RE: [RFC v2 2/4] fpga: Add new property to support user-key encrypted bitstream loading
From: Nava kishore Manne <hidden>
Date: 2021-07-09 08:49:04
Also in:
linux-arm-kernel, linux-fpga, lkml
Hi Greg, Thanks for providing the review comments. Please find my response inline.
-----Original Message----- From: Greg KH <gregkh@linuxfoundation.org> Sent: Wednesday, June 9, 2021 3:26 PM To: Nava kishore Manne <redacted> Cc: robh+dt@kernel.org; Michal Simek <redacted>; mdf@kernel.org; trix@redhat.com; arnd@arndb.de; Rajan Vaja [off-list ref]; Amit Sunil Dhamne [off-list ref]; Tejas Patel [off-list ref]; zou_wei@huawei.com; Sai Krishna Potthuri [off-list ref]; Ravi Patel [off-list ref]; iwamatsu@nigauri.org; Jiaying Liang [off-list ref]; devicetree@vger.kernel.org; linux-arm-kernel@lists.infradead.org; linux- kernel@vger.kernel.org; linux-fpga@vger.kernel.org; git [off-list ref]; chinnikishore369@gmail.com Subject: Re: [RFC v2 2/4] fpga: Add new property to support user-key encrypted bitstream loading On Wed, Jun 09, 2021 at 11:22:30AM +0530, Nava kishore Manne wrote:quoted
This patch Adds ‘encrypted-key-name’ property to support user-key encrypted bitstream loading use case. Signed-off-by: Nava kishore Manne <redacted> --- Changes for v2: -Both DT properties ie; encrypted-key-name and encrypted-user-key-fpga-configquoted
are targeted to use for the same use cases but ideally encrypted-key-namequoted
is enough to serve the purpose so updated the file to remove theunwantedquoted
encrypted-user-key-fpga-config property as suggested by Rob. Documentation/devicetree/bindings/fpga/fpga-region.txt | 3 +++ 1 file changed, 3 insertions(+)diff --git a/Documentation/devicetree/bindings/fpga/fpga-region.txtb/Documentation/devicetree/bindings/fpga/fpga-region.txt index d787d57491a1..0de4a1c54650 100644--- a/Documentation/devicetree/bindings/fpga/fpga-region.txt +++ b/Documentation/devicetree/bindings/fpga/fpga-region.txt@@ -177,6 +177,9 @@ Optional properties: it indicates that the FPGA has already been programmed with thisimage.quoted
If this property is in an overlay targeting a FPGA region, it is a request to program the FPGA with that image. +- encrypted-key-name : should contain the name of an encrypted key filelocatedquoted
+ on the firmware search path. It will be used to decrypt the FPGAimagequoted
+ file with user-key.What is the format this "user-key" is in? Where is the documentation for how to use this type of thing?
Will fix user key format issues in v3.
Will update this binding doc with user key encrypted bitstream loading use case info.
Use case info:
Reconfiguration with encrypted image using AES key
In this case, the FPGA Manager will decrypt the configuration data and
placed it into the programmable logic. To decrypt the configuration data
it uses AES key provided by the user.
DT Overlay contains:
/dts-v1/;
/plugin/;
&fpga_region0 {
#address-cells = <1>;
#size-cells = <1>;
firmware-name = "versal-gpio.bin";
encrypted-key-name = “Aes-key.nky”
gpio1: gpio@40000000 {
compatible = "xlnx,xps-gpio-1.00.a";
reg = <0x40000000 0x10000>;
gpio-controller;
#gpio-cells = <0x2>;
xlnx,gpio-width= <0x6>;
};
};
Regards,
Navakishore.