Re: [Suit] Fwd: Firmware Update Paper

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Wed, 04 December 2019 12:26 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C16E9120104 for <suit@ietfa.amsl.com>; Wed, 4 Dec 2019 04:26:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=EgvAAJic; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=armh.onmicrosoft.com header.b=zB2Z6iZL
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SobQr9ysNwHY for <suit@ietfa.amsl.com>; Wed, 4 Dec 2019 04:26:51 -0800 (PST)
Received: from EUR03-VE1-obe.outbound.protection.outlook.com (mail-eopbgr50047.outbound.protection.outlook.com [40.107.5.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0D3BA120119 for <suit@ietf.org>; Wed, 4 Dec 2019 04:26:50 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=IZFPoh7QTBBky3Sa8/lpkV+VH3UMVleT5EsIQz5yOuQ=; b=EgvAAJicS779PKxWliyAa7SWUqXE9+pioIK8yxAIEvWL7hrhV2o2CufC+1MLd42BB8uTmP4n5AxUbS/dYPTsxXu+rkSJ1HZHTAPUoftBQT8goCbdDxq2VXzQLIRqFIYbbjSkheHrt1G+0lzKPdyzdLHviMsgL+jpcmjJHB5ZUF0=
Received: from AM6PR08CA0041.eurprd08.prod.outlook.com (2603:10a6:20b:c0::29) by VI1PR0802MB2350.eurprd08.prod.outlook.com (2603:10a6:800:99::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2516.13; Wed, 4 Dec 2019 12:26:48 +0000
Received: from VE1EUR03FT032.eop-EUR03.prod.protection.outlook.com (2a01:111:f400:7e09::207) by AM6PR08CA0041.outlook.office365.com (2603:10a6:20b:c0::29) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2516.13 via Frontend Transport; Wed, 4 Dec 2019 12:26:47 +0000
Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=bestguesspass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT032.mail.protection.outlook.com (10.152.18.121) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2495.18 via Frontend Transport; Wed, 4 Dec 2019 12:26:47 +0000
Received: ("Tessian outbound 54081306375c:v37"); Wed, 04 Dec 2019 12:26:45 +0000
X-CR-MTA-TID: 64aa7808
Received: from 17a4298ccb96.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 86BC22DB-10F6-4122-81E6-1AE3D8D3ED6A.1; Wed, 04 Dec 2019 12:26:40 +0000
Received: from EUR02-AM5-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 17a4298ccb96.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Wed, 04 Dec 2019 12:26:40 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=gLHSXOoEhD4npnfr2ypB+Z6Ic6DFlajYOG9tuhxqX6KDb8rUZV2DCyzWjsdi+1KZ5zBBMyk23ypdu9tUPnkcVMknnSNnoTeqWFDi8O0Qw081xMfPaeJMi1Ud4VFshxzPrAOWmyQ1m7V6CiaKz1knOcVVdEGp6QSZDboKG/fPpKSoOkS7bwjKPrfN8ts8/FhuMMz63FDnwwlduUfGiyORKT50w6vAKbZp+sCvlrrlpYFv1okSdPRdg9r8KCN60fkmKZkJj6E2SMRI3VbKmJh49fIRAqleAIkKS258ZnRSFUVC2gAR7XLddQHFXGgWPuOmBXLCom3Lx6ooybdkuC9zgA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ZEx786VJQFFw74NhWtKa6RrBlc4xQZ1S8BiOfev/Oqg=; b=WbbG7wmlXbM3STax/rJ/ku4oKyQ/AnIrxrw7Fe5ZskPZMpzlLgZrMVZMp3s3a41qWU47Uam3SD8YCt/fUh2rp/gUWUDiSP7eS5P0aRaCejfrsIu+4HCMoM/0At53mUHUw3d8G4GO5m4wIoQ29GB6zgO17dqX7KcUnVOorAm1daYfLY1Ff84B8E4RLMC3Z+Y1hPhjSOfJjZbVYm2qXDtlbEaC2cBwkskRHi1UVz+3dqiGfSDPlghUYNKacUM/ersmqJMVvEwffaka4buRhz6TTyFyo+i2mMoEADlaD3K3feCxE1EsLBW5GYoK8OLx2KmUDbDE1ELw+9lEwD2RCXDQdQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ZEx786VJQFFw74NhWtKa6RrBlc4xQZ1S8BiOfev/Oqg=; b=zB2Z6iZLXNvCPrqegkZooP9PJgnLNLO4qda5fJBhMVh6nr1slqNKz72fJQ6pybHumPQD1kzDNkR8pAMOTkt6rHaeM2zcKBbcIE4RKLrLBHIMST75lGQ/rf2kVDVIQ2bXj5GpIaumd2NE8LfeozAmB3d0Qf1bRKqDdYPJDGOQAlo=
Received: from VI1PR08MB5360.eurprd08.prod.outlook.com (52.133.245.74) by VI1PR08MB4494.eurprd08.prod.outlook.com (20.179.25.21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2495.18; Wed, 4 Dec 2019 12:26:39 +0000
Received: from VI1PR08MB5360.eurprd08.prod.outlook.com ([fe80::4044:55a8:a969:fd1d]) by VI1PR08MB5360.eurprd08.prod.outlook.com ([fe80::4044:55a8:a969:fd1d%7]) with mapi id 15.20.2516.013; Wed, 4 Dec 2019 12:26:39 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: Emmanuel Baccelli <Emmanuel.Baccelli@inria.fr>, "suit@ietf.org" <suit@ietf.org>
Thread-Topic: [Suit] Fwd: Firmware Update Paper
Thread-Index: AQHVqj2tkJLkkD1tkU6oXdMBpNs+Yaep2i4AgAAJDgA=
Date: Wed, 04 Dec 2019 12:26:39 +0000
Message-ID: <VI1PR08MB5360CF7EFDF7C550D0D7E755FA5D0@VI1PR08MB5360.eurprd08.prod.outlook.com>
References: <VI1PR08MB53600B1D1A194F49B67B90DFFAC60@VI1PR08MB5360.eurprd08.prod.outlook.com> <20191127203651.GA117656@davidb.org> <CANK0pbaWkn7w2swRgkOqsTubE1os=rDo2BLjrTZ5eW6ePv3WnA@mail.gmail.com> <20191129183627.GA16289@davidb.org> <DB6PR0801MB1879D9742622EA0AE08A8B72EA430@DB6PR0801MB1879.eurprd08.prod.outlook.com> <CABNHR1yEFvgEzHjBhpqTW-FX+LQTVYuSJE_9SP9OMwzjWsdORQ@mail.gmail.com> <CANK0pbaf8TTtMOSKHD0D-73+MCzSdjk7p+6hVO0WzpSxhF2fVg@mail.gmail.com> <CABNHR1z4N=uH9d5DvyYi17DCULqu3T6Ve9k-_EJr-37zUjF-uw@mail.gmail.com> <CANK0pbYGbzu8VAr7ZuzUOY1yQ75qkMKQ6PAncZCfkH2=RZWNUQ@mail.gmail.com> <CABNHR1wOXx6QRYMMFgnNs12qtc5Ofs8MdR-Oe=d4KRCzXtaiQA@mail.gmail.com> <CANK0pbagZtjzE4vsW6ez76aT2sFeNj_vMr=fKP8Xo6kvCcSF9A@mail.gmail.com>
In-Reply-To: <CANK0pbagZtjzE4vsW6ez76aT2sFeNj_vMr=fKP8Xo6kvCcSF9A@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: fcd976ff-90a2-4d16-8f26-628ee4e8954c.1
x-checkrecipientchecked: true
Authentication-Results-Original: spf=none (sender IP is ) smtp.mailfrom=Hannes.Tschofenig@arm.com;
x-originating-ip: [80.92.119.90]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: 366f06a1-2b03-4051-708a-08d778b53b7b
X-MS-TrafficTypeDiagnostic: VI1PR08MB4494:|VI1PR0802MB2350:
X-Microsoft-Antispam-PRVS: <VI1PR0802MB235094C27C49C50713F47610FA5D0@VI1PR0802MB2350.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
x-ms-oob-tlc-oobclassifiers: OLM:9508;OLM:9508;
x-forefront-prvs: 0241D5F98C
X-Forefront-Antispam-Report-Untrusted: SFV:NSPM; SFS:(10009020)(4636009)(396003)(39860400002)(376002)(366004)(346002)(136003)(189003)(199004)(76176011)(478600001)(15650500001)(2501003)(81166006)(7736002)(99286004)(8676002)(5660300002)(14444005)(81156014)(8936002)(110136005)(74316002)(7696005)(52536014)(6436002)(11346002)(76116006)(3846002)(66556008)(66946007)(66476007)(7110500001)(14454004)(2420400007)(86362001)(790700001)(66446008)(64756008)(33656002)(316002)(71200400001)(6116002)(25786009)(229853002)(9686003)(186003)(966005)(6246003)(102836004)(71190400001)(6506007)(55016002)(26005)(6306002)(54896002)(2906002); DIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR08MB4494; H:VI1PR08MB5360.eurprd08.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: a2i5mFpEfcBfsr02caK1EQ5HUUihnzj2Qim+ZRz2i/r+ztAPYDMfSTlTtbpvZEzt5q4Oo+teTDh7g6drQJ/Pb0gOZT9v+XvIep88THw1B2YHGjFx/tldT9XYvZMOUik2ISZRZscbEP797bTrTROAVxLr0HHfS8OIHmf4QsSSZxIEmi/e1iyEJ8JiSnPP04RyX6xcWwZCVzkovrsJhGObt60wdL3dSFnuVh2j0ILb6BPtNoUj0Y+dTwxaK2y6NZETk0+cOab2XR8pt8wKEVyAAnsUmH8C61vnHJc7tGJJ42eEg31dNtrx0fXp6m+Jhd+gMvxhq4OtHavNiC9Iw9HSJc7SLsHm1JJ0ZyUWTHnHw3cvrSzzS6dYKJpOMeMI48deE+PIoyudKBmBKtf4HXcdzU7E4JfGl/iTHzSavmYq1zm632UEik8HexRn31K4b2yd8+uvQ839f5EUUqAo44hBaUavkjXDirL90Vfm9TmzPbY=
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_VI1PR08MB5360CF7EFDF7C550D0D7E755FA5D0VI1PR08MB5360eurp_"
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR08MB4494
Original-Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Hannes.Tschofenig@arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT032.eop-EUR03.prod.protection.outlook.com
X-Forefront-Antispam-Report: CIP:63.35.35.123; IPV:CAL; SCL:-1; CTRY:IE; EFV:NLI; SFV:NSPM; SFS:(10009020)(4636009)(136003)(39860400002)(396003)(376002)(346002)(40434004)(189003)(199004)(186003)(52536014)(76130400001)(2501003)(790700001)(6116002)(478600001)(26826003)(102836004)(26005)(6506007)(14454004)(25786009)(966005)(99286004)(70586007)(6246003)(110136005)(15650500001)(86362001)(70206006)(2420400007)(336012)(81156014)(81166006)(5660300002)(8676002)(8936002)(11346002)(9686003)(54896002)(6306002)(7696005)(3846002)(36906005)(229853002)(55016002)(316002)(33656002)(22756006)(71190400001)(356004)(5024004)(16586007)(74316002)(33964004)(14444005)(2906002)(7736002)(76176011); DIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR0802MB2350; H:64aa7808-outbound-1.mta.getcheckrecipient.com; FPR:; SPF:Pass; LANG:en; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; MX:1; A:1;
X-MS-Office365-Filtering-Correlation-Id-Prvs: 65bc6ad6-3631-4496-a247-08d778b5365f
X-Forefront-PRVS: 0241D5F98C
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: tpmTPAMX+6BBcT9foJWsgRueIH4lfcbaAYhxEjki/5Sjn1UMUJpi59e2G00BvhzQ8Wk4xs4X8k92mz6bm5jAsGdzxc83zu/5iTMF2bcXERbuOH4fNNvMAhiS/B7TLlV12yarwjiBqWFV9L992wMz5JFzzEHcOf5Kajr7Cu1ignf5cv6qijFBzNbIdboE+OUxj3cSKMM6T8qH5ZcRzWfKeMfdCsN/f7/mWJ2dmxJs3zY2vLZhs4H3oGjvEf0uGYZmlDACp2JOXjTean37MqwX51bI+d+BqN1047QZIpM9Hi6x9kLoQpJNG1PRhG/Jy0VPjCDZR74Cr68VlCz0bnZS4Pq66DW6zdINW/KUlcDGExNUi8ESOO4tsswRosMMugCNNY00vpQIHdyw7tQi2cyG/5OPkJoCuo8GY6Hr7/XT9uvgNYTdO258eksDVZaiF2QICgn0IvC/mIl5yu2wf7EXHmkkRoTOJfqzXO77fKHGeVc9aBSpCAZBs9wfx72fMv13L+NwMqtBV2HI5hJupXserOrsgBZTJzqm9MunxDvoEzU=
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Dec 2019 12:26:47.7142 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 366f06a1-2b03-4051-708a-08d778b53b7b
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR0802MB2350
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/7oE7iMqGEa8Kdu3_YK8MgbXG65M>
Subject: Re: [Suit] Fwd: Firmware Update Paper
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 04 Dec 2019 12:26:55 -0000

The signature verification was performed with the HACL library (ed25519) on an ARM Cortex-M0+ and took approx. 7 seconds -- so yes, pretty long indeed, in this case.

[SS] Does that scale linearly with image size? Do memory requirements (RAM usage) increase with the image size?


[EB] Not really: in the context of this paper, what is signed (and verified) is a hash of the image, not the image itself.

Adding to what Emmanuel said.

The memory requirements very much depend on the selected crypto implementation (and quite naturally the key size). There is also a relationship between the code size and the speed of execution. Code that has been hand-crafted for the specific MCU tends to be faster and consumes less memory than a generic implementation. This is inline with what is being stated in https://datatracker.ietf.org/doc/draft-ietf-lwig-curve-representations/. Needless to say that type of protection offered by an implementation (e.g., side channel attack resistance, such as resistance against remote timing attacks) has an impact on both code size as well as runtime performance.

It would be interesting to also analyze the heap requirements. As written in the paper, we focused only on the stack size.

Ciao
Hannes


IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.