Expand description
Cryptographic verification for CMOD modules.
Provides Ed25519 signature verification to ensure module integrity. The kernel maintains a key store of trusted public keys; modules must be signed by one of these keys to be loaded.
§Security Design
The signed payload is code + data only (everything after the header). The header (containing key_id and signature) is NOT part of the signed payload. This prevents an attacker from using a known key_id to trick the kernel into looking up a legitimate key while verifying a malicious signature.
Verification flow:
- Extract key_id (8 bytes) and signature (64 bytes) from header
- Look up the public key by key_id
- Verify signature over: module_data[HEADER_SIZE..] (code + data, excluding the header)
Structs§
- Trusted
Key - A trusted signing key with its identifier.
Enums§
- Verify
Result - Result of a signature verification attempt.
Constants§
- ED25519_
PUBLIC_ KEY_ SIZE - Size of an Ed25519 public key in bytes.
- ED25519_
SIGNATURE_ SIZE - Size of an Ed25519 signature in bytes.
- KEY_
ID_ SIZE - Size of a key ID.
Statics§
- TRUSTED_
KEYS 🔒 - Global trusted key store protected by a spinlock.
Functions§
- find_
trusted_ 🔒key - Lookup a trusted key by its ID.
- init
- Initialize the crypto subsystem.
- is_
key_ trusted - Check if a key ID is registered as trusted.
- register_
trusted_ key - Register a trusted signing key.
- remove_
trusted_ key - Remove a trusted signing key by ID.
- trusted_
key_ count - Number of registered trusted keys.
- verify_
cmod_ signature - Verify a CMOD module’s signature.
- verify_
signature - Verify an Ed25519 signature over data.