feat(esp_tee): Migrate TEE attestation to the PSA interface

This commit is contained in:
Laukik Hase
2026-01-16 12:28:57 +05:30
parent 5fe2a941f5
commit 89f555d698
22 changed files with 323 additions and 212 deletions
+5 -1
View File
@@ -188,7 +188,6 @@ endif()
set(mbedtls_targets mbedtls mbedx509 tfpsacrypto builtin)
target_include_directories(tfpsacrypto PUBLIC "port/include")
target_include_directories(tfpsacrypto PRIVATE "port/psa_crypto_storage/include")
if(CONFIG_MBEDTLS_HARDWARE_SHA OR CONFIG_MBEDTLS_HARDWARE_AES)
target_include_directories(tfpsacrypto PUBLIC "${COMPONENT_DIR}/port/psa_driver/include")
@@ -241,6 +240,11 @@ if(NOT ${IDF_TARGET} STREQUAL "linux")
endif()
endif()
# PSA Attestation
if(CONFIG_SECURE_TEE_ATTESTATION)
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/psa_attestation/psa_initial_attestation.c")
endif()
if(CONFIG_MBEDTLS_DYNAMIC_BUFFER)
set(mbedtls_target_sources ${mbedtls_target_sources}
"${COMPONENT_DIR}/port/dynamic/esp_mbedtls_dynamic_impl.c"
@@ -118,3 +118,6 @@ if(CONFIG_SOC_HMAC_SUPPORTED)
# HMAC-based PBKDF2 implementation
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/esp_hmac_pbkdf2.c")
endif()
# PSA Attestation
target_include_directories(tfpsacrypto PUBLIC "${COMPONENT_DIR}/port/psa_attestation")
@@ -0,0 +1,71 @@
/*
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*
* PSA Attestation implementation
*/
#ifndef PSA_INITIAL_ATTESTATION_H
#define PSA_INITIAL_ATTESTATION_H
#include <stddef.h>
#include <stdint.h>
#include "psa/crypto_values.h"
#ifdef __cplusplus
extern "C" {
#endif
#define PSA_INITIAL_ATTEST_API_VERSION_MAJOR 1 /*!< Major version of this implementation of the Attestation API */
#define PSA_INITIAL_ATTEST_API_VERSION_MINOR 0 /*!< Minor version of this implementation of the Attestation API */
#define PSA_INITIAL_ATTEST_MAX_TOKEN_SIZE 2048 /*!< Maximum size of an attestation token in bytes */
#define PSA_INITIAL_ATTEST_CHALLENGE_SIZE_32 (32u)
#define PSA_INITIAL_ATTEST_CHALLENGE_SIZE_48 (48u)
#define PSA_INITIAL_ATTEST_CHALLENGE_SIZE_64 (64u)
#define PSA_INITIAL_ATTEST_CHALLENGE_SIZE_MAX (PSA_INITIAL_ATTEST_CHALLENGE_SIZE_64) /*!< Maximum supported challenge size */
/**
* @brief Generate an entity attestation token
*
* Generates an attestation token containing device identity and security claims, signed and
* encoded in the JSON format.
*
* @param auth_challenge Pointer to a buffer containing the challenge data from the verifier
* @param challenge_size Size of the challenge in bytes. Must be 32, 48, or 64 bytes
* @param token_buf Pointer to a buffer where the attestation token will be written
* @param token_buf_size Size of the token buffer in bytes
* @param token_size On success, will be set to the actual size of the generated token
*
* @return psa_status_t PSA_SUCCESS on success,
* PSA_ERROR_INVALID_ARGUMENT if parameters are invalid,
* PSA_ERROR_BUFFER_TOO_SMALL if token_buf is too small,
* PSA_ERROR_NOT_SUPPORTED if the requested challenge size is not supported,
* or another error code on failure
*/
psa_status_t psa_initial_attest_get_token(const uint8_t *auth_challenge, size_t challenge_size,
uint8_t *token_buf, size_t token_buf_size, size_t *token_size);
/**
* @brief Get the size of the attestation token that would be generated
*
* This can be used to allocate an appropriately sized buffer before calling psa_initial_attest_get_token().
*
* @param challenge_size Size of the challenge in bytes. Must be 32, 48, or 64 bytes
* @param token_size On success, will be set to the size of the token that would be generated
*
* @return psa_status_t PSA_SUCCESS on success,
* PSA_ERROR_INVALID_ARGUMENT if challenge_size is invalid,
* PSA_ERROR_NOT_SUPPORTED if the requested challenge size is not supported,
* or another error code on failure
*/
psa_status_t psa_initial_attest_get_token_size(size_t challenge_size, size_t *token_size);
#ifdef __cplusplus
}
#endif
#endif // PSA_INITIAL_ATTESTATION_H
@@ -0,0 +1,36 @@
/*
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*
* PSA Attestation implementation
*/
#include "mbedtls/platform.h"
#include "mbedtls/platform_util.h"
#include "psa/initial_attestation.h"
#include <limits.h>
#include <stdint.h>
#include <string.h>
#include "esp_log.h"
static const char *TAG = "esp_psa_initial_attest";
/**
* @brief Dummy implementation of PSA attestation APIs
*
*/
psa_status_t psa_initial_attest_get_token(const uint8_t *auth_challenge, size_t challenge_size,
uint8_t *token_buf, size_t token_buf_size, size_t *token_size)
{
ESP_LOGE(TAG, "Attestation service is not supported");
return PSA_ERROR_NOT_SUPPORTED;
}
psa_status_t psa_initial_attest_get_token_size(size_t challenge_size, size_t *token_size)
{
ESP_LOGE(TAG, "Attestation service is not supported");
return PSA_ERROR_NOT_SUPPORTED;
}