@@ -754,3 +754,40 @@ pub trait CrngProvider {
754754 /// failures.
755755 fn fill_bytes_crng ( & self , buf : & mut [ u8 ] ) ;
756756}
757+
758+ /// A provider of the Platform Root Key (PRK).
759+ ///
760+ /// The PRK is a platform-unique secret which can be used to derive secret keys
761+ /// (e.g., TA unique keys, secure storage keys). It serves as the root of trust
762+ /// for cryptographic operations within the trusted or sandboxed execution
763+ /// environment. It resembles the root secret keys provided by trusted hardware
764+ /// devices (e.g., OP-TEE's Hardware Unique Key, DICE's Unique Device Secret,
765+ /// and TPM's Primary Seeds).
766+ ///
767+ /// Ideally, the platform should feature a persistent, hardware-backed key (e.g.,
768+ /// fused OTP, PUF-derived). The key should be unique per device, inaccessible
769+ /// outside the trusted environment, and never directly exposed---only used to
770+ /// derive other keys. If the platform lacks such hardware support (e.g., a
771+ /// userland platform), it may generate an ephemeral key from a boot nonce and
772+ /// CRNG, valid only for the current session.
773+ ///
774+ /// Note that we do not specify `set_platform_root_key` (yet). This is because
775+ /// each platform has its own way to initialize the PRK (e.g., no initialization
776+ /// if the PRK is baked into hardware, random numbers with different lengths,
777+ /// ...). The platform should initialize the PRK by itself or via the runner.
778+ pub trait PlatformRootKeyProvider {
779+ /// Returns a reference to the Platform Root Key.
780+ ///
781+ /// # Errors
782+ ///
783+ /// Returns [`PlatformRootKeyError`] if the PRK is not supported or not
784+ /// initialized.
785+ fn platform_root_key ( & self ) -> Result < & [ u8 ] , PlatformRootKeyError > {
786+ Err ( PlatformRootKeyError )
787+ }
788+ }
789+
790+ /// Error returned when the platform root key is not supported on the platform.
791+ #[ derive( Debug , Clone , Copy , PartialEq , Eq , Error ) ]
792+ #[ error( "platform root key is not supported on this platform" ) ]
793+ pub struct PlatformRootKeyError ;
0 commit comments