Merge branch 'feat/update_mbedtls_4_1_1_v6.0' into 'release/v6.0'

feat(mbedtls): update to version 4.1.0 (v6.0)

See merge request espressif/esp-idf!48175
This commit is contained in:
Mahavir Jain
2026-05-11 09:50:25 +05:30
40 changed files with 335 additions and 544 deletions
+2 -11
View File
@@ -560,22 +560,13 @@ menu "Security features"
depends on SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
default SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
help
Select the ECDSA key size. Three key sizes are supported depending upon on the target:
Select the ECDSA key size. Two key sizes are supported depending on the target:
- 192 bit key using NISTP192 curve (Legacy, not recommended)
- 256 bit key using NISTP256 curve (Recommended)
- 384 bit key using NISTP384 curve (Recommended)
The advantage of using 384 and 256 bit keys is the extra randomness which makes it difficult to be
bruteforced compared to 192 bit key.
At present, both key sizes are practically implausible to bruteforce.
config SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
bool "Using ECC curve NISTP192 (Legacy, not recommended)"
depends on SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
help
This legacy option is not recommended for new designs. Prefer NISTP256 or NISTP384.
config SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
bool "Using ECC curve NISTP256 (Recommended)"
depends on SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
@@ -710,7 +701,7 @@ menu "Security features"
Key file is an ECDSA private key (NIST256p curve) in PEM format for Secure Boot V1.
Key file is an RSA private key in PEM format for Secure Boot V2 (RSA scheme).
Key file is an ECDSA private key (NIST 192p, 256p or 384p) in PEM format for Secure Boot V2 (ECDSA scheme).
Key file is an ECDSA private key (256p or 384p) in PEM format for Secure Boot V2 (ECDSA scheme).
Path is evaluated relative to the project directory.
+1 -4
View File
@@ -43,7 +43,6 @@ if(CONFIG_SECURE_SIGNED_APPS)
set(bootloader_binary_files
${bootloader_binary_files}
"${BOOTLOADER_BUILD_DIR}/bootloader-reflash-digest.bin"
"${BOOTLOADER_BUILD_DIR}/secure-bootloader-key-192.bin"
"${BOOTLOADER_BUILD_DIR}/secure-bootloader-key-256.bin"
)
endif()
@@ -66,9 +65,7 @@ if(CONFIG_SECURE_SIGNED_APPS)
"Secure Boot Signing Key ${CONFIG_SECURE_BOOT_SIGNING_KEY} does not exist. Generate using:"
"\tidf.py secure-generate-signing-key ${CONFIG_SECURE_BOOT_SIGNING_KEY}")
else()
if(CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS)
set(scheme "ecdsa192")
elseif(CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS)
if(CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS)
set(scheme "ecdsa256")
elseif(CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS)
set(scheme "ecdsa384")
@@ -70,11 +70,9 @@ typedef enum {
#define ESP_SECURE_BOOT_SCHEME ESP_SECURE_BOOT_V2_ECDSA
#endif
/* Expected ECDSA curve ID from menuconfig "ECDSA key size" (matches ECDSA_CURVE_P192/P256/P384 in ROM) */
/* Expected ECDSA curve ID from menuconfig "ECDSA key size" (matches ECDSA_CURVE_P256/P384 in ROM) */
#if CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
#define ESP_SECURE_BOOT_ECDSA_CURVE_ID ECDSA_CURVE_P192
#elif CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
#define ESP_SECURE_BOOT_ECDSA_CURVE_ID ECDSA_CURVE_P256
#elif CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS
#define ESP_SECURE_BOOT_ECDSA_CURVE_ID ECDSA_CURVE_P384
@@ -13,9 +13,7 @@
ESP_LOG_ATTR_TAG(TAG, "secure_boot_v2_ecdsa");
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
#define ECDSA_INTEGER_LEN 24
#elif CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS
#define ECDSA_INTEGER_LEN 48
#else
#define ECDSA_INTEGER_LEN 32
@@ -41,13 +39,6 @@ esp_err_t verify_ecdsa_signature_block(const ets_secure_boot_signature_t *sig_bl
psa_ecc_family_t curve_family;
switch(trusted_block->ecdsa.key.curve_id) {
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
case ECDSA_CURVE_P192:
key_size = 24;
curve_family = PSA_ECC_FAMILY_SECP_R1;
psa_set_key_bits(&key_attributes, PSA_BYTES_TO_BITS(key_size));
break;
#endif /* CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS */
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
case ECDSA_CURVE_P256:
key_size = 32;
@@ -50,17 +50,6 @@ static esp_err_t validate_signature_block(const ets_secure_boot_sig_block_t *blo
}
#endif
#if SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED && CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
if (block->ecdsa.key.curve_id == ECDSA_CURVE_P192) {
// Enabling ECDSA-192 Curve mode
esp_err_t err = esp_efuse_enable_ecdsa_p192_curve_mode();
if (err != ESP_OK) {
ESP_LOGE(TAG, "Failed to enable ECDSA-192 curve mode: %d", err);
return err;
}
}
#endif
return ESP_OK;
}
@@ -79,17 +79,6 @@ static esp_err_t validate_signature_block(const ets_secure_boot_sig_block_t *blo
}
#endif
#if SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED && CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
if (block->ecdsa.key.curve_id == ECDSA_CURVE_P192) {
// Enabling ECDSA-192 Curve mode
esp_err_t err = esp_efuse_enable_ecdsa_p192_curve_mode();
if (err != ESP_OK) {
ESP_LOGE(TAG, "Failed to enable ECDSA-192 curve mode: %d", err);
return err;
}
}
#endif
return ESP_OK;
}
+11 -33
View File
@@ -493,59 +493,37 @@ void esp_mbedtls_cleanup(esp_tls_t *tls)
mbedtls_x509_crt_free(&tls->cacert);
mbedtls_x509_crt_free(&tls->clientcert);
/* For opaque keys (DS peripheral, hardware ECDSA), mbedtls_pk_free() does
* not destroy the PSA key — ownership is external. Destroy it manually
* before calling mbedtls_pk_free(). */
#ifdef CONFIG_ESP_TLS_USE_DS_PERIPHERAL
if (mbedtls_pk_get_type(&tls->clientkey) == MBEDTLS_PK_RSASSA_PSS) {
mbedtls_rsa_context *rsa = tls->clientkey.MBEDTLS_PRIVATE(pk_ctx);
if (rsa != NULL) {
mbedtls_rsa_free(rsa);
mbedtls_free(rsa);
rsa = NULL;
}
if (tls->clientkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) {
psa_destroy_key(tls->clientkey.MBEDTLS_PRIVATE(priv_id));
tls->clientkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL;
}
tls->clientkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
}
// Similar cleanup for server key
if (mbedtls_pk_get_type(&tls->serverkey) == MBEDTLS_PK_RSASSA_PSS) {
mbedtls_rsa_context *rsa = tls->serverkey.MBEDTLS_PRIVATE(pk_ctx);
if (rsa != NULL) {
mbedtls_rsa_free(rsa);
mbedtls_free(rsa);
rsa = NULL;
}
if (tls->serverkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) {
psa_destroy_key(tls->serverkey.MBEDTLS_PRIVATE(priv_id));
tls->serverkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL;
}
tls->serverkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
}
#endif
#ifdef CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN
/* In mbedtls v4.0, ECDSA keys require manual cleanup of the keypair structure */
if (mbedtls_pk_get_type(&tls->clientkey) == MBEDTLS_PK_ECDSA) {
ESP_LOGD(TAG, "Cleaning up client key");
mbedtls_ecp_keypair *keypair = tls->clientkey.MBEDTLS_PRIVATE(pk_ctx);
if (keypair != NULL) {
mbedtls_ecp_keypair_free(keypair);
mbedtls_free(keypair);
keypair = NULL;
if (tls->clientkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) {
psa_destroy_key(tls->clientkey.MBEDTLS_PRIVATE(priv_id));
tls->clientkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL;
}
psa_destroy_key(tls->clientkey.MBEDTLS_PRIVATE(priv_id));
tls->clientkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
}
// Similar cleanup for server key
if (mbedtls_pk_get_type(&tls->serverkey) == MBEDTLS_PK_ECDSA) {
mbedtls_ecp_keypair *keypair = tls->serverkey.MBEDTLS_PRIVATE(pk_ctx);
if (keypair != NULL) {
mbedtls_ecp_keypair_free(keypair);
mbedtls_free(keypair);
keypair = NULL;
if (tls->serverkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) {
psa_destroy_key(tls->serverkey.MBEDTLS_PRIVATE(priv_id));
tls->serverkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL;
}
psa_destroy_key(tls->serverkey.MBEDTLS_PRIVATE(priv_id));
tls->serverkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
}
#endif
+10 -1
View File
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2021-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -16,6 +16,7 @@
#endif
#include "esp_newlib.h"
#include "psa/crypto.h"
#include "esp_crypto_lock.h"
#if SOC_SHA_SUPPORT_SHA512
#define SHA_TYPE SHA2_512
#else
@@ -59,6 +60,14 @@ void setUp(void)
heap_caps_free(buf);
psa_destroy_key(key_id);
// Trigger lazy initialization of the MPI hardware mutex.
// In mbedtls 4.x, RSA key parsing goes through PSA which validates
// the key using MPI hardware, creating this lock on first use.
#if CONFIG_MBEDTLS_HARDWARE_MPI
esp_crypto_mpi_lock_acquire();
esp_crypto_mpi_lock_release();
#endif // CONFIG_MBEDTLS_HARDWARE_MPI
test_utils_record_free_mem();
TEST_ESP_OK(test_utils_set_leak_level(0, ESP_LEAK_TYPE_CRITICAL, ESP_COMP_LEAK_GENERAL));
TEST_ESP_OK(test_utils_set_leak_level(0, ESP_LEAK_TYPE_WARNING, ESP_COMP_LEAK_GENERAL));
@@ -94,7 +94,6 @@ TEST_CASE("esp_tls_server session create delete", "[esp-tls]")
TEST_ASSERT_LESS_THAN_INT(0, ret);
// free the allocated memory.
esp_tls_server_session_delete(tls);
}
#endif /* CONFIG_ESP_TLS_USING_MBEDTLS */
@@ -21,11 +21,11 @@
#define IDF_PERFORMANCE_MAX_TIME_SHA1_32KB 5000
#define IDF_PERFORMANCE_MAX_TIME_SHA512_32KB 4500
#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 21500
#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 45000
#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PRIVATE_OP 750000
#define IDF_PERFORMANCE_MAX_RSA_3072KEY_PUBLIC_OP 33000
#define IDF_PERFORMANCE_MAX_RSA_3072KEY_PRIVATE_OP 950000
#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 90000
#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 170000
#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PRIVATE_OP 3000000
// floating point instructions per divide and per sqrt (configured for worst-case with PSRAM workaround)
@@ -16,11 +16,11 @@
#define IDF_PERFORMANCE_MAX_TIME_SHA1_32KB 900
#define IDF_PERFORMANCE_MAX_TIME_SHA512_32KB 900
#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 17000
#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 36000
#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PRIVATE_OP 650000
#define IDF_PERFORMANCE_MAX_RSA_3072KEY_PUBLIC_OP 36000
#define IDF_PERFORMANCE_MAX_RSA_3072KEY_PRIVATE_OP 960000
#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 70000
#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 141000
#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PRIVATE_OP 2850000
#define IDF_PERFORMANCE_MAX_ADC_CONTINUOUS_STD_ATTEN3_NO_FILTER 3
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2020-2022 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -14,11 +14,11 @@
#define IDF_PERFORMANCE_MAX_TIME_SHA1_32KB 1000
#define IDF_PERFORMANCE_MAX_TIME_SHA512_32KB 900
#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 24000
#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 45000
#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PRIVATE_OP 700000
#define IDF_PERFORMANCE_MAX_RSA_3072KEY_PUBLIC_OP 45000
#define IDF_PERFORMANCE_MAX_RSA_3072KEY_PRIVATE_OP 1300000
#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 90000
#define IDF_PERFORMANCE_MAX_RSA_3072KEY_PRIVATE_OP 300000
#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 190000
#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PRIVATE_OP 3500000
// floating point instructions per divide and per sqrt (configured for worst-case with PSRAM workaround)
+42 -14
View File
@@ -22,7 +22,7 @@ if(NOT ${IDF_TARGET} STREQUAL "linux")
set(priv_requires soc esp_hw_support)
if(NOT BOOTLOADER_BUILD)
list(APPEND priv_requires esp_pm esp_driver_dma)
set(requires esp_security)
set(requires esp_security esp_hal_security)
endif()
endif()
@@ -33,6 +33,7 @@ set(mbedtls_include_dirs
"mbedtls/library"
"mbedtls/tf-psa-crypto/core"
"mbedtls/tf-psa-crypto/drivers/builtin/src/"
"mbedtls/tf-psa-crypto/extras"
)
if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL)
@@ -44,6 +45,7 @@ if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE)
list(APPEND mbedtls_include_dirs "esp_crt_bundle/include")
endif()
list(APPEND mbedtls_include_dirs "${COMPONENT_DIR}/port/psa_driver/include")
idf_component_register(SRCS "${mbedtls_srcs}"
@@ -54,6 +56,7 @@ idf_component_register(SRCS "${mbedtls_srcs}"
# Add MBEDTLS_MAJOR_VERSION definition to the component library
target_compile_definitions(${COMPONENT_LIB} INTERFACE MBEDTLS_MAJOR_VERSION=4)
target_compile_definitions(${COMPONENT_LIB} INTERFACE __STDC_WANT_LIB_EXT1__=0)
# Set the type of mbedtls component library
set(linkage_type PUBLIC)
@@ -177,8 +180,15 @@ if(CONFIG_MBEDTLS_SSL_PROTO_GMTSSL1_1)
set_property(TARGET mbedx509 PROPERTY SOURCES ${src_x509})
endif()
# Core libraries from the mbedTLS project
set(mbedtls_targets mbedtls mbedx509 tfpsacrypto builtin)
# Core libraries from the mbedTLS project, including 3rd-party (everest,
# p256-m) and the new tf-psa-crypto sub-libs introduced in 4.1
# (extras, platform, utilities). All of these need MBEDTLS_CONFIG_FILE
# and the optimization flags applied uniformly; previously the loop ran
# before the 3rd-party / new targets were appended, leaving them at the
# default ESP-IDF -Og without esp_config.h.
set(mbedtls_compile_targets mbedtls mbedx509 tfpsacrypto builtin
everest p256-m extras platform utilities)
set(mbedtls_link_targets mbedtls mbedx509 tfpsacrypto)
add_library(mbed-builtin ALIAS builtin)
set_target_properties(builtin PROPERTIES OUTPUT_NAME "mbed-builtin")
@@ -186,7 +196,10 @@ set_target_properties(builtin PROPERTIES OUTPUT_NAME "mbed-builtin")
target_include_directories(tfpsacrypto PUBLIC "port/include")
message(STATUS "Setting up mbedtls configuration")
foreach(target ${mbedtls_targets})
foreach(target ${mbedtls_compile_targets})
if(NOT TARGET ${target})
continue()
endif()
target_compile_definitions(${target} PUBLIC -DMBEDTLS_CONFIG_FILE="mbedtls/esp_config.h")
set_config_files_compile_definitions(${target})
target_compile_definitions(${target} PUBLIC MBEDTLS_MAJOR_VERSION=4)
@@ -200,9 +213,6 @@ foreach(target ${mbedtls_targets})
endif()
endforeach()
# 3rd party libraries from the mbedTLS project
list(APPEND mbedtls_targets everest p256m)
set(mbedtls_target_sources "${COMPONENT_DIR}/port/mbedtls_debug.c"
"${COMPONENT_DIR}/port/esp_platform_time.c"
"${COMPONENT_DIR}/port/esp_timing.c")
@@ -212,8 +222,8 @@ list(APPEND mbedtls_target_sources "${COMPONENT_DIR}/port/esp_psa_crypto_init.c"
# Only compile esp_psa_its.c if nvs_flash component is available
if(NOT ${IDF_TARGET} STREQUAL "linux")
if(IDF_BUILD_V2)
# For v2: conditionally compile source and link only if nvs_flash target exists
target_sources(
# For v2: conditionally compile source and link only if nvs_flash target exists
target_sources(
tfpsacrypto PRIVATE
"$<$<TARGET_EXISTS:idf::nvs_flash>:${COMPONENT_DIR}/port/psa_crypto_storage/esp_psa_its.c>"
)
@@ -270,13 +280,31 @@ endif()
# Add port files to mbedtls targets
target_sources(mbedtls PRIVATE ${mbedtls_target_sources})
target_compile_definitions(mbedtls PUBLIC __STDC_WANT_LIB_EXT1__=0)
if(NOT ${IDF_TARGET} STREQUAL "linux")
target_link_libraries(tfpsacrypto PUBLIC idf::esp_security)
# All tf-psa-crypto internal targets need esp_security includes because
# the public PSA crypto header chain (psa/crypto.h -> crypto_struct.h ->
# crypto_driver_contexts_composites.h) includes ESP driver context headers
# that depend on esp_security headers (e.g., esp_ds.h).
target_link_libraries(tfpsacrypto PRIVATE idf::esp_security)
target_link_libraries(builtin PRIVATE idf::esp_security)
target_link_libraries(p256m PRIVATE idf::esp_security)
target_link_libraries(p256-m PRIVATE idf::esp_security)
target_link_libraries(extras PRIVATE idf::esp_security)
target_link_libraries(platform PRIVATE idf::esp_security)
target_link_libraries(utilities PRIVATE idf::esp_security)
target_link_libraries(mbedtls PRIVATE idf::esp_security)
target_link_libraries(mbedx509 PRIVATE idf::esp_security)
endif()
# Workaround: CMake 4.x Unix Makefiles generator fails to create build-order
# dependencies for STATIC library targets consumed via $<TARGET_OBJECTS:> when
# they are also linked via target_link_libraries in the same target. This
# ensures builtin/everest/p256-m are compiled before tfpsacrypto archives
# their objects into libtfpsacrypto.a.
add_dependencies(tfpsacrypto builtin everest p256-m extras platform utilities)
# Choose peripheral type
if(CONFIG_SOC_SHA_SUPPORTED)
@@ -377,11 +405,11 @@ if(CONFIG_SOC_HMAC_SUPPORTED)
endif()
if(CONFIG_SOC_DIG_SIGN_SUPPORTED AND CONFIG_MBEDTLS_HARDWARE_RSA_DS_PERIPHERAL)
target_sources(tfpsacrypto PRIVATE
target_sources(tfpsacrypto PRIVATE
"${COMPONENT_DIR}/port/psa_driver/esp_rsa_ds/psa_crypto_driver_esp_rsa_ds.c"
"${COMPONENT_DIR}/port/psa_driver/esp_rsa_ds/psa_crypto_driver_esp_rsa_ds_utilities.c"
)
target_link_libraries(tfpsacrypto PRIVATE idf::efuse)
target_link_libraries(tfpsacrypto PRIVATE idf::efuse)
endif()
if(CONFIG_SOC_HMAC_SUPPORTED)
@@ -479,7 +507,7 @@ if(CONFIG_PM_ENABLE)
target_link_libraries(tfpsacrypto PRIVATE idf::esp_pm)
endif()
target_link_libraries(${COMPONENT_LIB} ${linkage_type} ${mbedtls_targets})
target_link_libraries(${COMPONENT_LIB} ${linkage_type} ${mbedtls_link_targets})
# Ensure PSA crypto initialization is included in the build
if(NOT ${IDF_TARGET} STREQUAL "linux")
+4 -25
View File
@@ -392,8 +392,7 @@ menu "mbedTLS"
config MBEDTLS_X509_CREATE_C
bool "X.509 certificate creation"
default n
depends on MBEDTLS_BIGNUM_C && \
MBEDTLS_PK_WRITE_C && MBEDTLS_MD_C
depends on MBEDTLS_PK_WRITE_C && MBEDTLS_MD_C
help
Support for creating X.509 certificates and CSRs.
@@ -729,7 +728,7 @@ menu "mbedTLS"
config MBEDTLS_KEY_EXCHANGE_ECJPAKE
bool "Enable ECJPAKE based ciphersuite modes"
depends on MBEDTLS_ECJPAKE_C && MBEDTLS_ECP_DP_SECP256R1_ENABLED
depends on MBEDTLS_ECP_DP_SECP256R1_ENABLED
default n
help
Enable to support ciphersuites with prefix TLS-ECJPAKE-WITH-
@@ -978,21 +977,9 @@ menu "mbedTLS"
endmenu
menu "Asymmetric Ciphers"
config MBEDTLS_BIGNUM_C
bool "Enable multiple precision integer (bignum) support"
default y
help
Enable support for multiple precision integer (bignum) operations.
This is required for RSA, DSA, DHM, ECDH and ECDSA.
If you don't need any of these algorithms, you can disable this option
to save code size.
config MBEDTLS_RSA_C
bool "RSA public key cryptosystem"
default y
select MBEDTLS_BIGNUM_C
help
Enable RSA. Needed to use RSA-xxx TLS ciphersuites.
@@ -1091,7 +1078,6 @@ menu "mbedTLS"
config MBEDTLS_DHM_C
bool "Diffie-Hellman-Merkle key exchange (DHM)"
default n
select MBEDTLS_BIGNUM_C
depends on MBEDTLS_ECP_C
help
Enable DHM. Needed to use DHE-xxx TLS ciphersuites.
@@ -1107,13 +1093,6 @@ menu "mbedTLS"
help
Enable ECDH. Needed to use ECDHE-xxx TLS ciphersuites.
config MBEDTLS_ECJPAKE_C
bool "Elliptic curve J-PAKE"
depends on MBEDTLS_ECP_C
default n
help
Enable ECJPAKE. Needed to use ECJPAKE-xxx TLS ciphersuites.
config MBEDTLS_ECDSA_C
bool "Elliptic Curve DSA"
depends on MBEDTLS_ECDH_C && MBEDTLS_ECP_C
@@ -1354,7 +1333,7 @@ menu "mbedTLS"
config MBEDTLS_HARDWARE_MPI
bool "Enable hardware MPI (bignum) acceleration"
default y
depends on !SPIRAM_CACHE_WORKAROUND_STRATEGY_DUPLDST && SOC_MPI_SUPPORTED && MBEDTLS_BIGNUM_C
depends on !SPIRAM_CACHE_WORKAROUND_STRATEGY_DUPLDST && SOC_MPI_SUPPORTED
help
Enable hardware accelerated multiple precision integer operations.
@@ -1586,7 +1565,7 @@ menu "mbedTLS"
bool "Enable PKCS number 7"
default y
depends on MBEDTLS_ASN1_PARSE_C && MBEDTLS_PK_PARSE_C && \
MBEDTLS_X509_CRT_PARSE_C && MBEDTLS_X509_CRL_PARSE_C && MBEDTLS_BIGNUM_C && MBEDTLS_MD_C
MBEDTLS_X509_CRT_PARSE_C && MBEDTLS_X509_CRL_PARSE_C && MBEDTLS_MD_C
help
Enable PKCS number 7 core for using PKCS number 7-formatted signatures.
@@ -10,7 +10,6 @@ CONFIG_MBEDTLS_VERSION_C=n
CONFIG_MBEDTLS_HAVE_TIME=y
CONFIG_MBEDTLS_PLATFORM_TIME_ALT=n
CONFIG_MBEDTLS_HAVE_TIME_DATE=n
CONFIG_MBEDTLS_BIGNUM_C=y
CONFIG_MBEDTLS_INTERNAL_MEM_ALLOC=y
CONFIG_MBEDTLS_EXTERNAL_MEM_ALLOC=n
CONFIG_MBEDTLS_DEFAULT_MEM_ALLOC=n
@@ -116,7 +115,6 @@ CONFIG_MBEDTLS_ECP_C=y
CONFIG_MBEDTLS_ECP_NIST_OPTIM=y
CONFIG_MBEDTLS_ECP_FIXED_POINT_OPTIM=n
CONFIG_MBEDTLS_ECDH_C=y
CONFIG_MBEDTLS_ECJPAKE_C=n
CONFIG_MBEDTLS_ECDSA_C=y
CONFIG_MBEDTLS_PK_PARSE_EC_EXTENDED=y
CONFIG_MBEDTLS_PK_PARSE_EC_COMPRESSED=y
@@ -31,17 +31,18 @@ include_directories("${COMPONENT_DIR}/port/include")
# Add PSA driver include directory globally for mbedtls targets
include_directories("${COMPONENT_DIR}/port/psa_driver/include")
# Import mbedtls library targets
add_subdirectory(mbedtls)
# Set TF_PSA_CRYPTO_CONFIG_FILE before processing subdirectories to prevent override
# Set TF_PSA_CRYPTO_USER_CONFIG_FILE before add_subdirectory so that
# all targets (including extras, platform, utilities) pick it up
set(
TF_PSA_CRYPTO_USER_CONFIG_FILE "${COMPONENT_DIR}/esp_tee/esp_tee_mbedtls_config.h"
CACHE STRING "Path to the PSA Crypto configuration file"
FORCE
)
set(mbedtls_targets mbedtls tfpsacrypto builtin mbedx509 everest p256m)
# Import mbedtls library targets
add_subdirectory(mbedtls)
set(mbedtls_targets mbedtls tfpsacrypto builtin mbedx509 everest p256-m extras platform utilities)
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/esp_hardware.c")
@@ -50,6 +51,7 @@ foreach(target ${mbedtls_targets})
-DMBEDTLS_CONFIG_FILE="${COMPONENT_DIR}/esp_tee/esp_tee_mbedtls_config.h")
set_config_files_compile_definitions(${target})
target_compile_definitions(${target} PUBLIC MBEDTLS_MAJOR_VERSION=4)
target_compile_definitions(${target} PUBLIC __STDC_WANT_LIB_EXT1__=0)
if(CONFIG_COMPILER_STATIC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU") # TODO IDF-10087
target_compile_options(${target} PRIVATE "-fno-analyzer")
endif()
@@ -48,18 +48,12 @@
#define MBEDTLS_ASN1_WRITE_C
#define MBEDTLS_ASN1_PARSE_C
#define MBEDTLS_BIGNUM_C
#if CONFIG_SECURE_TEE_SEC_STG_SUPPORT_SECP384R1_SIGN
#define PSA_WANT_ECC_SECP_R1_384 1
#define MBEDTLS_ECP_DP_SECP384R1_ENABLED
#else
#undef PSA_WANT_ECC_SECP_R1_384
#undef MBEDTLS_ECP_DP_SECP384R1_ENABLED
#endif
#define PSA_WANT_ECC_SECP_R1_256 1
#define MBEDTLS_ECP_DP_SECP256R1_ENABLED
#define MBEDTLS_ECP_C
#define MBEDTLS_ECDSA_C
#ifdef CONFIG_MBEDTLS_ECDSA_DETERMINISTIC
#define PSA_WANT_ALG_DETERMINISTIC_ECDSA 1
@@ -121,34 +115,30 @@
#undef PSA_WANT_ECC_BRAINPOOL_P_R1_512
#undef PSA_WANT_ECC_MONTGOMERY_255
#undef PSA_WANT_ECC_MONTGOMERY_448
#undef MBEDTLS_ECP_DP_BP256R1_ENABLED
#undef MBEDTLS_ECP_DP_BP384R1_ENABLED
#undef MBEDTLS_ECP_DP_BP512R1_ENABLED
#undef MBEDTLS_ECP_DP_SECP192K1_ENABLED
#undef MBEDTLS_ECP_DP_SECP224K1_ENABLED
#undef MBEDTLS_ECP_DP_SECP256K1_ENABLED
#undef MBEDTLS_ECP_DP_CURVE25519_ENABLED
#undef MBEDTLS_ECP_DP_CURVE448_ENABLED
/* Disable unused cipher/algorithm types */
#undef PSA_WANT_KEY_TYPE_ARIA
#undef MBEDTLS_ARIA_C
#undef PSA_WANT_KEY_TYPE_CAMELLIA
#undef MBEDTLS_CAMELLIA_C
#undef PSA_WANT_KEY_TYPE_DES
#undef MBEDTLS_DES_C
#undef PSA_WANT_ALG_RIPEMD160
#undef MBEDTLS_RIPEMD160_C
#undef PSA_WANT_ALG_CHACHA20
#undef MBEDTLS_CHACHA20_C
#undef PSA_WANT_ALG_SHA3_224
#undef MBEDTLS_SHA3_224_C
#undef PSA_WANT_ALG_SHA3_256
#undef MBEDTLS_SHA3_256_C
#undef PSA_WANT_ALG_SHA3_384
#undef MBEDTLS_SHA3_384_C
#undef PSA_WANT_ALG_SHA3_512
#undef MBEDTLS_SHA3_512_C
#undef PSA_WANT_ALG_CHACHA20_POLY1305
#undef PSA_WANT_ALG_CCM
#undef PSA_WANT_ALG_CMAC
#define MBEDTLS_AES_ROM_TABLES
#if SOC_AES_SUPPORTED
#define MBEDTLS_AES_FEWER_TABLES
#endif
/* Disable unused hash algorithms */
#undef PSA_WANT_ALG_MD5
#undef PSA_WANT_ALG_SHA3_224
#undef PSA_WANT_ALG_SHA3_256
#undef PSA_WANT_ALG_SHA3_384
#undef PSA_WANT_ALG_SHA3_512
/* Disable RSA — not used by TEE */
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_BASIC
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_IMPORT
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_EXPORT
@@ -158,21 +148,19 @@
#undef PSA_WANT_ALG_RSA_PKCS1V15_SIGN
#undef PSA_WANT_ALG_RSA_OAEP
#undef PSA_WANT_ALG_RSA_PSS
#undef MBEDTLS_RSA_C
/* Disable DH key exchange — not used by TEE */
#undef PSA_WANT_KEY_TYPE_DH_KEY_PAIR_BASIC
#undef PSA_WANT_KEY_TYPE_DH_KEY_PAIR_IMPORT
#undef PSA_WANT_KEY_TYPE_DH_KEY_PAIR_EXPORT
#undef PSA_WANT_KEY_TYPE_DH_KEY_PAIR_GENERATE
#undef PSA_WANT_KEY_TYPE_DH_PUBLIC_KEY
#undef PSA_WANT_ALG_FFDH
#undef MBEDTLS_ECDH_C
#undef MBEDTLS_CCM_C
#undef MBEDTLS_CHACHA20_C
#undef MBEDTLS_CHACHAPOLY_C
/* Disable TLS and other unused modules */
#undef MBEDTLS_DEBUG_C
#undef MBEDTLS_PSA_ITS_FILE_C
#undef MBEDTLS_PSA_CRYPTO_STORAGE_C
#undef MBEDTLS_SSL_CLI_C
#undef MBEDTLS_SSL_SRV_C
@@ -188,5 +176,48 @@
#define MBEDTLS_AES_FEWER_TABLES
#endif
/* Disable Diffie-Hellman groups — TEE has no TLS or DH key exchange */
#undef PSA_WANT_DH_RFC7919_2048
#undef PSA_WANT_DH_RFC7919_3072
#undef PSA_WANT_DH_RFC7919_4096
#undef PSA_WANT_DH_RFC7919_6144
#undef PSA_WANT_DH_RFC7919_8192
/* Disable key derivation and TLS KDFs not used by TEE */
#undef PSA_WANT_ALG_HKDF
#undef PSA_WANT_ALG_HKDF_EXTRACT
#undef PSA_WANT_ALG_HKDF_EXPAND
#undef PSA_WANT_ALG_TLS12_PSK_TO_MS
#undef PSA_WANT_ALG_TLS12_ECJPAKE_TO_PMS
/* Disable EC-JPAKE — not used by TEE */
#undef PSA_WANT_ALG_JPAKE
/* Disable LMS/LMOTS hash-based signatures — not used by TEE */
#undef MBEDTLS_LMS_C
/* Disable self-test functions to save code size */
#undef MBEDTLS_SELF_TEST
/* TEE uses EXTERNAL_RNG, no need for CTR-DRBG */
#undef MBEDTLS_CTR_DRBG_C
/* Disable PEM/Base64 — TEE uses DER format */
#undef MBEDTLS_PEM_PARSE_C
#undef MBEDTLS_PEM_WRITE_C
#undef MBEDTLS_BASE64_C
/* Disable PK layer — TEE uses PSA API directly */
#undef MBEDTLS_PK_C
#undef MBEDTLS_PK_PARSE_C
#undef MBEDTLS_PK_WRITE_C
/* Disable NIST key wrapping and PKCS5 — not used by TEE */
#undef MBEDTLS_NIST_KW_C
#undef MBEDTLS_PKCS5_C
/* TEE has no filesystem */
#undef MBEDTLS_FS_IO
/* ESP-TEE is single threaded so we can disable threading in mbedTLS */
#undef MBEDTLS_THREADING_C
+2 -2
View File
@@ -55,7 +55,7 @@ int ecp_mul_restartable_internal( mbedtls_ecp_group *grp, mbedtls_ecp_point *R,
mbedtls_ecp_restart_ctx *rs_ctx )
{
int ret = MBEDTLS_ERR_ECP_BAD_INPUT_DATA;
if (grp->id != MBEDTLS_ECP_DP_SECP192R1 && grp->id != MBEDTLS_ECP_DP_SECP256R1
if (grp->id != MBEDTLS_ECP_DP_SECP256R1
#if SOC_ECC_SUPPORT_CURVE_P384
&& (grp->id != MBEDTLS_ECP_DP_SECP384R1 || !ecc_ll_is_p384_curve_operations_supported())
#endif
@@ -90,7 +90,7 @@ int mbedtls_ecp_check_pubkey( const mbedtls_ecp_group *grp,
return MBEDTLS_ERR_ECP_BAD_INPUT_DATA;
}
if (grp->id != MBEDTLS_ECP_DP_SECP192R1 && grp->id != MBEDTLS_ECP_DP_SECP256R1
if (grp->id != MBEDTLS_ECP_DP_SECP256R1
#if SOC_ECC_SUPPORT_CURVE_P384
&& (grp->id != MBEDTLS_ECP_DP_SECP384R1 || !ecc_ll_is_p384_curve_operations_supported())
#endif
+1 -1
View File
@@ -26,7 +26,7 @@ struct _hr_time
struct timeval start;
};
unsigned long mbedtls_timing_get_timer( struct mbedtls_timing_hr_time *val, int reset )
unsigned long long mbedtls_timing_get_timer( struct mbedtls_timing_hr_time *val, int reset )
{
struct _hr_time *t = (struct _hr_time *) val;
@@ -277,7 +277,7 @@
#ifdef CONFIG_MBEDTLS_HARDWARE_ECC
#ifdef CONFIG_MBEDTLS_ECC_OTHER_CURVES_SOFT_FALLBACK
/* Use hardware accelerator for SECP192R1 and SECP256R1 curves,
/* Use hardware accelerator for SECP256R1 curves,
* software implementation for rest of the curves
*/
#define MBEDTLS_ECP_MUL_ALT_SOFT_FALLBACK
@@ -525,63 +525,53 @@
#endif
/**
* \def MBEDTLS_ECP_DP_SECP192R1_ENABLED
*
* MBEDTLS_ECP_XXXX_ENABLED: Enables specific curves within the Elliptic Curve
* module. By default all supported curves are enabled.
*
* Comment macros to disable the curve and functions for it
*/
/* Short Weierstrass curves (supporting ECP, ECDH, ECDSA) */
/* Short Weierstrass curves (supporting ECDH, ECDSA) */
#ifdef CONFIG_MBEDTLS_ECP_DP_SECP256R1_ENABLED
#define MBEDTLS_ECP_DP_SECP256R1_ENABLED
#define PSA_WANT_ECC_SECP_R1_256 1
#else
#undef MBEDTLS_ECP_DP_SECP256R1_ENABLED
#undef PSA_WANT_ECC_SECP_R1_256
#endif
#ifdef CONFIG_MBEDTLS_ECP_DP_SECP384R1_ENABLED
#define MBEDTLS_ECP_DP_SECP384R1_ENABLED
#define PSA_WANT_ECC_SECP_R1_384 1
#else
#undef MBEDTLS_ECP_DP_SECP384R1_ENABLED
#undef PSA_WANT_ECC_SECP_R1_384
#endif
#ifdef CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
#define PSA_WANT_ECC_SECP_R1_192 1
#else
#undef PSA_WANT_ECC_SECP_R1_192
#endif
#ifdef CONFIG_MBEDTLS_ECP_DP_SECP521R1_ENABLED
#define MBEDTLS_ECP_DP_SECP521R1_ENABLED
#define PSA_WANT_ECC_SECP_R1_521 1
#else
#undef MBEDTLS_ECP_DP_SECP521R1_ENABLED
#undef PSA_WANT_ECC_SECP_R1_521
#endif
#ifdef CONFIG_MBEDTLS_ECP_DP_SECP256K1_ENABLED
#define MBEDTLS_ECP_DP_SECP256K1_ENABLED
#define PSA_WANT_ECC_SECP_K1_256 1
#else
#undef MBEDTLS_ECP_DP_SECP256K1_ENABLED
#undef PSA_WANT_ECC_SECP_K1_256
#endif
#ifdef CONFIG_MBEDTLS_ECP_DP_BP256R1_ENABLED
#define MBEDTLS_ECP_DP_BP256R1_ENABLED
#define PSA_WANT_ECC_BRAINPOOL_P_R1_256 1
#else
#undef MBEDTLS_ECP_DP_BP256R1_ENABLED
#undef PSA_WANT_ECC_BRAINPOOL_P_R1_256
#endif
#ifdef CONFIG_MBEDTLS_ECP_DP_BP384R1_ENABLED
#define MBEDTLS_ECP_DP_BP384R1_ENABLED
#define PSA_WANT_ECC_BRAINPOOL_P_R1_384 1
#else
#undef MBEDTLS_ECP_DP_BP384R1_ENABLED
#undef PSA_WANT_ECC_BRAINPOOL_P_R1_384
#endif
#ifdef CONFIG_MBEDTLS_ECP_DP_BP512R1_ENABLED
#define MBEDTLS_ECP_DP_BP512R1_ENABLED
#define PSA_WANT_ECC_BRAINPOOL_P_R1_512 1
#else
#undef MBEDTLS_ECP_DP_BP512R1_ENABLED
#undef PSA_WANT_ECC_BRAINPOOL_P_R1_512
#endif
/* Montgomery curves (supporting ECP) */
/* Montgomery curves */
#ifdef CONFIG_MBEDTLS_ECP_DP_CURVE25519_ENABLED
#define MBEDTLS_ECP_DP_CURVE25519_ENABLED
#define PSA_WANT_ECC_MONTGOMERY_255 1
#else
#undef MBEDTLS_ECP_DP_CURVE25519_ENABLED
#endif
#ifdef MBEDTLS_ECP_DP_CURVE448_ENABLED
#undef MBEDTLS_ECP_DP_CURVE448_ENABLED
#undef PSA_WANT_ECC_MONTGOMERY_255
#endif
/**
@@ -1836,29 +1826,7 @@
#undef MBEDTLS_BASE64_C
#endif
/**
* \def MBEDTLS_BIGNUM_C
*
* Enable the multi-precision integer library.
*
* Module: library/bignum.c
* library/bignum_core.c
* library/bignum_mod.c
* library/bignum_mod_raw.c
* Caller: library/dhm.c
* library/ecp.c
* library/ecdsa.c
* library/rsa.c
* library/rsa_alt_helpers.c
* library/ssl_tls.c
*
* This module is required for RSA, DHM and ECC (ECDH, ECDSA) support.
*/
#ifdef CONFIG_MBEDTLS_BIGNUM_C
#define MBEDTLS_BIGNUM_C
#else
#undef MBEDTLS_BIGNUM_C
#endif
/* MBEDTLS_BIGNUM_C is deprecated in mbedtls 4.x - PSA handles bignum internally */
/**
* \def MBEDTLS_CAMELLIA_C
@@ -2120,9 +2088,9 @@
* Requires: MBEDTLS_ECP_C
*/
#ifdef CONFIG_MBEDTLS_ECDH_C
#define MBEDTLS_ECDH_C
#define PSA_WANT_ALG_ECDH 1
#else
#undef MBEDTLS_ECDH_C
#undef PSA_WANT_ALG_ECDH
#endif
/**
@@ -2141,51 +2109,26 @@
* short Weierstrass curve.
*/
#ifdef CONFIG_MBEDTLS_ECDSA_C
#define MBEDTLS_ECDSA_C
#define PSA_WANT_ALG_ECDSA 1
#else
#undef MBEDTLS_ECDSA_C
#undef PSA_WANT_ALG_ECDSA
#endif
/**
* \def MBEDTLS_ECJPAKE_C
*
* Enable the elliptic curve J-PAKE library.
*
* \warning This is currently experimental. EC J-PAKE support is based on the
* Thread v1.0.0 specification; incompatible changes to the specification
* might still happen. For this reason, this is disabled by default.
*
* Module: library/ecjpake.c
* Caller:
*
* This module is used by the following key exchanges:
* ECJPAKE
*
* Requires: MBEDTLS_ECP_C and MBEDTLS_MD_C
*
*/
#ifdef CONFIG_MBEDTLS_ECJPAKE_C
#define MBEDTLS_ECJPAKE_C
#else
#undef MBEDTLS_ECJPAKE_C
#endif
/**
* \def MBEDTLS_ECP_C
*
* Enable the elliptic curve over GF(p) library.
*
* Module: library/ecp.c
* Caller: library/ecdh.c
* library/ecdsa.c
* library/ecjpake.c
*
* Requires: MBEDTLS_BIGNUM_C and at least one MBEDTLS_ECP_DP_XXX_ENABLED
*/
/* MBEDTLS_ECP_C is deprecated in mbedtls 4.x - use PSA ECC key types instead */
#ifdef CONFIG_MBEDTLS_ECP_C
#define MBEDTLS_ECP_C
#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_BASIC 1
#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_IMPORT 1
#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_EXPORT 1
#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_GENERATE 1
#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE 1
#define PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY 1
#else
#undef MBEDTLS_ECP_C
#undef PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_BASIC
#undef PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_IMPORT
#undef PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_EXPORT
#undef PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_GENERATE
#undef PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE
#undef PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY
#endif
/**
@@ -2563,10 +2506,16 @@
* Requires: MBEDTLS_BIGNUM_C, MBEDTLS_OID_C
*/
#ifdef CONFIG_MBEDTLS_RSA_C
#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR 1
#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_BASIC 1
#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_IMPORT 1
#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_EXPORT 1
#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE 1
#define PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY 1
#else
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_BASIC
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_IMPORT
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_EXPORT
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE
#undef PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY
#endif
@@ -9,7 +9,6 @@
#include "esp_types.h"
#include "soc/soc_caps.h"
#include "psa/crypto_driver_common.h"
#include "hal/hmac_types.h"
#if SOC_KEY_MANAGER_SUPPORTED
#include "esp_key_mgr.h"
@@ -13,7 +13,6 @@
#include <inttypes.h>
#include <esp_random.h>
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include <mbedtls/private/ecdh.h>
#include <mbedtls/private/ecdsa.h>
#include <mbedtls/error.h>
#include "psa/crypto.h"
@@ -47,7 +47,6 @@
static bool crypto_ec_point_mul_curve_supported(const mbedtls_ecp_group *grp)
{
switch (grp->id) {
case MBEDTLS_ECP_DP_SECP192R1:
case MBEDTLS_ECP_DP_SECP256R1:
#if SOC_ECC_SUPPORT_CURVE_P384
case MBEDTLS_ECP_DP_SECP384R1:
@@ -73,7 +72,7 @@ static int crypto_ec_point_mul_ecc_hw(const mbedtls_ecp_group *grp,
return MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE;
}
if (curve_len != P192_LEN && curve_len != P256_LEN
if (curve_len != P256_LEN
#if SOC_ECC_SUPPORT_CURVE_P384
&& curve_len != P384_LEN
#endif
@@ -163,71 +162,6 @@ static int crypto_ec_key_cache_public_key_buf(crypto_ec_key_wrapper_t *wrapper,
return 0;
}
static int crypto_ec_key_cache_public_key_from_pk(crypto_ec_key_wrapper_t *wrapper,
mbedtls_pk_context *pkey)
{
unsigned char buf[PSA_EXPORT_PUBLIC_KEY_MAX_SIZE];
size_t pub_len = 0;
mbedtls_ecp_keypair *ec;
int ret;
if (!wrapper || !pkey) {
return -1;
}
ec = (mbedtls_ecp_keypair *)(pkey->MBEDTLS_PRIVATE(pk_ctx));
if (!ec) {
return -1;
}
ret = mbedtls_ecp_point_write_binary(&ec->MBEDTLS_PRIVATE(grp),
&ec->MBEDTLS_PRIVATE(Q),
MBEDTLS_ECP_PF_UNCOMPRESSED,
&pub_len, buf, sizeof(buf));
if (ret != 0) {
return -1;
}
return crypto_ec_key_cache_public_key_buf(wrapper, buf, pub_len);
}
static int crypto_ec_key_cache_private_key_from_pk(crypto_ec_key_wrapper_t *wrapper,
mbedtls_pk_context *pkey)
{
mbedtls_ecp_keypair *ec;
mbedtls_mpi *d;
int ret;
if (!wrapper || !pkey) {
return -1;
}
ec = (mbedtls_ecp_keypair *)(pkey->MBEDTLS_PRIVATE(pk_ctx));
if (!ec) {
return -1;
}
if (wrapper->cached_private_key) {
return 0;
}
d = os_calloc(1, sizeof(*d));
if (!d) {
return -1;
}
mbedtls_mpi_init(d);
ret = mbedtls_mpi_copy(d, &ec->MBEDTLS_PRIVATE(d));
if (ret != 0) {
mbedtls_mpi_free(d);
os_free(d);
return -1;
}
wrapper->cached_private_key = d;
return 0;
}
static int crypto_ec_key_cache_private_key_from_psa(crypto_ec_key_wrapper_t *wrapper)
{
psa_key_attributes_t key_attributes = PSA_KEY_ATTRIBUTES_INIT;
@@ -1542,11 +1476,6 @@ static int init_group_in_wrapper(crypto_ec_key_wrapper_t *wrapper)
static psa_ecc_family_t group_id_to_psa(mbedtls_ecp_group_id grp_id, size_t *bits)
{
switch (grp_id) {
case MBEDTLS_ECP_DP_SECP192R1:
if (bits) {
*bits = 192;
}
return PSA_ECC_FAMILY_SECP_R1;
case MBEDTLS_ECP_DP_SECP256R1:
if (bits) {
*bits = 256;
@@ -1582,16 +1511,6 @@ static psa_ecc_family_t group_id_to_psa(mbedtls_ecp_group_id grp_id, size_t *bit
*bits = 255;
}
return PSA_ECC_FAMILY_MONTGOMERY;
case MBEDTLS_ECP_DP_SECP192K1:
if (bits) {
*bits = 192;
}
return PSA_ECC_FAMILY_SECP_K1;
// case MBEDTLS_ECP_DP_SECP224K1:
// if (bits) {
// *bits = 224;
// }
// return PSA_ECC_FAMILY_SECP_K1;
case MBEDTLS_ECP_DP_SECP256K1:
if (bits) {
*bits = 256;
@@ -1627,6 +1546,46 @@ static size_t crypto_ecdh_output_size(const crypto_ec_key_wrapper_t *wrapper)
return PSA_BITS_TO_BYTES(key_bits);
}
/* Reverse mapping: PSA ECC family + bit size to mbedtls group ID */
static mbedtls_ecp_group_id psa_to_group_id(psa_ecc_family_t family, size_t bits)
{
switch (family) {
case PSA_ECC_FAMILY_SECP_R1:
if (bits == 256) {
return MBEDTLS_ECP_DP_SECP256R1;
} else if (bits == 384) {
return MBEDTLS_ECP_DP_SECP384R1;
} else if (bits == 521) {
return MBEDTLS_ECP_DP_SECP521R1;
}
break;
case PSA_ECC_FAMILY_BRAINPOOL_P_R1:
if (bits == 256) {
return MBEDTLS_ECP_DP_BP256R1;
} else if (bits == 384) {
return MBEDTLS_ECP_DP_BP384R1;
} else if (bits == 512) {
return MBEDTLS_ECP_DP_BP512R1;
}
break;
case PSA_ECC_FAMILY_MONTGOMERY:
if (bits == 255) {
return MBEDTLS_ECP_DP_CURVE25519;
} else if (bits == 448) {
return MBEDTLS_ECP_DP_CURVE448;
}
break;
case PSA_ECC_FAMILY_SECP_K1:
if (bits == 256) {
return MBEDTLS_ECP_DP_SECP256K1;
}
break;
default:
break;
}
return MBEDTLS_ECP_DP_NONE;
}
struct crypto_ec_key * crypto_ec_key_set_pub(const struct crypto_ec_group *group,
const u8 *buf, size_t len)
{
@@ -1977,55 +1936,35 @@ struct crypto_bignum *crypto_ec_key_get_private_key(struct crypto_ec_key *key)
return (struct crypto_bignum *)wrapper->cached_private_key;
}
mbedtls_pk_context *pkey_ctx = os_calloc(1, sizeof(mbedtls_pk_context));
if (!pkey_ctx) {
return NULL;
}
// Export raw private key bytes from PSA
unsigned char key_buf[PSA_BITS_TO_BYTES(PSA_VENDOR_ECC_MAX_CURVE_BITS)];
size_t key_len = 0;
mbedtls_pk_init(pkey_ctx);
int ret = mbedtls_pk_copy_from_psa(wrapper->key_id, pkey_ctx);
if (ret != 0) {
wpa_printf(MSG_ERROR, "Failed to copy key from PSA");
mbedtls_pk_free(pkey_ctx);
os_free(pkey_ctx);
psa_status_t status = psa_export_key(wrapper->key_id,
key_buf, sizeof(key_buf), &key_len);
if (status != PSA_SUCCESS) {
wpa_printf(MSG_ERROR, "Failed to export private key from PSA: %d", status);
return NULL;
}
mbedtls_mpi *d = os_calloc(1, sizeof(mbedtls_mpi));
if (!d) {
mbedtls_pk_free(pkey_ctx);
os_free(pkey_ctx);
mbedtls_platform_zeroize(key_buf, sizeof(key_buf));
return NULL;
}
mbedtls_mpi_init(d);
// Access the EC keypair directly from the PK context
// pkey_ctx->pk_ctx points to the underlying EC keypair
mbedtls_ecp_keypair *ec_key = (mbedtls_ecp_keypair *)(pkey_ctx->MBEDTLS_PRIVATE(pk_ctx));
if (!ec_key) {
wpa_printf(MSG_ERROR, "Failed to get EC keypair from PK context");
mbedtls_mpi_free(d);
os_free(d);
mbedtls_pk_free(pkey_ctx);
os_free(pkey_ctx);
return NULL;
}
int ret = mbedtls_mpi_read_binary(d, key_buf, key_len);
mbedtls_platform_zeroize(key_buf, sizeof(key_buf));
ret = mbedtls_mpi_copy(d, &ec_key->MBEDTLS_PRIVATE(d));
if (ret != 0) {
wpa_printf(MSG_ERROR, "Failed to copy private key");
wpa_printf(MSG_ERROR, "Failed to read private key into mpi: -0x%04x", -ret);
mbedtls_mpi_free(d);
os_free(d);
mbedtls_pk_free(pkey_ctx);
os_free(pkey_ctx);
return NULL;
}
mbedtls_pk_free(pkey_ctx);
os_free(pkey_ctx);
// Cache the private key in wrapper for later cleanup
wrapper->cached_private_key = d;
@@ -2202,22 +2141,7 @@ struct crypto_ec_key *crypto_ec_key_parse_priv(const u8 *privkey, size_t privkey
psa_key_type_t key_type = psa_get_key_type(&key_attributes);
psa_ecc_family_t ecc_family = PSA_KEY_TYPE_ECC_GET_FAMILY(key_type);
int key_bits = psa_get_key_bits(&key_attributes);
if (ecc_family != 0 && key_bits > 0) {
// Map PSA ECC family to mbedtls curve ID
mbedtls_ecp_group_id grp_id = MBEDTLS_ECP_DP_NONE;
if (ecc_family == PSA_ECC_FAMILY_SECP_R1) {
if (key_bits == 256) {
grp_id = MBEDTLS_ECP_DP_SECP256R1;
} else if (key_bits == 384) {
grp_id = MBEDTLS_ECP_DP_SECP384R1;
} else if (key_bits == 521) {
grp_id = MBEDTLS_ECP_DP_SECP521R1;
}
}
wrapper->curve_id = grp_id;
} else {
wrapper->curve_id = MBEDTLS_ECP_DP_NONE;
}
wrapper->curve_id = psa_to_group_id(ecc_family, key_bits);
// Allow ECDH as enrollment algorithm for key agreement operations
// Note: While usage flags allow DERIVE, the algorithm policy must also permit ECDH.
@@ -2231,12 +2155,10 @@ struct crypto_ec_key *crypto_ec_key_parse_priv(const u8 *privkey, size_t privkey
}
#if CONFIG_MBEDTLS_HARDWARE_MPI && !CONFIG_MBEDTLS_HARDWARE_ECC
if (crypto_ec_key_cache_private_key_from_pk(wrapper, kctx) < 0 &&
crypto_ec_key_cache_private_key_from_psa(wrapper) < 0) {
if (crypto_ec_key_cache_private_key_from_psa(wrapper) < 0) {
wpa_printf(MSG_DEBUG, "Failed to cache private key scalar");
}
if (crypto_ec_key_cache_public_key_from_pk(wrapper, kctx) < 0 &&
crypto_ec_key_cache_public_key_from_private_scalar(wrapper) < 0) {
if (crypto_ec_key_cache_public_key_from_private_scalar(wrapper) < 0) {
wpa_printf(MSG_DEBUG, "Failed to cache private key public component");
}
#endif
@@ -2560,76 +2482,58 @@ struct crypto_ec_key *crypto_ec_parse_subpub_key(const unsigned char *p, size_t
return NULL;
}
// Get the EC keypair from the PK context
mbedtls_ecp_keypair *ec = (mbedtls_ecp_keypair *)(pk_ctx.MBEDTLS_PRIVATE(pk_ctx));
if (!ec) {
wpa_printf(MSG_ERROR, "Failed to get EC keypair from parsed key");
mbedtls_pk_free(&pk_ctx);
return NULL;
}
mbedtls_ecp_group_id grp_id = ec->MBEDTLS_PRIVATE(grp).id;
// Convert mbedtls curve ID to PSA curve family and bits
size_t key_bits = 0;
psa_ecc_family_t ecc_family = group_id_to_psa(grp_id, &key_bits);
if (ecc_family == 0) {
wpa_printf(MSG_ERROR, "Unsupported or invalid curve: %d", grp_id);
mbedtls_pk_free(&pk_ctx);
return NULL;
}
// Export public key in uncompressed format for PSA import
unsigned char pub_key_buf[PSA_EXPORT_PUBLIC_KEY_MAX_SIZE] = {0};
size_t pub_key_len = 0;
ret = mbedtls_ecp_point_write_binary(
&ec->MBEDTLS_PRIVATE(grp),
&ec->MBEDTLS_PRIVATE(Q),
MBEDTLS_ECP_PF_UNCOMPRESSED,
&pub_key_len,
pub_key_buf,
sizeof(pub_key_buf)
);
// Get curve info via PSA attributes instead of accessing pk_ctx internals
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
ret = mbedtls_pk_get_psa_attributes(&pk_ctx, PSA_KEY_USAGE_VERIFY_HASH, &attributes);
if (ret != 0) {
wpa_printf(MSG_ERROR, "Failed to export public key: -0x%04x", -ret);
wpa_printf(MSG_ERROR, "Failed to get PSA attributes: -0x%04x", -ret);
mbedtls_pk_free(&pk_ctx);
return NULL;
}
// Done with mbedtls temporary context
mbedtls_pk_free(&pk_ctx);
psa_key_type_t key_type = psa_get_key_type(&attributes);
size_t key_bits = psa_get_key_bits(&attributes);
psa_ecc_family_t ecc_family = PSA_KEY_TYPE_ECC_GET_FAMILY(key_type);
mbedtls_ecp_group_id grp_id = psa_to_group_id(ecc_family, key_bits);
if (grp_id == MBEDTLS_ECP_DP_NONE) {
wpa_printf(MSG_ERROR, "Unsupported curve: family=0x%x bits=%zu", ecc_family, key_bits);
psa_reset_key_attributes(&attributes);
mbedtls_pk_free(&pk_ctx);
return NULL;
}
// Create wrapper structure
crypto_ec_key_wrapper_t *wrapper = os_calloc(1, sizeof(crypto_ec_key_wrapper_t));
if (!wrapper) {
wpa_printf(MSG_ERROR, "Memory allocation failed for key wrapper");
psa_reset_key_attributes(&attributes);
mbedtls_pk_free(&pk_ctx);
return NULL;
}
wrapper->curve_id = grp_id; // Store curve ID
mbedtls_ecp_group_init(&wrapper->group); // Initialize group structure
wrapper->group.id = MBEDTLS_ECP_DP_NONE; // Mark as not loaded yet (lazy init)
wrapper->curve_id = grp_id;
mbedtls_ecp_group_init(&wrapper->group);
wrapper->group.id = MBEDTLS_ECP_DP_NONE;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
// Configure attributes for import
psa_set_key_usage_flags(&attributes,
PSA_KEY_USAGE_VERIFY_HASH | PSA_KEY_USAGE_VERIFY_MESSAGE | PSA_KEY_USAGE_EXPORT);
psa_set_key_algorithm(&attributes, PSA_ALG_ECDSA(PSA_ALG_SHA_256));
psa_set_key_type(&attributes, PSA_KEY_TYPE_ECC_PUBLIC_KEY(ecc_family));
psa_set_key_bits(&attributes, key_bits);
psa_status_t status = psa_import_key(&attributes, pub_key_buf, pub_key_len, &wrapper->key_id);
// Import directly from PK context into PSA
ret = mbedtls_pk_import_into_psa(&pk_ctx, &attributes, &wrapper->key_id);
psa_reset_key_attributes(&attributes);
mbedtls_pk_free(&pk_ctx);
if (status != PSA_SUCCESS) {
wpa_printf(MSG_ERROR, "Failed to import key to PSA: %d", status);
if (ret != 0) {
wpa_printf(MSG_ERROR, "Failed to import key to PSA: -0x%04x", -ret);
mbedtls_ecp_group_free(&wrapper->group);
os_free(wrapper);
return NULL;
}
#if CONFIG_MBEDTLS_HARDWARE_MPI && !CONFIG_MBEDTLS_HARDWARE_ECC
if (crypto_ec_key_cache_public_key_buf(wrapper, pub_key_buf, pub_key_len) < 0) {
if (crypto_ec_key_ensure_public_key_cached(wrapper) < 0) {
wpa_printf(MSG_DEBUG, "Failed to cache parsed SPKI public key");
}
#endif
@@ -3150,13 +3054,7 @@ struct crypto_ec_key *crypto_ec_key_parse_pub(const u8 *der, size_t der_len)
return NULL;
}
// Extract curve ID from parsed key
mbedtls_ecp_keypair *ec = (mbedtls_ecp_keypair *)(pkey->MBEDTLS_PRIVATE(pk_ctx));
mbedtls_ecp_group_id grp_id = MBEDTLS_ECP_DP_NONE;
if (ec) {
grp_id = ec->MBEDTLS_PRIVATE(grp).id;
}
// Extract curve info via PSA attributes instead of accessing pk_ctx internals
psa_key_attributes_t key_attributes = PSA_KEY_ATTRIBUTES_INIT;
ret = mbedtls_pk_get_psa_attributes(pkey, PSA_KEY_USAGE_VERIFY_HASH, &key_attributes);
if (ret != 0) {
@@ -3166,19 +3064,27 @@ struct crypto_ec_key *crypto_ec_key_parse_pub(const u8 *der, size_t der_len)
return NULL;
}
// Derive mbedtls group ID from PSA attributes
psa_key_type_t key_type = psa_get_key_type(&key_attributes);
size_t key_bits = psa_get_key_bits(&key_attributes);
mbedtls_ecp_group_id grp_id = psa_to_group_id(
PSA_KEY_TYPE_ECC_GET_FAMILY(key_type), key_bits);
// Create wrapper structure
crypto_ec_key_wrapper_t *wrapper = os_calloc(1, sizeof(crypto_ec_key_wrapper_t));
if (!wrapper) {
wpa_printf(MSG_ERROR, "Memory allocation failed for key wrapper");
psa_reset_key_attributes(&key_attributes);
mbedtls_pk_free(pkey);
os_free(pkey);
return NULL;
}
wrapper->curve_id = grp_id; // Store curve ID
wrapper->curve_id = grp_id;
mbedtls_ecp_group_init(&wrapper->group);
wrapper->group.id = MBEDTLS_ECP_DP_NONE; // Mark as not loaded yet (lazy init)
wrapper->group.id = MBEDTLS_ECP_DP_NONE;
ret = mbedtls_pk_import_into_psa(pkey, &key_attributes, &wrapper->key_id);
psa_reset_key_attributes(&key_attributes);
if (ret != 0) {
wpa_printf(MSG_ERROR, "mbedtls_pk_import_into_psa failed with %d", ret);
mbedtls_ecp_group_free(&wrapper->group);
@@ -3187,15 +3093,16 @@ struct crypto_ec_key *crypto_ec_key_parse_pub(const u8 *der, size_t der_len)
os_free(pkey);
return NULL;
}
#if CONFIG_MBEDTLS_HARDWARE_MPI && !CONFIG_MBEDTLS_HARDWARE_ECC
if (crypto_ec_key_cache_public_key_from_pk(wrapper, pkey) < 0) {
wpa_printf(MSG_DEBUG, "Failed to cache parsed public key");
}
#endif
psa_reset_key_attributes(&key_attributes);
mbedtls_pk_free(pkey);
os_free(pkey);
#if CONFIG_MBEDTLS_HARDWARE_MPI && !CONFIG_MBEDTLS_HARDWARE_ECC
if (crypto_ec_key_ensure_public_key_cached(wrapper) < 0) {
wpa_printf(MSG_DEBUG, "Failed to cache parsed public key");
}
#endif
return (struct crypto_ec_key *)wrapper;
}
@@ -47,7 +47,7 @@ static u32 dpp_test_prod_limit_us(void)
#if !defined(CONFIG_MBEDTLS_HARDWARE_ECC) && !defined(CONFIG_MBEDTLS_HARDWARE_MPI)
return 0;
#elif CONFIG_IDF_TARGET_ESP32 || CONFIG_IDF_TARGET_ESP32S2 || CONFIG_IDF_TARGET_ESP32S3 || CONFIG_IDF_TARGET_ESP32C3
return 300000;
return 305000;
#elif SOC_ECC_SUPPORTED
return 100000;
#else