Merge branch 'fix/tee_reentrant_svc_and_non_det_sign_v6.1' into 'release/v6.1'

feat(esp_tee): Backports to v6.1

See merge request espressif/esp-idf!52291
This commit is contained in:
Jiang Jiang Jian
2026-09-04 23:17:06 +08:00
28 changed files with 899 additions and 332 deletions
@@ -27,7 +27,6 @@
#pragma once
#define MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS
#ifndef CONFIG_IDF_TARGET_LINUX
#undef MBEDTLS_PSA_BUILTIN_GET_ENTROPY
#define MBEDTLS_PSA_DRIVER_GET_ENTROPY
@@ -43,6 +42,12 @@
#if SOC_AES_SUPPORTED
#define ESP_AES_DRIVER_ENABLED
#define MBEDTLS_PSA_ACCEL_KEY_TYPE_AES
#define MBEDTLS_PSA_ACCEL_ALG_ECB_NO_PADDING
#define MBEDTLS_PSA_ACCEL_ALG_CBC_NO_PADDING
#define MBEDTLS_PSA_ACCEL_ALG_CBC_PKCS7
#define MBEDTLS_PSA_ACCEL_ALG_CFB
#define MBEDTLS_PSA_ACCEL_ALG_CTR
#define MBEDTLS_PSA_ACCEL_ALG_OFB
#endif
#define MBEDTLS_CIPHER_MODE_XTS
@@ -55,12 +60,10 @@
#endif
#define PSA_WANT_ECC_SECP_R1_256 1
#ifdef CONFIG_MBEDTLS_ECDSA_DETERMINISTIC
#define PSA_WANT_ALG_DETERMINISTIC_ECDSA 1
#else
/* ECDSA signatures over TEE secure-storage keys are compulsorily
* non-deterministic (randomized nonce) */
#undef PSA_WANT_ALG_DETERMINISTIC_ECDSA
#undef MBEDTLS_HMAC_DRBG_C
#endif
#if SOC_SHA_SUPPORTED
#define ESP_SHA_DRIVER_ENABLED
@@ -119,11 +122,14 @@
/* Disable unused cipher/algorithm types */
#undef PSA_WANT_KEY_TYPE_ARIA
#undef PSA_WANT_KEY_TYPE_CAMELLIA
#undef PSA_WANT_KEY_TYPE_CHACHA20
#undef PSA_WANT_KEY_TYPE_DES
#undef PSA_WANT_ALG_RIPEMD160
#undef PSA_WANT_ALG_STREAM_CIPHER
#undef PSA_WANT_ALG_CHACHA20
#undef PSA_WANT_ALG_CHACHA20_POLY1305
#undef PSA_WANT_ALG_CCM
#undef PSA_WANT_ALG_CCM_STAR_NO_TAG
#undef PSA_WANT_ALG_CMAC
#define MBEDTLS_AES_ROM_TABLES
@@ -165,6 +171,8 @@
#undef MBEDTLS_SSL_SRV_C
#undef PSA_WANT_ALG_TLS12_PRF
#undef PSA_WANT_ALG_TLS12_PSK_TO_MS
#undef PSA_WANT_ALG_TLS12_ECJPAKE_TO_PMS
#undef PSA_WANT_ALG_PBKDF2_HMAC
#undef PSA_WANT_ALG_PBKDF2_AES_CMAC_PRF_128
@@ -191,8 +199,8 @@
/* Disable self-test functions to save code size */
#undef MBEDTLS_SELF_TEST
/* TEE uses EXTERNAL_RNG, no need for CTR-DRBG */
#undef MBEDTLS_CTR_DRBG_C
/* CTR-DRBG for strengthening the RNG operations in TEE */
#define MBEDTLS_CTR_DRBG_C
/* Disable PEM/Base64 — TEE uses DER format */
#undef MBEDTLS_PEM_PARSE_C
+4 -7
View File
@@ -75,21 +75,18 @@ int esp_ecc_point_multiply(const ecc_point_t *point, const uint8_t *scalar, ecc_
int esp_ecc_point_verify(const ecc_point_t *point)
{
int result;
const unsigned len = point->len;
/* point->len drives a fixed-stride MMIO write loop in the HAL; an unvalidated oversized
* value (attacker-controlled via the TEE secure service) walks past the ECC register block
* and can reach other peripheral registers (CWE-787). Reject non-curve lengths up front and
* return 0 (point not verified) -- the fail-safe value for this routine. */
if (point->len != P192_LEN && point->len != P256_LEN
if (len != P192_LEN && len != P256_LEN
#if SOC_ECC_SUPPORT_CURVE_P384
&& point->len != P384_LEN
&& len != P384_LEN
#endif
) {
return 0;
}
esp_ecc_acquire_hardware();
ecc_hal_write_verify_param(point->x, point->y, point->len);
ecc_hal_write_verify_param(point->x, point->y, len);
ecc_hal_set_mode(ECC_MODE_VERIFY);
ecc_hal_start_calc();
+68 -1
View File
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2021-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -11,6 +11,62 @@
#include <entropy_poll.h>
#include "psa/crypto.h"
#if ESP_TEE_BUILD
#include "mbedtls/private/ctr_drbg.h"
#include "mbedtls/platform_util.h"
#include "esp_cpu.h"
#include "esp_fault.h"
#include "hal/efuse_hal.h"
#include "hal/rng_ll.h"
#define CTR_DRBG_RESEED_INTERVAL 1024
static mbedtls_ctr_drbg_context s_ctr_drbg;
static int esp_tee_entropy_func(void *data, unsigned char *output, unsigned int len)
{
(void)data;
/* Explicitly enable the RNG */
rng_ll_enable();
esp_fill_random(output, len);
return 0;
}
static void esp_tee_ctr_drbg_init(void)
{
static bool s_ctr_drbg_initialized = false;
if (!s_ctr_drbg_initialized) {
/* Personalization data for CTR-DRBG seeding */
struct {
uint8_t mac[6];
uint32_t random;
uint32_t cycle_cnt;
} data = {};
rng_ll_enable();
data.random = esp_random();
efuse_hal_get_mac(data.mac);
data.cycle_cnt = esp_cpu_get_cycle_count();
mbedtls_ctr_drbg_init(&s_ctr_drbg);
mbedtls_ctr_drbg_set_reseed_interval(&s_ctr_drbg, CTR_DRBG_RESEED_INTERVAL);
int ret = mbedtls_ctr_drbg_seed(&s_ctr_drbg, esp_tee_entropy_func, NULL,
(const unsigned char *)&data, sizeof(data));
mbedtls_platform_zeroize(&data, sizeof(data));
if (ret != 0) {
abort();
}
ESP_FAULT_ASSERT(ret == 0);
s_ctr_drbg_initialized = true;
}
ESP_FAULT_ASSERT(s_ctr_drbg_initialized);
}
#endif // ESP_TEE_BUILD
int mbedtls_hardware_poll( void *data,
unsigned char *output, size_t len, size_t *olen )
{
@@ -27,7 +83,18 @@ psa_status_t mbedtls_psa_external_get_random(
if (context == NULL || output == NULL || output_length == NULL) {
return PSA_ERROR_INVALID_ARGUMENT;
}
#if ESP_TEE_BUILD
esp_tee_ctr_drbg_init();
int ret = mbedtls_ctr_drbg_random(&s_ctr_drbg, output, output_size);
if (ret != 0) {
return PSA_ERROR_HARDWARE_FAILURE;
}
ESP_FAULT_ASSERT(ret == 0);
#else
esp_fill_random(output, output_size);
#endif
*output_length = output_size;
return PSA_SUCCESS;
}
@@ -1003,6 +1003,10 @@ psa_status_t esp_ecdsa_opaque_sign_hash_complete(
#if CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN
if (key_source == ESP_ECDSA_KEY_SOURCE_TEE) {
/* TEE key path */
if (PSA_ALG_ECDSA_IS_DETERMINISTIC(operation->alg)) {
ESP_LOGW(TAG, "Deterministic ECDSA unsupported for TEE keys; using randomized nonce");
}
const char *tee_key_id = NULL;
uint8_t stored_curve;
+9 -6
View File
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2018-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2018-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -9,6 +9,7 @@
#include <assert.h>
#include "psa/crypto.h"
#include "mbedtls/platform_util.h"
#include "hal/sha_hal.h"
#include "hal/sha_types.h"
@@ -64,18 +65,20 @@ void esp_sha(esp_sha_type sha_type, const unsigned char *input, size_t ilen, uns
if (alg == PSA_ALG_NONE) {
ESP_LOGE(TAG, "SHA type %d not supported", (int)sha_type);
abort();
return;
}
size_t olen;
size_t output_len = PSA_HASH_LENGTH(alg);
status = psa_hash_compute(alg, input, ilen, output, output_len, &olen);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "SHA computation failed, status %d", status);
abort();
ESP_LOGE(TAG, "SHA computation failed (status %d), output zeroed", (int)status);
mbedtls_platform_zeroize(output, output_len);
return;
}
if (olen != output_len) {
ESP_LOGE(TAG, "SHA output length mismatch, expected %u, got %u", output_len, olen);
abort();
ESP_LOGE(TAG, "SHA output length mismatch (expected %u, got %u), output zeroed", output_len, olen);
mbedtls_platform_zeroize(output, output_len);
return;
}
}
@@ -112,12 +112,6 @@ TEST_CASE("Test esp_sha()", "[hw_crypto]")
#endif
}
/* NOTE: This test attempts to mmap 1MB of flash starting from address 0x00, which overlaps
* the entire TEE protected region, causing the mmap operation to fail and triggering an
* exception in the subsequent steps.
*/
#if !CONFIG_SECURE_ENABLE_TEE
TEST_CASE("Test esp_sha() function with long input", "[hw_crypto]")
{
int r = -1;
@@ -176,4 +170,3 @@ TEST_CASE("Test esp_sha() function with long input", "[hw_crypto]")
}
#endif
#endif // SOC_SHA_SUPPORTED && CONFIG_MBEDTLS_HARDWARE_SHA