ECDSA sign/verify with nettle
> tests/crypto: Add ECDSA sign/verify tests
> hw/arm/aspeed_ast10x0: Remove obsolete unimplemented SBC mapping
> hw/misc/aspeed_sbc: Increase register space to 0x1000
> hw/arm/aspeed_ast10x0: Wire SEC SRAM to the SBC model
> hw/misc/aspeed_sbc: Support the ECDSA verify command
> tests/qtest: Add ASPEED SBC ECDSA engine test
>
> qapi/crypto.json | 33 ++-
> include/hw/arm/aspeed_soc.h | 1 -
> include/hw/misc/aspeed_sbc.h | 6 +-
> hw/arm/aspeed_ast10x0.c | 14 +-
> hw/misc/aspeed_sbc.c | 158 +++++++++++++-
> tests/qtest/aspeed-sbc-test.c | 194 +++++++++++++++++
> tests/unit/test-crypto-akcipher.c | 236 +++++++++++++++++++++
> crypto/akcipher-gcrypt.c.inc | 340 +++++++++++++++++++++++++++++-
> crypto/akcipher-nettle.c.inc | 272 ++++++++++++++++++++++++
> hw/misc/trace-events | 2 +
> tests/qtest/meson.build | 2 +
> 11 files changed, 1242 insertions(+), 16 deletions(-)
> create mode 100644 tests/qtest/aspeed-sbc-test.c
>
Applied to
https://github.com/legoater/qemu aspeed-next
Thanks,
C.