Skip to content

[crypto] Add CMVP service indicator and approval checks - #31277

Merged
siemen11 merged 1 commit into
lowRISC:earlgrey_1.0.0from
siemen11:service_indicator
Sep 17, 2026
Merged

siemen11 merged 1 commit into
lowRISC:earlgrey_1.0.0from
siemen11:service_indicator

Conversation

@siemen11

Copy link
Copy Markdown
Contributor

Add a service indicator showing whether a crypto function was allowed concerning CMVP or not.

In addition, this indicator reflects:

  • We limit the key size on KDFs (minimum 112-bit key length for KDF-CTR and KMAC-KDF).
  • We limit the usage of RSA (RSA-2048 key generation marked non-approved per SP 800-131A; only 3072 and 4096 are approved).
  • We limit HMAC key size (minimum 112-bit key length for approved generation).
  • We limit CMAC tag size (minimum 64-bit tag length per SP 800-38B).
  • We distinguish DRBG entropy sources (hardware-seeded CSRNG generation is approved; manual/external seeding is non-approved).
  • We mark non-approved algorithms as non-approved (e.g., HKDF, X25519).

@siemen11
siemen11 requested review from a team and alees24 and removed request for a team September 10, 2026 14:27
@siemen11
siemen11 requested review from andrea-caforio, johannheyszl and nasahlpa and removed request for alees24 September 10, 2026 14:28
@siemen11
siemen11 force-pushed the service_indicator branch 2 times, most recently from 44f80e1 to 313f5da Compare September 10, 2026 15:17
siemen11 added a commit to siemen11/opentitan that referenced this pull request Sep 10, 2026
Add a service indicator showing whether a crypto function was allowed concerning CMVP or not.

In addition, this indicator reflects:
- We limit the key size on KDFs (minimum 112-bit key length for KDF-CTR and KMAC-KDF).
- We limit the usage of RSA (RSA-2048 key generation marked non-approved per SP 800-131A; only 3072 and 4096 are approved).
- We limit HMAC key size (minimum 112-bit key length for approved generation).
- We limit CMAC tag size (minimum 64-bit tag length per SP 800-38B).
- We distinguish DRBG entropy sources (hardware-seeded CSRNG generation is approved; manual/external seeding is non-approved).
- We mark non-approved algorithms as non-approved (e.g., HKDF, X25519).

Signed-off-by: Siemen Dhooghe <sdhooghe@google.com>
@siemen11
siemen11 force-pushed the service_indicator branch 2 times, most recently from 8f4b270 to 888c669 Compare September 10, 2026 16:35
@siemen11 siemen11 added the CI:Rerun Rerun failed CI jobs label Sep 10, 2026
@github-actions github-actions Bot removed the CI:Rerun Rerun failed CI jobs label Sep 10, 2026

@andrea-caforio andrea-caforio left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @siemen11.

@siemen11
siemen11 force-pushed the service_indicator branch 3 times, most recently from 8c3eb46 to ab4aa6e Compare September 11, 2026 22:03
@siemen11
siemen11 requested a review from GillonB September 14, 2026 07:58
Add a service indicator showing whether a crypto function was allowed concerning CMVP or not.

In addition, this indicator reflects:
- We limit the key size on KDFs (minimum 112-bit key length for KDF-CTR and KMAC-KDF).
- We limit the usage of RSA (RSA-2048 key generation marked non-approved per SP 800-131A; only 3072 and 4096 are approved).
- We limit HMAC key size (minimum 112-bit key length for approved generation).
- We limit CMAC tag size (minimum 64-bit tag length per SP 800-38B).
- We distinguish DRBG entropy sources (hardware-seeded CSRNG generation is approved; manual/external seeding is non-approved).
- We mark non-approved algorithms as non-approved (e.g., HKDF, X25519).

Signed-off-by: Siemen Dhooghe <sdhooghe@google.com>
@siemen11

Copy link
Copy Markdown
Contributor Author

Merging as failing tests are unrelated

@siemen11
siemen11 merged commit 00346f2 into lowRISC:earlgrey_1.0.0 Sep 17, 2026
33 of 35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants