diff --git a/components/esp_tee/scripts/esp_tee_sec_stg_keygen/README.md b/components/esp_tee/scripts/esp_tee_sec_stg_keygen/README.md index 59ea02d58af..d32d46ebcbc 100644 --- a/components/esp_tee/scripts/esp_tee_sec_stg_keygen/README.md +++ b/components/esp_tee/scripts/esp_tee_sec_stg_keygen/README.md @@ -40,16 +40,13 @@ python esp_tee_sec_stg_keygen.py -k ecdsa_p256 -o ecdsa_p256_k1.bin -i ecdsa_p25 python esp_tee_sec_stg_keygen.py -k aes256 -o aes256_gcm_k0.bin --write-once ``` -#### With custom key and IV +#### With custom key ```bash # Generate 32 bytes AES key openssl rand 32 > aes_key.bin -# Generate 12 bytes IV (optional) -openssl rand 12 >> aes_key.bin - -# Generate AES key blob using custom key + IV +# Generate AES key blob using custom key python esp_tee_sec_stg_keygen.py -k aes256 -o aes256_gcm_k1.bin -i aes_key.bin ``` diff --git a/components/esp_tee/scripts/esp_tee_sec_stg_keygen/esp_tee_sec_stg_keygen.py b/components/esp_tee/scripts/esp_tee_sec_stg_keygen/esp_tee_sec_stg_keygen.py index 6a70113d32f..7c1f4818d3d 100644 --- a/components/esp_tee/scripts/esp_tee_sec_stg_keygen/esp_tee_sec_stg_keygen.py +++ b/components/esp_tee/scripts/esp_tee_sec_stg_keygen/esp_tee_sec_stg_keygen.py @@ -1,5 +1,5 @@ #!/usr/bin/env python3 -# SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD +# SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD # SPDX-License-Identifier: Apache-2.0 import argparse @@ -17,8 +17,6 @@ from cryptography.hazmat.primitives.asymmetric import ec # === Constants === SEC_STG_KEY_DATA_SZ = 256 AES_KEY_LEN = 32 -AES_DEFAULT_IV_LEN = 16 -AES_GCM_IV_LEN = 12 ECDSA_P256_LEN = 32 ECDSA_P192_LEN = 24 @@ -48,22 +46,10 @@ def generate_aes256_key(flags: Flags, key_file: Optional[str] = None) -> bytes: raise ValueError('AES key file must be at least 32 bytes long') key = key_data[:AES_KEY_LEN] - iv_data = key_data[AES_KEY_LEN:] - - iv_len = len(iv_data) - if iv_len == 0: - iv = os.urandom(AES_DEFAULT_IV_LEN) - elif iv_len == AES_GCM_IV_LEN: - iv = iv_data + b'\x00' * (AES_DEFAULT_IV_LEN - AES_GCM_IV_LEN) - elif iv_len == AES_DEFAULT_IV_LEN: - iv = iv_data - else: - raise ValueError('IV length must be exactly 12 or 16 bytes, or omitted to generate one') else: key = os.urandom(AES_KEY_LEN) - iv = os.urandom(AES_DEFAULT_IV_LEN) - packed = struct.pack('aes256.key, AES256_KEY_LEN); - esp_fill_random(&keyctx->aes256.iv, AES256_DEFAULT_IV_LEN); return 0; } @@ -408,7 +405,6 @@ esp_err_t esp_tee_sec_storage_ecdsa_sign(const esp_tee_sec_storage_key_cfg_t *cf size_t keyctx_len = sizeof(keyctx); err = secure_storage_read(cfg->id, (void *)&keyctx, &keyctx_len); if (err != ESP_OK) { - ESP_LOGE(TAG, "Failed to fetch key from storage"); return err; } @@ -535,15 +531,14 @@ esp_err_t esp_tee_sec_storage_ecdsa_get_pubkey(const esp_tee_sec_storage_key_cfg static esp_err_t tee_sec_storage_crypt_common(const char *key_id, const uint8_t *input, size_t len, const uint8_t *aad, size_t aad_len, uint8_t *tag, size_t tag_len, uint8_t *output, - bool is_encrypt) + uint8_t *iv, size_t iv_len, bool is_encrypt) { - if (key_id == NULL || input == NULL || output == NULL || tag == NULL) { - ESP_LOGE(TAG, "Invalid arguments"); + if (key_id == NULL || input == NULL || output == NULL || tag == NULL || iv == NULL) { return ESP_ERR_INVALID_ARG; } - if (len == 0 || tag_len == 0) { - ESP_LOGE(TAG, "Invalid input/tag length"); + if (len == 0 || tag_len == 0 || iv_len != AES256_GCM_IV_LEN) { + ESP_LOGE(TAG, "Invalid input/tag/iv length"); return ESP_ERR_INVALID_SIZE; } @@ -557,7 +552,6 @@ static esp_err_t tee_sec_storage_crypt_common(const char *key_id, const uint8_t size_t keyctx_len = sizeof(keyctx); err = secure_storage_read(key_id, (void *)&keyctx, &keyctx_len); if (err != ESP_OK) { - ESP_LOGE(TAG, "Failed to fetch key from storage"); return err; } @@ -577,7 +571,11 @@ static esp_err_t tee_sec_storage_crypt_common(const char *key_id, const uint8_t } if (is_encrypt) { - ret = mbedtls_gcm_crypt_and_tag(&gcm, MBEDTLS_GCM_ENCRYPT, len, keyctx.aes256.iv, AES256_GCM_IV_LEN, + /* Generate a fresh random IV for each encryption operation */ + memset(iv, 0x00, iv_len); + esp_fill_random(iv, iv_len); + + ret = mbedtls_gcm_crypt_and_tag(&gcm, MBEDTLS_GCM_ENCRYPT, len, iv, iv_len, aad, aad_len, input, output, tag_len, tag); if (ret != 0) { ESP_LOGE(TAG, "Error in encrypting data: %d", ret); @@ -585,7 +583,7 @@ static esp_err_t tee_sec_storage_crypt_common(const char *key_id, const uint8_t goto exit; } } else { - ret = mbedtls_gcm_auth_decrypt(&gcm, len, keyctx.aes256.iv, AES256_GCM_IV_LEN, + ret = mbedtls_gcm_auth_decrypt(&gcm, len, iv, iv_len, aad, aad_len, tag, tag_len, input, output); if (ret != 0) { ESP_LOGE(TAG, "Error in decrypting data: %d", ret); @@ -600,14 +598,24 @@ exit: return err; } -esp_err_t esp_tee_sec_storage_aead_encrypt(const esp_tee_sec_storage_aead_ctx_t *ctx, uint8_t *tag, size_t tag_len, uint8_t *output) +esp_err_t esp_tee_sec_storage_aead_encrypt(esp_tee_sec_storage_aead_ctx_t *ctx, uint8_t *tag, size_t tag_len, uint8_t *output) { - return tee_sec_storage_crypt_common(ctx->key_id, ctx->input, ctx->input_len, ctx->aad, ctx->aad_len, tag, tag_len, output, true); + if (ctx == NULL) { + return ESP_ERR_INVALID_ARG; + } + + return tee_sec_storage_crypt_common(ctx->key_id, ctx->input, ctx->input_len, ctx->aad, ctx->aad_len, + tag, tag_len, output, (uint8_t *)ctx->iv, AES256_GCM_IV_LEN, true); } esp_err_t esp_tee_sec_storage_aead_decrypt(const esp_tee_sec_storage_aead_ctx_t *ctx, const uint8_t *tag, size_t tag_len, uint8_t *output) { - return tee_sec_storage_crypt_common(ctx->key_id, ctx->input, ctx->input_len, ctx->aad, ctx->aad_len, (uint8_t *)tag, tag_len, output, false); + if (ctx == NULL) { + return ESP_ERR_INVALID_ARG; + } + + return tee_sec_storage_crypt_common(ctx->key_id, ctx->input, ctx->input_len, ctx->aad, ctx->aad_len, + (uint8_t *)tag, tag_len, output, (uint8_t *)ctx->iv, AES256_GCM_IV_LEN, false); } esp_err_t esp_tee_sec_storage_ecdsa_sign_pbkdf2(const esp_tee_sec_storage_pbkdf2_ctx_t *ctx, diff --git a/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage_wrapper.c b/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage_wrapper.c index 828b6bd550e..f602697401a 100644 --- a/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage_wrapper.c +++ b/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage_wrapper.c @@ -28,7 +28,7 @@ esp_err_t esp_tee_sec_storage_ecdsa_get_pubkey(const esp_tee_sec_storage_key_cfg return esp_tee_service_call_with_noniram_intr_disabled(3, SS_ESP_TEE_SEC_STORAGE_ECDSA_GET_PUBKEY, cfg, out_pubkey); } -esp_err_t esp_tee_sec_storage_aead_encrypt(const esp_tee_sec_storage_aead_ctx_t *ctx, uint8_t *tag, size_t tag_len, uint8_t *output) +esp_err_t esp_tee_sec_storage_aead_encrypt(esp_tee_sec_storage_aead_ctx_t *ctx, uint8_t *tag, size_t tag_len, uint8_t *output) { return esp_tee_service_call_with_noniram_intr_disabled(5, SS_ESP_TEE_SEC_STORAGE_AEAD_ENCRYPT, ctx, tag, tag_len, output); } diff --git a/components/esp_tee/subproject/main/core/esp_secure_services_iram.c b/components/esp_tee/subproject/main/core/esp_secure_services_iram.c index 0413e147b7c..80611ba5a08 100644 --- a/components/esp_tee/subproject/main/core/esp_secure_services_iram.c +++ b/components/esp_tee/subproject/main/core/esp_secure_services_iram.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -151,13 +151,15 @@ esp_err_t _ss_esp_tee_sec_storage_ecdsa_get_pubkey(const esp_tee_sec_storage_key return esp_tee_sec_storage_ecdsa_get_pubkey(cfg, out_pubkey); } -esp_err_t _ss_esp_tee_sec_storage_aead_encrypt(const esp_tee_sec_storage_aead_ctx_t *ctx, uint8_t *tag, size_t tag_len, uint8_t *output) +esp_err_t _ss_esp_tee_sec_storage_aead_encrypt(esp_tee_sec_storage_aead_ctx_t *ctx, uint8_t *tag, size_t tag_len, uint8_t *output) { bool valid_addr = (esp_tee_ptr_in_ree((void *)ctx->input) && + esp_tee_ptr_in_ree((void *)ctx->iv) && esp_tee_ptr_in_ree((void *)tag) && esp_tee_ptr_in_ree((void *)output)); valid_addr &= (esp_tee_ptr_in_ree((void *)(ctx->input + ctx->input_len)) && + esp_tee_ptr_in_ree((void *)(ctx->iv + AES_GCM_SUPPORTED_IV_LEN)) && esp_tee_ptr_in_ree((void *)(tag + tag_len)) && esp_tee_ptr_in_ree((void *)(output + ctx->input_len))); @@ -176,10 +178,12 @@ esp_err_t _ss_esp_tee_sec_storage_aead_encrypt(const esp_tee_sec_storage_aead_ct esp_err_t _ss_esp_tee_sec_storage_aead_decrypt(const esp_tee_sec_storage_aead_ctx_t *ctx, const uint8_t *tag, size_t tag_len, uint8_t *output) { bool valid_addr = (esp_tee_ptr_in_ree((void *)ctx->input) && + esp_tee_ptr_in_ree((void *)ctx->iv) && esp_tee_ptr_in_ree((void *)tag) && esp_tee_ptr_in_ree((void *)output)); valid_addr &= (esp_tee_ptr_in_ree((void *)(ctx->input + ctx->input_len)) && + esp_tee_ptr_in_ree((void *)(ctx->iv + AES_GCM_SUPPORTED_IV_LEN)) && esp_tee_ptr_in_ree((void *)(tag + tag_len)) && esp_tee_ptr_in_ree((void *)(output + ctx->input_len))); diff --git a/components/esp_tee/test_apps/tee_cli_app/README.md b/components/esp_tee/test_apps/tee_cli_app/README.md index b9f4c399083..e57e581d946 100644 --- a/components/esp_tee/test_apps/tee_cli_app/README.md +++ b/components/esp_tee/test_apps/tee_cli_app/README.md @@ -97,11 +97,12 @@ tee_sec_stg_encrypt <key_id> TEE Secure storage key ID <plaintext> Plaintext to be encrypted -tee_sec_stg_decrypt <key_id> <ciphertext> <tag> +tee_sec_stg_decrypt <key_id> <ciphertext> <tag> <iv> Decrypt data using AES-GCM key with the given ID from secure storage <key_id> TEE Secure storage key ID <ciphertext> Ciphertext to be decrypted <tag> AES-GCM authentication tag + <iv> AES-GCM initialization vector help [<string>] [-v <0|1>] Print the summary of all registered commands if no arguments are given, @@ -135,8 +136,8 @@ I (8180) tee_attest: Attestation token - Data: - The TEE secure storage service provides the following commands: - `tee_sec_stg_gen_key`: Generate and store a new key (ECDSA or AES) in the TEE secure storage with the specified ID - `tee_sec_stg_sign`: Sign a message using an ECDSA `secp256r1` key pair with the specified ID and verify the signature - - `tee_sec_stg_encrypt`: Encrypt data with AES256-GCM using the key with the specified ID and outputs the ciphertext and tag - - `tee_sec_stg_decrypt`: Decrypt ciphertext using key with the specified ID and tag for integrity verification + - `tee_sec_stg_encrypt`: Encrypt data with AES256-GCM using the key with the specified ID and outputs the ciphertext, tag and the IV used + - `tee_sec_stg_decrypt`: Decrypt ciphertext using key with the specified ID, tag and used IV for integrity verification - The `get_msg_sha256` command computes the SHA256 hash of a given message, which can be used as input for the `tee_sec_stg_sign` command. <details> @@ -163,14 +164,16 @@ I (6444) tee_sec_stg: Signature verified successfully! ```log esp32c6> tee_sec_stg_gen_key aes256_k0 0 -I (2784) tee_sec_stg: Generated AES256 key with ID key0 +I (2784) tee_sec_stg: Generated AES256 key with ID aes256_k0 esp32c6> tee_sec_stg_encrypt aes256_k0 b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9 I (3084) tee_sec_stg: Ciphertext - -58054310a96d48c2dccdf2e34005aa63b40817723d3ec3d597ab362efea084c1 -I (3594) tee_sec_stg: Tag - -caeedb43e08dc3b4e35a58b2412908cc -esp32c6> tee_sec_stg_decrypt aes256_k0 58054310a96d48c2dccdf2e34005aa63b40817723d3ec3d597ab362efea084c1 caeedb43e08dc3b4e35a58b2412908cc -I (4314) tee_sec_stg: Decrypted plaintext - +40ff09c61af2f94611fb605806489380132b0000f2c63863366aad56ad327e95 +I (3084) tee_sec_stg: Tag - +8136e8bfc3c70ca792fa486b3eeca72b +I (3084) tee_sec_stg: IV - +0f202954f1a1a138a2ab8b06 +esp32c6> tee_sec_stg_decrypt aes256_k0 40ff09c61af2f94611fb605806489380132b0000f2c63863366aad56ad327e95 8136e8bfc3c70ca792fa486b3eeca72b 0f202954f1a1a138a2ab8b06 +I (3594) tee_sec_stg: Decrypted plaintext - b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9 ``` diff --git a/components/esp_tee/test_apps/tee_cli_app/main/app_main.c b/components/esp_tee/test_apps/tee_cli_app/main/app_main.c index 678ed9c1f6e..0fe39ffacee 100644 --- a/components/esp_tee/test_apps/tee_cli_app/main/app_main.c +++ b/components/esp_tee/test_apps/tee_cli_app/main/app_main.c @@ -33,7 +33,7 @@ static void setup_console(void) * This can be customized, made dynamic, etc. */ repl_config.prompt = PROMPT_STR ">"; - repl_config.max_cmdline_length = 128; + repl_config.max_cmdline_length = 256; /* Register help command */ ESP_ERROR_CHECK(esp_console_register_help_command()); diff --git a/components/esp_tee/test_apps/tee_cli_app/main/tee_srv_sec_str.c b/components/esp_tee/test_apps/tee_cli_app/main/tee_srv_sec_str.c index 6d81b8f2ef9..8a093ff0009 100644 --- a/components/esp_tee/test_apps/tee_cli_app/main/tee_srv_sec_str.c +++ b/components/esp_tee/test_apps/tee_cli_app/main/tee_srv_sec_str.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -416,8 +416,12 @@ static int tee_sec_stg_encrypt(int argc, char **argv) char tag_hexstr[AES256_GCM_TAG_LEN * 2 + 1]; hexbuf_to_hexstr(tag, sizeof(tag), tag_hexstr, sizeof(tag_hexstr)); + char iv_hexstr[AES_GCM_SUPPORTED_IV_LEN * 2 + 1]; + hexbuf_to_hexstr(ctx.iv, sizeof(ctx.iv), iv_hexstr, sizeof(iv_hexstr)); + ESP_LOGI(TAG, "Ciphertext -\n%s", ciphertext); ESP_LOGI(TAG, "Tag -\n%s", tag_hexstr); + ESP_LOGI(TAG, "IV -\n%s", iv_hexstr); free(plaintext_buf); free(ciphertext_buf); @@ -448,6 +452,7 @@ static struct { struct arg_str *key_str_id; struct arg_str *ciphertext; struct arg_str *tag; + struct arg_str *iv; struct arg_end *end; } tee_sec_stg_decrypt_args; @@ -466,6 +471,10 @@ static int tee_sec_stg_decrypt(int argc, char **argv) uint8_t tag[AES256_GCM_TAG_LEN]; hexstr_to_hexbuf(tag_hexstr, strlen(tag_hexstr), tag, sizeof(tag)); + const char *iv_hexstr = tee_sec_stg_decrypt_args.iv->sval[0]; + uint8_t iv[AES_GCM_SUPPORTED_IV_LEN]; + hexstr_to_hexbuf(iv_hexstr, strlen(iv_hexstr), iv, sizeof(iv)); + const char *ciphertext = tee_sec_stg_decrypt_args.ciphertext->sval[0]; size_t ciphertext_len = strnlen(ciphertext, MAX_AES_PLAINTEXT_LEN); if (ciphertext_len == MAX_AES_PLAINTEXT_LEN && ciphertext[MAX_AES_PLAINTEXT_LEN] != '\0') { @@ -499,6 +508,8 @@ static int tee_sec_stg_decrypt(int argc, char **argv) .input = (uint8_t *)ciphertext_buf, .input_len = ciphertext_buf_len }; + /* Copying the IV generated during encryption */ + memcpy(ctx.iv, iv, sizeof(iv)); err = esp_tee_sec_storage_aead_decrypt(&ctx, tag, sizeof(tag), plaintext_buf); if (err != ESP_OK) { @@ -528,7 +539,8 @@ void register_srv_sec_stg_decrypt(void) tee_sec_stg_decrypt_args.key_str_id = arg_str1(NULL, NULL, "<key_id>", "TEE Secure storage key ID"); tee_sec_stg_decrypt_args.ciphertext = arg_str1(NULL, NULL, "<ciphertext>", "Ciphertext to be decrypted"); tee_sec_stg_decrypt_args.tag = arg_str1(NULL, NULL, "<tag>", "AES-GCM authentication tag"); - tee_sec_stg_decrypt_args.end = arg_end(3); + tee_sec_stg_decrypt_args.iv = arg_str1(NULL, NULL, "<iv>", "AES-GCM initialization vector"); + tee_sec_stg_decrypt_args.end = arg_end(4); const esp_console_cmd_t tee_sec_stg = { .command = "tee_sec_stg_decrypt", diff --git a/components/esp_tee/test_apps/tee_cli_app/pytest_tee_cli.py b/components/esp_tee/test_apps/tee_cli_app/pytest_tee_cli.py index 4a32919eee1..4f7c17fc3e4 100644 --- a/components/esp_tee/test_apps/tee_cli_app/pytest_tee_cli.py +++ b/components/esp_tee/test_apps/tee_cli_app/pytest_tee_cli.py @@ -77,8 +77,9 @@ def test_tee_cli_secure_storage(dut: Dut) -> None: dut.write(f'tee_sec_stg_encrypt {sec_stg_key_ids.get(i)} {test_msg_hash}') test_msg_cipher = dut.expect(r'Ciphertext -\s*([0-9a-fA-F]{64})', timeout=30)[1].decode() test_msg_tag = dut.expect(r'Tag -\s*([0-9a-fA-F]{32})', timeout=30)[1].decode() + test_msg_iv = dut.expect(r'IV -\s*([0-9a-fA-F]{24})', timeout=30)[1].decode() - dut.write(f'tee_sec_stg_decrypt {sec_stg_key_ids.get(i)} {test_msg_cipher} {test_msg_tag}') + dut.write(f'tee_sec_stg_decrypt {sec_stg_key_ids.get(i)} {test_msg_cipher} {test_msg_tag} {test_msg_iv}') test_msg_decipher = dut.expect(r'Decrypted plaintext -\s*([0-9a-fA-F]{64})', timeout=30)[1].decode() assert test_msg_decipher == test_msg_hash diff --git a/components/esp_tee/test_apps/tee_test_fw/main/test_esp_tee_sec_stg.c b/components/esp_tee/test_apps/tee_test_fw/main/test_esp_tee_sec_stg.c index 2f979eb137e..5f45309d0f6 100644 --- a/components/esp_tee/test_apps/tee_test_fw/main/test_esp_tee_sec_stg.c +++ b/components/esp_tee/test_apps/tee_test_fw/main/test_esp_tee_sec_stg.c @@ -246,7 +246,7 @@ TEST_CASE("Test TEE Secure Storage - Operations with invalid/non-existent keys", .aad = aad, .aad_len = sizeof(aad), .input = plaintext, - .input_len = SZ + .input_len = SZ, }; // Test ECDSA key with AES operation diff --git a/examples/security/tee/tee_secure_storage/README.md b/examples/security/tee/tee_secure_storage/README.md index 194e22420ec..8f25dceb505 100644 --- a/examples/security/tee/tee_secure_storage/README.md +++ b/examples/security/tee/tee_secure_storage/README.md @@ -78,11 +78,12 @@ I (1001) Plaintext: 4c 6f 72 65 6d 20 69 70 73 75 6d 20 64 6f 6c 6f I (1001) Plaintext: 72 20 73 69 74 20 61 6d 65 74 2c 20 63 6f 6e 73 I (1011) Plaintext: 65 63 74 65 74 75 72 20 61 64 69 70 69 73 63 69 I (1021) Plaintext: 6e 67 20 65 6c 69 74 2e -I (1111) Encrypted data: 18 85 a2 97 7d 20 be 53 47 b7 3f 6f 52 06 8a 44 -I (1111) Encrypted data: 3b 7e 2e 25 7b 33 5d 4f 2a e5 17 5e bc d7 4e 23 -I (1111) Encrypted data: 2a 8f 89 a1 80 9c 6c 6b 00 e6 c6 39 7b 3f 75 65 -I (1121) Encrypted data: cd d5 f6 f6 3c 9a fb bb -I (1131) Tag: 6d 7f 1f 8e 1e a9 2c d9 d2 7f 9b db 16 cc 9b 68 +I (1111) Encrypted data: 8a c5 1b cf 9f 5a 7c 73 a6 e7 5a bf 2a 25 bf e2 +I (1111) Encrypted data: 80 8a 2e 3e 7a 26 9a 14 d0 c3 1b c3 f9 48 40 cc +I (1111) Encrypted data: ea 0b 61 c6 45 8c 39 b6 66 8c 28 5a 10 f3 66 b6 +I (1121) Encrypted data: ce 7d 94 7a d8 ba 18 2a +I (1131) IV: b9 3f 51 52 f4 0b 32 71 7e 45 56 33 +I (1131) Tag: e8 78 6f 56 0a 14 95 cb b2 c3 ae 14 3c 7c 26 5d I (1131) example_tee_sec_stg: Done with encryption/decryption! I (1141) main_task: Returned from app_main() ``` diff --git a/examples/security/tee/tee_secure_storage/main/tee_main.c b/examples/security/tee/tee_secure_storage/main/tee_main.c index 767a9fbd7d7..a704da822a3 100644 --- a/examples/security/tee/tee_secure_storage/main/tee_main.c +++ b/examples/security/tee/tee_secure_storage/main/tee_main.c @@ -223,6 +223,7 @@ static void example_tee_sec_stg_encrypt_decrypt(void *pvParameter) goto exit; } + ESP_LOG_BUFFER_HEX("IV", ctx.iv, AES_GCM_SUPPORTED_IV_LEN); ESP_LOG_BUFFER_HEX("Tag", tag, sizeof(tag)); ESP_LOGI(TAG, "Done with encryption/decryption!");