mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-03 03:31:41 +03:00
refactor(esp_tee): Remove leftover references to the secure storage AES-GCM IV
This commit is contained in:
@@ -40,16 +40,13 @@ python esp_tee_sec_stg_keygen.py -k ecdsa_p256 -o ecdsa_p256_k1.bin -i ecdsa_p25
|
||||
python esp_tee_sec_stg_keygen.py -k aes256 -o aes256_gcm_k0.bin --write-once
|
||||
```
|
||||
|
||||
#### With custom key and IV
|
||||
#### With custom key
|
||||
|
||||
```bash
|
||||
# Generate 32 bytes AES key
|
||||
openssl rand 32 > aes_key.bin
|
||||
|
||||
# Generate 12 bytes IV (optional)
|
||||
openssl rand 12 >> aes_key.bin
|
||||
|
||||
# Generate AES key blob using custom key + IV
|
||||
# Generate AES key blob using custom key
|
||||
python esp_tee_sec_stg_keygen.py -k aes256 -o aes256_gcm_k1.bin -i aes_key.bin
|
||||
```
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
#!/usr/bin/env python3
|
||||
# SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
# SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
import argparse
|
||||
@@ -16,8 +16,6 @@ from cryptography.hazmat.primitives.asymmetric import ec
|
||||
# === Constants ===
|
||||
SEC_STG_KEY_DATA_SZ = 256
|
||||
AES_KEY_LEN = 32
|
||||
AES_DEFAULT_IV_LEN = 16
|
||||
AES_GCM_IV_LEN = 12
|
||||
ECDSA_P256_LEN = 32
|
||||
ECDSA_P384_LEN = 48
|
||||
|
||||
@@ -47,22 +45,10 @@ def generate_aes256_key(flags: Flags, key_file: str | None = None) -> bytes:
|
||||
raise ValueError('AES key file must be at least 32 bytes long')
|
||||
|
||||
key = key_data[:AES_KEY_LEN]
|
||||
iv_data = key_data[AES_KEY_LEN:]
|
||||
|
||||
iv_len = len(iv_data)
|
||||
if iv_len == 0:
|
||||
iv = os.urandom(AES_DEFAULT_IV_LEN)
|
||||
elif iv_len == AES_GCM_IV_LEN:
|
||||
iv = iv_data + b'\x00' * (AES_DEFAULT_IV_LEN - AES_GCM_IV_LEN)
|
||||
elif iv_len == AES_DEFAULT_IV_LEN:
|
||||
iv = iv_data
|
||||
else:
|
||||
raise ValueError('IV length must be exactly 12 or 16 bytes, or omitted to generate one')
|
||||
else:
|
||||
key = os.urandom(AES_KEY_LEN)
|
||||
iv = os.urandom(AES_DEFAULT_IV_LEN)
|
||||
|
||||
packed = struct.pack('<II32s16s', KeyType.AES256.value, flags.value, key, iv)
|
||||
packed = struct.pack('<II32s', KeyType.AES256.value, flags.value, key)
|
||||
return packed + b'\x00' * (SEC_STG_KEY_DATA_SZ - len(packed))
|
||||
|
||||
|
||||
|
||||
@@ -35,7 +35,6 @@
|
||||
|
||||
#define AES256_KEY_LEN 32
|
||||
#define AES256_KEY_BITS (AES256_KEY_LEN * 8)
|
||||
#define AES256_DEFAULT_IV_LEN 16
|
||||
#define AES256_GCM_IV_LEN 12
|
||||
#define ECDSA_SECP384R1_KEY_LEN 48
|
||||
#define ECDSA_SECP256R1_KEY_LEN 32
|
||||
@@ -62,7 +61,6 @@ typedef struct {
|
||||
/* Structure to hold AES-256 key and IV */
|
||||
typedef struct {
|
||||
uint8_t key[AES256_KEY_LEN]; /* Key for AES-256 */
|
||||
uint8_t iv[AES256_DEFAULT_IV_LEN]; /* Initialization vector for AES-256 */
|
||||
} __attribute__((aligned(4))) __attribute__((__packed__)) sec_stg_aes256_t;
|
||||
|
||||
/* Structure to hold the cryptographic keys in NVS */
|
||||
@@ -449,9 +447,7 @@ static int generate_aes256_key(sec_stg_key_t *keyctx)
|
||||
}
|
||||
|
||||
ESP_LOGD(TAG, "Generating AES-256 key...");
|
||||
|
||||
esp_fill_random(&keyctx->aes256.key, AES256_KEY_LEN);
|
||||
esp_fill_random(&keyctx->aes256.iv, AES256_DEFAULT_IV_LEN);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -324,7 +324,7 @@ class TEESerial(IdfSerial):
|
||||
'type': 'aes256',
|
||||
'input': 'aes256_key.bin',
|
||||
'write_once': False,
|
||||
'b64': 'qZxftt2T8mOpLxALIfsDqI65srqPxrJtCVnDU8wrKXbFCJekDRzXqINlU5s=',
|
||||
'b64': 'qZxftt2T8mOpLxALIfsDqI65srqPxrJtCVnDU8wrKXY=',
|
||||
},
|
||||
{'key': 'p256_key0', 'type': 'ecdsa_p256', 'input': None, 'write_once': False},
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user