On 03/31/2018 07:30 PM, Gilad Ben-Yossef wrote: ... >> Are there other crypto drivers doing this? > > I thought the exact same thing until I ran into a presentation about the s390 > secure keys implementation. I basically imitated their use (or abuse?) > of the Crypto API > assuming it is the way to go. > > Take a look at arch/s390/crypto/paes_s390.c > > The slide for the presentation describing this is here: > http://schd.ws/hosted_files/ossna2017/89/LC2017SecKeyDmCryptV5.pdf > > And they seem to even have support for it in the DM-Crypt tools, which at > the time they claimed to be in the process of getting it up-streamed. It is "in the process", but definitely not accepted. We are just discussing how to integrate paes wrapped keys in cryptsetup and it will definitely not be the way presented in the slides above. If you plan more such ciphers, I would welcome some unified way in crypto API how to handle these HSM keys flavors. For kernel dm-crypt, there is no change needed (dmcrypt just treats it as a normal cipher key). (I would say that it is not the best idea either, IMHO it would be better to use kernel keyring reference instead and somehow handle hw keys through keyring.) Milan