mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat(esp_tee): Clear out all sensitive buffers explicitly after TEE crypto operations
This commit is contained in:
@@ -242,6 +242,7 @@ static int esp_aes_process_dma_ext_ram(esp_aes_context *ctx, const unsigned char
|
||||
unsigned char *output_buf = NULL;
|
||||
const unsigned char *dma_input;
|
||||
chunk_len = MIN(AES_MAX_CHUNK_WRITE_SIZE, len);
|
||||
const size_t alloc_chunk_len = chunk_len;
|
||||
|
||||
size_t input_alignment = 1;
|
||||
size_t output_alignment = 1;
|
||||
@@ -309,10 +310,12 @@ static int esp_aes_process_dma_ext_ram(esp_aes_context *ctx, const unsigned char
|
||||
|
||||
cleanup:
|
||||
|
||||
if (realloc_input) {
|
||||
if (realloc_input && input_buf) {
|
||||
mbedtls_platform_zeroize(input_buf, alloc_chunk_len);
|
||||
free(input_buf);
|
||||
}
|
||||
if (realloc_output) {
|
||||
if (realloc_output && output_buf) {
|
||||
mbedtls_platform_zeroize(output_buf, alloc_chunk_len);
|
||||
free(output_buf);
|
||||
}
|
||||
|
||||
@@ -455,7 +458,7 @@ static esp_err_t generate_descriptor_list(const uint8_t *buffer, const size_t le
|
||||
dma_descriptors = (crypto_dma_desc_t *) aes_dma_calloc(dma_descs_needed, sizeof(crypto_dma_desc_t), MALLOC_CAP_DMA | MALLOC_CAP_INTERNAL, NULL);
|
||||
if (dma_descriptors == NULL) {
|
||||
ESP_LOGE(TAG, "Failed to allocate memory for the array of DMA descriptors");
|
||||
return ESP_FAIL;
|
||||
goto err;
|
||||
}
|
||||
|
||||
size_t populated_dma_descs = 0;
|
||||
@@ -464,7 +467,7 @@ static esp_err_t generate_descriptor_list(const uint8_t *buffer, const size_t le
|
||||
start_alignment_stream_buffer = aes_dma_calloc(alignment_buffer_size, sizeof(uint8_t), AES_DMA_ALLOC_CAPS | (esp_ptr_external_ram(buffer) ? MALLOC_CAP_SPIRAM : MALLOC_CAP_INTERNAL) , NULL);
|
||||
if (start_alignment_stream_buffer == NULL) {
|
||||
ESP_LOGE(TAG, "Failed to allocate memory for start alignment buffer");
|
||||
return ESP_FAIL;
|
||||
goto err;
|
||||
}
|
||||
|
||||
memset(start_alignment_stream_buffer, 0, unaligned_start_bytes);
|
||||
@@ -486,7 +489,7 @@ static esp_err_t generate_descriptor_list(const uint8_t *buffer, const size_t le
|
||||
end_alignment_stream_buffer = aes_dma_calloc(alignment_buffer_size, sizeof(uint8_t), AES_DMA_ALLOC_CAPS | (esp_ptr_external_ram(buffer) ? MALLOC_CAP_SPIRAM : MALLOC_CAP_INTERNAL), NULL);
|
||||
if (end_alignment_stream_buffer == NULL) {
|
||||
ESP_LOGE(TAG, "Failed to allocate memory for end alignment buffer");
|
||||
return ESP_FAIL;
|
||||
goto err;
|
||||
}
|
||||
|
||||
memset(end_alignment_stream_buffer, 0, unaligned_end_bytes);
|
||||
@@ -500,7 +503,7 @@ static esp_err_t generate_descriptor_list(const uint8_t *buffer, const size_t le
|
||||
|
||||
if (dma_desc_link(dma_descriptors, dma_descs_needed, cache_line_size) != ESP_OK) {
|
||||
ESP_LOGE(TAG, "DMA descriptors cache sync C2M failed");
|
||||
return ESP_FAIL;
|
||||
goto err;
|
||||
}
|
||||
|
||||
ret:
|
||||
@@ -521,6 +524,18 @@ ret:
|
||||
*end_alignment_buffer = end_alignment_stream_buffer;
|
||||
|
||||
return ESP_OK;
|
||||
|
||||
err:
|
||||
if (start_alignment_stream_buffer) {
|
||||
mbedtls_platform_zeroize(start_alignment_stream_buffer, alignment_buffer_size);
|
||||
free(start_alignment_stream_buffer);
|
||||
}
|
||||
if (end_alignment_stream_buffer) {
|
||||
mbedtls_platform_zeroize(end_alignment_stream_buffer, alignment_buffer_size);
|
||||
free(end_alignment_stream_buffer);
|
||||
}
|
||||
free(dma_descriptors);
|
||||
return ESP_FAIL;
|
||||
}
|
||||
|
||||
int esp_aes_process_dma(esp_aes_context *ctx, const unsigned char *input, unsigned char *output, size_t len, uint8_t *stream_out)
|
||||
@@ -585,19 +600,12 @@ int esp_aes_process_dma(esp_aes_context *ctx, const unsigned char *input, unsign
|
||||
}
|
||||
|
||||
size_t input_alignment_buffer_size = MAX(2 * input_cache_line_size, AES_BLOCK_BYTES);
|
||||
size_t output_alignment_buffer_size = MAX(2 * output_cache_line_size, AES_BLOCK_BYTES);
|
||||
|
||||
crypto_dma_desc_t *input_desc = NULL;
|
||||
uint8_t *input_start_stream_buffer = NULL;
|
||||
uint8_t *input_end_stream_buffer = NULL;
|
||||
|
||||
if (generate_descriptor_list(input, len, &input_start_stream_buffer, &input_end_stream_buffer, input_alignment_buffer_size, input_cache_line_size, NULL, NULL, &input_desc, NULL, false) != ESP_OK) {
|
||||
mbedtls_platform_zeroize(output, len);
|
||||
ESP_LOGE(TAG, "Generating input DMA descriptors failed");
|
||||
return -1;
|
||||
}
|
||||
|
||||
size_t output_alignment_buffer_size = MAX(2 * output_cache_line_size, AES_BLOCK_BYTES);
|
||||
|
||||
crypto_dma_desc_t *output_desc = NULL;
|
||||
uint8_t *output_start_stream_buffer = NULL;
|
||||
uint8_t *output_end_stream_buffer = NULL;
|
||||
@@ -605,10 +613,16 @@ int esp_aes_process_dma(esp_aes_context *ctx, const unsigned char *input, unsign
|
||||
size_t output_end_alignment = 0;
|
||||
size_t output_dma_desc_num = 0;
|
||||
|
||||
if (generate_descriptor_list(input, len, &input_start_stream_buffer, &input_end_stream_buffer, input_alignment_buffer_size, input_cache_line_size, NULL, NULL, &input_desc, NULL, false) != ESP_OK) {
|
||||
ESP_LOGE(TAG, "Generating input DMA descriptors failed");
|
||||
ret = -1;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (generate_descriptor_list(output, len, &output_start_stream_buffer, &output_end_stream_buffer, output_alignment_buffer_size, output_cache_line_size, &output_start_alignment, &output_end_alignment, &output_desc, &output_dma_desc_num, true) != ESP_OK) {
|
||||
mbedtls_platform_zeroize(output, len);
|
||||
ESP_LOGE(TAG, "Generating output DMA descriptors failed");
|
||||
return -1;
|
||||
ret = -1;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
crypto_dma_desc_t *out_desc_tail = &output_desc[output_dma_desc_num - 1];
|
||||
@@ -701,11 +715,23 @@ cleanup:
|
||||
mbedtls_platform_zeroize(output, len);
|
||||
}
|
||||
|
||||
free(input_start_stream_buffer);
|
||||
free(input_end_stream_buffer);
|
||||
if (input_start_stream_buffer) {
|
||||
mbedtls_platform_zeroize(input_start_stream_buffer, input_alignment_buffer_size);
|
||||
free(input_start_stream_buffer);
|
||||
}
|
||||
if (input_end_stream_buffer) {
|
||||
mbedtls_platform_zeroize(input_end_stream_buffer, input_alignment_buffer_size);
|
||||
free(input_end_stream_buffer);
|
||||
}
|
||||
|
||||
free(output_start_stream_buffer);
|
||||
free(output_end_stream_buffer);
|
||||
if (output_start_stream_buffer) {
|
||||
mbedtls_platform_zeroize(output_start_stream_buffer, output_alignment_buffer_size);
|
||||
free(output_start_stream_buffer);
|
||||
}
|
||||
if (output_end_stream_buffer) {
|
||||
mbedtls_platform_zeroize(output_end_stream_buffer, output_alignment_buffer_size);
|
||||
free(output_end_stream_buffer);
|
||||
}
|
||||
|
||||
free(input_desc);
|
||||
free(output_desc);
|
||||
@@ -914,12 +940,24 @@ cleanup:
|
||||
free(aad_end_stream_buffer);
|
||||
free(aad_desc);
|
||||
|
||||
free(input_start_stream_buffer);
|
||||
free(input_end_stream_buffer);
|
||||
if (input_start_stream_buffer) {
|
||||
mbedtls_platform_zeroize(input_start_stream_buffer, input_alignment_buffer_size);
|
||||
free(input_start_stream_buffer);
|
||||
}
|
||||
if (input_end_stream_buffer) {
|
||||
mbedtls_platform_zeroize(input_end_stream_buffer, input_alignment_buffer_size);
|
||||
free(input_end_stream_buffer);
|
||||
}
|
||||
free(input_desc);
|
||||
|
||||
free(output_start_stream_buffer);
|
||||
free(output_end_stream_buffer);
|
||||
if (output_start_stream_buffer) {
|
||||
mbedtls_platform_zeroize(output_start_stream_buffer, output_alignment_buffer_size);
|
||||
free(output_start_stream_buffer);
|
||||
}
|
||||
if (output_end_stream_buffer) {
|
||||
mbedtls_platform_zeroize(output_end_stream_buffer, output_alignment_buffer_size);
|
||||
free(output_end_stream_buffer);
|
||||
}
|
||||
free(output_desc);
|
||||
|
||||
free(len_buf);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -10,6 +10,7 @@
|
||||
#include "esp_ds.h"
|
||||
#include "rsa_dec_alt.h"
|
||||
#include "mbedtls/rsa.h"
|
||||
#include "mbedtls/platform_util.h"
|
||||
#include "esp_ds_common.h"
|
||||
#include "esp_log.h"
|
||||
|
||||
@@ -214,6 +215,7 @@ int esp_ds_rsa_decrypt(void *ctx, size_t *olen,
|
||||
esp_ds_data_t *s_ds_data = esp_ds_get_data_ctx();
|
||||
if (s_ds_data == NULL) {
|
||||
ESP_LOGE(TAG, "s_ds_data is NULL, cannot perform decryption");
|
||||
memset(input_tmp, 0, data_len * sizeof(uint32_t));
|
||||
free(input_tmp);
|
||||
return -1;
|
||||
}
|
||||
@@ -275,15 +277,19 @@ int esp_ds_rsa_decrypt(void *ctx, size_t *olen,
|
||||
}
|
||||
|
||||
memcpy(output, output_tmp, *olen);
|
||||
mbedtls_platform_zeroize(output_tmp, data_len * sizeof(uint32_t));
|
||||
free(output_tmp);
|
||||
mbedtls_platform_zeroize(input_tmp, data_len * sizeof(uint32_t));
|
||||
free(input_tmp);
|
||||
return 0;
|
||||
exit:
|
||||
esp_ds_release_ds_lock();
|
||||
if (input_tmp) {
|
||||
mbedtls_platform_zeroize(input_tmp, data_len * sizeof(uint32_t));
|
||||
free(input_tmp);
|
||||
}
|
||||
if (output_tmp) {
|
||||
mbedtls_platform_zeroize(output_tmp, data_len * sizeof(uint32_t));
|
||||
free(output_tmp);
|
||||
}
|
||||
if (olen) {
|
||||
|
||||
@@ -311,6 +311,7 @@ int esp_ds_rsa_sign( void *ctx,
|
||||
&esp_ds_ctx);
|
||||
if (ds_r != ESP_OK) {
|
||||
ESP_LOGE(TAG, "Error in esp_ds_start_sign, returned %d ", ds_r);
|
||||
memset(signature, 0, sig_len);
|
||||
heap_caps_free(signature);
|
||||
return -1;
|
||||
}
|
||||
@@ -322,6 +323,7 @@ int esp_ds_rsa_sign( void *ctx,
|
||||
} else {
|
||||
ESP_LOGE(TAG, "Error in esp_ds_finish_sign, returned %d ", ds_r);
|
||||
}
|
||||
memset(signature, 0, sig_len);
|
||||
heap_caps_free(signature);
|
||||
return -1;
|
||||
}
|
||||
@@ -329,6 +331,7 @@ int esp_ds_rsa_sign( void *ctx,
|
||||
for (unsigned int i = 0; i < (data_len); i++) {
|
||||
((uint32_t *)sig)[i] = SWAP_INT32(((uint32_t *)signature)[(data_len) - (i + 1)]);
|
||||
}
|
||||
memset(signature, 0, sig_len);
|
||||
heap_caps_free(signature);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*
|
||||
@@ -27,6 +27,7 @@
|
||||
#include "esp_crypto_dma.h"
|
||||
#include "esp_heap_caps.h"
|
||||
#include "hal/dma_types.h"
|
||||
#include "mbedtls/platform_util.h"
|
||||
#include "soc/ext_mem_defs.h"
|
||||
#include "soc/periph_defs.h"
|
||||
|
||||
@@ -186,6 +187,10 @@ static esp_err_t esp_sha_dma_process_ext(esp_sha_type sha_type, const void *inpu
|
||||
buf_copy = heap_caps_aligned_alloc(SOC_GDMA_EXT_MEM_ENC_ALIGNMENT, buf_len, heap_caps);
|
||||
if (buf_copy == NULL) {
|
||||
ESP_LOGE(TAG, "Failed to allocate aligned internal memory");
|
||||
if (input_copy) {
|
||||
mbedtls_platform_zeroize(input_copy, ilen);
|
||||
free(input_copy);
|
||||
}
|
||||
return ret;
|
||||
}
|
||||
memcpy(buf_copy, buf, buf_len);
|
||||
@@ -197,10 +202,12 @@ static esp_err_t esp_sha_dma_process_ext(esp_sha_type sha_type, const void *inpu
|
||||
ret = esp_sha_dma_process(sha_type, dma_input, ilen, dma_buf, buf_len, is_first_block);
|
||||
|
||||
if (realloc_input) {
|
||||
mbedtls_platform_zeroize(input_copy, ilen);
|
||||
free(input_copy);
|
||||
}
|
||||
|
||||
if (realloc_buf) {
|
||||
mbedtls_platform_zeroize(buf_copy, buf_len);
|
||||
free(buf_copy);
|
||||
}
|
||||
|
||||
@@ -318,6 +325,7 @@ int esp_sha_dma(esp_sha_type sha_type, const void *input, uint32_t ilen,
|
||||
{
|
||||
int ret = 0;
|
||||
unsigned char *dma_cap_buf = NULL;
|
||||
uint32_t dma_cap_buf_len = 0;
|
||||
|
||||
if (buf_len > block_length(sha_type)) {
|
||||
ESP_LOGE(TAG, "SHA DMA buf_len cannot exceed max size for a single block");
|
||||
@@ -339,6 +347,7 @@ int esp_sha_dma(esp_sha_type sha_type, const void *input, uint32_t ilen,
|
||||
goto cleanup;
|
||||
}
|
||||
memcpy(dma_cap_buf, buf, buf_len);
|
||||
dma_cap_buf_len = buf_len;
|
||||
buf = dma_cap_buf;
|
||||
}
|
||||
|
||||
@@ -375,7 +384,10 @@ int esp_sha_dma(esp_sha_type sha_type, const void *input, uint32_t ilen,
|
||||
}
|
||||
|
||||
cleanup:
|
||||
free(dma_cap_buf);
|
||||
if (dma_cap_buf) {
|
||||
mbedtls_platform_zeroize(dma_cap_buf, dma_cap_buf_len);
|
||||
free(dma_cap_buf);
|
||||
}
|
||||
return ret;
|
||||
}
|
||||
#endif /* SOC_SHA_SUPPORT_DMA */
|
||||
|
||||
Reference in New Issue
Block a user