Trusted access control for secure boot process for storage controllers or drivers
Systems and techniques are described herein for image authentication for secure boot. For example, a process the image authentication can include: receiving, a request to load an image during a secure boot process; performing, at the secure entity, a secure boot configuration action set in response to receiving the request; requesting the image from a storage device; transmitting the image to a cryptographic hardware component; obtaining, at the cryptographic hardware component, a digest corresponding to at least a portion of the image; storing the digest in the secured register of the cryptographic hardware component; storing the image in a secured memory device portion; obtaining, at the secure entity, a previously calculated digest corresponding to the image from the secured memory device portion; obtaining, at the secure entity, the digest from the secured register; and performing a comparison to determine whether the digest and the previously calculated digest match.
1 . A method for image authentication for secure boot, the method comprising:
receiving, at a secure entity, a request to load an image during a secure boot process;
performing, at the secure entity, a secure boot configuration action set in response to receiving the request;
requesting the image from a storage device;
transmitting the image to a cryptographic hardware component;
obtaining, at the cryptographic hardware component, a digest corresponding to at least a portion of the image;
configuring a register of the cryptographic hardware component to be exclusively read by the secure entity, wherein the register is configurable to be exclusively read by the secure entity or to be read by at least one additional entity, different from the secure entity;
storing the digest in the register of the cryptographic hardware component;
storing the image in a secured memory device portion;
obtaining, at the secure entity, a previously calculated digest corresponding to the image from the secured memory device portion;
obtaining, at the secure entity, the digest from the register; and
performing a comparison to determine whether the digest and the previously calculated digest match.
2 . The method of claim 1 , wherein performing the secure boot configuration action set comprises:
configuring a protection unit to include an association between the secure entity and the secured memory device portion for read and write access; and
configuring the protection unit to include an association between a storage controller and the secured memory device portion for write access.
3 . The method of claim 1 , wherein performing the secure boot configuration action set comprises:
configuring a protection unit to include an association between the secure entity and the register for read access.
4 . The method of claim 1 , wherein performing the secure boot configuration action set comprises:
configuring a data path to the secured memory device portion to exclude use of the data path by other components of a computing device.
5 . The method of claim 1 , wherein the request to load the image includes a location of the image on the storage device.
6 . The method of claim 1 , wherein performing the comparison to determine whether the digest and the previously calculated digest match determines a match, and wherein the secure boot process is allowed to continue based on the match.
7 . The method of claim 1 , wherein performing the comparison to determine whether the digest and the previously calculated digest match determines a failed match, and wherein the secure boot process is halted based on the failed match.
8 . The method of claim 7 , further comprising:
removing the image from the secured memory device portion based on the failed match.
9 . The method of claim 1 , wherein obtaining, at the cryptographic hardware component, the digest corresponding to the portion of the image comprises executing a hashing algorithm at the cryptographic hardware component using the portion of the image as input.
10 . The method of claim 1 , further comprising configuring the register of the cryptographic hardware component to be read by the at least one additional entity.
11 . An apparatus for image authentication for secure boot, the apparatus comprising:
at least one memory; and
at least one processor coupled to the at least one memory and configured to:
receive, at a secure entity, a request to load an image during a secure boot process;
perform a secure boot configuration action set in response to receiving the request;
request the image from a storage device;
transmit the image to a cryptographic hardware component;
obtain a digest corresponding to at least a portion of the image;
configure a register of the cryptographic hardware component to be exclusively read by the secure entity, wherein the register is configurable to be exclusively read by the secure entity or to be read by at least one additional entity, different from the secure entity;
store the digest in the register of the cryptographic hardware component;
store the image in a secured memory device portion;
obtain a previously calculated digest corresponding to the image from the secured memory device portion;
obtain the digest from the register; and
perform a comparison to determine whether the digest and the previously calculated digest match.
12 . The apparatus of claim 11 , wherein, to perform the secure boot configuration action set, the at least one processor is further configured to:
configure a protection unit to include an association between the secure entity and the secured memory device portion for read and write access; and
configure the protection unit to include an association between a storage controller and the secured memory device portion for write access.
13 . The apparatus of claim 11 , wherein, to perform the secure boot configuration action set, the at least one processor is further configured to:
configure a protection unit to include an association between the secure entity and the register for read access.
14 . The apparatus of claim 11 , wherein, to perform the secure boot configuration action set, the at least one processor is further configured to:
configure a data path to the secured memory device portion to exclude use of the data path by other components of a computing device.
15 . The apparatus of claim 11 , wherein the request to load the image includes a location of the image on the storage device.
16 . The apparatus of claim 11 , wherein performing the comparison to determine whether the digest and the previously calculated digest match determines a match, and wherein the secure boot process is allowed to continue based on the match.
17 . The apparatus of claim 11 , wherein performing the comparison to determine whether the digest and the previously calculated digest match determines a failed match, and wherein the secure boot process is halted based on the failed match.
18 . The apparatus of claim 17 , wherein the at least one processor is further configured to:
remove the image from the secured memory device portion based on the failed match.
19 . The apparatus of claim 11 , wherein, to obtain, at the cryptographic hardware component, the digest, the cryptographic hardware component executes a hashing algorithm using the portion of the image as input.
20 . The apparatus of claim 11 , wherein the secure entity is further configured to:
receive the request to load the image during the secure boot process;
perform the secure boot configuration action set in response to receiving the request;
obtain the previously calculated digest; and
obtain the digest from the secured register.
21 . The apparatus of claim 11 , further comprising the cryptographic hardware component configured to:
obtain the digest corresponding to at least the portion of the image.
22 . The apparatus of claim 11 , wherein the at least one processor is configured to configure the register of the cryptographic hardware component to be read by the at least one additional entity.
23 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to:
receive, at a secure entity, a request to load an image during a secure boot process;
perform a secure boot configuration action set in response to receiving the request;
request the image from a storage device;
transmit the image to a cryptographic hardware component;
obtain, via the cryptographic hardware component, a digest corresponding to at least a portion of the image;
configure a register of the cryptographic hardware component to be exclusively read by the secure entity, wherein the register is configurable to be exclusively read by the secure entity or to be read by at least one additional entity, different from the secure entity;
store the digest in the register of the cryptographic hardware component, wherein the register of the cryptographic hardware component is configured to be exclusively read by a secure entity, and wherein at least one register of the cryptographic hardware component is configured be readable by an additional entity, different from the secure entity;
store the image in a secured memory device portion;
obtain a previously calculated digest corresponding to the image from the secured memory device portion;
obtain the digest from the register; and
perform a comparison to determine whether the digest and the previously calculated digest match.
24 . The non-transitory computer-readable medium of claim 23 , wherein, to perform the secure boot configuration action set, the instructions further cause the one or more processors to:
configure a protection unit to include an association between the secure entity and the secured memory device portion for read and write access; and
configure the protection unit to include an association between a storage controller and the secured memory device portion for write access.
25 . The non-transitory computer-readable medium of claim 23 , wherein, to perform the secure boot configuration action set, the instructions further cause the one or more processors to:
configure a protection unit to include an association between the secure entity and the register for read access.
26 . The non-transitory computer-readable medium of claim 23 , wherein, to perform the secure boot configuration action set, the instructions further cause the one or more processors to:
configure a data path to the secured memory device portion to exclude use of the data path by other components of a computing device.
27 . The non-transitory computer-readable medium of claim 23 , wherein the request to load the image includes a location of the image on the storage device.
28 . The non-transitory computer-readable medium of claim 23 , wherein performing the comparison to determine whether the digest and the previously calculated digest match determines a match, and wherein the secure boot process is allowed to continue based on the match.
29 . The non-transitory computer-readable medium of claim 23 , wherein performing the comparison to determine whether the digest and the previously calculated digest match determines a failed match, and wherein the secure boot process is halted based on the failed match.
30 . The non-transitory computer-readable medium of claim 29 , wherein the instructions further cause the one or more processors to:
remove the image from the secured memory device portion based on the failed match.