mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat: code cleanup
This commit is contained in:
@@ -29,7 +29,9 @@ Before the project configuration and build, be sure to set the correct chip targ
|
||||
|
||||
Open the project configuration menu (`idf.py menuconfig`).
|
||||
|
||||
- Configure the secure storage example key ID at `Example Configuration → TEE: Secure Storage Key ID`.
|
||||
- Configure unique secure storage key IDs for each workflow:
|
||||
- `Example Configuration → TEE: Secure Storage Key ID for signing`
|
||||
- `Example Configuration → TEE: Secure Storage Key ID for encryption`
|
||||
|
||||
TEE Secure Storage follows the NVS partition format and uses an XTS-AES encryption scheme derived via the HMAC peripheral or software-based HMAC implementation. It supports two key derivation modes, configurable via `CONFIG_SECURE_TEE_SEC_STG_MODE`:
|
||||
|
||||
|
||||
@@ -1,11 +1,17 @@
|
||||
menu "Example Configuration"
|
||||
|
||||
config EXAMPLE_TEE_SEC_STG_KEY_STR_ID
|
||||
string "TEE: Secure Storage Key ID"
|
||||
default "key_id_0"
|
||||
config EXAMPLE_TEE_SEC_STG_SIGN_KEY_STR_ID
|
||||
string "TEE: Secure Storage Key ID for signing"
|
||||
default "sign_key_id_0"
|
||||
help
|
||||
This configuration sets the key string identifier from the TEE secure storage
|
||||
storing the ECDSA keypair for executing sign/verify operations
|
||||
from the TEE side
|
||||
Identifier for the ECDSA keypair stored in secure storage and used for
|
||||
sign/verify operations in this example.
|
||||
|
||||
config EXAMPLE_TEE_SEC_STG_ENC_KEY_STR_ID
|
||||
string "TEE: Secure Storage Key ID for encryption"
|
||||
default "aes_key_id_0"
|
||||
help
|
||||
Identifier for the AES-256 key stored in secure storage and used for
|
||||
the AEAD encryption/decryption part of this example.
|
||||
|
||||
endmenu
|
||||
|
||||
@@ -15,9 +15,6 @@
|
||||
#include "freertos/FreeRTOS.h"
|
||||
#include "freertos/task.h"
|
||||
|
||||
// #include "mbedtls/ecp.h"
|
||||
// #include "mbedtls/ecdsa.h"
|
||||
// #include "mbedtls/sha256.h"
|
||||
#include "psa/crypto.h"
|
||||
|
||||
#include "esp_tee_sec_storage.h"
|
||||
@@ -29,7 +26,8 @@
|
||||
#define AES256_GCM_TAG_LEN (16)
|
||||
#define AES256_GCM_AAD_LEN (16)
|
||||
|
||||
#define KEY_STR_ID (CONFIG_EXAMPLE_TEE_SEC_STG_KEY_STR_ID)
|
||||
#define SIGN_KEY_STR_ID (CONFIG_EXAMPLE_TEE_SEC_STG_SIGN_KEY_STR_ID)
|
||||
#define ENC_KEY_STR_ID (CONFIG_EXAMPLE_TEE_SEC_STG_ENC_KEY_STR_ID)
|
||||
#define MAX_AES_PLAINTEXT_LEN (128)
|
||||
|
||||
static const char *message = "Lorem ipsum dolor sit amet, consectetur adipiscing elit.";
|
||||
@@ -93,7 +91,7 @@ static void example_tee_sec_stg_sign_verify(void *pvParameter)
|
||||
}
|
||||
|
||||
esp_tee_sec_storage_key_cfg_t cfg = {
|
||||
.id = (const char *)(KEY_STR_ID),
|
||||
.id = (const char *)(SIGN_KEY_STR_ID),
|
||||
.type = ESP_SEC_STG_KEY_ECDSA_SECP256R1
|
||||
};
|
||||
|
||||
@@ -161,7 +159,7 @@ static void example_tee_sec_stg_encrypt_decrypt(void *pvParameter)
|
||||
}
|
||||
|
||||
esp_tee_sec_storage_key_cfg_t cfg = {
|
||||
.id = (const char *)(KEY_STR_ID),
|
||||
.id = (const char *)(ENC_KEY_STR_ID),
|
||||
.type = ESP_SEC_STG_KEY_AES256
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user