From 8ad5504eb174cebb00fad0187611b395b46d5706 Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Fri, 10 Jul 2026 10:33:49 +0800 Subject: [PATCH 1/4] feat(mbedtls): update to version 4.1.1 --- components/mbedtls/mbedtls | 2 +- docs/en/api-reference/protocols/mbedtls.rst | 2 +- docs/zh_CN/api-reference/protocols/mbedtls.rst | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/components/mbedtls/mbedtls b/components/mbedtls/mbedtls index a2b32072ea8..2d4f3710465 160000 --- a/components/mbedtls/mbedtls +++ b/components/mbedtls/mbedtls @@ -1 +1 @@ -Subproject commit a2b32072ea898afc1ed5b6caf6931e36028c91d6 +Subproject commit 2d4f37104654bb8784e42d93d4a28f06a9d7d391 diff --git a/docs/en/api-reference/protocols/mbedtls.rst b/docs/en/api-reference/protocols/mbedtls.rst index 016329edde8..12de4c79eea 100644 --- a/docs/en/api-reference/protocols/mbedtls.rst +++ b/docs/en/api-reference/protocols/mbedtls.rst @@ -415,5 +415,5 @@ Reducing Binary Size Under ``Component Config`` > ``mbedTLS``, several Mbed TLS features are enabled by default. These can be disabled if not needed to save code size. More information is available in the :ref:`Minimizing Binary Size ` documentation. -.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v3.6.5/ +.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v4.1.1/ .. _`Knowledge Base`: https://mbed-tls.readthedocs.io/en/latest/kb/ diff --git a/docs/zh_CN/api-reference/protocols/mbedtls.rst b/docs/zh_CN/api-reference/protocols/mbedtls.rst index 3e2a318a454..f6371bf6534 100644 --- a/docs/zh_CN/api-reference/protocols/mbedtls.rst +++ b/docs/zh_CN/api-reference/protocols/mbedtls.rst @@ -415,5 +415,5 @@ Mbed TLS 配置系统支持预设配置。``Component Config`` > ``mbedTLS`` 中 在 ``Component Config`` > ``mbedTLS`` 配置中,多个 Mbed TLS 功能已默认启用。如无需使用,可以禁用以减小固件大小。详情请参阅 :ref:`最小化固件大小 `。 -.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v3.6.5/ +.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v4.1.1/ .. _`Knowledge Base`: https://mbed-tls.readthedocs.io/en/latest/kb/ From 73712ff5fd5e2916803559fcb7ba9a6200b44cae Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Tue, 14 Jul 2026 16:26:55 +0800 Subject: [PATCH 2/4] feat(mbedtls): add option to choose constant-time prime generation mbedtls 4.1.1 made the small-factor test in prime generation constant-time (a CT GCD against the product of primes up to 997, run for every prime candidate). This makes RSA key generation roughly ten times slower on ESP chips and starves the idle task since the software GCD never yields, tripping the task watchdog. Add MBEDTLS_CONSTANT_TIME_PRIME_GEN under the new "Security hardening" menu, default y so the upstream constant-time behavior ships as the secure default. When disabled, esp_config.h defines MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME and mbedtls uses the pre-3.6.7 variable-time trial division, restoring key generation performance on devices where no untrusted co-resident code could time key generation. --- components/mbedtls/Kconfig | 27 +++++++++++++++++++ .../mbedtls/port/include/mbedtls/esp_config.h | 12 +++++++++ 2 files changed, 39 insertions(+) diff --git a/components/mbedtls/Kconfig b/components/mbedtls/Kconfig index 2fc7f968f1f..f1bcdf83628 100644 --- a/components/mbedtls/Kconfig +++ b/components/mbedtls/Kconfig @@ -1419,6 +1419,33 @@ menu "mbedTLS" priority level and any level from 1 to 3 can be selected (based on the availability). Note: Higher value indicates high interrupt priority. + menu "Security hardening" + + config MBEDTLS_CONSTANT_TIME_PRIME_GEN + bool "Constant-time prime generation" + default y + help + Use mbedtls' constant-time small-factor test (a + constant-time GCD against the product of all odd primes up + to 997) when generating prime numbers, e.g. during RSA key + generation. + + The constant-time implementation avoids a timing side + channel in prime generation, but it makes RSA key + generation roughly ten times slower, and its long + non-yielding software computations can starve the idle + task and trigger the task watchdog, so key generation code + may need a larger watchdog timeout or the watchdog + disabled. + + If disabled, the variable-time trial division that mbedtls + used before versions 3.6.7/4.1.1 is used instead, + restoring key generation performance. Only consider + disabling this if no untrusted code running on the device + could observe the timing of key generation operations. + + endmenu # Security hardening + config MBEDTLS_HARDWARE_AES bool "Enable hardware AES acceleration" default y diff --git a/components/mbedtls/port/include/mbedtls/esp_config.h b/components/mbedtls/port/include/mbedtls/esp_config.h index 596a30faddb..2cb7ee2d622 100644 --- a/components/mbedtls/port/include/mbedtls/esp_config.h +++ b/components/mbedtls/port/include/mbedtls/esp_config.h @@ -257,6 +257,18 @@ #undef MBEDTLS_MPI_MUL_MPI_ALT #endif +/* mbedtls 4.1.1 made the small-factor test used in prime + * generation constant-time, which slows RSA key generation down roughly + * tenfold and starves the idle task (the computation never yields the CPU). + * The constant-time variant is the default; when it is explicitly disabled, + * fall back to the variable-time trial division from earlier releases. See + * MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME in + * tf-psa-crypto/drivers/builtin/src/bignum.c. + */ +#ifndef CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN +#define MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME +#endif + #if defined(CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY) || defined(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN) || defined(CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN) #define ESP_ECDSA_DRIVER_ENABLED #ifdef CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY From 57ff98ca13fa6854c6fba76a422439923008e061 Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Tue, 14 Jul 2026 16:45:38 +0800 Subject: [PATCH 3/4] test(mbedtls): add PSA RSA key generation test The test only runs with MBEDTLS_CONSTANT_TIME_PRIME_GEN disabled: with the constant-time prime generation that is now the default, RSA-2048 key generation takes over a minute on most targets (~86 s on ESP32-S3), exceeding the test timeout and starving the task watchdog. --- components/mbedtls/mbedtls | 2 +- .../test_apps/mbedtls_ut/main/test_psa_rsa.c | 49 ++++++++++++++++++- 2 files changed, 49 insertions(+), 2 deletions(-) diff --git a/components/mbedtls/mbedtls b/components/mbedtls/mbedtls index 2d4f3710465..ce3f3485a12 160000 --- a/components/mbedtls/mbedtls +++ b/components/mbedtls/mbedtls @@ -1 +1 @@ -Subproject commit 2d4f37104654bb8784e42d93d4a28f06a9d7d391 +Subproject commit ce3f3485a121c100f58f36d700cb35b060f6e866 diff --git a/components/mbedtls/test_apps/mbedtls_ut/main/test_psa_rsa.c b/components/mbedtls/test_apps/mbedtls_ut/main/test_psa_rsa.c index 84bec7b6992..1251f7e0fa8 100644 --- a/components/mbedtls/test_apps/mbedtls_ut/main/test_psa_rsa.c +++ b/components/mbedtls/test_apps/mbedtls_ut/main/test_psa_rsa.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Unlicense OR CC0-1.0 */ @@ -8,6 +8,7 @@ #include #include "esp_log.h" +#include "sdkconfig.h" #include "psa/crypto.h" #include "mbedtls/pk.h" @@ -17,6 +18,10 @@ #include "ccomp_timer.h" #include "test_utils.h" +#if CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT +#include "esp_task_wdt.h" +#endif + typedef enum { PSA_RSA_KEY_SIZE_2048, PSA_RSA_KEY_SIZE_3072, @@ -301,3 +306,45 @@ TEST_CASE("test performance RSA key operations", "[bignum]") keysize++; } } + +/* With constant-time prime generation the RSA-2048 key generation below takes + * over a minute on most targets (~86 s on ESP32-S3), exceeding the test + * timeout and starving the task watchdog, so only run it with the faster + * variable-time implementation. + */ +#if CONFIG_MBEDTLS_HARDWARE_MPI && !CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN + +TEST_CASE("PSA RSA generate key", "[mbedtls][timeout=60]") +{ +#if CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT + /* Check that generating keys doesn't starve the watchdog: long-running + * computations in key generation must not monopolize the CPU. */ + esp_task_wdt_config_t twdt_config = { + .timeout_ms = 1000, + .idle_core_mask = (1 << 0), // Watch core 0 idle + .trigger_panic = true, + }; + TEST_ASSERT_EQUAL(ESP_OK, esp_task_wdt_init(&twdt_config)); +#endif // CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT + + psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; + psa_key_id_t key_id; + + TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init()); + + psa_set_key_type(&attributes, PSA_KEY_TYPE_RSA_KEY_PAIR); + psa_set_key_algorithm(&attributes, PSA_ALG_RSA_PKCS1V15_CRYPT); + psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT); + psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE); + psa_set_key_bits(&attributes, 2048); + + TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_generate_key(&attributes, &key_id)); + + TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_destroy_key(key_id)); + psa_reset_key_attributes(&attributes); + +#if CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT + TEST_ASSERT_EQUAL(ESP_OK, esp_task_wdt_deinit()); +#endif // CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT +} +#endif // CONFIG_MBEDTLS_HARDWARE_MPI && !CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN From 2552d48f270694a27f2e403d040e9f9f3c6aad6d Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Tue, 21 Jul 2026 16:25:50 +0800 Subject: [PATCH 4/4] fix(mbedtls): revert to non constant time rsa key gen --- components/mbedtls/Kconfig | 8 ++++---- components/mbedtls/port/include/mbedtls/esp_config.h | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/components/mbedtls/Kconfig b/components/mbedtls/Kconfig index f1bcdf83628..069b15c4672 100644 --- a/components/mbedtls/Kconfig +++ b/components/mbedtls/Kconfig @@ -1423,7 +1423,7 @@ menu "mbedTLS" config MBEDTLS_CONSTANT_TIME_PRIME_GEN bool "Constant-time prime generation" - default y + default n help Use mbedtls' constant-time small-factor test (a constant-time GCD against the product of all odd primes up @@ -1440,9 +1440,9 @@ menu "mbedTLS" If disabled, the variable-time trial division that mbedtls used before versions 3.6.7/4.1.1 is used instead, - restoring key generation performance. Only consider - disabling this if no untrusted code running on the device - could observe the timing of key generation operations. + restoring key generation performance. + + Please see issue: https://github.com/Mbed-TLS/mbedtls/issues/10830 endmenu # Security hardening diff --git a/components/mbedtls/port/include/mbedtls/esp_config.h b/components/mbedtls/port/include/mbedtls/esp_config.h index 2cb7ee2d622..bc30d7000fa 100644 --- a/components/mbedtls/port/include/mbedtls/esp_config.h +++ b/components/mbedtls/port/include/mbedtls/esp_config.h @@ -260,7 +260,7 @@ /* mbedtls 4.1.1 made the small-factor test used in prime * generation constant-time, which slows RSA key generation down roughly * tenfold and starves the idle task (the computation never yields the CPU). - * The constant-time variant is the default; when it is explicitly disabled, + * The non constant-time variant is the default; when it is disabled, * fall back to the variable-time trial division from earlier releases. See * MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME in * tf-psa-crypto/drivers/builtin/src/bignum.c.