mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
Merge branch 'feat/mbedtls_update_3.6.7' into 'release/v5.5'
feat(mbedtls): update to version 3.6.7 See merge request espressif/esp-idf!50621
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
# SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
# SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD
|
||||
# SPDX-License-Identifier: Unlicense OR CC0-1.0
|
||||
import os
|
||||
from typing import Callable
|
||||
@@ -12,11 +12,11 @@ from pytest_embedded_idf.utils import idf_parametrize
|
||||
SAVE_BIN_SIZE_TH = {
|
||||
'disable_sae_h2e': {
|
||||
'esp32': 16700,
|
||||
'esp32c2': 19700,
|
||||
'esp32c2': 19450,
|
||||
'esp32c3': 19600,
|
||||
'esp32c5': 19650,
|
||||
'esp32c6': 19650,
|
||||
'esp32c61': 19700,
|
||||
'esp32c5': 19400,
|
||||
'esp32c6': 19400,
|
||||
'esp32c61': 19450,
|
||||
'esp32s2': 16600,
|
||||
'esp32s3': 16550,
|
||||
'default': 16000,
|
||||
|
||||
@@ -540,6 +540,31 @@ menu "mbedTLS"
|
||||
priority level and any level from 1 to 3 can be selected (based on the availability).
|
||||
Note: Higher value indicates high interrupt priority.
|
||||
|
||||
menu "Security hardening"
|
||||
|
||||
config MBEDTLS_CONSTANT_TIME_PRIME_GEN
|
||||
bool "Constant-time prime generation"
|
||||
default y
|
||||
help
|
||||
Use mbedtls' constant-time small-factor test (a constant-time
|
||||
GCD against the product of all odd primes up to 997) when
|
||||
generating prime numbers, e.g. during RSA key generation.
|
||||
|
||||
The constant-time implementation avoids a timing side channel
|
||||
in prime generation, but it makes RSA key generation roughly
|
||||
ten times slower, and its long non-yielding software
|
||||
computations can starve the idle task and trigger the task
|
||||
watchdog, so key generation code may need a larger watchdog
|
||||
timeout or the watchdog disabled.
|
||||
|
||||
If disabled, the variable-time trial division that mbedtls
|
||||
used before version 3.6.7 is used instead, restoring key
|
||||
generation performance. Only consider disabling this if no
|
||||
untrusted code running on the device could observe the timing
|
||||
of key generation operations.
|
||||
|
||||
endmenu # Security hardening
|
||||
|
||||
config MBEDTLS_HARDWARE_SHA
|
||||
bool "Enable hardware SHA acceleration"
|
||||
default y
|
||||
|
||||
Submodule components/mbedtls/mbedtls updated: 9d669eadb1...2b96dd8eeb
@@ -212,6 +212,17 @@
|
||||
#undef MBEDTLS_MPI_MUL_MPI_ALT
|
||||
#endif
|
||||
|
||||
/* mbedtls 3.6.7 made the small-factor test used in prime generation
|
||||
* constant-time, which slows RSA key generation down roughly tenfold and
|
||||
* starves the idle task (the computation never yields the CPU). The
|
||||
* constant-time variant is the default; when it is explicitly disabled,
|
||||
* fall back to the variable-time trial division from earlier releases. See
|
||||
* MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME in library/bignum.c.
|
||||
*/
|
||||
#ifndef CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN
|
||||
#define MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME
|
||||
#endif
|
||||
|
||||
#ifdef CONFIG_MBEDTLS_ATCA_HW_ECDSA_SIGN
|
||||
#define MBEDTLS_ECDSA_SIGN_ALT
|
||||
#endif
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
* Focus on testing functionality where we use ESP32 hardware
|
||||
* accelerated crypto features
|
||||
*
|
||||
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2021-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -570,6 +570,12 @@ static void rsa_key_operations(int keysize, bool check_performance, bool generat
|
||||
}
|
||||
|
||||
|
||||
/* With constant-time prime generation the RSA-2048 key generation below takes
|
||||
* over a minute on most targets (~86 s on ESP32-S3), exceeding the test
|
||||
* timeout and starving the task watchdog, so only run it with the faster
|
||||
* variable-time implementation.
|
||||
*/
|
||||
#if !CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN
|
||||
TEST_CASE("mbedtls RSA Generate Key", "[mbedtls][timeout=60]")
|
||||
{
|
||||
|
||||
@@ -607,5 +613,6 @@ TEST_CASE("mbedtls RSA Generate Key", "[mbedtls][timeout=60]")
|
||||
#endif // CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT
|
||||
|
||||
}
|
||||
#endif // !CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN
|
||||
|
||||
#endif // CONFIG_MBEDTLS_HARDWARE_MPI
|
||||
|
||||
Reference in New Issue
Block a user