mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat(esp_tee): Migrate TEE attestation to the PSA interface
This commit is contained in:
@@ -188,7 +188,6 @@ endif()
|
||||
set(mbedtls_targets mbedtls mbedx509 tfpsacrypto builtin)
|
||||
|
||||
target_include_directories(tfpsacrypto PUBLIC "port/include")
|
||||
target_include_directories(tfpsacrypto PRIVATE "port/psa_crypto_storage/include")
|
||||
|
||||
if(CONFIG_MBEDTLS_HARDWARE_SHA OR CONFIG_MBEDTLS_HARDWARE_AES)
|
||||
target_include_directories(tfpsacrypto PUBLIC "${COMPONENT_DIR}/port/psa_driver/include")
|
||||
@@ -241,6 +240,11 @@ if(NOT ${IDF_TARGET} STREQUAL "linux")
|
||||
endif()
|
||||
endif()
|
||||
|
||||
# PSA Attestation
|
||||
if(CONFIG_SECURE_TEE_ATTESTATION)
|
||||
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/psa_attestation/psa_initial_attestation.c")
|
||||
endif()
|
||||
|
||||
if(CONFIG_MBEDTLS_DYNAMIC_BUFFER)
|
||||
set(mbedtls_target_sources ${mbedtls_target_sources}
|
||||
"${COMPONENT_DIR}/port/dynamic/esp_mbedtls_dynamic_impl.c"
|
||||
|
||||
@@ -118,3 +118,6 @@ if(CONFIG_SOC_HMAC_SUPPORTED)
|
||||
# HMAC-based PBKDF2 implementation
|
||||
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/esp_hmac_pbkdf2.c")
|
||||
endif()
|
||||
|
||||
# PSA Attestation
|
||||
target_include_directories(tfpsacrypto PUBLIC "${COMPONENT_DIR}/port/psa_attestation")
|
||||
|
||||
@@ -0,0 +1,71 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*
|
||||
* PSA Attestation implementation
|
||||
*/
|
||||
|
||||
#ifndef PSA_INITIAL_ATTESTATION_H
|
||||
#define PSA_INITIAL_ATTESTATION_H
|
||||
|
||||
#include <stddef.h>
|
||||
#include <stdint.h>
|
||||
|
||||
#include "psa/crypto_values.h"
|
||||
|
||||
#ifdef __cplusplus
|
||||
extern "C" {
|
||||
#endif
|
||||
|
||||
#define PSA_INITIAL_ATTEST_API_VERSION_MAJOR 1 /*!< Major version of this implementation of the Attestation API */
|
||||
#define PSA_INITIAL_ATTEST_API_VERSION_MINOR 0 /*!< Minor version of this implementation of the Attestation API */
|
||||
|
||||
#define PSA_INITIAL_ATTEST_MAX_TOKEN_SIZE 2048 /*!< Maximum size of an attestation token in bytes */
|
||||
|
||||
#define PSA_INITIAL_ATTEST_CHALLENGE_SIZE_32 (32u)
|
||||
#define PSA_INITIAL_ATTEST_CHALLENGE_SIZE_48 (48u)
|
||||
#define PSA_INITIAL_ATTEST_CHALLENGE_SIZE_64 (64u)
|
||||
#define PSA_INITIAL_ATTEST_CHALLENGE_SIZE_MAX (PSA_INITIAL_ATTEST_CHALLENGE_SIZE_64) /*!< Maximum supported challenge size */
|
||||
|
||||
/**
|
||||
* @brief Generate an entity attestation token
|
||||
*
|
||||
* Generates an attestation token containing device identity and security claims, signed and
|
||||
* encoded in the JSON format.
|
||||
*
|
||||
* @param auth_challenge Pointer to a buffer containing the challenge data from the verifier
|
||||
* @param challenge_size Size of the challenge in bytes. Must be 32, 48, or 64 bytes
|
||||
* @param token_buf Pointer to a buffer where the attestation token will be written
|
||||
* @param token_buf_size Size of the token buffer in bytes
|
||||
* @param token_size On success, will be set to the actual size of the generated token
|
||||
*
|
||||
* @return psa_status_t PSA_SUCCESS on success,
|
||||
* PSA_ERROR_INVALID_ARGUMENT if parameters are invalid,
|
||||
* PSA_ERROR_BUFFER_TOO_SMALL if token_buf is too small,
|
||||
* PSA_ERROR_NOT_SUPPORTED if the requested challenge size is not supported,
|
||||
* or another error code on failure
|
||||
*/
|
||||
psa_status_t psa_initial_attest_get_token(const uint8_t *auth_challenge, size_t challenge_size,
|
||||
uint8_t *token_buf, size_t token_buf_size, size_t *token_size);
|
||||
|
||||
/**
|
||||
* @brief Get the size of the attestation token that would be generated
|
||||
*
|
||||
* This can be used to allocate an appropriately sized buffer before calling psa_initial_attest_get_token().
|
||||
*
|
||||
* @param challenge_size Size of the challenge in bytes. Must be 32, 48, or 64 bytes
|
||||
* @param token_size On success, will be set to the size of the token that would be generated
|
||||
*
|
||||
* @return psa_status_t PSA_SUCCESS on success,
|
||||
* PSA_ERROR_INVALID_ARGUMENT if challenge_size is invalid,
|
||||
* PSA_ERROR_NOT_SUPPORTED if the requested challenge size is not supported,
|
||||
* or another error code on failure
|
||||
*/
|
||||
psa_status_t psa_initial_attest_get_token_size(size_t challenge_size, size_t *token_size);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
#endif
|
||||
|
||||
#endif // PSA_INITIAL_ATTESTATION_H
|
||||
@@ -0,0 +1,36 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*
|
||||
* PSA Attestation implementation
|
||||
*/
|
||||
|
||||
#include "mbedtls/platform.h"
|
||||
#include "mbedtls/platform_util.h"
|
||||
#include "psa/initial_attestation.h"
|
||||
|
||||
#include <limits.h>
|
||||
#include <stdint.h>
|
||||
#include <string.h>
|
||||
|
||||
#include "esp_log.h"
|
||||
|
||||
static const char *TAG = "esp_psa_initial_attest";
|
||||
|
||||
/**
|
||||
* @brief Dummy implementation of PSA attestation APIs
|
||||
*
|
||||
*/
|
||||
psa_status_t psa_initial_attest_get_token(const uint8_t *auth_challenge, size_t challenge_size,
|
||||
uint8_t *token_buf, size_t token_buf_size, size_t *token_size)
|
||||
{
|
||||
ESP_LOGE(TAG, "Attestation service is not supported");
|
||||
return PSA_ERROR_NOT_SUPPORTED;
|
||||
}
|
||||
|
||||
psa_status_t psa_initial_attest_get_token_size(size_t challenge_size, size_t *token_size)
|
||||
{
|
||||
ESP_LOGE(TAG, "Attestation service is not supported");
|
||||
return PSA_ERROR_NOT_SUPPORTED;
|
||||
}
|
||||
Reference in New Issue
Block a user