mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH RFC 0/3] security: ima: support TSM measurement registers
@ 2026-09-30 13:43 Yeoreum Yun
  2026-09-30 13:43 ` [PATCH RFC 1/3] virt: coco: introduce tsm_default_tm() and tsm_mr_read()/write() Yeoreum Yun
                   ` (3 more replies)
  0 siblings, 4 replies; 9+ messages in thread
From: Yeoreum Yun @ 2026-09-30 13:43 UTC (permalink / raw)
  To: linux-coco, linux-kernel, linux-arm-kernel, Eric Snowberg,
	linux-integrity, linux-security-module
  Cc: Dan Williams, Mimi Zohar, Roberto Sassu, Dmitry Kasatkin,
	Paul Moore, James Morris, Serge E. Hallyn, Catalin Marinas,
	Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar,
	Aneesh Kumar K.V, Jiri Pirko, Yeoreum Yun

Confidential computing guests without a TPM can use TSM measurement
registers to record IMA measurement digests instead of TPM PCRs.

This series introduces in-kernel interfaces for accessing TSM
measurement registers, abstracts IMA's measurement-register operations,
and adds a TSM backend for Intel TDX and Arm CCA.

The following mappings between TPM PCR indices and TSM measurement
registers are defined for Intel TDX [0] and proposed for Arm CCA [1]:

  TPM PCR index | Intel TDX register | Arm CCA register
  --------------+--------------------+-----------------
  0             | MRTD               | RIM
  1, 7          | RTMR[0]            | REM[0]
  2-6           | RTMR[1]            | REM[1]
  8-15          | RTMR[2]            | REM[2]

These mappings allow IMA to translate PCR indices into the corresponding
TSM measurement registers.

The TPM backend remains preferred when it is available at IMA
initialization. Otherwise, IMA falls back to a supported TSM backend.
Only one backend is selected; IMA measurements are not extended to both
TPM PCRs and TSM measurement registers.

The attestation proccess for guest with TSM measurement register will
be done with Confidential Compute Event Log (CCEL) which is exported by
/sys/firmware/acpi/tables/data/CCEL. Here is brief process in arm64:

  Verifier                 Realm guest              RMM / Platform
     |                         |                           |
     |--- Challenge (nonce) -->|                           |
     |                         |--- Request token -------->|
     |                         |    with challenge         |
     |                         |                           |
     |                         |<-- CCA token T -----------|
     |<-- CCA token T ---------|                           |
     |<-- CCEL event log ------|                           |
     |<-- IMA measurement log -|                           |
     |                         |                           |
 Verify token T:               |                           |
  - signatures                 |                           |
  - Platform/Realm             |                           |
    token binding              |                           |
  - challenge freshness        |                           |
  - platform/RIM policy        |                           |
  - verify measurement logs    |                           |
     |                         |                           |
     | ----ACCEPT / REJECT---->|                           |

This patch based on arm-cca-mr series [3].

Link: [0] https://uefi.org/specs/UEFI/2.11/38_Confidential_Computing.html#intel-trust-domain-extension
Link: [1] https://github.com/tianocore/edk2/issues/11383
Link: [2] https://github.com/tianocore/edk2/issues/11384
Link: [3] https://lore.kernel.org/all/20260929-arm_cca_mr-v2-0-1d98bba187fd@arm.com/

---
Yeoreum Yun (3):
      virt: coco: introduce tsm_default_tm() and tsm_mr_read()/write()
      security: IMA: introduce ima_mr structure
      security: IMA: use TSM measurement registers

 drivers/virt/coco/guest/tsm-mr.c          | 159 +++++++++++++---
 include/linux/tsm-mr.h                    |  26 +++
 security/integrity/ima/Makefile           |   3 +-
 security/integrity/ima/ima.h              |   7 +-
 security/integrity/ima/ima_api.c          |   4 +-
 security/integrity/ima/ima_crypto.c       | 137 +++++---------
 security/integrity/ima/ima_fs.c           |  16 +-
 security/integrity/ima/ima_init.c         |   7 +-
 security/integrity/ima/ima_mr.c           |  48 +++++
 security/integrity/ima/ima_mr.h           |  76 ++++++++
 security/integrity/ima/ima_mr_tpm.c       | 155 ++++++++++++++++
 security/integrity/ima/ima_mr_tsm.c       | 290 ++++++++++++++++++++++++++++++
 security/integrity/ima/ima_queue.c        |  39 ++--
 security/integrity/ima/ima_template.c     |   4 +-
 security/integrity/ima/ima_template_lib.c |   2 +-
 15 files changed, 819 insertions(+), 154 deletions(-)
---
base-commit: b561246f45174b7472c24b75358ea95bae72b7b8
change-id: 20260929-ima_tgx_integration_v2-1c54aeeaeaee

Best regards,
-- 
Sincerely,
Yeoreum Yun


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2026-10-01 16:39 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30 13:43 [PATCH RFC 0/3] security: ima: support TSM measurement registers Yeoreum Yun
2026-09-30 13:43 ` [PATCH RFC 1/3] virt: coco: introduce tsm_default_tm() and tsm_mr_read()/write() Yeoreum Yun
2026-09-30 13:44 ` [PATCH RFC 2/3] security: IMA: introduce ima_mr structure Yeoreum Yun
2026-09-30 13:44 ` [PATCH RFC 3/3] security: IMA: use TSM measurement registers Yeoreum Yun
2026-10-01 11:27 ` [PATCH RFC 0/3] security: ima: support " Roberto Sassu
2026-10-01 11:45   ` Roberto Sassu
2026-10-01 14:24     ` Yeoreum Yun
2026-10-01 15:18     ` Jason Gunthorpe
2026-10-01 16:39       ` Yeoreum Yun

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®