From b40f14cff6e63b4aa52c730e3d2ee060cba5f867 Mon Sep 17 00:00:00 2001 From: "harshal.patil" Date: Fri, 19 Sep 2025 12:02:35 +0530 Subject: [PATCH 1/4] fix(bootloader_support): Reorder write protection bits of some shared security efuses --- components/bootloader/Kconfig.projbuild | 5 +++-- .../src/esp32h2/flash_encryption_secure_features.c | 2 +- components/bootloader_support/src/flash_encrypt.c | 7 ------- components/esp_security/src/init.c | 8 +++++--- 4 files changed, 9 insertions(+), 13 deletions(-) diff --git a/components/bootloader/Kconfig.projbuild b/components/bootloader/Kconfig.projbuild index 4c75181f8f7..8d27927acc8 100644 --- a/components/bootloader/Kconfig.projbuild +++ b/components/bootloader/Kconfig.projbuild @@ -1136,8 +1136,9 @@ menu "Security features" config SECURE_FLASH_PSEUDO_ROUND_FUNC bool "Permanently enable XTS-AES's pseudo rounds function" - default y - depends on SECURE_FLASH_ENCRYPTION_MODE_RELEASE && SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND + default y if SECURE_FLASH_ENCRYPTION_MODE_RELEASE + default n + depends on SECURE_FLASH_ENC_ENABLED && SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND help If set (default), the bootloader will permanently enable the XTS-AES peripheral's pseudo rounds function. Note: Enabling this config would burn an efuse. diff --git a/components/bootloader_support/src/esp32h2/flash_encryption_secure_features.c b/components/bootloader_support/src/esp32h2/flash_encryption_secure_features.c index d4b063a4d6b..bb3517616ed 100644 --- a/components/bootloader_support/src/esp32h2/flash_encryption_secure_features.c +++ b/components/bootloader_support/src/esp32h2/flash_encryption_secure_features.c @@ -36,7 +36,7 @@ esp_err_t esp_flash_encryption_enable_secure_features(void) esp_efuse_write_field_bit(ESP_EFUSE_DIS_DIRECT_BOOT); -#if defined(CONFIG_SECURE_FLASH_ENCRYPTION_MODE_RELEASE) && defined(SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND) +#if defined(CONFIG_SECURE_FLASH_PSEUDO_ROUND_FUNC) if (spi_flash_encrypt_ll_is_pseudo_rounds_function_supported()) { ESP_LOGI(TAG, "Enable XTS-AES pseudo rounds function..."); uint8_t xts_pseudo_level = CONFIG_SECURE_FLASH_PSEUDO_ROUND_FUNC_STRENGTH; diff --git a/components/bootloader_support/src/flash_encrypt.c b/components/bootloader_support/src/flash_encrypt.c index 381f17ed40e..dcfc5798a2b 100644 --- a/components/bootloader_support/src/flash_encrypt.c +++ b/components/bootloader_support/src/flash_encrypt.c @@ -210,13 +210,6 @@ void esp_flash_encryption_set_release_mode(void) #endif // CONFIG_SOC_FLASH_ENCRYPTION_XTS_AES_128_DERIVED #endif // !CONFIG_IDF_TARGET_ESP32 -#ifdef SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND - if (spi_flash_encrypt_ll_is_pseudo_rounds_function_supported()) { - uint8_t xts_pseudo_level = ESP_XTS_AES_PSEUDO_ROUNDS_LOW; - esp_efuse_write_field_blob(ESP_EFUSE_XTS_DPA_PSEUDO_LEVEL, &xts_pseudo_level, ESP_EFUSE_XTS_DPA_PSEUDO_LEVEL[0]->bit_count); - } -#endif - #ifdef CONFIG_IDF_TARGET_ESP32 esp_efuse_write_field_bit(ESP_EFUSE_WR_DIS_DIS_CACHE); #else diff --git a/components/esp_security/src/init.c b/components/esp_security/src/init.c index 11d01f89d91..51adb01edf6 100644 --- a/components/esp_security/src/init.c +++ b/components/esp_security/src/init.c @@ -42,6 +42,8 @@ ESP_SYSTEM_INIT_FN(esp_security_init, SECONDARY, BIT(0), 103) esp_crypto_dpa_protection_startup(); #endif + esp_err_t err = ESP_FAIL; + #if CONFIG_ESP_CRYPTO_FORCE_ECC_CONSTANT_TIME_POINT_MUL bool force_constant_time = true; #if CONFIG_IDF_TARGET_ESP32H2 @@ -51,7 +53,7 @@ ESP_SYSTEM_INIT_FN(esp_security_init, SECONDARY, BIT(0), 103) #endif if (!esp_efuse_read_field_bit(ESP_EFUSE_ECC_FORCE_CONST_TIME) && force_constant_time) { ESP_EARLY_LOGD(TAG, "Forcefully enabling ECC constant time operations"); - esp_err_t err = esp_efuse_write_field_bit(ESP_EFUSE_ECC_FORCE_CONST_TIME); + err = esp_efuse_write_field_bit(ESP_EFUSE_ECC_FORCE_CONST_TIME); if (err != ESP_OK) { ESP_EARLY_LOGE(TAG, "Enabling ECC constant time operations forcefully failed."); return err; @@ -60,14 +62,14 @@ ESP_SYSTEM_INIT_FN(esp_security_init, SECONDARY, BIT(0), 103) #endif #if CONFIG_ESP_ECDSA_ENABLE_P192_CURVE - esp_err_t err; err = esp_efuse_enable_ecdsa_p192_curve_mode(); if (err != ESP_OK) { return err; } #endif - return ESP_OK; + err = ESP_OK; + return err; } void esp_security_init_include_impl(void) From dd3d58a31565e51366b4d310c23b20406dc543ac Mon Sep 17 00:00:00 2001 From: "harshal.patil" Date: Mon, 1 Sep 2025 15:44:29 +0530 Subject: [PATCH 2/4] fix(bootloader_support): Reorder write disabling ECDSA_CURVE_MODE --- components/esp_security/src/init.c | 14 ++++++++++++++ .../security-features-enablement-workflows.rst | 1 + 2 files changed, 15 insertions(+) diff --git a/components/esp_security/src/init.c b/components/esp_security/src/init.c index 51adb01edf6..207706b0064 100644 --- a/components/esp_security/src/init.c +++ b/components/esp_security/src/init.c @@ -13,6 +13,9 @@ #include "esp_security_priv.h" #include "esp_err.h" #include "hal/efuse_hal.h" +#if SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED +#include "hal/ecdsa_ll.h" +#endif #if SOC_KEY_MANAGER_ECDSA_KEY_DEPLOY || SOC_KEY_MANAGER_FE_KEY_DEPLOY #include "hal/key_mgr_ll.h" @@ -68,6 +71,17 @@ ESP_SYSTEM_INIT_FN(esp_security_init, SECONDARY, BIT(0), 103) } #endif +#if CONFIG_SECURE_BOOT_V2_ENABLED && SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED + // Also write protect the ECDSA_CURVE_MODE efuse bit. + if (ecdsa_ll_is_configurable_curve_supported()) { + err = esp_efuse_write_field_bit(ESP_EFUSE_WR_DIS_ECDSA_CURVE_MODE); + if (err != ESP_OK) { + ESP_LOGE(TAG, "Failed to write protect the ECDSA_CURVE_MODE efuse bit."); + return err; + } + } +#endif + err = ESP_OK; return err; } diff --git a/docs/en/security/security-features-enablement-workflows.rst b/docs/en/security/security-features-enablement-workflows.rst index 9ff9f717896..e021022320a 100644 --- a/docs/en/security/security-features-enablement-workflows.rst +++ b/docs/en/security/security-features-enablement-workflows.rst @@ -485,6 +485,7 @@ In this workflow we shall use ``espsecure`` tool to generate signing keys and us :SOC_EFUSE_DIS_USB_JTAG: - ``DIS_USB_JTAG``: Disable USB switch to JTAG. :SOC_EFUSE_DIS_PAD_JTAG: - ``DIS_PAD_JTAG``: Disable JTAG permanently. :SOC_EFUSE_REVOKE_BOOT_KEY_DIGESTS: - ``SECURE_BOOT_AGGRESSIVE_REVOKE``: Aggressive revocation of key digests, see :ref:`secure-boot-v2-aggressive-key-revocation` for more details. + :SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED: - ``WR_DIS_ECDSA_CURVE_MODE``: Disable writing to the ECDSA curve mode eFuse bit (As this write protection bit is shared with ECC_FORCE_CONST_TIME, it is recommended to write protect this bit only after configuring the ECC_FORCE_CONST_TIME efuse). The respective eFuses can be burned by running: From 8d9f3669c7631191dae44fdf691f62602e02ebfb Mon Sep 17 00:00:00 2001 From: Shen Mengjing Date: Fri, 12 Sep 2025 19:09:50 +0800 Subject: [PATCH 3/4] docs: Add the updated CN translation --- docs/en/security/security-features-enablement-workflows.rst | 2 +- docs/zh_CN/security/security-features-enablement-workflows.rst | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/en/security/security-features-enablement-workflows.rst b/docs/en/security/security-features-enablement-workflows.rst index e021022320a..0a9a7966421 100644 --- a/docs/en/security/security-features-enablement-workflows.rst +++ b/docs/en/security/security-features-enablement-workflows.rst @@ -485,7 +485,7 @@ In this workflow we shall use ``espsecure`` tool to generate signing keys and us :SOC_EFUSE_DIS_USB_JTAG: - ``DIS_USB_JTAG``: Disable USB switch to JTAG. :SOC_EFUSE_DIS_PAD_JTAG: - ``DIS_PAD_JTAG``: Disable JTAG permanently. :SOC_EFUSE_REVOKE_BOOT_KEY_DIGESTS: - ``SECURE_BOOT_AGGRESSIVE_REVOKE``: Aggressive revocation of key digests, see :ref:`secure-boot-v2-aggressive-key-revocation` for more details. - :SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED: - ``WR_DIS_ECDSA_CURVE_MODE``: Disable writing to the ECDSA curve mode eFuse bit (As this write protection bit is shared with ECC_FORCE_CONST_TIME, it is recommended to write protect this bit only after configuring the ECC_FORCE_CONST_TIME efuse). + :SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED: - ``WR_DIS_ECDSA_CURVE_MODE``: Disable writing to the ECDSA curve mode eFuse bit. As this write protection bit is shared with ``ECC_FORCE_CONST_TIME``, it is recommended to write protect this bit only after configuring the ``ECC_FORCE_CONST_TIME`` eFuse. The respective eFuses can be burned by running: diff --git a/docs/zh_CN/security/security-features-enablement-workflows.rst b/docs/zh_CN/security/security-features-enablement-workflows.rst index 7ed7cccf465..9e2ec82a035 100644 --- a/docs/zh_CN/security/security-features-enablement-workflows.rst +++ b/docs/zh_CN/security/security-features-enablement-workflows.rst @@ -485,6 +485,7 @@ flash 加密指南 :SOC_EFUSE_DIS_USB_JTAG: - ``DIS_USB_JTAG``:禁止从 USB 切换到 JTAG :SOC_EFUSE_DIS_PAD_JTAG: - ``DIS_PAD_JTAG``:永久禁用 JTAG。 :SOC_EFUSE_REVOKE_BOOT_KEY_DIGESTS: - ``SECURE_BOOT_AGGRESSIVE_REVOKE``:主动吊销密钥摘要。详请请参阅 :ref:`secure-boot-v2-aggressive-key-revocation`。 + :SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED: - ``WR_DIS_ECDSA_CURVE_MODE``:禁止写入 ECDSA 曲线模式的 eFuse 位。由于此写保护位与 ``ECC_FORCE_CONST_TIME`` 共享,建议先配置好 ``ECC_FORCE_CONST_TIME`` eFuse 字段后,再设置此写保护位)。 运行以下命令烧录相应的 eFuse: From 5fa0347a8b60b5dc4d652f566d86f79d456bc0c4 Mon Sep 17 00:00:00 2001 From: "harshal.patil" Date: Fri, 19 Sep 2025 12:51:50 +0530 Subject: [PATCH 4/4] fix(bootloader_support): Allow pre-programmed XTS-AES psuedo round level efuses - The API esp_flash_encryption_set_release_mode() by defualt programs the XTS-AES pseudo round level efuse to level low but did not considered any existing value that would have been programmed in the efuse bit. --- .../bootloader_support/include/esp_flash_encrypt.h | 4 ++++ .../src/esp32h2/flash_encryption_secure_features.c | 2 +- components/bootloader_support/src/flash_encrypt.c | 12 ++++++++++++ 3 files changed, 17 insertions(+), 1 deletion(-) diff --git a/components/bootloader_support/include/esp_flash_encrypt.h b/components/bootloader_support/include/esp_flash_encrypt.h index efc061edf50..e81457450f6 100644 --- a/components/bootloader_support/include/esp_flash_encrypt.h +++ b/components/bootloader_support/include/esp_flash_encrypt.h @@ -215,6 +215,10 @@ bool esp_flash_encryption_cfg_verify_release_mode(void); * It burns: * - "disable encrypt in dl mode" * - set FLASH_CRYPT_CNT efuse to max + * + * In case of the targets that support the XTS-AES peripheral's pseudo rounds function, + * this API would configure the pseudo rounds level efuse bit to level low if the efuse bit + * is not set already. */ void esp_flash_encryption_set_release_mode(void); diff --git a/components/bootloader_support/src/esp32h2/flash_encryption_secure_features.c b/components/bootloader_support/src/esp32h2/flash_encryption_secure_features.c index bb3517616ed..23f3c915dd3 100644 --- a/components/bootloader_support/src/esp32h2/flash_encryption_secure_features.c +++ b/components/bootloader_support/src/esp32h2/flash_encryption_secure_features.c @@ -36,7 +36,7 @@ esp_err_t esp_flash_encryption_enable_secure_features(void) esp_efuse_write_field_bit(ESP_EFUSE_DIS_DIRECT_BOOT); -#if defined(CONFIG_SECURE_FLASH_PSEUDO_ROUND_FUNC) +#if CONFIG_SECURE_FLASH_PSEUDO_ROUND_FUNC if (spi_flash_encrypt_ll_is_pseudo_rounds_function_supported()) { ESP_LOGI(TAG, "Enable XTS-AES pseudo rounds function..."); uint8_t xts_pseudo_level = CONFIG_SECURE_FLASH_PSEUDO_ROUND_FUNC_STRENGTH; diff --git a/components/bootloader_support/src/flash_encrypt.c b/components/bootloader_support/src/flash_encrypt.c index dcfc5798a2b..362eea9a3c2 100644 --- a/components/bootloader_support/src/flash_encrypt.c +++ b/components/bootloader_support/src/flash_encrypt.c @@ -210,6 +210,18 @@ void esp_flash_encryption_set_release_mode(void) #endif // CONFIG_SOC_FLASH_ENCRYPTION_XTS_AES_128_DERIVED #endif // !CONFIG_IDF_TARGET_ESP32 +#ifdef SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND + if (spi_flash_encrypt_ll_is_pseudo_rounds_function_supported()) { + uint8_t xts_pseudo_level = 0; + esp_efuse_read_field_blob(ESP_EFUSE_XTS_DPA_PSEUDO_LEVEL, &xts_pseudo_level, ESP_EFUSE_XTS_DPA_PSEUDO_LEVEL[0]->bit_count); + + if (xts_pseudo_level == ESP_XTS_AES_PSEUDO_ROUNDS_DISABLE) { + xts_pseudo_level = ESP_XTS_AES_PSEUDO_ROUNDS_LOW; + esp_efuse_write_field_blob(ESP_EFUSE_XTS_DPA_PSEUDO_LEVEL, &xts_pseudo_level, ESP_EFUSE_XTS_DPA_PSEUDO_LEVEL[0]->bit_count); + } + } +#endif + #ifdef CONFIG_IDF_TARGET_ESP32 esp_efuse_write_field_bit(ESP_EFUSE_WR_DIS_DIS_CACHE); #else