feat(esp_tee): Restrict REE access to TEE-owned secure storage keys

This commit is contained in:
Laukik Hase
2026-09-03 12:15:31 +05:30
parent 6a605263e8
commit a1bc64d14e
13 changed files with 170 additions and 45 deletions
@@ -18,6 +18,8 @@ options:
-o, --output OUTPUT output binary file name
-i, --input INPUT input key file (.pem for ecdsa, .bin for aes)
--write-once make key persistent - cannot be modified or deleted once written
--tee-only mark key as owned exclusively by the TEE - the REE cannot use, generate or clear it
-h, --help Show this message and exit
```
### ECDSA Keys
@@ -31,7 +33,7 @@ python esp_tee_sec_stg_keygen.py -k ecdsa_p192 -o ecdsa_p192_k0.bin
```bash
openssl ecparam -name prime256v1 -genkey -noout -out ecdsa_p256.pem
python esp_tee_sec_stg_keygen.py -k ecdsa_p256 -o ecdsa_p256_k1.bin -i ecdsa_p256.pem --write-once
python esp_tee_sec_stg_keygen.py -k ecdsa_p256 -o ecdsa_p256_k1.bin -i ecdsa_p256.pem --write-once --tee-only
```
### AES-256 Key
@@ -32,6 +32,7 @@ class KeyType(Enum):
class Flags(IntFlag):
NONE = 0x00000000
WRITE_ONCE = 0x00000001
TEE_ONLY = 0x00000002
# === Key Generators ===
@@ -113,6 +114,11 @@ def parse_args() -> argparse.Namespace:
action='store_true',
help='make key persistent - cannot be modified or deleted once written',
)
parser.add_argument(
'--tee-only',
action='store_true',
help='mark key as owned exclusively by the TEE - the REE cannot use, generate or clear it',
)
return parser.parse_args()
@@ -123,12 +129,16 @@ def main() -> None:
flags = Flags.NONE
if args.write_once:
flags |= Flags.WRITE_ONCE
if args.tee_only:
flags |= Flags.TEE_ONLY
print(f'[+] Generating key of type: {key_type.name} (value: {key_type.value})')
if args.input:
print(f'[+] Using user-provided key file: {args.input}')
if args.write_once:
print('[+] WRITE_ONCE flag is set')
if args.tee_only:
print('[+] TEE_ONLY flag is set')
key_data = generate_key_data(key_type, flags, args.input)