Skip to content

fw(uno): enable aes_xts crypto support in uno firmware - #773

Open
v-akkalaria wants to merge 3 commits into
Azure:mainfrom
v-akkalaria:akash/aes_xts_support
Open

v-akkalaria wants to merge 3 commits into
Azure:mainfrom
v-akkalaria:akash/aes_xts_support

Conversation

@v-akkalaria

@v-akkalaria v-akkalaria commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Brings up the AES-XTS crypto operations on the CP HSM uno platform, on top of the AES-GCM bulk-key support.

As with AES-GCM, AES-XTS bulk crypto runs on the dedicated bulk-crypto backend, not on the CP1 HSM core. The HSM's role is key management: generate/import the AES-256 key, register it with the backend, and return an opaque bulk_key_id; the host then drives XTS encrypt/decrypt directly against the backend using that handle. Behavior matches mainline.

Changes

  • Core DDI handlers (fw/core/lib/src/ddi/mbor): the five ops that can produce a bulk key — AesGenerateKey, HkdfDerive, KbkdfDerive, UnmaskKey, RsaUnwrap — now accept AesXtsBulk256 / DdiKeyClass::AesXtsBulk and route it through the existing bulk-key commit path (bulk::commit_key), returning bulk_key_id.
    • bulk::is_gcm_bulk → bulk::is_bulk (now covers GCM and XTS).
    • UnmaskKey no longer rejects AesXtsBulk256 masked keys.
    • AesGenerateKey derives the bulk/non-bulk split from from_ddi::aes_bulk + bulk::is_bulk, so the bulk kind list lives in one place.
  • No PAL trait or Uno PAL changes: the Uno bulk-key path from fw(uno): enable aes_gcm crypto support in uno firmware #657 (FP registration, slot lifecycle, session/partition teardown, fp_bulk_lock) already handles AesXtsBulk256 (AesBulkKeyType::Xts). Platforms without a bulk backend still return UnsupportedCmd.

Test report

DDI integration suite (ddi/mbor/types/tests/integration) — Uno HW (Manticore EVB and Blade setup with 64 VMs). Tests resolved with respect to current uno mainline fw:

DDI test resolved
integration::aes_xts_bulk_stress::test_aes_xts_encrypt_decrypt_multi_threaded_stress
integration::aes_xts_encrypt_decrypt::test_aes_xts_encrypt_decrypt
integration::aes_xts_encrypt_decrypt::test_aes_xts_encrypt_with_gcm_key_in_the_mix
integration::aes_xts_encrypt_decrypt::test_aes_xts_encrypt_with_identical_key_content
integration::attest_key::test_attest_aes_xts_bulk_key
integration::masked_key_aes_gen::test_unmask_xts_bulk_key_preserves_attributes
integration::masked_key_aes_gen::test_unmask_xts_bulk_session_key_preserves_attributes
integration::secret_hkdf_derive::test_secret_hkdf_aes_xts_secret256
integration::secret_hkdf_derive::test_secret_hkdf_aes_xts_secret384
integration::secret_hkdf_derive::test_secret_hkdf_aes_xts_secret521
integration::secret_kbkdf_derive::test_secret_kbkdf_aes_xts_secret256
integration::secret_kbkdf_derive::test_secret_kbkdf_aes_xts_secret384
integration::secret_kbkdf_derive::test_secret_kbkdf_aes_xts_secret521

Emu (--features emu): AES / HKDF / KBKDF / unmask / RSA-unwrap / masked-key suites 159/159 pass (bulk ops return UnsupportedCmd on the backend-less std PAL, as before).

API tests: all AES-XTS related API tests (test_aes_xts*) passed.

All azihsm_ddi_tbor_tests passed.

Performance (uno HW, mcr_perf with 128 threads, shared_session, 5 s stabilize, 100 s run)

Perf test case name RPS - mainline RPS - PR changes
aes-xts-decrypt-16m 552 551
aes-xts-decrypt-4k 1483025 1482721
aes-xts-encrypt-16m 553 548
aes-xts-encrypt-4k 1482878 1482846

Copilot AI balanced review requested due to automatic review settings October 6, 2026 07:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Firmware cryptographic behavior depends on Uno hardware and its external bulk-crypto backend, requiring final human validation.

Review effort: Balanced
Findings: None

What changed in this PR

Enables AES-XTS bulk-key creation and import across Uno firmware’s MBOR key-management paths.

Changes:

  • Adds AES-XTS routing to the existing bulk backend.
  • Enables generation, derivation, unmasking, and RSA unwrapping.
  • Generalizes shared GCM-only bulk helpers for GCM and XTS.
File Description
fw/​core/​lib/​src/​ddi/​mbor/​aes_generate_key.rs Generates XTS bulk-key halves.
fw/​core/​lib/​src/​ddi/​mbor/​bulk.rs Generalizes bulk-kind detection.
fw/​core/​lib/​src/​ddi/​mbor/​from_ddi.rs Maps XTS key sizes.
fw/​core/​lib/​src/​ddi/​mbor/​hkdf_derive.rs Documents XTS bulk derivation.
fw/​core/​lib/​src/​ddi/​mbor/​kbkdf_derive.rs Documents XTS bulk derivation.
fw/​core/​lib/​src/​ddi/​mbor/​kdf.rs Resolves XTS derivation targets.
fw/​core/​lib/​src/​ddi/​mbor/​rsa_unwrap.rs Imports RSA-unwrapped XTS halves.
fw/​core/​lib/​src/​ddi/​mbor/​unmask_key.rs Reimports masked XTS halves.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread fw/core/lib/src/ddi/mbor/aes_generate_key.rs Outdated
Comment thread fw/core/lib/src/ddi/mbor/kdf.rs
Copilot AI balanced review requested due to automatic review settings October 9, 2026 09:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

AES generation still duplicates the bulk-kind list despite the stated centralized classification design.

1 open finding

🧠 Review effort: Balanced

Comment thread fw/core/lib/src/ddi/mbor/aes_generate_key.rs Outdated
Copilot AI balanced review requested due to automatic review settings October 9, 2026 10:20

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

XTS is consistently integrated across all key-producing paths with appropriate existing integration coverage.

0 open findings

1 resolved since last review

🧠 Review effort: Balanced

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants