feat(esp_tee): Add support for TEE secure storage encryption for ESP32-C61

This commit is contained in:
Laukik Hase
2025-11-19 10:57:43 +05:30
parent 2cb0fa5c34
commit 65436262d5
2 changed files with 55 additions and 10 deletions
@@ -16,6 +16,8 @@
#if SOC_HMAC_SUPPORTED
#include "esp_hmac.h"
#include "esp_hmac_pbkdf2.h"
#else
#include "mbedtls/md.h"
#endif
#include "mbedtls/aes.h"
@@ -139,25 +141,60 @@ static int rand_func(void *rng_state, unsigned char *output, size_t len)
}
#if CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE
static esp_err_t compute_nvs_keys_with_hmac(hmac_key_id_t hmac_key_id, nvs_sec_cfg_t *cfg)
static esp_err_t compute_nvs_keys_with_hmac(esp_efuse_block_t key_blk, nvs_sec_cfg_t *cfg)
{
uint32_t ekey_seed[8] = {[0 ... 7] = EKEY_SEED};
uint32_t tkey_seed[8] = {[0 ... 7] = TKEY_SEED};
const uint32_t ekey_seed[8] = {[0 ... 7] = EKEY_SEED};
const uint32_t tkey_seed[8] = {[0 ... 7] = TKEY_SEED};
esp_err_t err = ESP_FAIL;
memset(cfg, 0x00, sizeof(nvs_sec_cfg_t));
esp_err_t err = ESP_FAIL;
#if SOC_HMAC_SUPPORTED
hmac_key_id_t hmac_key_id = (hmac_key_id_t)(key_blk - EFUSE_BLK_KEY0);
if (hmac_key_id < 0 || hmac_key_id >= HMAC_KEY_MAX) {
return ESP_ERR_INVALID_ARG;
}
err = esp_hmac_calculate(hmac_key_id, ekey_seed, sizeof(ekey_seed), (uint8_t *)cfg->eky);
err |= esp_hmac_calculate(hmac_key_id, tkey_seed, sizeof(tkey_seed), (uint8_t *)cfg->tky);
if (err != ESP_OK) {
memset(cfg, 0x00, sizeof(nvs_sec_cfg_t));
ESP_LOGE(TAG, "Failed to calculate seed HMAC");
return err;
}
ESP_FAULT_ASSERT(err == ESP_OK);
#else
const mbedtls_md_info_t *md_info = mbedtls_md_info_from_type(MBEDTLS_MD_SHA256);
if (md_info == NULL) {
return ESP_FAIL;
}
uint8_t key_buf[SHA256_DIGEST_SZ] = {0};
/* NOTE: The eFuse key for SoCs without HMAC support should NOT be
* read-protected when burning in the eFuse
*/
err = esp_efuse_read_block(key_blk, key_buf, 0, sizeof(key_buf) * 8);
if (err != ESP_OK) {
return err;
}
int ret = mbedtls_md_hmac(md_info, key_buf, sizeof(key_buf),
(const uint8_t *)ekey_seed, sizeof(ekey_seed),
cfg->eky);
ret |= mbedtls_md_hmac(md_info, key_buf, sizeof(key_buf),
(const uint8_t *)tkey_seed, sizeof(tkey_seed),
cfg->tky);
if (ret != 0) {
memset(cfg, 0x00, sizeof(nvs_sec_cfg_t));
ESP_LOGE(TAG, "Failed to calculate seed HMAC");
return ESP_FAIL;
}
ESP_FAULT_ASSERT(err == ESP_OK);
ESP_FAULT_ASSERT(ret == 0);
memset(key_buf, 0x00, sizeof(key_buf));
#endif
/* NOTE: If the XTS E-key and T-key are the same, we have a hash collision */
ESP_FAULT_ASSERT(memcmp(cfg->eky, cfg->tky, NVS_KEY_SIZE) != 0);
return ESP_OK;
}
#endif
@@ -170,13 +207,17 @@ static esp_err_t read_security_cfg_hmac(nvs_sec_cfg_t *cfg)
#if CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE
esp_efuse_block_t hmac_key_blk = (esp_efuse_block_t)(EFUSE_BLK_KEY0 + (esp_efuse_block_t)CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID);
esp_efuse_purpose_t hmac_efuse_blk_purpose = esp_efuse_get_key_purpose(hmac_key_blk);
if (hmac_efuse_blk_purpose != ESP_EFUSE_KEY_PURPOSE_HMAC_UP) {
ESP_LOGE(TAG, "HMAC key is not burnt in eFuse block");
esp_efuse_purpose_t purpose = esp_efuse_get_key_purpose(hmac_key_blk);
#if SOC_HMAC_SUPPORTED
if (purpose != ESP_EFUSE_KEY_PURPOSE_HMAC_UP) {
#else
if (purpose != ESP_EFUSE_KEY_PURPOSE_USER) {
#endif
ESP_LOGE(TAG, "Key is not burnt in eFuse block with expected purpose");
return ESP_ERR_NOT_FOUND;
}
esp_err_t err = compute_nvs_keys_with_hmac((hmac_key_id_t)CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID, cfg);
esp_err_t err = compute_nvs_keys_with_hmac(hmac_key_blk, cfg);
if (err != ESP_OK) {
return err;
}
@@ -80,6 +80,10 @@
#define MBEDTLS_ECP_VERIFY_ALT
#endif
#if !SOC_HMAC_SUPPORTED
#define MBEDTLS_MD_C
#endif
#define MBEDTLS_ENTROPY_C
#endif /* ESP_TEE_MBEDTLS_CONFIG_H */