diff --git a/components/esp_tee/scripts/esp_tee_sec_stg_keygen/README.md b/components/esp_tee/scripts/esp_tee_sec_stg_keygen/README.md index a7a040b7225..3e949fab7b2 100644 --- a/components/esp_tee/scripts/esp_tee_sec_stg_keygen/README.md +++ b/components/esp_tee/scripts/esp_tee_sec_stg_keygen/README.md @@ -40,16 +40,13 @@ python esp_tee_sec_stg_keygen.py -k ecdsa_p256 -o ecdsa_p256_k1.bin -i ecdsa_p25 python esp_tee_sec_stg_keygen.py -k aes256 -o aes256_gcm_k0.bin --write-once ``` -#### With custom key and IV +#### With custom key ```bash # Generate 32 bytes AES key openssl rand 32 > aes_key.bin -# Generate 12 bytes IV (optional) -openssl rand 12 >> aes_key.bin - -# Generate AES key blob using custom key + IV +# Generate AES key blob using custom key python esp_tee_sec_stg_keygen.py -k aes256 -o aes256_gcm_k1.bin -i aes_key.bin ``` diff --git a/components/esp_tee/scripts/esp_tee_sec_stg_keygen/esp_tee_sec_stg_keygen.py b/components/esp_tee/scripts/esp_tee_sec_stg_keygen/esp_tee_sec_stg_keygen.py index 64c3f332240..49b3836a437 100644 --- a/components/esp_tee/scripts/esp_tee_sec_stg_keygen/esp_tee_sec_stg_keygen.py +++ b/components/esp_tee/scripts/esp_tee_sec_stg_keygen/esp_tee_sec_stg_keygen.py @@ -1,5 +1,5 @@ #!/usr/bin/env python3 -# SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD +# SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD # SPDX-License-Identifier: Apache-2.0 import argparse @@ -16,8 +16,6 @@ from cryptography.hazmat.primitives.asymmetric import ec # === Constants === SEC_STG_KEY_DATA_SZ = 256 AES_KEY_LEN = 32 -AES_DEFAULT_IV_LEN = 16 -AES_GCM_IV_LEN = 12 ECDSA_P256_LEN = 32 ECDSA_P384_LEN = 48 @@ -47,22 +45,10 @@ def generate_aes256_key(flags: Flags, key_file: str | None = None) -> bytes: raise ValueError('AES key file must be at least 32 bytes long') key = key_data[:AES_KEY_LEN] - iv_data = key_data[AES_KEY_LEN:] - - iv_len = len(iv_data) - if iv_len == 0: - iv = os.urandom(AES_DEFAULT_IV_LEN) - elif iv_len == AES_GCM_IV_LEN: - iv = iv_data + b'\x00' * (AES_DEFAULT_IV_LEN - AES_GCM_IV_LEN) - elif iv_len == AES_DEFAULT_IV_LEN: - iv = iv_data - else: - raise ValueError('IV length must be exactly 12 or 16 bytes, or omitted to generate one') else: key = os.urandom(AES_KEY_LEN) - iv = os.urandom(AES_DEFAULT_IV_LEN) - packed = struct.pack('aes256.key, AES256_KEY_LEN); - esp_fill_random(&keyctx->aes256.iv, AES256_DEFAULT_IV_LEN); return 0; } diff --git a/components/esp_tee/test_apps/tee_test_fw/conftest.py b/components/esp_tee/test_apps/tee_test_fw/conftest.py index 6deea2af395..77ed8394c7e 100644 --- a/components/esp_tee/test_apps/tee_test_fw/conftest.py +++ b/components/esp_tee/test_apps/tee_test_fw/conftest.py @@ -324,7 +324,7 @@ class TEESerial(IdfSerial): 'type': 'aes256', 'input': 'aes256_key.bin', 'write_once': False, - 'b64': 'qZxftt2T8mOpLxALIfsDqI65srqPxrJtCVnDU8wrKXbFCJekDRzXqINlU5s=', + 'b64': 'qZxftt2T8mOpLxALIfsDqI65srqPxrJtCVnDU8wrKXY=', }, {'key': 'p256_key0', 'type': 'ecdsa_p256', 'input': None, 'write_once': False}, {