Merge branch 'feat/mbedtls_update_4.1.1_v6.1' into 'release/v6.1'

Feat/mbedtls update 4.1.1 (v6.1)

See merge request espressif/esp-idf!50978
This commit is contained in:
Mahavir Jain
2026-08-27 12:26:56 +05:30
6 changed files with 90 additions and 4 deletions
+27
View File
@@ -1416,6 +1416,33 @@ menu "mbedTLS"
priority level and any level from 1 to 3 can be selected (based on the availability).
Note: Higher value indicates high interrupt priority.
menu "Security hardening"
config MBEDTLS_CONSTANT_TIME_PRIME_GEN
bool "Constant-time prime generation"
default n
help
Use mbedtls' constant-time small-factor test (a
constant-time GCD against the product of all odd primes up
to 997) when generating prime numbers, e.g. during RSA key
generation.
The constant-time implementation avoids a timing side
channel in prime generation, but it makes RSA key
generation roughly ten times slower, and its long
non-yielding software computations can starve the idle
task and trigger the task watchdog, so key generation code
may need a larger watchdog timeout or the watchdog
disabled.
If disabled, the variable-time trial division that mbedtls
used before versions 3.6.7/4.1.1 is used instead,
restoring key generation performance.
Please see issue: https://github.com/Mbed-TLS/mbedtls/issues/10830
endmenu # Security hardening
config MBEDTLS_HARDWARE_AES
bool "Enable hardware AES acceleration"
default y
@@ -257,6 +257,18 @@
#undef MBEDTLS_MPI_MUL_MPI_ALT
#endif
/* mbedtls 4.1.1 made the small-factor test used in prime
* generation constant-time, which slows RSA key generation down roughly
* tenfold and starves the idle task (the computation never yields the CPU).
* The non constant-time variant is the default; when it is disabled,
* fall back to the variable-time trial division from earlier releases. See
* MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME in
* tf-psa-crypto/drivers/builtin/src/bignum.c.
*/
#ifndef CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN
#define MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME
#endif
#if defined(CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY) || defined(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN) || defined(CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN)
#define ESP_ECDSA_DRIVER_ENABLED
#ifdef CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Unlicense OR CC0-1.0
*/
@@ -8,6 +8,7 @@
#include <string.h>
#include "esp_log.h"
#include "sdkconfig.h"
#include "psa/crypto.h"
#include "mbedtls/pk.h"
@@ -18,6 +19,10 @@
#include "test_utils.h"
#include "crypto_performance.h"
#if CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT
#include "esp_task_wdt.h"
#endif
typedef enum {
PSA_RSA_KEY_SIZE_2048,
PSA_RSA_KEY_SIZE_3072,
@@ -302,3 +307,45 @@ TEST_CASE("test performance RSA key operations", "[bignum]")
keysize++;
}
}
/* With constant-time prime generation the RSA-2048 key generation below takes
* over a minute on most targets (~86 s on ESP32-S3), exceeding the test
* timeout and starving the task watchdog, so only run it with the faster
* variable-time implementation.
*/
#if CONFIG_MBEDTLS_HARDWARE_MPI && !CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN
TEST_CASE("PSA RSA generate key", "[mbedtls][timeout=60]")
{
#if CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT
/* Check that generating keys doesn't starve the watchdog: long-running
* computations in key generation must not monopolize the CPU. */
esp_task_wdt_config_t twdt_config = {
.timeout_ms = 1000,
.idle_core_mask = (1 << 0), // Watch core 0 idle
.trigger_panic = true,
};
TEST_ASSERT_EQUAL(ESP_OK, esp_task_wdt_init(&twdt_config));
#endif // CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_id_t key_id;
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
psa_set_key_type(&attributes, PSA_KEY_TYPE_RSA_KEY_PAIR);
psa_set_key_algorithm(&attributes, PSA_ALG_RSA_PKCS1V15_CRYPT);
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
psa_set_key_bits(&attributes, 2048);
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_generate_key(&attributes, &key_id));
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_destroy_key(key_id));
psa_reset_key_attributes(&attributes);
#if CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT
TEST_ASSERT_EQUAL(ESP_OK, esp_task_wdt_deinit());
#endif // CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT
}
#endif // CONFIG_MBEDTLS_HARDWARE_MPI && !CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN
+1 -1
View File
@@ -413,5 +413,5 @@ Reducing Binary Size
Under ``Component Config`` > ``mbedTLS``, several Mbed TLS features are enabled by default. These can be disabled if not needed to save code size. More information is available in the :ref:`Minimizing Binary Size <minimizing_binary_mbedtls>` documentation.
.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v3.6.5/
.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v4.1.1/
.. _`Knowledge Base`: https://mbed-tls.readthedocs.io/en/latest/kb/
@@ -413,5 +413,5 @@ Mbed TLS 配置系统支持预设配置。``Component Config`` > ``mbedTLS`` 中
在 ``Component Config`` > ``mbedTLS`` 配置中,多个 Mbed TLS 功能已默认启用。如无需使用,可以禁用以减小固件大小。详情请参阅 :ref:`最小化固件大小 <minimizing_binary_mbedtls>`。
.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v3.6.5/
.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v4.1.1/
.. _`Knowledge Base`: https://mbed-tls.readthedocs.io/en/latest/kb/