mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
change(security): disable Key Manager support on ESP32-C5/P4/S31
The Key Manager hardware peripheral in its current form needs further design changes before it can be offered as a production feature. Until a revised peripheral design is available, withdraw ESP-IDF support for it on all Key Manager capable targets.
This commit is contained in:
committed by
Harshal Patil
parent
ae2088092e
commit
a827d27b12
@@ -49,7 +49,7 @@ else() # BOOTLOADER_BUILD
|
||||
list(APPEND srcs "src/esp_crypto_lock.c" "src/esp_crypto_periph_clk.c"
|
||||
"src/${target}/esp_crypto_clk.c")
|
||||
|
||||
if(CONFIG_SOC_KEY_MANAGER_FE_KEY_DEPLOY)
|
||||
if(CONFIG_SOC_KEY_MANAGER_SUPPORTED AND CONFIG_SOC_KEY_MANAGER_FE_KEY_DEPLOY)
|
||||
list(APPEND srcs "src/esp_key_mgr.c")
|
||||
endif()
|
||||
endif()
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2023-2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2023-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -122,7 +122,7 @@ void esp_crypto_ecdsa_lock_acquire(void);
|
||||
void esp_crypto_ecdsa_lock_release(void);
|
||||
#endif /* SOC_ECDSA_SUPPORTED */
|
||||
|
||||
#ifdef SOC_KEY_MANAGER_SUPPORTED
|
||||
#if SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT
|
||||
/**
|
||||
* @brief Acquire lock for Key Manager peripheral
|
||||
*
|
||||
@@ -134,7 +134,7 @@ void esp_crypto_key_manager_lock_acquire(void);
|
||||
*
|
||||
*/
|
||||
void esp_crypto_key_manager_lock_release(void);
|
||||
#endif /* SOC_KEY_MANAGER_SUPPORTED */
|
||||
#endif /* SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT */
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
|
||||
@@ -8,7 +8,7 @@
|
||||
#include "esp_err.h"
|
||||
#include "soc/soc_caps.h"
|
||||
|
||||
#if SOC_KEY_MANAGER_SUPPORTED
|
||||
#if SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT
|
||||
|
||||
#ifdef __cplusplus
|
||||
extern "C" {
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2022-2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2022-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -52,10 +52,10 @@ static _lock_t s_crypto_ecdsa_lock;
|
||||
#endif /* SOC_ECDSA_USES_MPI */
|
||||
#endif /* SOC_ECDSA_SUPPORTED */
|
||||
|
||||
#ifdef SOC_KEY_MANAGER_SUPPORTED
|
||||
#if SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT
|
||||
/* Lock for Key Manager peripheral */
|
||||
static _lock_t s_crypto_key_manager_lock;
|
||||
#endif /* SOC_KEY_MANAGER_SUPPORTED */
|
||||
#endif /* SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT */
|
||||
|
||||
#ifdef SOC_HMAC_SUPPORTED
|
||||
void esp_crypto_hmac_lock_acquire(void)
|
||||
@@ -159,7 +159,7 @@ void esp_crypto_ecdsa_lock_release(void)
|
||||
}
|
||||
#endif /* SOC_ECDSA_SUPPORTED */
|
||||
|
||||
#ifdef SOC_KEY_MANAGER_SUPPORTED
|
||||
#if SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT
|
||||
void esp_crypto_key_manager_lock_acquire(void)
|
||||
{
|
||||
_lock_acquire(&s_crypto_key_manager_lock);
|
||||
@@ -169,7 +169,7 @@ void esp_crypto_key_manager_lock_release(void)
|
||||
{
|
||||
_lock_release(&s_crypto_key_manager_lock);
|
||||
}
|
||||
#endif /* SOC_KEY_MANAGER_SUPPORTED */
|
||||
#endif /* SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT */
|
||||
#else /* NON_OS_BUILD */
|
||||
#ifdef SOC_HMAC_SUPPORTED
|
||||
void esp_crypto_hmac_lock_acquire(void) {}
|
||||
@@ -213,9 +213,9 @@ void esp_crypto_ecdsa_lock_acquire(void) {}
|
||||
void esp_crypto_ecdsa_lock_release(void) {}
|
||||
#endif /* SOC_ECDSA_SUPPORTED */
|
||||
|
||||
#ifdef SOC_KEY_MANAGER_SUPPORTED
|
||||
#if SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT
|
||||
void esp_crypto_key_manager_lock_acquire(void) {}
|
||||
|
||||
void esp_crypto_key_manager_lock_release(void) {}
|
||||
#endif /* SOC_KEY_MANAGER_SUPPORTED */
|
||||
#endif /* SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT */
|
||||
#endif /* !NON_OS_BUILD */
|
||||
|
||||
@@ -32,7 +32,7 @@
|
||||
#if SOC_ECDSA_SUPPORTED
|
||||
#include "hal/ecdsa_ll.h"
|
||||
#endif
|
||||
#if SOC_KEY_MANAGER_SUPPORTED
|
||||
#if SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT
|
||||
#include "hal/key_mgr_ll.h"
|
||||
#endif
|
||||
/* Crypto DMA, shared between AES and SHA */
|
||||
@@ -154,7 +154,7 @@ void esp_crypto_ecdsa_enable_periph_clk(bool enable)
|
||||
}
|
||||
#endif
|
||||
|
||||
#if SOC_KEY_MANAGER_SUPPORTED
|
||||
#if SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT
|
||||
void esp_crypto_key_mgr_enable_periph_clk(bool enable)
|
||||
{
|
||||
KEY_MANAGER_RCC_ATOMIC() {
|
||||
|
||||
@@ -20,7 +20,6 @@
|
||||
#include "hal/huk_hal.h"
|
||||
#include "rom/key_mgr.h"
|
||||
|
||||
#if SOC_KEY_MANAGER_SUPPORTED
|
||||
static const char *TAG = "esp_key_mgr";
|
||||
|
||||
ESP_STATIC_ASSERT(sizeof(esp_key_mgr_key_recovery_info_t) == sizeof(struct huk_key_block), "Size of esp_key_mgr_key_recovery_info_t should match huk_key_block (from ROM)");
|
||||
@@ -1072,4 +1071,3 @@ cleanup:
|
||||
esp_key_mgr_release_hardware(true);
|
||||
return esp_ret;
|
||||
}
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user