feat: add NVS based secure storage layer for PSA

(cherry picked from commit 31c7bad7f74ce8e54ea0563b670df37a58215600)

Co-authored-by: Mahavir Jain <mahavir@espressif.com>
This commit is contained in:
Ashish Sharma
2025-12-19 07:29:00 +08:00
co-authored by Mahavir Jain
parent f306dbea84
commit 06d03e1a12
22 changed files with 856 additions and 131 deletions
+11 -6
View File
@@ -113,6 +113,7 @@ static esp_err_t handle_session_command1(session_t *cur_session,
psa_set_key_usage_flags(&key_attributes, PSA_KEY_USAGE_DECRYPT | PSA_KEY_USAGE_ENCRYPT);
psa_set_key_algorithm(&key_attributes, alg);
psa_set_key_type(&key_attributes, PSA_KEY_TYPE_AES);
psa_set_key_lifetime(&key_attributes, PSA_KEY_LIFETIME_VOLATILE);
psa_set_key_bits(&key_attributes, sizeof(cur_session->sym_key) * 8);
status = psa_import_key(&key_attributes, cur_session->sym_key, sizeof(cur_session->sym_key), &key_id);
if (status != PSA_SUCCESS) {
@@ -447,21 +448,25 @@ static esp_err_t sec1_close_session(protocomm_security_handle_t handle, uint32_t
// if (cur_session->state == SESSION_STATE_DONE) {
/* Free AES context data */
if (cur_session->key_id != 0) {
psa_status_t status = psa_destroy_key(cur_session->key_id);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "psa_destroy_key failed with status=%d", status);
// return ESP_FAIL;
}
status = psa_destroy_key(cur_session->key_id_sym);
}
if (cur_session->key_id_sym != 0) {
psa_status_t status = psa_destroy_key(cur_session->key_id_sym);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "psa_destroy_key failed with status=%d", status);
// return ESP_FAIL;
}
status = psa_cipher_abort(&cur_session->ctx_aes);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "psa_cipher_abort failed with status=%d", status);
// return ESP_FAIL;
}
}
psa_status_t status = psa_cipher_abort(&cur_session->ctx_aes);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "psa_cipher_abort failed with status=%d", status);
// return ESP_FAIL;
}
// }
memset(cur_session, 0, sizeof(session_t));
@@ -21,7 +21,7 @@
/* setUp runs before every test */
void setUp(void)
{
#if SOC_SHA_SUPPORTED
#if CONFIG_MBEDTLS_HARDWARE_SHA
// Execute esp_sha operation to allocate internal SHA semaphore (in case of ESP32)
// and initial DMA setup memory which is considered as leaked otherwise
const uint8_t input_buffer[64] = {0};
@@ -35,7 +35,7 @@ void setUp(void)
#if SOC_SHA_SUPPORT_SHA512
esp_sha(SHA2_512, input_buffer, sizeof(input_buffer), output_buffer);
#endif // SOC_SHA_SUPPORT_SHA512
#endif // SOC_SHA_SUPPORTED
#endif // CONFIG_MBEDTLS_HARDWARE_SHA
#if defined(CONFIG_MBEDTLS_HARDWARE_MPI)
esp_mpi_enable_hardware_hw_op();
@@ -55,6 +55,7 @@ void setUp(void)
psa_set_key_algorithm(&attributes, PSA_ALG_CBC_NO_PADDING);
psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
psa_set_key_bits(&attributes, 128);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
status = psa_import_key(&attributes, key, sizeof(key), &key_id);
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
size_t output_len = 0;
@@ -67,7 +68,11 @@ void setUp(void)
status = psa_cipher_encrypt(key_id, PSA_ALG_CBC_NO_PADDING, plaintext_long, sizeof(plaintext_long), ciphertext_long, sizeof(ciphertext_long), &output_len);
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
psa_destroy_key(key_id);
#endif // SOC_AES_SUPPORTED
// Destroying the key again to get rid of nvs flash memory leak
// If the key doesn't exist, PSA looks for it in nvs and that
// allocates some memory which is considered as leak otherwise
psa_destroy_key(key_id);
// #endif // SOC_AES_SUPPORTED
test_utils_record_free_mem();
TEST_ESP_OK(test_utils_set_leak_level(50, ESP_LEAK_TYPE_CRITICAL, ESP_COMP_LEAK_GENERAL));