]> git.dujemihanovic.xyz Git - u-boot.git/commitdiff
lib: ecdsa: Add ECDSA384 support
authorChia-Wei Wang <chiawei_wang@aspeedtech.com>
Mon, 14 Oct 2024 09:56:18 +0000 (17:56 +0800)
committerTom Rini <trini@konsulko.com>
Mon, 21 Oct 2024 23:52:52 +0000 (17:52 -0600)
Add ECDSA384 algorithm support for image signing and verification.

Signed-off-by: Chia-Wei Wang <chiawei_wang@aspeedtech.com>
Reviewed-by: Simon Glass <sjg@chromium.org>
include/u-boot/ecdsa.h
lib/ecdsa/ecdsa-verify.c
tools/image-sig-host.c

index 8f9f5e7d6e7c8df6dc3aefd8ea89905852cadf6e..f0ac0f327e9b0a39037e9caac9669063a73052a2 100644 (file)
@@ -65,6 +65,7 @@ int ecdsa_verify(struct image_sign_info *info,
 /** @} */
 
 #define ECDSA256_BYTES (256 / 8)
+#define ECDSA384_BYTES (384 / 8)
 #define ECDSA521_BYTES ((521 + 7) / 8)
 
 #endif
index 4d1835b598afc304ebe4e5ff7f7cef6d87b18622..629b662cf6ca861416b54e8d89b1d472c335a34b 100644 (file)
@@ -22,8 +22,10 @@ static int ecdsa_key_size(const char *curve_name)
 {
        if (!strcmp(curve_name, "prime256v1"))
                return 256;
-       else
-               return 0;
+       else if (!strcmp(curve_name, "secp384r1"))
+               return 384;
+
+       return 0;
 }
 
 static int fdt_get_key(struct ecdsa_public_key *key, const void *fdt, int node)
@@ -121,12 +123,18 @@ int ecdsa_verify(struct image_sign_info *info,
        return ecdsa_verify_hash(dev, info, hash, sig, sig_len);
 }
 
-U_BOOT_CRYPTO_ALGO(ecdsa) = {
+U_BOOT_CRYPTO_ALGO(ecdsa256) = {
        .name = "ecdsa256",
        .key_len = ECDSA256_BYTES,
        .verify = ecdsa_verify,
 };
 
+U_BOOT_CRYPTO_ALGO(ecdsa384) = {
+       .name = "ecdsa384",
+       .key_len = ECDSA384_BYTES,
+       .verify = ecdsa_verify,
+};
+
 /*
  * uclass definition for ECDSA API
  *
index 21b4fa5d39df5775061b2b697dc8f0ef7d1f9824..5285263c61634ac93e88796ecd6fad818c764e51 100644 (file)
@@ -76,6 +76,13 @@ struct crypto_algo crypto_algos[] = {
                .add_verify_data = ecdsa_add_verify_data,
                .verify = ecdsa_verify,
        },
+       {
+               .name = "ecdsa384",
+               .key_len = ECDSA384_BYTES,
+               .sign = ecdsa_sign,
+               .add_verify_data = ecdsa_add_verify_data,
+               .verify = ecdsa_verify,
+       },
        {
                .name = "secp521r1",
                .key_len = ECDSA521_BYTES,