mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
feat(esp_tee): Use CTR-DRBG for assisting random number generation in TEE
- For ESP-TEE, fault-assert in `esp_random()` if the RNG is held in a freeze state
This commit is contained in:
@@ -12,7 +12,6 @@
|
||||
#include "esp_fault.h"
|
||||
#include "esp_efuse.h"
|
||||
#include "esp_efuse_chip.h"
|
||||
#include "esp_random.h"
|
||||
#include "spi_flash_mmap.h"
|
||||
#if SOC_HMAC_SUPPORTED
|
||||
#include "psa_crypto_driver_esp_hmac_opaque.h"
|
||||
@@ -314,6 +313,13 @@ bool esp_tee_sec_storage_is_key_tee_owned(const char *key_id)
|
||||
|
||||
esp_err_t esp_tee_sec_storage_init(void)
|
||||
{
|
||||
/* Explicitly seeds the CTR-DRBG before any PSA operations */
|
||||
uint8_t random;
|
||||
psa_status_t ret = psa_generate_random(&random, sizeof(random));
|
||||
if (ret != PSA_SUCCESS) {
|
||||
return ESP_FAIL;
|
||||
}
|
||||
|
||||
nvs_sec_cfg_t cfg = {};
|
||||
esp_err_t err = read_security_cfg_hmac(&cfg);
|
||||
if (err != ESP_OK) {
|
||||
@@ -479,9 +485,9 @@ static int generate_aes256_key(sec_stg_key_t *keyctx)
|
||||
}
|
||||
|
||||
ESP_LOGD(TAG, "Generating AES-256 key...");
|
||||
esp_fill_random(&keyctx->aes256.key, AES256_KEY_LEN);
|
||||
psa_status_t status = psa_generate_random(keyctx->aes256.key, AES256_KEY_LEN);
|
||||
|
||||
return 0;
|
||||
return (status == PSA_SUCCESS) ? 0 : -1;
|
||||
}
|
||||
|
||||
esp_err_t esp_tee_sec_storage_gen_key(const esp_tee_sec_storage_key_cfg_t *cfg)
|
||||
@@ -747,7 +753,11 @@ static esp_err_t tee_sec_storage_crypt_common(const char *key_id, const uint8_t
|
||||
}
|
||||
|
||||
if (is_encrypt) {
|
||||
esp_fill_random(iv, iv_len);
|
||||
status = psa_generate_random(iv, iv_len);
|
||||
if (status != PSA_SUCCESS) {
|
||||
err = ESP_FAIL;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
size_t output_length = 0;
|
||||
status = psa_aead_encrypt(psa_key_id, PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_GCM, tag_len),
|
||||
|
||||
@@ -27,6 +27,9 @@
|
||||
#if SOC_ECDSA_SUPPORTED
|
||||
#include "hal/ecdsa_ll.h"
|
||||
#endif
|
||||
#if SOC_RNG_SUPPORTED
|
||||
#include "hal/rng_ll.h"
|
||||
#endif
|
||||
|
||||
#include "esp_tee.h"
|
||||
#include "esp_attr.h"
|
||||
@@ -77,4 +80,11 @@ void IRAM_ATTR esp_tee_soc_reset_crypto_peripherals(void)
|
||||
ecdsa_ll_reset_register();
|
||||
ecdsa_ll_enable_bus_clock(false);
|
||||
#endif
|
||||
|
||||
#if SOC_RNG_SUPPORTED
|
||||
rng_ll_enable();
|
||||
#if RNG_LL_NEEDS_RESET_WHEN_WAKEUP
|
||||
rng_ll_reset();
|
||||
#endif
|
||||
#endif
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user