tbbr_cot.c 17.5 KB
Newer Older
Juan Castillo's avatar
Juan Castillo committed
1
/*
2
 * Copyright (c) 2015-2018, ARM Limited and Contributors. All rights reserved.
Juan Castillo's avatar
Juan Castillo committed
3
 *
dp-arm's avatar
dp-arm committed
4
 * SPDX-License-Identifier: BSD-3-Clause
Juan Castillo's avatar
Juan Castillo committed
5
6
 */

Isla Mitchell's avatar
Isla Mitchell committed
7
8
#include <stddef.h>

9
10
11
#include <platform_def.h>

#include <drivers/auth/auth_mod.h>
12
#if USE_TBBR_DEFS
13
#include <tools_share/tbbr_oid.h>
14
#else
Juan Castillo's avatar
Juan Castillo committed
15
#include <platform_oid.h>
16
#endif
Isla Mitchell's avatar
Isla Mitchell committed
17

Juan Castillo's avatar
Juan Castillo committed
18
19
20
21
22

/*
 * Maximum key and hash sizes (in DER format)
 */
#define PK_DER_LEN			294
23
#define HASH_DER_LEN			83
Juan Castillo's avatar
Juan Castillo committed
24
25
26
27
28
29

/*
 * The platform must allocate buffers to store the authentication parameters
 * extracted from the certificates. In this case, because of the way the CoT is
 * established, we can reuse some of the buffers on different stages
 */
30
static unsigned char tb_fw_hash_buf[HASH_DER_LEN];
31
32
static unsigned char tb_fw_config_hash_buf[HASH_DER_LEN];
static unsigned char hw_config_hash_buf[HASH_DER_LEN];
33
34
35
static unsigned char scp_fw_hash_buf[HASH_DER_LEN];
static unsigned char soc_fw_hash_buf[HASH_DER_LEN];
static unsigned char tos_fw_hash_buf[HASH_DER_LEN];
36
37
static unsigned char tos_fw_extra1_hash_buf[HASH_DER_LEN];
static unsigned char tos_fw_extra2_hash_buf[HASH_DER_LEN];
38
39
40
41
static unsigned char nt_world_bl_hash_buf[HASH_DER_LEN];
static unsigned char trusted_world_pk_buf[PK_DER_LEN];
static unsigned char non_trusted_world_pk_buf[PK_DER_LEN];
static unsigned char content_pk_buf[PK_DER_LEN];
42
43
44
static unsigned char soc_fw_config_hash_buf[HASH_DER_LEN];
static unsigned char tos_fw_config_hash_buf[HASH_DER_LEN];
static unsigned char nt_fw_config_hash_buf[HASH_DER_LEN];
Juan Castillo's avatar
Juan Castillo committed
45
46
47
48

/*
 * Parameter type descriptors
 */
49
50
51
52
53
static auth_param_type_desc_t trusted_nv_ctr = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_NV_CTR, TRUSTED_FW_NVCOUNTER_OID);
static auth_param_type_desc_t non_trusted_nv_ctr = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_NV_CTR, NON_TRUSTED_FW_NVCOUNTER_OID);

Juan Castillo's avatar
Juan Castillo committed
54
55
56
57
58
59
60
61
62
static auth_param_type_desc_t subject_pk = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_PUB_KEY, 0);
static auth_param_type_desc_t sig = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_SIG, 0);
static auth_param_type_desc_t sig_alg = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_SIG_ALG, 0);
static auth_param_type_desc_t raw_data = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_RAW_DATA, 0);

63
64
65
66
static auth_param_type_desc_t trusted_world_pk = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_PUB_KEY, TRUSTED_WORLD_PK_OID);
static auth_param_type_desc_t non_trusted_world_pk = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_PUB_KEY, NON_TRUSTED_WORLD_PK_OID);
Juan Castillo's avatar
Juan Castillo committed
67

68
69
70
71
72
73
74
75
static auth_param_type_desc_t scp_fw_content_pk = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_PUB_KEY, SCP_FW_CONTENT_CERT_PK_OID);
static auth_param_type_desc_t soc_fw_content_pk = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_PUB_KEY, SOC_FW_CONTENT_CERT_PK_OID);
static auth_param_type_desc_t tos_fw_content_pk = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_PUB_KEY, TRUSTED_OS_FW_CONTENT_CERT_PK_OID);
static auth_param_type_desc_t nt_fw_content_pk = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_PUB_KEY, NON_TRUSTED_FW_CONTENT_CERT_PK_OID);
Juan Castillo's avatar
Juan Castillo committed
76

77
78
static auth_param_type_desc_t tb_fw_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, TRUSTED_BOOT_FW_HASH_OID);
79
80
81
82
static auth_param_type_desc_t tb_fw_config_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, TRUSTED_BOOT_FW_CONFIG_HASH_OID);
static auth_param_type_desc_t hw_config_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, HW_CONFIG_HASH_OID);
83
84
85
86
static auth_param_type_desc_t scp_fw_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, SCP_FW_HASH_OID);
static auth_param_type_desc_t soc_fw_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, SOC_AP_FW_HASH_OID);
87
88
static auth_param_type_desc_t soc_fw_config_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, SOC_FW_CONFIG_HASH_OID);
89
90
static auth_param_type_desc_t tos_fw_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, TRUSTED_OS_FW_HASH_OID);
91
92
static auth_param_type_desc_t tos_fw_config_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, TRUSTED_OS_FW_CONFIG_HASH_OID);
93
94
95
96
static auth_param_type_desc_t tos_fw_extra1_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, TRUSTED_OS_FW_EXTRA1_HASH_OID);
static auth_param_type_desc_t tos_fw_extra2_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, TRUSTED_OS_FW_EXTRA2_HASH_OID);
97
98
static auth_param_type_desc_t nt_world_bl_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, NON_TRUSTED_WORLD_BOOTLOADER_HASH_OID);
99
100
static auth_param_type_desc_t nt_fw_config_hash = AUTH_PARAM_TYPE_DESC(
		AUTH_PARAM_HASH, NON_TRUSTED_FW_CONFIG_HASH_OID);
101
static auth_param_type_desc_t scp_bl2u_hash = AUTH_PARAM_TYPE_DESC(
102
		AUTH_PARAM_HASH, SCP_FWU_CFG_HASH_OID);
103
static auth_param_type_desc_t bl2u_hash = AUTH_PARAM_TYPE_DESC(
104
		AUTH_PARAM_HASH, AP_FWU_CFG_HASH_OID);
105
static auth_param_type_desc_t ns_bl2u_hash = AUTH_PARAM_TYPE_DESC(
106
		AUTH_PARAM_HASH, FWU_HASH_OID);
Juan Castillo's avatar
Juan Castillo committed
107
108
109
110
111
112
113
114

/*
 * TBBR Chain of trust definition
 */
static const auth_img_desc_t cot_desc[] = {
	/*
	 * BL2
	 */
115
116
	[TRUSTED_BOOT_FW_CERT_ID] = {
		.img_id = TRUSTED_BOOT_FW_CERT_ID,
Juan Castillo's avatar
Juan Castillo committed
117
118
119
120
121
122
123
124
125
126
127
		.img_type = IMG_CERT,
		.parent = NULL,
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
					.pk = &subject_pk,
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
128
129
130
131
132
133
134
			},
			[1] = {
				.type = AUTH_METHOD_NV_CTR,
				.param.nv_ctr = {
					.cert_nv_ctr = &trusted_nv_ctr,
					.plat_nv_ctr = &trusted_nv_ctr
				}
Juan Castillo's avatar
Juan Castillo committed
135
136
137
138
			}
		},
		.authenticated_data = {
			[0] = {
139
				.type_desc = &tb_fw_hash,
Juan Castillo's avatar
Juan Castillo committed
140
				.data = {
141
					.ptr = (void *)tb_fw_hash_buf,
Juan Castillo's avatar
Juan Castillo committed
142
143
					.len = (unsigned int)HASH_DER_LEN
				}
144
145
146
147
148
149
150
151
152
153
154
155
156
157
			},
			[1] = {
				.type_desc = &tb_fw_config_hash,
				.data = {
					.ptr = (void *)tb_fw_config_hash_buf,
					.len = (unsigned int)HASH_DER_LEN
				}
			},
			[2] = {
				.type_desc = &hw_config_hash,
				.data = {
					.ptr = (void *)hw_config_hash_buf,
					.len = (unsigned int)HASH_DER_LEN
				}
Juan Castillo's avatar
Juan Castillo committed
158
159
160
161
162
163
			}
		}
	},
	[BL2_IMAGE_ID] = {
		.img_id = BL2_IMAGE_ID,
		.img_type = IMG_RAW,
164
		.parent = &cot_desc[TRUSTED_BOOT_FW_CERT_ID],
Juan Castillo's avatar
Juan Castillo committed
165
166
167
168
169
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
170
					.hash = &tb_fw_hash,
Juan Castillo's avatar
Juan Castillo committed
171
172
173
174
				}
			}
		}
	},
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
	/* HW Config */
	[HW_CONFIG_ID] = {
		.img_id = HW_CONFIG_ID,
		.img_type = IMG_RAW,
		.parent = &cot_desc[TRUSTED_BOOT_FW_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
					.hash = &hw_config_hash,
				}
			}
		}
	},
	/* TB FW Config */
	[TB_FW_CONFIG_ID] = {
		.img_id = TB_FW_CONFIG_ID,
		.img_type = IMG_RAW,
		.parent = &cot_desc[TRUSTED_BOOT_FW_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
					.hash = &tb_fw_config_hash,
				}
			}
		}
	},
Juan Castillo's avatar
Juan Castillo committed
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
	/*
	 * Trusted key certificate
	 */
	[TRUSTED_KEY_CERT_ID] = {
		.img_id = TRUSTED_KEY_CERT_ID,
		.img_type = IMG_CERT,
		.parent = NULL,
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
					.pk = &subject_pk,
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
221
222
223
224
225
226
227
			},
			[1] = {
				.type = AUTH_METHOD_NV_CTR,
				.param.nv_ctr = {
					.cert_nv_ctr = &trusted_nv_ctr,
					.plat_nv_ctr = &trusted_nv_ctr
				}
Juan Castillo's avatar
Juan Castillo committed
228
229
230
231
			}
		},
		.authenticated_data = {
			[0] = {
232
				.type_desc = &trusted_world_pk,
Juan Castillo's avatar
Juan Castillo committed
233
				.data = {
234
					.ptr = (void *)trusted_world_pk_buf,
Juan Castillo's avatar
Juan Castillo committed
235
236
237
238
					.len = (unsigned int)PK_DER_LEN
				}
			},
			[1] = {
239
				.type_desc = &non_trusted_world_pk,
Juan Castillo's avatar
Juan Castillo committed
240
				.data = {
241
					.ptr = (void *)non_trusted_world_pk_buf,
Juan Castillo's avatar
Juan Castillo committed
242
243
244
245
246
247
					.len = (unsigned int)PK_DER_LEN
				}
			}
		}
	},
	/*
248
	 * SCP Firmware
Juan Castillo's avatar
Juan Castillo committed
249
	 */
250
251
	[SCP_FW_KEY_CERT_ID] = {
		.img_id = SCP_FW_KEY_CERT_ID,
Juan Castillo's avatar
Juan Castillo committed
252
253
254
255
256
257
		.img_type = IMG_CERT,
		.parent = &cot_desc[TRUSTED_KEY_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
258
					.pk = &trusted_world_pk,
Juan Castillo's avatar
Juan Castillo committed
259
260
261
262
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
263
264
265
266
267
268
269
			},
			[1] = {
				.type = AUTH_METHOD_NV_CTR,
				.param.nv_ctr = {
					.cert_nv_ctr = &trusted_nv_ctr,
					.plat_nv_ctr = &trusted_nv_ctr
				}
Juan Castillo's avatar
Juan Castillo committed
270
271
272
273
			}
		},
		.authenticated_data = {
			[0] = {
274
				.type_desc = &scp_fw_content_pk,
Juan Castillo's avatar
Juan Castillo committed
275
				.data = {
276
					.ptr = (void *)content_pk_buf,
Juan Castillo's avatar
Juan Castillo committed
277
278
279
280
281
					.len = (unsigned int)PK_DER_LEN
				}
			}
		}
	},
282
283
	[SCP_FW_CONTENT_CERT_ID] = {
		.img_id = SCP_FW_CONTENT_CERT_ID,
Juan Castillo's avatar
Juan Castillo committed
284
		.img_type = IMG_CERT,
285
		.parent = &cot_desc[SCP_FW_KEY_CERT_ID],
Juan Castillo's avatar
Juan Castillo committed
286
287
288
289
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
290
					.pk = &scp_fw_content_pk,
Juan Castillo's avatar
Juan Castillo committed
291
292
293
294
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
295
296
297
298
299
300
301
			},
			[1] = {
				.type = AUTH_METHOD_NV_CTR,
				.param.nv_ctr = {
					.cert_nv_ctr = &trusted_nv_ctr,
					.plat_nv_ctr = &trusted_nv_ctr
				}
Juan Castillo's avatar
Juan Castillo committed
302
303
304
305
			}
		},
		.authenticated_data = {
			[0] = {
306
				.type_desc = &scp_fw_hash,
Juan Castillo's avatar
Juan Castillo committed
307
				.data = {
308
					.ptr = (void *)scp_fw_hash_buf,
Juan Castillo's avatar
Juan Castillo committed
309
310
311
312
313
					.len = (unsigned int)HASH_DER_LEN
				}
			}
		}
	},
314
315
	[SCP_BL2_IMAGE_ID] = {
		.img_id = SCP_BL2_IMAGE_ID,
Juan Castillo's avatar
Juan Castillo committed
316
		.img_type = IMG_RAW,
317
		.parent = &cot_desc[SCP_FW_CONTENT_CERT_ID],
Juan Castillo's avatar
Juan Castillo committed
318
319
320
321
322
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
323
					.hash = &scp_fw_hash,
Juan Castillo's avatar
Juan Castillo committed
324
325
326
327
328
				}
			}
		}
	},
	/*
329
	 * SoC Firmware
Juan Castillo's avatar
Juan Castillo committed
330
	 */
331
332
	[SOC_FW_KEY_CERT_ID] = {
		.img_id = SOC_FW_KEY_CERT_ID,
Juan Castillo's avatar
Juan Castillo committed
333
334
335
336
337
338
		.img_type = IMG_CERT,
		.parent = &cot_desc[TRUSTED_KEY_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
339
					.pk = &trusted_world_pk,
Juan Castillo's avatar
Juan Castillo committed
340
341
342
343
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
344
345
346
347
348
349
350
			},
			[1] = {
				.type = AUTH_METHOD_NV_CTR,
				.param.nv_ctr = {
					.cert_nv_ctr = &trusted_nv_ctr,
					.plat_nv_ctr = &trusted_nv_ctr
				}
Juan Castillo's avatar
Juan Castillo committed
351
352
353
354
			}
		},
		.authenticated_data = {
			[0] = {
355
				.type_desc = &soc_fw_content_pk,
Juan Castillo's avatar
Juan Castillo committed
356
				.data = {
357
					.ptr = (void *)content_pk_buf,
Juan Castillo's avatar
Juan Castillo committed
358
359
360
361
362
					.len = (unsigned int)PK_DER_LEN
				}
			}
		}
	},
363
364
	[SOC_FW_CONTENT_CERT_ID] = {
		.img_id = SOC_FW_CONTENT_CERT_ID,
Juan Castillo's avatar
Juan Castillo committed
365
		.img_type = IMG_CERT,
366
		.parent = &cot_desc[SOC_FW_KEY_CERT_ID],
Juan Castillo's avatar
Juan Castillo committed
367
368
369
370
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
371
					.pk = &soc_fw_content_pk,
Juan Castillo's avatar
Juan Castillo committed
372
373
374
375
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
376
377
378
379
380
381
382
			},
			[1] = {
				.type = AUTH_METHOD_NV_CTR,
				.param.nv_ctr = {
					.cert_nv_ctr = &trusted_nv_ctr,
					.plat_nv_ctr = &trusted_nv_ctr
				}
Juan Castillo's avatar
Juan Castillo committed
383
384
385
386
			}
		},
		.authenticated_data = {
			[0] = {
387
				.type_desc = &soc_fw_hash,
Juan Castillo's avatar
Juan Castillo committed
388
				.data = {
389
					.ptr = (void *)soc_fw_hash_buf,
Juan Castillo's avatar
Juan Castillo committed
390
391
					.len = (unsigned int)HASH_DER_LEN
				}
392
393
394
395
396
397
398
			},
			[1] = {
				.type_desc = &soc_fw_config_hash,
				.data = {
					.ptr = (void *)soc_fw_config_hash_buf,
					.len = (unsigned int)HASH_DER_LEN
				}
Juan Castillo's avatar
Juan Castillo committed
399
400
401
402
403
404
			}
		}
	},
	[BL31_IMAGE_ID] = {
		.img_id = BL31_IMAGE_ID,
		.img_type = IMG_RAW,
405
		.parent = &cot_desc[SOC_FW_CONTENT_CERT_ID],
Juan Castillo's avatar
Juan Castillo committed
406
407
408
409
410
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
411
					.hash = &soc_fw_hash,
Juan Castillo's avatar
Juan Castillo committed
412
413
414
415
				}
			}
		}
	},
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
	/* SOC FW Config */
	[SOC_FW_CONFIG_ID] = {
		.img_id = SOC_FW_CONFIG_ID,
		.img_type = IMG_RAW,
		.parent = &cot_desc[SOC_FW_CONTENT_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
					.hash = &soc_fw_config_hash,
				}
			}
		}
	},
Juan Castillo's avatar
Juan Castillo committed
431
	/*
432
	 * Trusted OS Firmware
Juan Castillo's avatar
Juan Castillo committed
433
	 */
434
435
	[TRUSTED_OS_FW_KEY_CERT_ID] = {
		.img_id = TRUSTED_OS_FW_KEY_CERT_ID,
Juan Castillo's avatar
Juan Castillo committed
436
437
438
439
440
441
		.img_type = IMG_CERT,
		.parent = &cot_desc[TRUSTED_KEY_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
442
					.pk = &trusted_world_pk,
Juan Castillo's avatar
Juan Castillo committed
443
444
445
446
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
447
448
449
450
451
452
453
			},
			[1] = {
				.type = AUTH_METHOD_NV_CTR,
				.param.nv_ctr = {
					.cert_nv_ctr = &trusted_nv_ctr,
					.plat_nv_ctr = &trusted_nv_ctr
				}
Juan Castillo's avatar
Juan Castillo committed
454
455
456
457
			}
		},
		.authenticated_data = {
			[0] = {
458
				.type_desc = &tos_fw_content_pk,
Juan Castillo's avatar
Juan Castillo committed
459
				.data = {
460
					.ptr = (void *)content_pk_buf,
Juan Castillo's avatar
Juan Castillo committed
461
462
463
464
465
					.len = (unsigned int)PK_DER_LEN
				}
			}
		}
	},
466
467
	[TRUSTED_OS_FW_CONTENT_CERT_ID] = {
		.img_id = TRUSTED_OS_FW_CONTENT_CERT_ID,
Juan Castillo's avatar
Juan Castillo committed
468
		.img_type = IMG_CERT,
469
		.parent = &cot_desc[TRUSTED_OS_FW_KEY_CERT_ID],
Juan Castillo's avatar
Juan Castillo committed
470
471
472
473
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
474
					.pk = &tos_fw_content_pk,
Juan Castillo's avatar
Juan Castillo committed
475
476
477
478
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
479
480
481
482
483
484
485
			},
			[1] = {
				.type = AUTH_METHOD_NV_CTR,
				.param.nv_ctr = {
					.cert_nv_ctr = &trusted_nv_ctr,
					.plat_nv_ctr = &trusted_nv_ctr
				}
Juan Castillo's avatar
Juan Castillo committed
486
487
488
489
			}
		},
		.authenticated_data = {
			[0] = {
490
				.type_desc = &tos_fw_hash,
Juan Castillo's avatar
Juan Castillo committed
491
				.data = {
492
					.ptr = (void *)tos_fw_hash_buf,
Juan Castillo's avatar
Juan Castillo committed
493
494
					.len = (unsigned int)HASH_DER_LEN
				}
495
496
497
498
499
500
501
502
503
504
505
506
507
508
			},
			[1] = {
				.type_desc = &tos_fw_extra1_hash,
				.data = {
					.ptr = (void *)tos_fw_extra1_hash_buf,
					.len = (unsigned int)HASH_DER_LEN
				}
			},
			[2] = {
				.type_desc = &tos_fw_extra2_hash,
				.data = {
					.ptr = (void *)tos_fw_extra2_hash_buf,
					.len = (unsigned int)HASH_DER_LEN
				}
509
510
511
512
513
514
515
			},
			[3] = {
				.type_desc = &tos_fw_config_hash,
				.data = {
					.ptr = (void *)tos_fw_config_hash_buf,
					.len = (unsigned int)HASH_DER_LEN
				}
Juan Castillo's avatar
Juan Castillo committed
516
517
518
519
520
521
			}
		}
	},
	[BL32_IMAGE_ID] = {
		.img_id = BL32_IMAGE_ID,
		.img_type = IMG_RAW,
522
		.parent = &cot_desc[TRUSTED_OS_FW_CONTENT_CERT_ID],
Juan Castillo's avatar
Juan Castillo committed
523
524
525
526
527
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
528
					.hash = &tos_fw_hash,
Juan Castillo's avatar
Juan Castillo committed
529
530
531
532
				}
			}
		}
	},
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
	[BL32_EXTRA1_IMAGE_ID] = {
		.img_id = BL32_EXTRA1_IMAGE_ID,
		.img_type = IMG_RAW,
		.parent = &cot_desc[TRUSTED_OS_FW_CONTENT_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
					.hash = &tos_fw_extra1_hash,
				}
			}
		}
	},
	[BL32_EXTRA2_IMAGE_ID] = {
		.img_id = BL32_EXTRA2_IMAGE_ID,
		.img_type = IMG_RAW,
		.parent = &cot_desc[TRUSTED_OS_FW_CONTENT_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
					.hash = &tos_fw_extra2_hash,
				}
			}
		}
	},
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
	/* TOS FW Config */
	[TOS_FW_CONFIG_ID] = {
		.img_id = TOS_FW_CONFIG_ID,
		.img_type = IMG_RAW,
		.parent = &cot_desc[TRUSTED_OS_FW_CONTENT_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
					.hash = &tos_fw_config_hash,
				}
			}
		}
	},
Juan Castillo's avatar
Juan Castillo committed
576
	/*
577
	 * Non-Trusted Firmware
Juan Castillo's avatar
Juan Castillo committed
578
	 */
579
580
	[NON_TRUSTED_FW_KEY_CERT_ID] = {
		.img_id = NON_TRUSTED_FW_KEY_CERT_ID,
Juan Castillo's avatar
Juan Castillo committed
581
582
583
584
585
586
		.img_type = IMG_CERT,
		.parent = &cot_desc[TRUSTED_KEY_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
587
					.pk = &non_trusted_world_pk,
Juan Castillo's avatar
Juan Castillo committed
588
589
590
591
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
592
593
594
595
596
597
598
			},
			[1] = {
				.type = AUTH_METHOD_NV_CTR,
				.param.nv_ctr = {
					.cert_nv_ctr = &non_trusted_nv_ctr,
					.plat_nv_ctr = &non_trusted_nv_ctr
				}
Juan Castillo's avatar
Juan Castillo committed
599
600
601
602
			}
		},
		.authenticated_data = {
			[0] = {
603
				.type_desc = &nt_fw_content_pk,
Juan Castillo's avatar
Juan Castillo committed
604
				.data = {
605
					.ptr = (void *)content_pk_buf,
Juan Castillo's avatar
Juan Castillo committed
606
607
608
609
610
					.len = (unsigned int)PK_DER_LEN
				}
			}
		}
	},
611
612
	[NON_TRUSTED_FW_CONTENT_CERT_ID] = {
		.img_id = NON_TRUSTED_FW_CONTENT_CERT_ID,
Juan Castillo's avatar
Juan Castillo committed
613
		.img_type = IMG_CERT,
614
		.parent = &cot_desc[NON_TRUSTED_FW_KEY_CERT_ID],
Juan Castillo's avatar
Juan Castillo committed
615
616
617
618
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
619
					.pk = &nt_fw_content_pk,
Juan Castillo's avatar
Juan Castillo committed
620
621
622
623
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
624
625
626
627
628
629
630
			},
			[1] = {
				.type = AUTH_METHOD_NV_CTR,
				.param.nv_ctr = {
					.cert_nv_ctr = &non_trusted_nv_ctr,
					.plat_nv_ctr = &non_trusted_nv_ctr
				}
Juan Castillo's avatar
Juan Castillo committed
631
632
633
634
			}
		},
		.authenticated_data = {
			[0] = {
635
				.type_desc = &nt_world_bl_hash,
Juan Castillo's avatar
Juan Castillo committed
636
				.data = {
637
					.ptr = (void *)nt_world_bl_hash_buf,
Juan Castillo's avatar
Juan Castillo committed
638
639
					.len = (unsigned int)HASH_DER_LEN
				}
640
641
642
643
644
645
646
			},
			[1] = {
				.type_desc = &nt_fw_config_hash,
				.data = {
					.ptr = (void *)nt_fw_config_hash_buf,
					.len = (unsigned int)HASH_DER_LEN
				}
Juan Castillo's avatar
Juan Castillo committed
647
648
649
650
651
652
			}
		}
	},
	[BL33_IMAGE_ID] = {
		.img_id = BL33_IMAGE_ID,
		.img_type = IMG_RAW,
653
		.parent = &cot_desc[NON_TRUSTED_FW_CONTENT_CERT_ID],
Juan Castillo's avatar
Juan Castillo committed
654
655
656
657
658
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
659
					.hash = &nt_world_bl_hash,
Juan Castillo's avatar
Juan Castillo committed
660
661
662
				}
			}
		}
663
	},
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
	/* NT FW Config */
	[NT_FW_CONFIG_ID] = {
		.img_id = NT_FW_CONFIG_ID,
		.img_type = IMG_RAW,
		.parent = &cot_desc[NON_TRUSTED_FW_CONTENT_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
					.hash = &nt_fw_config_hash,
				}
			}
		}
	},
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
	/*
	 * FWU auth descriptor.
	 */
	[FWU_CERT_ID] = {
		.img_id = FWU_CERT_ID,
		.img_type = IMG_CERT,
		.parent = NULL,
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_SIG,
				.param.sig = {
					.pk = &subject_pk,
					.sig = &sig,
					.alg = &sig_alg,
					.data = &raw_data,
				}
			}
		},
		.authenticated_data = {
			[0] = {
				.type_desc = &scp_bl2u_hash,
				.data = {
701
					.ptr = (void *)scp_fw_hash_buf,
702
703
704
705
706
707
					.len = (unsigned int)HASH_DER_LEN
				}
			},
			[1] = {
				.type_desc = &bl2u_hash,
				.data = {
708
					.ptr = (void *)tb_fw_hash_buf,
709
710
711
712
713
714
					.len = (unsigned int)HASH_DER_LEN
				}
			},
			[2] = {
				.type_desc = &ns_bl2u_hash,
				.data = {
715
					.ptr = (void *)nt_world_bl_hash_buf,
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
					.len = (unsigned int)HASH_DER_LEN
				}
			}
		}
	},
	/*
	 * SCP_BL2U
	 */
	[SCP_BL2U_IMAGE_ID] = {
		.img_id = SCP_BL2U_IMAGE_ID,
		.img_type = IMG_RAW,
		.parent = &cot_desc[FWU_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
					.hash = &scp_bl2u_hash,
				}
			}
		}
	},
	/*
	 * BL2U
	 */
	[BL2U_IMAGE_ID] = {
		.img_id = BL2U_IMAGE_ID,
		.img_type = IMG_RAW,
		.parent = &cot_desc[FWU_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
					.hash = &bl2u_hash,
				}
			}
		}
	},
	/*
	 * NS_BL2U
	 */
	[NS_BL2U_IMAGE_ID] = {
		.img_id = NS_BL2U_IMAGE_ID,
		.img_type = IMG_RAW,
		.parent = &cot_desc[FWU_CERT_ID],
		.img_auth_methods = {
			[0] = {
				.type = AUTH_METHOD_HASH,
				.param.hash = {
					.data = &raw_data,
					.hash = &ns_bl2u_hash,
				}
			}
		}
Juan Castillo's avatar
Juan Castillo committed
771
772
773
774
775
	}
};

/* Register the CoT in the authentication module */
REGISTER_COT(cot_desc);