mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat(esp_tee): Restrict REE access to TEE-owned secure storage keys
This commit is contained in:
@@ -204,7 +204,7 @@ static int tee_sec_stg_gen_key(int argc, char **argv)
|
||||
|
||||
err = esp_tee_sec_storage_clear_key(cfg.id);
|
||||
if (err != ESP_OK && err != ESP_ERR_NOT_FOUND) {
|
||||
ESP_LOGE(TAG, "Failed to clear key %d!", cfg.id);
|
||||
ESP_LOGE(TAG, "Failed to clear key %s!", cfg.id);
|
||||
goto exit;
|
||||
}
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD
|
||||
# SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
import hashlib
|
||||
import http.server
|
||||
@@ -135,10 +135,6 @@ def test_tee_cli_attestation(dut: Dut) -> None:
|
||||
dut.expect('ESP-TEE: Secure services demonstration', timeout=30)
|
||||
time.sleep(1)
|
||||
|
||||
att_key_id = dut.app.sdkconfig.get('SECURE_TEE_ATT_KEY_STR_ID')
|
||||
dut.write(f'tee_sec_stg_gen_key {att_key_id} 1')
|
||||
dut.expect(r'Generated ECDSA_SECP256R1 key with ID (\S+)', timeout=30)
|
||||
|
||||
# Get the Entity Attestation token from TEE and verify its signature
|
||||
dut.write('tee_att_info')
|
||||
dut.expect(r'Attestation token - Length: (\d+)', timeout=30)
|
||||
|
||||
@@ -5,8 +5,8 @@ CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
|
||||
# Reducing TEE I/DRAM sizes
|
||||
# 24KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x6000
|
||||
# 16KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x4000
|
||||
# 17KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x4400
|
||||
|
||||
# Disable TEE logs (also disable all panic logs)
|
||||
CONFIG_SECURE_TEE_DEBUG_MODE=n
|
||||
|
||||
@@ -2,8 +2,8 @@
|
||||
# builds across various configurations - and is not intended for production use.
|
||||
|
||||
# Reducing TEE IRAM size
|
||||
# 30KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7800
|
||||
# 31KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7C00
|
||||
|
||||
# TEE Secure Storage: Release mode
|
||||
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
|
||||
|
||||
Reference in New Issue
Block a user