rpmb.c 7.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324
  1. /*
  2. * Copyright 2014, Staubli Faverges
  3. * Pierre Aubert
  4. *
  5. * eMMC- Replay Protected Memory Block
  6. * According to JEDEC Standard No. 84-A441
  7. *
  8. * SPDX-License-Identifier: GPL-2.0+
  9. */
  10. #include <config.h>
  11. #include <common.h>
  12. #include <memalign.h>
  13. #include <mmc.h>
  14. #include <u-boot/sha256.h>
  15. #include "mmc_private.h"
  16. /* Request codes */
  17. #define RPMB_REQ_KEY 1
  18. #define RPMB_REQ_WCOUNTER 2
  19. #define RPMB_REQ_WRITE_DATA 3
  20. #define RPMB_REQ_READ_DATA 4
  21. #define RPMB_REQ_STATUS 5
  22. /* Response code */
  23. #define RPMB_RESP_KEY 0x0100
  24. #define RPMB_RESP_WCOUNTER 0x0200
  25. #define RPMB_RESP_WRITE_DATA 0x0300
  26. #define RPMB_RESP_READ_DATA 0x0400
  27. /* Error codes */
  28. #define RPMB_OK 0
  29. #define RPMB_ERR_GENERAL 1
  30. #define RPMB_ERR_AUTH 2
  31. #define RPMB_ERR_COUNTER 3
  32. #define RPMB_ERR_ADDRESS 4
  33. #define RPMB_ERR_WRITE 5
  34. #define RPMB_ERR_READ 6
  35. #define RPMB_ERR_KEY 7
  36. #define RPMB_ERR_CNT_EXPIRED 0x80
  37. #define RPMB_ERR_MSK 0x7
  38. /* Sizes of RPMB data frame */
  39. #define RPMB_SZ_STUFF 196
  40. #define RPMB_SZ_MAC 32
  41. #define RPMB_SZ_DATA 256
  42. #define RPMB_SZ_NONCE 16
  43. #define SHA256_BLOCK_SIZE 64
  44. /* Error messages */
  45. static const char * const rpmb_err_msg[] = {
  46. "",
  47. "General failure",
  48. "Authentication failure",
  49. "Counter failure",
  50. "Address failure",
  51. "Write failure",
  52. "Read failure",
  53. "Authentication key not yet programmed",
  54. };
  55. /* Structure of RPMB data frame. */
  56. struct s_rpmb {
  57. unsigned char stuff[RPMB_SZ_STUFF];
  58. unsigned char mac[RPMB_SZ_MAC];
  59. unsigned char data[RPMB_SZ_DATA];
  60. unsigned char nonce[RPMB_SZ_NONCE];
  61. unsigned long write_counter;
  62. unsigned short address;
  63. unsigned short block_count;
  64. unsigned short result;
  65. unsigned short request;
  66. };
  67. static int mmc_set_blockcount(struct mmc *mmc, unsigned int blockcount,
  68. bool is_rel_write)
  69. {
  70. struct mmc_cmd cmd = {0};
  71. cmd.cmdidx = MMC_CMD_SET_BLOCK_COUNT;
  72. cmd.cmdarg = blockcount & 0x0000FFFF;
  73. if (is_rel_write)
  74. cmd.cmdarg |= 1 << 31;
  75. cmd.resp_type = MMC_RSP_R1;
  76. return mmc_send_cmd(mmc, &cmd, NULL);
  77. }
  78. static int mmc_rpmb_request(struct mmc *mmc, const struct s_rpmb *s,
  79. unsigned int count, bool is_rel_write)
  80. {
  81. struct mmc_cmd cmd = {0};
  82. struct mmc_data data;
  83. int ret;
  84. ret = mmc_set_blockcount(mmc, count, is_rel_write);
  85. if (ret) {
  86. #ifdef CONFIG_MMC_RPMB_TRACE
  87. printf("%s:mmc_set_blockcount-> %d\n", __func__, ret);
  88. #endif
  89. return 1;
  90. }
  91. cmd.cmdidx = MMC_CMD_WRITE_MULTIPLE_BLOCK;
  92. cmd.cmdarg = 0;
  93. cmd.resp_type = MMC_RSP_R1b;
  94. data.src = (const char *)s;
  95. data.blocks = 1;
  96. data.blocksize = MMC_MAX_BLOCK_LEN;
  97. data.flags = MMC_DATA_WRITE;
  98. ret = mmc_send_cmd(mmc, &cmd, &data);
  99. if (ret) {
  100. #ifdef CONFIG_MMC_RPMB_TRACE
  101. printf("%s:mmc_send_cmd-> %d\n", __func__, ret);
  102. #endif
  103. return 1;
  104. }
  105. return 0;
  106. }
  107. static int mmc_rpmb_response(struct mmc *mmc, struct s_rpmb *s,
  108. unsigned short expected)
  109. {
  110. struct mmc_cmd cmd = {0};
  111. struct mmc_data data;
  112. int ret;
  113. ret = mmc_set_blockcount(mmc, 1, false);
  114. if (ret) {
  115. #ifdef CONFIG_MMC_RPMB_TRACE
  116. printf("%s:mmc_set_blockcount-> %d\n", __func__, ret);
  117. #endif
  118. return -1;
  119. }
  120. cmd.cmdidx = MMC_CMD_READ_MULTIPLE_BLOCK;
  121. cmd.cmdarg = 0;
  122. cmd.resp_type = MMC_RSP_R1;
  123. data.dest = (char *)s;
  124. data.blocks = 1;
  125. data.blocksize = MMC_MAX_BLOCK_LEN;
  126. data.flags = MMC_DATA_READ;
  127. ret = mmc_send_cmd(mmc, &cmd, &data);
  128. if (ret) {
  129. #ifdef CONFIG_MMC_RPMB_TRACE
  130. printf("%s:mmc_send_cmd-> %d\n", __func__, ret);
  131. #endif
  132. return -1;
  133. }
  134. /* Check the response and the status */
  135. if (be16_to_cpu(s->request) != expected) {
  136. #ifdef CONFIG_MMC_RPMB_TRACE
  137. printf("%s:response= %x\n", __func__,
  138. be16_to_cpu(s->request));
  139. #endif
  140. return -1;
  141. }
  142. ret = be16_to_cpu(s->result);
  143. if (ret) {
  144. printf("%s %s\n", rpmb_err_msg[ret & RPMB_ERR_MSK],
  145. (ret & RPMB_ERR_CNT_EXPIRED) ?
  146. "Write counter has expired" : "");
  147. }
  148. /* Return the status of the command */
  149. return ret;
  150. }
  151. static int mmc_rpmb_status(struct mmc *mmc, unsigned short expected)
  152. {
  153. ALLOC_CACHE_ALIGN_BUFFER(struct s_rpmb, rpmb_frame, 1);
  154. memset(rpmb_frame, 0, sizeof(struct s_rpmb));
  155. rpmb_frame->request = cpu_to_be16(RPMB_REQ_STATUS);
  156. if (mmc_rpmb_request(mmc, rpmb_frame, 1, false))
  157. return -1;
  158. /* Read the result */
  159. return mmc_rpmb_response(mmc, rpmb_frame, expected);
  160. }
  161. static void rpmb_hmac(unsigned char *key, unsigned char *buff, int len,
  162. unsigned char *output)
  163. {
  164. sha256_context ctx;
  165. int i;
  166. unsigned char k_ipad[SHA256_BLOCK_SIZE];
  167. unsigned char k_opad[SHA256_BLOCK_SIZE];
  168. sha256_starts(&ctx);
  169. /* According to RFC 4634, the HMAC transform looks like:
  170. SHA(K XOR opad, SHA(K XOR ipad, text))
  171. where K is an n byte key.
  172. ipad is the byte 0x36 repeated blocksize times
  173. opad is the byte 0x5c repeated blocksize times
  174. and text is the data being protected.
  175. */
  176. for (i = 0; i < RPMB_SZ_MAC; i++) {
  177. k_ipad[i] = key[i] ^ 0x36;
  178. k_opad[i] = key[i] ^ 0x5c;
  179. }
  180. /* remaining pad bytes are '\0' XOR'd with ipad and opad values */
  181. for ( ; i < SHA256_BLOCK_SIZE; i++) {
  182. k_ipad[i] = 0x36;
  183. k_opad[i] = 0x5c;
  184. }
  185. sha256_update(&ctx, k_ipad, SHA256_BLOCK_SIZE);
  186. sha256_update(&ctx, buff, len);
  187. sha256_finish(&ctx, output);
  188. /* Init context for second pass */
  189. sha256_starts(&ctx);
  190. /* start with outer pad */
  191. sha256_update(&ctx, k_opad, SHA256_BLOCK_SIZE);
  192. /* then results of 1st hash */
  193. sha256_update(&ctx, output, RPMB_SZ_MAC);
  194. /* finish up 2nd pass */
  195. sha256_finish(&ctx, output);
  196. }
  197. int mmc_rpmb_get_counter(struct mmc *mmc, unsigned long *pcounter)
  198. {
  199. int ret;
  200. ALLOC_CACHE_ALIGN_BUFFER(struct s_rpmb, rpmb_frame, 1);
  201. /* Fill the request */
  202. memset(rpmb_frame, 0, sizeof(struct s_rpmb));
  203. rpmb_frame->request = cpu_to_be16(RPMB_REQ_WCOUNTER);
  204. if (mmc_rpmb_request(mmc, rpmb_frame, 1, false))
  205. return -1;
  206. /* Read the result */
  207. ret = mmc_rpmb_response(mmc, rpmb_frame, RPMB_RESP_WCOUNTER);
  208. if (ret)
  209. return ret;
  210. *pcounter = be32_to_cpu(rpmb_frame->write_counter);
  211. return 0;
  212. }
  213. int mmc_rpmb_set_key(struct mmc *mmc, void *key)
  214. {
  215. ALLOC_CACHE_ALIGN_BUFFER(struct s_rpmb, rpmb_frame, 1);
  216. /* Fill the request */
  217. memset(rpmb_frame, 0, sizeof(struct s_rpmb));
  218. rpmb_frame->request = cpu_to_be16(RPMB_REQ_KEY);
  219. memcpy(rpmb_frame->mac, key, RPMB_SZ_MAC);
  220. if (mmc_rpmb_request(mmc, rpmb_frame, 1, true))
  221. return -1;
  222. /* read the operation status */
  223. return mmc_rpmb_status(mmc, RPMB_RESP_KEY);
  224. }
  225. int mmc_rpmb_read(struct mmc *mmc, void *addr, unsigned short blk,
  226. unsigned short cnt, unsigned char *key)
  227. {
  228. ALLOC_CACHE_ALIGN_BUFFER(struct s_rpmb, rpmb_frame, 1);
  229. int i;
  230. for (i = 0; i < cnt; i++) {
  231. /* Fill the request */
  232. memset(rpmb_frame, 0, sizeof(struct s_rpmb));
  233. rpmb_frame->address = cpu_to_be16(blk + i);
  234. rpmb_frame->request = cpu_to_be16(RPMB_REQ_READ_DATA);
  235. if (mmc_rpmb_request(mmc, rpmb_frame, 1, false))
  236. break;
  237. /* Read the result */
  238. if (mmc_rpmb_response(mmc, rpmb_frame, RPMB_RESP_READ_DATA))
  239. break;
  240. /* Check the HMAC if key is provided */
  241. if (key) {
  242. unsigned char ret_hmac[RPMB_SZ_MAC];
  243. rpmb_hmac(key, rpmb_frame->data, 284, ret_hmac);
  244. if (memcmp(ret_hmac, rpmb_frame->mac, RPMB_SZ_MAC)) {
  245. printf("MAC error on block #%d\n", i);
  246. break;
  247. }
  248. }
  249. /* Copy data */
  250. memcpy(addr + i * RPMB_SZ_DATA, rpmb_frame->data, RPMB_SZ_DATA);
  251. }
  252. return i;
  253. }
  254. int mmc_rpmb_write(struct mmc *mmc, void *addr, unsigned short blk,
  255. unsigned short cnt, unsigned char *key)
  256. {
  257. ALLOC_CACHE_ALIGN_BUFFER(struct s_rpmb, rpmb_frame, 1);
  258. unsigned long wcount;
  259. int i;
  260. for (i = 0; i < cnt; i++) {
  261. if (mmc_rpmb_get_counter(mmc, &wcount)) {
  262. printf("Cannot read RPMB write counter\n");
  263. break;
  264. }
  265. /* Fill the request */
  266. memset(rpmb_frame, 0, sizeof(struct s_rpmb));
  267. memcpy(rpmb_frame->data, addr + i * RPMB_SZ_DATA, RPMB_SZ_DATA);
  268. rpmb_frame->address = cpu_to_be16(blk + i);
  269. rpmb_frame->block_count = cpu_to_be16(1);
  270. rpmb_frame->write_counter = cpu_to_be32(wcount);
  271. rpmb_frame->request = cpu_to_be16(RPMB_REQ_WRITE_DATA);
  272. /* Computes HMAC */
  273. rpmb_hmac(key, rpmb_frame->data, 284, rpmb_frame->mac);
  274. if (mmc_rpmb_request(mmc, rpmb_frame, 1, true))
  275. break;
  276. /* Get status */
  277. if (mmc_rpmb_status(mmc, RPMB_RESP_WRITE_DATA))
  278. break;
  279. }
  280. return i;
  281. }