mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
feat(esp_tee): Add some required fields in the attestation token
- Chip ID from the ROM - Device MAC address from eFuse BLK1 - Device Optional Unique ID from eFuse BLK2
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -161,11 +161,35 @@ esp_err_t esp_att_utils_eat_data_to_json(struct esp_att_sw_claim_list *head, con
|
||||
|
||||
json_gen_obj_set_int(&json_gen, "nonce", cfg->nonce);
|
||||
json_gen_obj_set_int(&json_gen, "client_id", cfg->client_id);
|
||||
json_gen_obj_set_int(&json_gen, "chip_id", cfg->chip_id);
|
||||
json_gen_obj_set_int(&json_gen, "device_ver", cfg->device_ver);
|
||||
|
||||
char dev_id_hexstr[ESP_ATT_EAT_DEV_ID_SZ * 2 + 1] = {0};
|
||||
esp_err_t err = esp_att_utils_hexbuf_to_hexstr(cfg->device_id, sizeof(cfg->device_id), dev_id_hexstr, sizeof(dev_id_hexstr));
|
||||
json_gen_push_object(&json_gen, "ueid");
|
||||
|
||||
char mac_hexstr[ESP_ATT_EAT_UEID_MAC_SZ * 2 + 1] = {0};
|
||||
esp_err_t err = esp_att_utils_hexbuf_to_hexstr(cfg->ueid_mac, sizeof(cfg->ueid_mac),
|
||||
mac_hexstr, sizeof(mac_hexstr));
|
||||
if (err != ESP_OK) {
|
||||
free(json_buf);
|
||||
return err;
|
||||
}
|
||||
json_gen_obj_set_string(&json_gen, "mac", mac_hexstr);
|
||||
|
||||
char opt_id_hexstr[ESP_ATT_EAT_UEID_OPT_ID_SZ * 2 + 1] = {0};
|
||||
err = esp_att_utils_hexbuf_to_hexstr(cfg->ueid_opt_id, sizeof(cfg->ueid_opt_id),
|
||||
opt_id_hexstr, sizeof(opt_id_hexstr));
|
||||
if (err != ESP_OK) {
|
||||
free(json_buf);
|
||||
return err;
|
||||
}
|
||||
json_gen_obj_set_string(&json_gen, "optional_id", opt_id_hexstr);
|
||||
|
||||
json_gen_pop_object(&json_gen);
|
||||
|
||||
char dev_id_hexstr[ESP_ATT_EAT_DEV_ID_SZ * 2 + 1] = {0};
|
||||
err = esp_att_utils_hexbuf_to_hexstr(cfg->device_id, sizeof(cfg->device_id), dev_id_hexstr, sizeof(dev_id_hexstr));
|
||||
if (err != ESP_OK) {
|
||||
free(json_buf);
|
||||
return err;
|
||||
}
|
||||
json_gen_obj_set_string(&json_gen, "device_id", dev_id_hexstr);
|
||||
@@ -186,6 +210,7 @@ esp_err_t esp_att_utils_eat_data_to_json(struct esp_att_sw_claim_list *head, con
|
||||
esp_err_t err = part_metadata_to_json(&claim->metadata, &claim_json);
|
||||
if (err != ESP_OK || claim_json == NULL) {
|
||||
ESP_LOGE(TAG, "Failed to format the FW metadata to JSON!");
|
||||
free(json_buf);
|
||||
return err;
|
||||
}
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -50,49 +50,23 @@ static void free_sw_claim_list(void)
|
||||
}
|
||||
}
|
||||
|
||||
static esp_err_t fetch_device_id(uint8_t *devid_buf)
|
||||
static esp_err_t fetch_ueids(esp_att_token_cfg_t *cfg)
|
||||
{
|
||||
if (devid_buf == NULL) {
|
||||
return ESP_ERR_INVALID_ARG;
|
||||
}
|
||||
|
||||
uint8_t mac_addr[6] = {0};
|
||||
esp_err_t err = esp_efuse_read_field_blob(ESP_EFUSE_MAC, mac_addr, sizeof(mac_addr) * 8);
|
||||
/* UEID: raw eFuse MAC */
|
||||
esp_err_t err = esp_efuse_read_field_blob(ESP_EFUSE_MAC, cfg->ueid_mac,
|
||||
ESP_ATT_EAT_UEID_MAC_SZ * 8);
|
||||
if (err != ESP_OK) {
|
||||
ESP_LOGE(TAG, "Failed to read MAC from eFuse!");
|
||||
goto exit;
|
||||
return err;
|
||||
}
|
||||
|
||||
mbedtls_sha256_context ctx;
|
||||
mbedtls_sha256_init(&ctx);
|
||||
|
||||
int ret = mbedtls_sha256_starts(&ctx, false);
|
||||
if (ret != 0) {
|
||||
mbedtls_sha256_free(&ctx);
|
||||
err = ESP_FAIL;
|
||||
goto exit;
|
||||
/* UEID: 128-bit OPTIONAL_UNIQUE_ID */
|
||||
err = esp_efuse_read_field_blob(ESP_EFUSE_OPTIONAL_UNIQUE_ID, cfg->ueid_opt_id,
|
||||
ESP_ATT_EAT_UEID_OPT_ID_SZ * 8);
|
||||
if (err != ESP_OK) {
|
||||
return err;
|
||||
}
|
||||
|
||||
ret = mbedtls_sha256_update(&ctx, (const unsigned char *)mac_addr, sizeof(mac_addr));
|
||||
if (ret != 0) {
|
||||
mbedtls_sha256_free(&ctx);
|
||||
err = ESP_FAIL;
|
||||
goto exit;
|
||||
}
|
||||
|
||||
uint8_t digest[SHA256_DIGEST_SZ] = {0};
|
||||
ret = mbedtls_sha256_finish(&ctx, digest);
|
||||
if (ret != 0) {
|
||||
mbedtls_sha256_free(&ctx);
|
||||
err = ESP_FAIL;
|
||||
goto exit;
|
||||
}
|
||||
|
||||
memcpy(devid_buf, digest, SHA256_DIGEST_SZ);
|
||||
mbedtls_sha256_free(&ctx);
|
||||
|
||||
exit:
|
||||
return err;
|
||||
return ESP_OK;
|
||||
}
|
||||
|
||||
static esp_err_t populate_att_token_cfg(esp_att_token_cfg_t *cfg, const esp_att_ecdsa_keypair_t *keypair)
|
||||
@@ -101,18 +75,29 @@ static esp_err_t populate_att_token_cfg(esp_att_token_cfg_t *cfg, const esp_att_
|
||||
return ESP_ERR_INVALID_ARG;
|
||||
}
|
||||
|
||||
esp_err_t err = fetch_device_id(cfg->device_id);
|
||||
esp_err_t err = fetch_ueids(cfg);
|
||||
if (err != ESP_OK) {
|
||||
ESP_LOGE(TAG, "Failed to get the device ID!");
|
||||
ESP_LOGE(TAG, "Failed to get the UEIDs!");
|
||||
return err;
|
||||
}
|
||||
|
||||
/* Device ID = SHA-256 of the MAC */
|
||||
int ret = mbedtls_sha256(cfg->ueid_mac, sizeof(cfg->ueid_mac), cfg->device_id, 0);
|
||||
if (ret != 0) {
|
||||
ESP_LOGE(TAG, "Failed to derive the device ID!");
|
||||
return ESP_FAIL;
|
||||
}
|
||||
|
||||
err = esp_att_utils_ecdsa_get_pubkey_digest(keypair, cfg->instance_id, sizeof(cfg->instance_id));
|
||||
if (err != ESP_OK) {
|
||||
ESP_LOGE(TAG, "Failed to get ECDSA public key hash!");
|
||||
return err;
|
||||
}
|
||||
|
||||
/* Chip ID read from the ROM */
|
||||
extern const uint32_t _rom_chip_id;
|
||||
cfg->chip_id = _rom_chip_id;
|
||||
/* Chip revision read from eFuse */
|
||||
cfg->device_ver = efuse_hal_chip_revision();
|
||||
/* TODO: Decide what all fields we need here */
|
||||
cfg->device_stat = 0xA5;
|
||||
|
||||
+13
-8
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -33,6 +33,8 @@ extern "C" {
|
||||
#define ESP_ATT_HDR_JSON_MAX_SZ (128)
|
||||
|
||||
#define ESP_ATT_EAT_DEV_ID_SZ (32)
|
||||
#define ESP_ATT_EAT_UEID_MAC_SZ (6) /* eFuse MAC */
|
||||
#define ESP_ATT_EAT_UEID_OPT_ID_SZ (16) /* eFuse OPTIONAL_UNIQUE_ID */
|
||||
#define ESP_ATT_CLAIM_JSON_MAX_SZ (448)
|
||||
#define ESP_ATT_EAT_JSON_MAX_SZ (1344)
|
||||
|
||||
@@ -110,13 +112,16 @@ typedef struct {
|
||||
* @brief Structure to hold the Entity Attestation Token initial configuration
|
||||
*/
|
||||
typedef struct {
|
||||
uint32_t nonce; /**< Nonce value */
|
||||
uint32_t client_id; /**< Client identifier (Attestation relying party) */
|
||||
uint32_t device_ver; /**< Device version */
|
||||
uint8_t device_id[SHA256_DIGEST_SZ]; /**< Device identifier */
|
||||
uint8_t instance_id[SHA256_DIGEST_SZ]; /**< Instance identifier */
|
||||
char psa_cert_ref[32]; /**< PSA certificate reference */
|
||||
uint8_t device_stat; /**< Flags indicating device status */
|
||||
uint32_t nonce; /**< Nonce value */
|
||||
uint32_t client_id; /**< Client identifier (Attestation relying party) */
|
||||
uint32_t chip_id; /**< Chip identifier */
|
||||
uint32_t device_ver; /**< Device version */
|
||||
uint8_t ueid_mac[ESP_ATT_EAT_UEID_MAC_SZ]; /**< Device UEID: MAC from eFuse */
|
||||
uint8_t ueid_opt_id[ESP_ATT_EAT_UEID_OPT_ID_SZ]; /**< Device UEID: OPTIONAL_UNIQUE_ID from eFuse */
|
||||
uint8_t device_id[SHA256_DIGEST_SZ]; /**< Device identifier (SHA-256 of MAC) */
|
||||
uint8_t instance_id[SHA256_DIGEST_SZ]; /**< Instance identifier */
|
||||
char psa_cert_ref[32]; /**< PSA certificate reference */
|
||||
uint8_t device_stat; /**< Flags indicating device status */
|
||||
} esp_att_token_cfg_t;
|
||||
/**
|
||||
* @brief Structure to hold an ECDSA key pair
|
||||
|
||||
@@ -123,10 +123,9 @@ help [<string>] [-v <0|1>]
|
||||
|
||||
```log
|
||||
esp32c6> tee_att_info
|
||||
I (8180) tee_attest: Attestation token - Length: 1455
|
||||
I (8180) tee_attest: Attestation token - Length: 1620
|
||||
I (8180) tee_attest: Attestation token - Data:
|
||||
'{"header":{"magic":"44fef7cc","encr_alg":"","sign_alg":"ecdsa_secp256r1_sha256","key_id":"tee_att_key0"},"eat":{"nonce":-1582119980,"client_id":262974944,"device_ver":0,"device_id":"cd9c173cb3675c7adfae243f0cd9841e4bce003237cb5321927a85a86cb4b32e","instance_id":"9616ef0ecf02cdc89a3749f8fc16b3103d5100bd42d9312fcd04593baa7bac64","psa_cert_ref":"0716053550477-10100","device_status":165,"sw_claims":{"tee":{"type":1,"ver":"v0.3.0","idf_ver":"v5.1.4-241-g7ff01fd46f-dirty","secure_ver":0,"part_chip_rev":{"min":0,"max":99},"part_digest":{"type":0,"calc_digest":"94536998e1dcb2a036477cb2feb01ed4fff67ba6208f30482346c62bca64b280","digest_validated":true,"sign_verified":true}},"app":{"type":2,"ver":"v0.1.0","idf_ver":"v5.1.4-241-g7ff01fd46f-dirty","secure_ver":0,"part_chip_rev":{"min":0,"max":99},"part_digest":{"type":0,"calc_digest":"3d4c038fcec76852b4d07acb9e94afaf5fca69fc2eb212a32032d09ce5b4f2b3","digest_validated":true,"sign_verified":true,"secure_padding":true}},"bootloader":{"type":0,"ver":"","idf_ver":"","secure_ver":-1,"part_chip_rev":{"min":0,"max":99},"part_digest":{"type":0,"calc_digest":"1bef421beb1a4642c6fcefb3e37fd4afad60cb4074e538f42605b012c482b946","digest_validated":true,"sign_verified":true}}}},"public_key":{"compressed":"02039c4bfab0762af1aff2fe5596b037f629cf839da8c4a9c0018afedfccf519a6"},"sign":{"r":"915e749f5a780bc21a2b21821cfeb54286dc742e9f12f2387e3de9b8b1a70bc9","s":"1e583236f2630b0fe8e291645ffa35d429f14035182e19868508d4dac0e1a441"}}'
|
||||
|
||||
'{"header":{"magic":"44fef7cc","encr_alg":"","sign_alg":"ecdsa_secp256r1_sha256","key_id":"tee_att_key0"},"eat":{"nonce":-1582119980,"client_id":262974944,"chip_id":13,"device_ver":0,"ueid":{"mac":"d885ac67c978","optional_id":"94fa4d7e305682714d48e7bbd710c961"},"device_id":"cd9c173cb3675c7adfae243f0cd9841e4bce003237cb5321927a85a86cb4b32e","instance_id":"9616ef0ecf02cdc89a3749f8fc16b3103d5100bd42d9312fcd04593baa7bac64","psa_cert_ref":"0716053550477-10100","device_status":165,"sw_claims":{"tee":{"type":1,"ver":"v0.3.0","idf_ver":"v5.1.4-241-g7ff01fd46f-dirty","secure_ver":0,"part_chip_rev":{"min":0,"max":99},"part_digest":{"type":0,"calc_digest":"94536998e1dcb2a036477cb2feb01ed4fff67ba6208f30482346c62bca64b280","digest_validated":true,"sign_verified":true}},"app":{"type":2,"ver":"v0.1.0","idf_ver":"v5.1.4-241-g7ff01fd46f-dirty","secure_ver":0,"part_chip_rev":{"min":0,"max":99},"part_digest":{"type":0,"calc_digest":"3d4c038fcec76852b4d07acb9e94afaf5fca69fc2eb212a32032d09ce5b4f2b3","digest_validated":true,"sign_verified":true,"secure_padding":true}},"bootloader":{"type":0,"ver":"","idf_ver":"","secure_ver":-1,"part_chip_rev":{"min":0,"max":99},"part_digest":{"type":0,"calc_digest":"1bef421beb1a4642c6fcefb3e37fd4afad60cb4074e538f42605b012c482b946","digest_validated":true,"sign_verified":true}}}},"public_key":{"compressed":"02039c4bfab0762af1aff2fe5596b037f629cf839da8c4a9c0018afedfccf519a6"},"sign":{"r":"915e749f5a780bc21a2b21821cfeb54286dc742e9f12f2387e3de9b8b1a70bc9","s":"1e583236f2630b0fe8e291645ffa35d429f14035182e19868508d4dac0e1a441"}}'
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
Reference in New Issue
Block a user