This thread has been locked.

If you have a related question, please click the "Ask a related question" button in the top right corner. The newly created question will be automatically linked to this question.

DRA821U: Encryption and decryption from runtime on DRA821

Part Number: DRA821U

Hello

I've got a question regarding capabilities and available tools for encrypting (or blobing) and decrytping arbitrary "files" from runtime.

To give some more context, let's imagine the following scenario:

  • My Linux OS receives an update containg a new fitImage (with Linux kernel, focus on fitImage with Linux kernel, let's forget abotu tispl for now)
  • Linux uses "special Linux tool*" that will encrypt the new fitImage with hardware bound key (or any key saved in secure storage during the provisioning)
  • Reboot
  • U-BOOT (let's assume U-boot proper after SPL, so already running on Cortex-A) - before loading fitImage, uses a "special U-BOOT tool*" to decrypt (deblob) fitImage 
  • U-BOOT loades fitImage

By:

  • "special Linux tool" - I mean any Linux tool/app/whatever that performs encryption/decryption operation using either hardware-bound key (or programmed by user) in a secure way, e.g. utilizing SoC specific mechanims / DMSC /  OPTEE / whatever 
  • "special U-BOOT tool" - I mean any U-BOOT api / shell command (e.g. I can imagine some shell command like ti_encrypt/ti_decrypt) that is capable of encrypting / decrypting arbitrary payload utilizing SoC specific mechanims / DMSC /  OPTEE / whatever

I would be greateful if you could suggest if you provide anything like this, or perhaps you suggest any other solution that would allow me to achieve what I described above.

 

  • Hi PB,

    While TI doesn't provide an out-of-the-box solution for runtime fitImage encryption/decryption, we can definitely guide you through a approach using  OP-TEE + TIFS.

    Linux encrypting image:

    1. Create an OP-TEE user-space application in Linux that:
      1.  Communicates with a Trusted Application (TA) running in the secure world
      2.  Sends the fitImage data to the TA for encryption
    2. The Trusted Application handles encryption using hardware-bound keys:
      1. DKEK (Derived Key Encryption Key) - derived from the device's unique encryption )
      2. DSMEK (Derived Secondary Encryption Key) - an alternative hardware-bound key
    3. Store the encrypted fitImage to your boot media (eMMC, SD card, etc.)

    Uboot Decrypting image: 

    1. At this stage, OP-TEE is already running (loaded during the boot flow as part of tispl.bin)
    2. U-Boot makes an SMC (Secure Monitor Call) to the Trusted Application:
      1. Passes the encrypted fitImage location
      2. TA decrypts it using the same DKEK/DSMEK key
      3. Decrypted image is returned to U-Boot

    Reference

    Regards
    Diwakar