mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
feat(esp_tee): Restrict REE access to TEE-owned secure storage keys
This commit is contained in:
@@ -204,7 +204,7 @@ static int tee_sec_stg_gen_key(int argc, char **argv)
|
||||
|
||||
err = esp_tee_sec_storage_clear_key(cfg.id);
|
||||
if (err != ESP_OK && err != ESP_ERR_NOT_FOUND) {
|
||||
ESP_LOGE(TAG, "Failed to clear key %d!", cfg.id);
|
||||
ESP_LOGE(TAG, "Failed to clear key %s!", cfg.id);
|
||||
goto exit;
|
||||
}
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD
|
||||
# SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
import hashlib
|
||||
import http.server
|
||||
@@ -135,10 +135,6 @@ def test_tee_cli_attestation(dut: Dut) -> None:
|
||||
dut.expect('ESP-TEE: Secure services demonstration', timeout=30)
|
||||
time.sleep(1)
|
||||
|
||||
att_key_id = dut.app.sdkconfig.get('SECURE_TEE_ATT_KEY_STR_ID')
|
||||
dut.write(f'tee_sec_stg_gen_key {att_key_id} 1')
|
||||
dut.expect(r'Generated ECDSA_SECP256R1 key with ID (\S+)', timeout=30)
|
||||
|
||||
# Get the Entity Attestation token from TEE and verify its signature
|
||||
dut.write('tee_att_info')
|
||||
dut.expect(r'Attestation token - Length: (\d+)', timeout=30)
|
||||
|
||||
@@ -5,8 +5,8 @@ CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
|
||||
# Reducing TEE I/DRAM sizes
|
||||
# 24KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x6000
|
||||
# 16KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x4000
|
||||
# 17KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x4400
|
||||
|
||||
# Disable TEE logs (also disable all panic logs)
|
||||
CONFIG_SECURE_TEE_DEBUG_MODE=n
|
||||
|
||||
@@ -2,8 +2,8 @@
|
||||
# builds across various configurations - and is not intended for production use.
|
||||
|
||||
# Reducing TEE IRAM size
|
||||
# 30KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7800
|
||||
# 31KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7C00
|
||||
|
||||
# TEE Secure Storage: Release mode
|
||||
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
|
||||
|
||||
@@ -418,6 +418,7 @@ class TEESerial(IdfSerial):
|
||||
'type': 'ecdsa_p256',
|
||||
'input': 'ecdsa_p256_key.pem',
|
||||
'write_once': True,
|
||||
'tee_only': True,
|
||||
'b64': (
|
||||
'LS0tLS1CRUdJTiBFQyBQUklWQVRFIEtFWS0tLS0tCk1IY0NBUUVFSUlNU1VpUktHaVZjSTIvbUZFekI3eXRIOVJj'
|
||||
'd0wyUThkNDhONHNFUHFYc0RvQW9HQ0NxR1NNNDkKQXdFSG9VUURRZ0FFSkYxYXRZQUxrdnB4cCt4N3c1dmVPQ1Vj'
|
||||
@@ -493,6 +494,7 @@ class TEESerial(IdfSerial):
|
||||
[sys.executable, ESP_TEE_SEC_STG_KEYGEN, '-k', entry['type'], '-o', str(tmp_dir / f'{entry["key"]}.bin')]
|
||||
+ (['-i', entry['input']] if entry['input'] else [])
|
||||
+ (['--write-once'] if entry['write_once'] else [])
|
||||
+ (['--tee-only'] if entry.get('tee_only') else [])
|
||||
for entry in self.KEY_DEFS
|
||||
]
|
||||
|
||||
|
||||
@@ -365,6 +365,38 @@ TEST_CASE("Test TEE Secure Storage - Null Pointer and Zero Length", "[sec_storag
|
||||
TEST_ESP_OK(esp_tee_sec_storage_clear_key(key_cfg.id));
|
||||
}
|
||||
|
||||
#if CONFIG_SECURE_TEE_ATTESTATION
|
||||
TEST_CASE("Test TEE Secure Storage - Attestation key is not REE-accessible", "[sec_storage]")
|
||||
{
|
||||
const char *att_key_id = CONFIG_SECURE_TEE_ATT_KEY_STR_ID;
|
||||
|
||||
esp_tee_sec_storage_key_cfg_t key_cfg = {
|
||||
.id = att_key_id,
|
||||
.type = ESP_SEC_STG_KEY_ECDSA_SECP256R1
|
||||
};
|
||||
|
||||
uint8_t digest[SHA256_DIGEST_SZ];
|
||||
esp_fill_random(digest, sizeof(digest));
|
||||
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_gen_key(&key_cfg));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_clear_key(att_key_id));
|
||||
|
||||
esp_tee_sec_storage_ecdsa_sign_t sign = {};
|
||||
esp_tee_sec_storage_ecdsa_pubkey_t pubkey = {};
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_ecdsa_sign(&key_cfg, digest, sizeof(digest), &sign));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_ecdsa_get_pubkey(&key_cfg, &pubkey));
|
||||
|
||||
uint8_t data[31], tag[12], iv[12];
|
||||
esp_tee_sec_storage_aead_ctx_t aead_ctx = {
|
||||
.key_id = att_key_id,
|
||||
.input = data,
|
||||
.input_len = sizeof(data),
|
||||
};
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_aead_encrypt(&aead_ctx, iv, sizeof(iv), tag, sizeof(tag), data));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_aead_decrypt(&aead_ctx, iv, sizeof(iv), tag, sizeof(tag), data));
|
||||
}
|
||||
#endif
|
||||
|
||||
TEST_CASE("Test TEE Secure Storage - Verify data encryption", "[sec_storage_encr]")
|
||||
{
|
||||
ESP_LOGI(TAG, "Populating NVS-based TEE Secure Storage; encrypted with XTS-AES-512");
|
||||
@@ -423,6 +455,22 @@ TEST_CASE("Test TEE Secure Storage - WRITE_ONCE keys", "[sec_storage]")
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_STATE, esp_tee_sec_storage_clear_key(key_cfg.id));
|
||||
}
|
||||
|
||||
TEST_CASE("Test TEE Secure Storage - TEE_ONLY keys", "[sec_storage]")
|
||||
{
|
||||
const char *key_id = "key_id_tee_only";
|
||||
esp_tee_sec_storage_key_cfg_t key_cfg = {
|
||||
.id = key_id,
|
||||
.type = ESP_SEC_STG_KEY_ECDSA_SECP256R1,
|
||||
.flags = SEC_STORAGE_FLAG_TEE_ONLY,
|
||||
};
|
||||
|
||||
esp_err_t err = esp_tee_sec_storage_clear_key(key_cfg.id);
|
||||
TEST_ASSERT_TRUE(err == ESP_OK || err == ESP_ERR_NOT_FOUND);
|
||||
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_gen_key(&key_cfg));
|
||||
TEST_ESP_ERR(ESP_ERR_NOT_FOUND, esp_tee_sec_storage_clear_key(key_cfg.id));
|
||||
}
|
||||
|
||||
static void test_aead_encrypt_decrypt(const char *key_id, const uint8_t *input, size_t len)
|
||||
{
|
||||
uint8_t *ciphertext = heap_caps_malloc(len, MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL);
|
||||
@@ -524,10 +572,19 @@ TEST_CASE("Test TEE Secure Storage - Host-generated keys", "[sec_storage_host_ke
|
||||
size_t token_len = 0;
|
||||
TEST_ESP_OK(psa_initial_attest_get_token(auth_challenge, challenge_size, token_buf, token_buf_size, &token_len));
|
||||
free(token_buf);
|
||||
|
||||
const char *attest_key_id = "attest_key";
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_STATE, esp_tee_sec_storage_clear_key(attest_key_id));
|
||||
#endif /* CONFIG_SECURE_TEE_ATTESTATION */
|
||||
|
||||
const char *attest_key_id = "attest_key";
|
||||
esp_tee_sec_storage_key_cfg_t attest_cfg = {
|
||||
.id = attest_key_id,
|
||||
.type = ESP_SEC_STG_KEY_ECDSA_SECP256R1,
|
||||
};
|
||||
esp_tee_sec_storage_ecdsa_sign_t attest_sign = {0};
|
||||
esp_tee_sec_storage_ecdsa_pubkey_t attest_pubkey = {0};
|
||||
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_ecdsa_sign(&attest_cfg, digest_buf, SHA256_DIGEST_SZ, &attest_sign));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_ecdsa_get_pubkey(&attest_cfg, &attest_pubkey));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_clear_key(attest_key_id));
|
||||
}
|
||||
|
||||
#if CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN
|
||||
|
||||
Reference in New Issue
Block a user