Skip to content

Add KeyStack PTA - #1104

Open
Sangho Lee (sangho2) wants to merge 2 commits into
mainfrom
sanghle/optee/keystack_pta
Open

Add KeyStack PTA#1104
Sangho Lee (sangho2) wants to merge 2 commits into
mainfrom
sanghle/optee/keystack_pta

Conversation

@sangho2

@sangho2Sangho Lee (sangho2) commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

This PR introduces a KeyStack PTA which derives a stack of keys based on a requesting TA's UUID, Secure Version Number (SVN), and extra data, enabling anti-rollback key derivation.

@sangho2

Copy link
Copy Markdown
ContributorAuthor

Replace #831 with this PR to maintain the compatibility with the mainline OP-TEE OS.

@sangho2Sangho Lee (sangho2) added the discussion Open questions label Jul 29, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/optee/keystack_pta branch from 6c43996 to 8ab855fCompareJuly 29, 2026 23:41
@sangho2Sangho Lee (sangho2) changed the title [DRAFT] Add KeyStack PTAAdd KeyStack PTAJul 29, 2026
Comment on lines +39 to +46
// TODO: Replace this placeholder with the UUID agreed upon with the
// consuming TA before this PTA is treated as a stable interface.
pub(crate) const UUID: TeeUuid = TeeUuid {
time_low: 0x978a_f7a7,
time_mid: 0x074f,
time_hi_and_version: 0x4f59,
clock_seq_and_node: [0xb3, 0xae, 0x33, 0xa5, 0x93, 0xc1, 0xd4, 0x88],
};

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

UUID

@sangho2
Sangho Lee (sangho2) marked this pull request as ready for review July 29, 2026 23:56
Comment threadlitebox_shim_optee/src/syscalls/tests.rs Fixed
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/optee/keystack_pta branch from aa30b82 to d575fc8CompareJuly 30, 2026 17:38
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/optee/keystack_pta branch from d575fc8 to a3a7ee0CompareJuly 31, 2026 02:01
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 No breaking API changes detected

Note: this does not mean API is unchanged, or even that there are no breaking changes; simply, none of the detections triggered.

@sangho2Sangho Lee (sangho2) added must-not-merge:blocked-on-other-changes Other changes/PRs to be handled first. Label not needed for non-main changes. and removed discussion Open questions labels Aug 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

must-not-merge:blocked-on-other-changesOther changes/PRs to be handled first. Label not needed for non-main changes.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@sangho2@github-advanced-security