mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat(esp_tee): Use CTR-DRBG for assisting random number generation in TEE
- For ESP-TEE, fault-assert in `esp_random()` if the RNG is held in a freeze state
This commit is contained in:
@@ -43,6 +43,12 @@
|
||||
#if SOC_AES_SUPPORTED
|
||||
#define ESP_AES_DRIVER_ENABLED
|
||||
#define MBEDTLS_PSA_ACCEL_KEY_TYPE_AES
|
||||
#define MBEDTLS_PSA_ACCEL_ALG_ECB_NO_PADDING
|
||||
#define MBEDTLS_PSA_ACCEL_ALG_CBC_NO_PADDING
|
||||
#define MBEDTLS_PSA_ACCEL_ALG_CBC_PKCS7
|
||||
#define MBEDTLS_PSA_ACCEL_ALG_CFB
|
||||
#define MBEDTLS_PSA_ACCEL_ALG_CTR
|
||||
#define MBEDTLS_PSA_ACCEL_ALG_OFB
|
||||
#endif
|
||||
#define MBEDTLS_CIPHER_MODE_XTS
|
||||
|
||||
@@ -120,13 +126,16 @@
|
||||
/* Disable unused cipher/algorithm types */
|
||||
#undef PSA_WANT_KEY_TYPE_ARIA
|
||||
#undef PSA_WANT_KEY_TYPE_CAMELLIA
|
||||
#undef PSA_WANT_KEY_TYPE_CHACHA20
|
||||
#undef PSA_WANT_KEY_TYPE_DES
|
||||
#undef PSA_WANT_ALG_RIPEMD160
|
||||
#undef PSA_WANT_ALG_STREAM_CIPHER
|
||||
#undef PSA_WANT_ALG_CHACHA20
|
||||
#undef MBEDTLS_CHACHA20_C
|
||||
#undef PSA_WANT_ALG_CHACHA20_POLY1305
|
||||
#undef MBEDTLS_CHACHAPOLY_C
|
||||
#undef PSA_WANT_ALG_CCM
|
||||
#undef PSA_WANT_ALG_CCM_STAR_NO_TAG
|
||||
#undef PSA_WANT_ALG_CMAC
|
||||
|
||||
/* Disable unused hash algorithms */
|
||||
@@ -168,6 +177,8 @@
|
||||
#undef MBEDTLS_SSL_SRV_C
|
||||
|
||||
#undef PSA_WANT_ALG_TLS12_PRF
|
||||
#undef PSA_WANT_ALG_TLS12_PSK_TO_MS
|
||||
#undef PSA_WANT_ALG_TLS12_ECJPAKE_TO_PMS
|
||||
#undef PSA_WANT_ALG_PBKDF2_HMAC
|
||||
#undef PSA_WANT_ALG_PBKDF2_AES_CMAC_PRF_128
|
||||
|
||||
@@ -200,8 +211,8 @@
|
||||
/* Disable self-test functions to save code size */
|
||||
#undef MBEDTLS_SELF_TEST
|
||||
|
||||
/* TEE uses EXTERNAL_RNG, no need for CTR-DRBG */
|
||||
#undef MBEDTLS_CTR_DRBG_C
|
||||
/* CTR-DRBG for strengthening the RNG operations in TEE */
|
||||
#define MBEDTLS_CTR_DRBG_C
|
||||
|
||||
/* Disable PEM/Base64 — TEE uses DER format */
|
||||
#undef MBEDTLS_PEM_PARSE_C
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2021-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -11,6 +11,62 @@
|
||||
#include <entropy_poll.h>
|
||||
#include "psa/crypto.h"
|
||||
|
||||
#if ESP_TEE_BUILD
|
||||
#include "mbedtls/private/ctr_drbg.h"
|
||||
#include "mbedtls/platform_util.h"
|
||||
#include "esp_cpu.h"
|
||||
#include "esp_fault.h"
|
||||
#include "hal/efuse_hal.h"
|
||||
#include "hal/rng_ll.h"
|
||||
|
||||
#define CTR_DRBG_RESEED_INTERVAL 1024
|
||||
|
||||
static mbedtls_ctr_drbg_context s_ctr_drbg;
|
||||
|
||||
static int esp_tee_entropy_func(void *data, unsigned char *output, unsigned int len)
|
||||
{
|
||||
(void)data;
|
||||
/* Explicitly enable the RNG */
|
||||
rng_ll_enable();
|
||||
esp_fill_random(output, len);
|
||||
return 0;
|
||||
}
|
||||
|
||||
static void esp_tee_ctr_drbg_init(void)
|
||||
{
|
||||
static bool s_ctr_drbg_initialized = false;
|
||||
|
||||
if (!s_ctr_drbg_initialized) {
|
||||
/* Personalization data for CTR-DRBG seeding */
|
||||
struct {
|
||||
uint8_t mac[6];
|
||||
uint32_t random;
|
||||
uint32_t cycle_cnt;
|
||||
} data = {};
|
||||
|
||||
rng_ll_enable();
|
||||
data.random = esp_random();
|
||||
efuse_hal_get_mac(data.mac);
|
||||
data.cycle_cnt = esp_cpu_get_cycle_count();
|
||||
|
||||
mbedtls_ctr_drbg_init(&s_ctr_drbg);
|
||||
mbedtls_ctr_drbg_set_reseed_interval(&s_ctr_drbg, CTR_DRBG_RESEED_INTERVAL);
|
||||
|
||||
int ret = mbedtls_ctr_drbg_seed(&s_ctr_drbg, esp_tee_entropy_func, NULL,
|
||||
(const unsigned char *)&data, sizeof(data));
|
||||
mbedtls_platform_zeroize(&data, sizeof(data));
|
||||
if (ret != 0) {
|
||||
abort();
|
||||
}
|
||||
ESP_FAULT_ASSERT(ret == 0);
|
||||
|
||||
s_ctr_drbg_initialized = true;
|
||||
}
|
||||
|
||||
ESP_FAULT_ASSERT(s_ctr_drbg_initialized);
|
||||
}
|
||||
#endif // ESP_TEE_BUILD
|
||||
|
||||
int mbedtls_hardware_poll( void *data,
|
||||
unsigned char *output, size_t len, size_t *olen )
|
||||
{
|
||||
@@ -27,7 +83,18 @@ psa_status_t mbedtls_psa_external_get_random(
|
||||
if (context == NULL || output == NULL || output_length == NULL) {
|
||||
return PSA_ERROR_INVALID_ARGUMENT;
|
||||
}
|
||||
|
||||
#if ESP_TEE_BUILD
|
||||
esp_tee_ctr_drbg_init();
|
||||
int ret = mbedtls_ctr_drbg_random(&s_ctr_drbg, output, output_size);
|
||||
if (ret != 0) {
|
||||
return PSA_ERROR_HARDWARE_FAILURE;
|
||||
}
|
||||
ESP_FAULT_ASSERT(ret == 0);
|
||||
#else
|
||||
esp_fill_random(output, output_size);
|
||||
#endif
|
||||
|
||||
*output_length = output_size;
|
||||
return PSA_SUCCESS;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user