From 25b55da173bdc730fb1b404daa716b8b70481e7b Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Tue, 14 Jul 2026 15:55:26 +0800 Subject: [PATCH] feat(mbedtls): add option to choose constant-time prime generation --- components/mbedtls/Kconfig | 35 ++++++++++++++++--- components/mbedtls/mbedtls | 2 +- .../mbedtls/port/include/mbedtls/esp_config.h | 11 ++++++ components/mbedtls/test_apps/main/test_rsa.c | 9 ++++- 4 files changed, 50 insertions(+), 7 deletions(-) diff --git a/components/mbedtls/Kconfig b/components/mbedtls/Kconfig index 0b450f7ae22..c28c628344f 100644 --- a/components/mbedtls/Kconfig +++ b/components/mbedtls/Kconfig @@ -255,11 +255,11 @@ menu "mbedTLS" and in RFC 8446, Section 7.5, for TLS 1.3. config MBEDTLS_PKCS7_C - bool "Enable PKCS #7" + bool "Enable PKCS number 7" default y depends on MBEDTLS_X509_CRL_PARSE_C help - Enable PKCS #7 core for using PKCS #7-formatted signatures. + Enable PKCS number 7 core for using PKCS number 7-formatted signatures. config MBEDTLS_SSL_CID_PADDING_GRANULARITY int "Record plaintext padding" @@ -540,6 +540,31 @@ menu "mbedTLS" priority level and any level from 1 to 3 can be selected (based on the availability). Note: Higher value indicates high interrupt priority. + menu "Security hardening" + + config MBEDTLS_CONSTANT_TIME_PRIME_GEN + bool "Constant-time prime generation" + default n + help + Use mbedtls' constant-time small-factor test (a constant-time + GCD against the product of all odd primes up to 997) when + generating prime numbers, e.g. during RSA key generation. + + The constant-time implementation avoids a timing side channel + in prime generation, but it makes RSA key generation roughly + ten times slower, and its long non-yielding software + computations can starve the idle task and trigger the task + watchdog, so key generation code may need a larger watchdog + timeout or the watchdog disabled. + + If disabled, the variable-time trial division that mbedtls + used before version 3.6.7 is used instead, restoring key + generation performance. + + Please see issue: https://github.com/Mbed-TLS/mbedtls/issues/10830 + + endmenu # Security hardening + config MBEDTLS_HARDWARE_SHA bool "Enable hardware SHA acceleration" default y @@ -844,21 +869,21 @@ menu "mbedTLS" depends on MBEDTLS_KEY_EXCHANGE_ELLIPTIC_CURVE && MBEDTLS_ECDH_C && MBEDTLS_ECDSA_C default y help - Enable to support ciphersuites with prefix TLS-ECDHE-RSA-WITH- + Enable to support ciphersuites with prefix TLS-ECDHE-ECDSA-WITH- config MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA bool "Enable ECDH-ECDSA based ciphersuite modes" depends on MBEDTLS_KEY_EXCHANGE_ELLIPTIC_CURVE && MBEDTLS_ECDH_C && MBEDTLS_ECDSA_C default y help - Enable to support ciphersuites with prefix TLS-ECDHE-RSA-WITH- + Enable to support ciphersuites with prefix TLS-ECDH-ECDSA-WITH- config MBEDTLS_KEY_EXCHANGE_ECDH_RSA bool "Enable ECDH-RSA based ciphersuite modes" depends on MBEDTLS_KEY_EXCHANGE_ELLIPTIC_CURVE && MBEDTLS_ECDH_C default y help - Enable to support ciphersuites with prefix TLS-ECDHE-RSA-WITH- + Enable to support ciphersuites with prefix TLS-ECDH-RSA-WITH- config MBEDTLS_KEY_EXCHANGE_ECJPAKE bool "Enable ECJPAKE based ciphersuite modes" diff --git a/components/mbedtls/mbedtls b/components/mbedtls/mbedtls index 64c8e14bffd..2b96dd8eebe 160000 --- a/components/mbedtls/mbedtls +++ b/components/mbedtls/mbedtls @@ -1 +1 @@ -Subproject commit 64c8e14bffd76abaec7a04f9e44aba00a9aad1f5 +Subproject commit 2b96dd8eebe880f304c69976b3c2fa0c5100cbb6 diff --git a/components/mbedtls/port/include/mbedtls/esp_config.h b/components/mbedtls/port/include/mbedtls/esp_config.h index 6a95daa50ad..7a40177414f 100644 --- a/components/mbedtls/port/include/mbedtls/esp_config.h +++ b/components/mbedtls/port/include/mbedtls/esp_config.h @@ -212,6 +212,17 @@ #undef MBEDTLS_MPI_MUL_MPI_ALT #endif +/* mbedtls 3.6.7 made the small-factor test used in prime generation + * constant-time, which slows RSA key generation down roughly tenfold and + * starves the idle task (the computation never yields the CPU). The + * non constant-time variant is the default; when it is disabled, + * fall back to the variable-time trial division from earlier releases. See + * MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME in library/bignum.c. + */ +#ifndef CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN +#define MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME +#endif + #ifdef CONFIG_MBEDTLS_ATCA_HW_ECDSA_SIGN #define MBEDTLS_ECDSA_SIGN_ALT #endif diff --git a/components/mbedtls/test_apps/main/test_rsa.c b/components/mbedtls/test_apps/main/test_rsa.c index 457caaa45d6..f81b4084f0c 100644 --- a/components/mbedtls/test_apps/main/test_rsa.c +++ b/components/mbedtls/test_apps/main/test_rsa.c @@ -3,7 +3,7 @@ * Focus on testing functionality where we use ESP32 hardware * accelerated crypto features * - * SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2021-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -570,6 +570,12 @@ static void rsa_key_operations(int keysize, bool check_performance, bool generat } +/* With constant-time prime generation the RSA-2048 key generation below takes + * over a minute on most targets (~86 s on ESP32-S3), exceeding the test + * timeout and starving the task watchdog, so only run it with the faster + * variable-time implementation. + */ +#if !CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN TEST_CASE("mbedtls RSA Generate Key", "[mbedtls][timeout=60]") { @@ -607,5 +613,6 @@ TEST_CASE("mbedtls RSA Generate Key", "[mbedtls][timeout=60]") #endif // CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT } +#endif // !CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN #endif // CONFIG_MBEDTLS_HARDWARE_MPI