Keep the colleague's microbu-esp32c5 tree in this repository

obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but
that tree was gitignored, so a clone of this repository could not build the
firmware it ships. It is now committed here as ordinary files in its own
folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP
bridge's signature verification (--trust) used on the bench. Nothing is
fetched from or pushed to the colleague's repository; this repository and
its remotes carry everything. The folder's own .gitignore keeps build output,
downloaded components and private key material out, as it did there; the
committed file set is identical to that repository's tracked files.

The ESP32-C5 is still flashed from obu-firmware/, which only takes
vanetza-idf from microbu-esp32c5/, so the two stay separate folders.
FLASHING.md says how to take a newer version of the colleague's tree (copy
it over the folder, rebuild, test, commit).
This commit is contained in:
Ashin Walpola
2026-09-23 17:46:40 +02:00
parent 2f60623e18
commit 0e9525162d
9881 changed files with 1582523 additions and 17 deletions
@@ -0,0 +1,52 @@
# SystemX Hybrid-PQC ASN.1 Profile
This directory keeps the experimental certificate additions separate from
Vanetza's standard ASN.1 inputs. `hybrid-pqc.patch` contains the complete
experimental delta. The unmodified input modules are fetched from pinned
official ETSI Forge revisions during regeneration instead of being duplicated
in the source tree.
The IEEE inputs are from the official `v2025` tag of the ETSI Forge mirror:
* repository: `https://forge.etsi.org/rep/ITS/asn1/ieee1609.2.git`
* commit: `77e2c822a11bf8adbe9848ad3fd4f311925aff30`
* `Ieee1609Dot2.asn` SHA-256:
`82b5e35cbaadae1c6b2f087626b10d52afc73779c9ac6700c6445830d8824e0b`
* `Ieee1609Dot2BaseTypes.asn` SHA-256:
`bf2b3d66d394449319323f8a59d8084d963c3ad55d6790e1436ab897221690fe`
The two ETSI TS 103 097 inputs are fetched from the official Release 2
repository:
* repository: `https://forge.etsi.org/rep/ITS/asn1/sec_ts103097.git`
* commit: `65e6d8ea88b2bfb3aca3151dbedf07d89b97fd00`
* `EtsiTs103097Module.asn` SHA-256:
`245a3c10c176497f658c6a4d9ec804d3226dda2ac10a4351e382ddb5afe9ff72`
* `EtsiTs103097ExtensionModule.asn` SHA-256:
`b94c9b373567dd9bfb15d61c8c206d5630f6b0c481ef41ddd574c96784a9eb1a`
The patch adds only the certificate material used by this implementation:
* the fixed-size `FnDsa512Key` and `FnDsa512Signature` types;
* FN-DSA-512 choices in `PublicVerificationKey` and `Signature`;
* `altVerificationKey` and `altSignatureValue` in
`ToBeSignedCertificate`.
## Regeneration
Normal builds compile the committed generated files and do not need network
access, `asn1c`, Docker, or the patch utility. Regeneration is an explicit
maintainer action:
```shell
cmake -S . -B build-asn1 \
-DVANETZA_WITH_PQC=ON \
-DVANETZA_ASN1_WITH_ASN1C=ON \
-DVANETZA_ASN1_WITH_ISO=ON
cmake --build build-asn1 --target generate_asn1c
```
The generation target fetches and verifies the pristine inputs in its build
directory, applies `hybrid-pqc.patch`, invokes `asn1c`, and refreshes the
committed output under `vanetza/asn1/systemx-pqc`.
@@ -0,0 +1,101 @@
--- a/Ieee1609Dot2.asn
+++ b/Ieee1609Dot2.asn
@@ -10,7 +10,7 @@
Ieee1609Dot2 {iso(1) identified-organization(3) ieee(111)
standards-association-numbered-series-standards(2) wave-stds(1609)
- dot2(2) base(1) schema(1) major-version-2(2) minor-version-7(7)}
+ dot2(2) base(1) schema(1) major-version-2(2) minor-version-8(8)}
DEFINITIONS AUTOMATIC TAGS ::= BEGIN
@@ -24,6 +24,7 @@
EXT-TYPE,
Extension,
ExtId,
+ FnDsa512Key,
GeographicRegion,
GroupLinkageValue,
HashAlgorithm,
@@ -1048,6 +1049,13 @@
* @param certRequestExtensions: indicates additional permissions to request
* certificates containing endEntityExtensions.
*
+ * @param altVerificationKey: carries the alternative FN-DSA-512 public key
+ * in a hybrid authority certificate. It is absent from end-entity
+ * authorization tickets.
+ *
+ * @param altSignatureValue: carries the FN-DSA-512 signature generated by
+ * the issuer over this certificate.
+ *
* @note In IEEE Std 1609.2-2022 these were not marked optional; they are in
* this version of the standard; this is technically not backwards compatible
* but in practice there are no scenarios in which a legacy system will break
@@ -1160,7 +1168,9 @@
flags BIT STRING {usesCubk (0)} (SIZE (8)) OPTIONAL,
appExtensions SequenceOfAppExtensions OPTIONAL,
certIssueExtensions SequenceOfCertIssueExtensions OPTIONAL,
- certRequestExtension SequenceOfCertRequestExtensions OPTIONAL
+ certRequestExtension SequenceOfCertRequestExtensions OPTIONAL,
+ altVerificationKey PublicVerificationKey OPTIONAL,
+ altSignatureValue Signature OPTIONAL
}
(WITH COMPONENTS { ..., appPermissions PRESENT} |
WITH COMPONENTS { ..., certIssuePermissions PRESENT} |
--- a/Ieee1609Dot2BaseTypes.asn
+++ b/Ieee1609Dot2BaseTypes.asn
@@ -10,7 +10,7 @@
Ieee1609Dot2BaseTypes {iso(1) identified-organization(3) ieee(111)
standards-association-numbered-series-standards(2) wave-stds(1609) dot2(2)
- base(1) base-types(2) major-version-2(2) minor-version-5(5)}
+ base(1) base-types(2) major-version-2(2) minor-version-6(6)}
DEFINITIONS AUTOMATIC TAGS ::= BEGIN
@@ -724,7 +724,8 @@
...,
ecdsaBrainpoolP384r1Signature EcdsaP384Signature,
ecdsaNistP384Signature EcdsaP384Signature,
- sm2Signature EcsigP256Signature
+ sm2Signature EcsigP256Signature,
+ fnDsa512Signature FnDsa512Signature
}
/**
@@ -821,6 +822,12 @@
}
/**
+ * @brief This type contains an FN-DSA-512 signature as a fixed-size octet
+ * string.
+ */
+FnDsa512Signature ::= OCTET STRING (SIZE (666))
+
+/**
* @brief This structure specifies a point on an elliptic curve in Weierstrass
* form defined over a 256-bit prime number. The curves supported in this
* standard are NIST p256 as defined in FIPS 186-5, Brainpool p256r1 as
@@ -888,6 +895,12 @@
}
/**
+ * @brief This type contains an FN-DSA-512 public verification key as a
+ * fixed-size octet string.
+ */
+FnDsa512Key ::= OCTET STRING (SIZE (897))
+
+/**
* @brief This enumerated value indicates supported symmetric algorithms. The
* algorithm identifier identifies both the algorithm itself and a specific
* mode of operation. The symmetric algorithms supported in this version of
@@ -1045,7 +1058,8 @@
... ,
ecdsaBrainpoolP384r1 EccP384CurvePoint,
ecdsaNistP384 EccP384CurvePoint,
- ecsigSm2 EccP256CurvePoint
+ ecsigSm2 EccP256CurvePoint,
+ fnDsa512 FnDsa512Key
}
/**