Repository navigation
fw(uno): enable aes_xts crypto support in uno firmware - #773
Open
v-akkalaria wants to merge 3 commits into
Open
v-akkalaria wants to merge 3 commits into
v-akkalaria wants to merge 3 commits into
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Firmware cryptographic behavior depends on Uno hardware and its external bulk-crypto backend, requiring final human validation.
Review effort: Balanced
Findings: None
What changed in this PR
Enables AES-XTS bulk-key creation and import across Uno firmware’s MBOR key-management paths.
Changes:
- Adds AES-XTS routing to the existing bulk backend.
- Enables generation, derivation, unmasking, and RSA unwrapping.
- Generalizes shared GCM-only bulk helpers for GCM and XTS.
| File | Description |
|---|---|
fw/core/lib/src/ddi/mbor/aes_generate_key.rs |
Generates XTS bulk-key halves. |
fw/core/lib/src/ddi/mbor/bulk.rs |
Generalizes bulk-kind detection. |
fw/core/lib/src/ddi/mbor/from_ddi.rs |
Maps XTS key sizes. |
fw/core/lib/src/ddi/mbor/hkdf_derive.rs |
Documents XTS bulk derivation. |
fw/core/lib/src/ddi/mbor/kbkdf_derive.rs |
Documents XTS bulk derivation. |
fw/core/lib/src/ddi/mbor/kdf.rs |
Resolves XTS derivation targets. |
fw/core/lib/src/ddi/mbor/rsa_unwrap.rs |
Imports RSA-unwrapped XTS halves. |
fw/core/lib/src/ddi/mbor/unmask_key.rs |
Reimports masked XTS halves. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Rajib Dutta (radutta99)
self-requested a review
October 8, 2026 19:05
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Brings up the AES-XTS crypto operations on the CP HSM
unoplatform, on top of the AES-GCM bulk-key support.As with AES-GCM, AES-XTS bulk crypto runs on the dedicated bulk-crypto backend, not on the CP1 HSM core. The HSM's role is key management: generate/import the AES-256 key, register it with the backend, and return an opaque
bulk_key_id; the host then drives XTS encrypt/decrypt directly against the backend using that handle. Behavior matches mainline.Changes
fw/core/lib/src/ddi/mbor): the five ops that can produce a bulk key —AesGenerateKey,HkdfDerive,KbkdfDerive,UnmaskKey,RsaUnwrap— now acceptAesXtsBulk256/DdiKeyClass::AesXtsBulkand route it through the existing bulk-key commit path (bulk::commit_key), returningbulk_key_id.bulk::is_gcm_bulk→bulk::is_bulk(now covers GCM and XTS).UnmaskKeyno longer rejectsAesXtsBulk256masked keys.AesGenerateKeyderives the bulk/non-bulk split fromfrom_ddi::aes_bulk+bulk::is_bulk, so the bulk kind list lives in one place.fp_bulk_lock) already handlesAesXtsBulk256(AesBulkKeyType::Xts). Platforms without a bulk backend still returnUnsupportedCmd.Test report
DDI integration suite (
ddi/mbor/types/tests/integration) — Uno HW (Manticore EVB and Blade setup with 64 VMs). Tests resolved with respect to current uno mainline fw:Emu (
--features emu): AES / HKDF / KBKDF / unmask / RSA-unwrap / masked-key suites 159/159 pass (bulk ops returnUnsupportedCmdon the backend-less std PAL, as before).API tests: all AES-XTS related API tests (test_aes_xts*) passed.
All azihsm_ddi_tbor_tests passed.
Performance (uno HW, mcr_perf with 128 threads, shared_session, 5 s stabilize, 100 s run)