mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 10:40:47 +03:00
feat(esp_tee): Restrict REE access to TEE-owned secure storage keys
This commit is contained in:
@@ -18,6 +18,8 @@ options:
|
||||
-o, --output OUTPUT output binary file name
|
||||
-i, --input INPUT input key file (.pem for ecdsa, .bin for aes)
|
||||
--write-once make key persistent - cannot be modified or deleted once written
|
||||
--tee-only mark key as owned exclusively by the TEE - the REE cannot use, generate or clear it
|
||||
-h, --help Show this message and exit
|
||||
```
|
||||
|
||||
### ECDSA Keys
|
||||
@@ -31,7 +33,7 @@ python esp_tee_sec_stg_keygen.py -k ecdsa_p384 -o ecdsa_p384_k0.bin
|
||||
|
||||
```bash
|
||||
openssl ecparam -name prime256v1 -genkey -noout -out ecdsa_p256.pem
|
||||
python esp_tee_sec_stg_keygen.py -k ecdsa_p256 -o ecdsa_p256_k1.bin -i ecdsa_p256.pem --write-once
|
||||
python esp_tee_sec_stg_keygen.py -k ecdsa_p256 -o ecdsa_p256_k1.bin -i ecdsa_p256.pem --write-once --tee-only
|
||||
```
|
||||
|
||||
### AES-256 Key
|
||||
|
||||
@@ -31,6 +31,7 @@ class KeyType(Enum):
|
||||
class Flags(IntFlag):
|
||||
NONE = 0x00000000
|
||||
WRITE_ONCE = 0x00000001
|
||||
TEE_ONLY = 0x00000002
|
||||
|
||||
|
||||
# === Key Generators ===
|
||||
@@ -112,6 +113,11 @@ def parse_args() -> argparse.Namespace:
|
||||
action='store_true',
|
||||
help='make key persistent - cannot be modified or deleted once written',
|
||||
)
|
||||
parser.add_argument(
|
||||
'--tee-only',
|
||||
action='store_true',
|
||||
help='mark key as owned exclusively by the TEE - the REE cannot use, generate or clear it',
|
||||
)
|
||||
return parser.parse_args()
|
||||
|
||||
|
||||
@@ -122,12 +128,16 @@ def main() -> None:
|
||||
flags = Flags.NONE
|
||||
if args.write_once:
|
||||
flags |= Flags.WRITE_ONCE
|
||||
if args.tee_only:
|
||||
flags |= Flags.TEE_ONLY
|
||||
|
||||
print(f'[+] Generating key of type: {key_type.name} (value: {key_type.value})')
|
||||
if args.input:
|
||||
print(f'[+] Using user-provided key file: {args.input}')
|
||||
if args.write_once:
|
||||
print('[+] WRITE_ONCE flag is set')
|
||||
if args.tee_only:
|
||||
print('[+] TEE_ONLY flag is set')
|
||||
|
||||
key_data = generate_key_data(key_type, flags, args.input)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user