Skip to main content

Module crypto

Module crypto 

Source
Expand description

Cryptographic verification for CMOD modules.

Provides Ed25519 signature verification to ensure module integrity. The kernel maintains a key store of trusted public keys; modules must be signed by one of these keys to be loaded.

§Security Design

The signed payload is code + data only (everything after the header). The header (containing key_id and signature) is NOT part of the signed payload. This prevents an attacker from using a known key_id to trick the kernel into looking up a legitimate key while verifying a malicious signature.

Verification flow:

  1. Extract key_id (8 bytes) and signature (64 bytes) from header
  2. Look up the public key by key_id
  3. Verify signature over: module_data[HEADER_SIZE..] (code + data, excluding the header)

Structs§

TrustedKey
A trusted signing key with its identifier.

Enums§

VerifyResult
Result of a signature verification attempt.

Constants§

ED25519_PUBLIC_KEY_SIZE
Size of an Ed25519 public key in bytes.
ED25519_SIGNATURE_SIZE
Size of an Ed25519 signature in bytes.
KEY_ID_SIZE
Size of a key ID.

Statics§

TRUSTED_KEYS 🔒
Global trusted key store protected by a spinlock.

Functions§

find_trusted_key 🔒
Lookup a trusted key by its ID.
init
Initialize the crypto subsystem.
is_key_trusted
Check if a key ID is registered as trusted.
register_trusted_key
Register a trusted signing key.
remove_trusted_key
Remove a trusted signing key by ID.
trusted_key_count
Number of registered trusted keys.
verify_cmod_signature
Verify a CMOD module’s signature.
verify_signature
Verify an Ed25519 signature over data.