[Suit] MCUboot SUIT discussions

David Brown <david.brown@linaro.org> Thu, 21 June 2018 14:42 UTC

Return-Path: <david.brown@linaro.org>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 194D8130DF0 for <suit@ietfa.amsl.com>; Thu, 21 Jun 2018 07:42:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=linaro.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KsVAdA7ol_NF for <suit@ietfa.amsl.com>; Thu, 21 Jun 2018 07:42:36 -0700 (PDT)
Received: from mail-it0-x242.google.com (mail-it0-x242.google.com [IPv6:2607:f8b0:4001:c0b::242]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 72C90130E96 for <suit@ietf.org>; Thu, 21 Jun 2018 07:42:36 -0700 (PDT)
Received: by mail-it0-x242.google.com with SMTP id a3-v6so5148560itd.0 for <suit@ietf.org>; Thu, 21 Jun 2018 07:42:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=date:from:to:cc:subject:message-id:mime-version:content-disposition :user-agent; bh=5431D/sLkGfypsiueJ+RMDKjDeaEJVH5k5IX1IhBeyU=; b=PMxEFIQ7gweY8dT/8FeM69+kM57X3K1IjRBWQgMdPobp6TohNER2v3OdI8mk5H4sUI vcHuKM8VeuPPwfFfhlZTMN5GdA3h8zACG2wE8tjWy4HMtHz0O0o0ejZuds/8QTkpaxhB NwAMcUNXGLRNR/Dsk/A0GwLVwO/89dOW7hYRs=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:mime-version :content-disposition:user-agent; bh=5431D/sLkGfypsiueJ+RMDKjDeaEJVH5k5IX1IhBeyU=; b=CqWDd/qDN04Mpm0qhq7dbIDM3aEf/nOTfWsnv6GtCmschWT2UKTrqBBqcPR63CiO3P mJPqeNQCM/hnoKvtTUFKFGUmkBlDSBHUJc0llnLgxiSz7thfRFnz53wQNaonktL8a+m1 jS5Qb2FFIRfHk5ZNQSVn3MBFsRRAw48vEZZ/UMlosnaXQ5oejXp7wR2QwLcVyoSUF6RK Tgh2Hti/KsGAhrICOa3e4N8QOYgUItm0whr7aiIPLlJN0NEnE6YlMGQvk/1dDT0yj9X7 /e34bDPVz9KUFxMSNxvPu4LU6x3fmOo8EiPXKVUfmNh1I0wuaZTGQUo3M5c2I9oLJxx4 sn7w==
X-Gm-Message-State: APt69E2bBapIMOe+9xQwMdAFnIqZ9SvlTK41TNlEllcAVrljWU0iTtTb NYKFOPDfrFsM0ccqBLUQOJqaT8Cb32Y=
X-Google-Smtp-Source: ADUXVKJxJEW7I2JR3hLJEcCSbSi5bej3WWvQyMx8fxA+SKj7YByo154eDdXjjCYFFGWqUQiWN3o2aQ==
X-Received: by 2002:a02:9b39:: with SMTP id o54-v6mr20445395jak.32.1529592155634; Thu, 21 Jun 2018 07:42:35 -0700 (PDT)
Received: from davidb.org ([2601:283:4300:987c::9]) by smtp.gmail.com with ESMTPSA id f127-v6sm1530092iof.32.2018.06.21.07.42.34 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 21 Jun 2018 07:42:35 -0700 (PDT)
Date: Thu, 21 Jun 2018 08:42:33 -0600
From: David Brown <david.brown@linaro.org>
To: "dev-mcuboot@lists.runtime.co" <dev-mcuboot@lists.runtime.co>
Cc: suit <suit@ietf.org>
Message-ID: <20180621144233.GA19590@davidb.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Disposition: inline
User-Agent: Mutt/1.9.4 (2018-02-28)
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/ufL7fHDlE9yn-usBICAwOXK-Syk>
Subject: [Suit] MCUboot SUIT discussions
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Jun 2018 14:42:39 -0000

I've written up the following in preparation for today's discussion of
the interaction of the IETF SUIT work, and work to add dual image
support to MCUboot.

# MCUboot and SUIT

- Currently, MCUboot supports a single image.

- Last week's LITE, we discussed requirements for multiple-image
  support:

  - One possibility is to consider the two images as a single unit,
    and always update them together.  If used with delta compression,
    this handles the case of only one image changing by encoding just
    a reference to the unchanged parts.

  - Another possibility is to have the images separate.

    - Two possibilities: independent updates, or both together
      atomically.

      - We need both of these.  Both together would be equivalent to
        treating them as a single unit.

      - Image metadata will need to describe the relationship between
        the images, for example, stating that version A of the first
        image will require version B of the second image.

      - The bootloader (and presumably the image download code) will
        need to determine this relationship, and only perform the
        upgrade when the conditions have been met.

- The IETF SUIT project is working to define a manifest format for
  embedded device firmware upgrades.

  - Among other things, they are addressing the same kinds of issues
    that we have.

  - This is a working group, and participants can influence the
    development of the standard.

- Possible ways for MCUboot to use SUIT.

  - "Ignore" SUIT.  SUIT is defined in such a way that its manifest
    could be used for the download part of the process, and the images
    would still contain the existing TLV information about versions
    and signature.

    - This doesn't address the multiple-image issues.

    - It is likely to be redundant to the metadata contained in the
      SUIT manifest.

    - It may require redundant signing of images, if SUIT is used, as
      the TLV information will also need to contain a signature.

  - Use SUIT instead of TLV for MCUboot

    - Pro: This will address the multiple image format issues

    - Con: There will likely be additional code to parse the
      manifests.  It is unclear how significant this difference will
      be, given that we would have to extend the TLV format to
      describe multiple images.

    - Con: The SUIT manifest format is a work-in-progress, and will
      likely change over time until the standard is formalized.

    - Pro: This addresses one security concern with the current TLV
      format, namely that the TLV data is not covered in the
      signature.  This is fine for now, because the TLV currently only
      contains information about the signature, but if we add
      dependency information, that information would be subject to
      tampering.

- My (David Brown) suggestions:

  - Start by adding support for the "single big image" solution.  This
    shouldn't require manifest changes, and may not require any
    changes to MCUboot.

  - Become more involved with the SUIT working group, to make sure
    MCUboot's needs are considered.

  - Implement a prototype alternate to TLV that works with the SUIT
    manifest format.

    - I recommend a custom parser and signature verification code.
      The existing libraries for these formats generally use malloc
      and are larger, more general code than we need.

    - We should restrict the SUIT manifest to a limited subset of the
      full format.  For examples, a given build may require a specific
      signature type to be present.

    - This should be a compile-time decision, and the TLV code should
      be maintained.

  - My suggestion would be to keep the existing header, but with a
    different magic number, and place the manifest at the end of the
    image, where the current TLV is.

- Ideas for things to extend SUIT with:

  - One of the images to contain the acceptable public keys for the
    other image.