fix(esp_tee): fixes IV length check for TEE AEAD operations

This commit is contained in:
Ashish Sharma
2026-07-17 18:14:37 +05:30
committed by Laukik Hase
parent a43c51681a
commit c146cb5322
2 changed files with 20 additions and 6 deletions
@@ -145,11 +145,13 @@ esp_err_t esp_tee_sec_storage_ecdsa_get_pubkey(const esp_tee_sec_storage_key_cfg
*
* @param[in] ctx Pointer to the AEAD operation context
* @param[out] iv Pointer to the output buffer for the generated initialization vector
* @param[in] iv_len Length of the initialization vector buffer
* @param[in] iv_len Length of the initialization vector buffer; must be exactly 12 bytes (96-bit IV, per NIST SP 800-38D)
* @param[out] tag Pointer to the authentication tag buffer
* @param[in] tag_len Length of the authentication tag
* @param[in] tag_len Length of the authentication tag; must be 12 to 16 bytes (96- to 128-bit tag, per NIST SP 800-38D)
* @param[out] output Pointer to the output data buffer
*
* @note Non-standard @p iv_len / @p tag_len values are rejected with ESP_ERR_INVALID_SIZE.
*
* @return esp_err_t ESP_OK on success, appropriate error code otherwise.
*/
esp_err_t esp_tee_sec_storage_aead_encrypt(const esp_tee_sec_storage_aead_ctx_t *ctx, uint8_t *iv, size_t iv_len, uint8_t *tag, size_t tag_len, uint8_t *output);
@@ -159,11 +161,13 @@ esp_err_t esp_tee_sec_storage_aead_encrypt(const esp_tee_sec_storage_aead_ctx_t
*
* @param[in] ctx Pointer to the AEAD operation context
* @param[in] iv Pointer to the initialization vector used during encryption
* @param[in] iv_len Length of the initialization vector
* @param[in] iv_len Length of the initialization vector; must be exactly 12 bytes (96-bit IV, per NIST SP 800-38D)
* @param[in] tag Pointer to the authentication tag buffer
* @param[in] tag_len Length of the authentication tag
* @param[in] tag_len Length of the authentication tag; must be 12 to 16 bytes (96- to 128-bit tag, per NIST SP 800-38D)
* @param[out] output Pointer to the output data buffer
*
* @note Non-standard @p iv_len / @p tag_len values are rejected with ESP_ERR_INVALID_SIZE.
*
* @return esp_err_t ESP_OK on success, appropriate error code otherwise.
*/
esp_err_t esp_tee_sec_storage_aead_decrypt(const esp_tee_sec_storage_aead_ctx_t *ctx, const uint8_t *iv, size_t iv_len, const uint8_t *tag, size_t tag_len, uint8_t *output);
@@ -37,6 +37,8 @@
#define AES256_KEY_LEN 32
#define AES256_KEY_BITS (AES256_KEY_LEN * 8)
#define AES256_GCM_IV_LEN 12
#define AES256_GCM_TAG_LEN_MIN 12 /* NIST SP800-38D general-use minimum (96-bit tag) */
#define AES256_GCM_TAG_LEN_MAX 16 /* full GCM tag (128-bit) */
#define ECDSA_SECP384R1_KEY_LEN 48
#define ECDSA_SECP256R1_KEY_LEN 32
@@ -658,8 +660,16 @@ static esp_err_t tee_sec_storage_crypt_common(const char *key_id, const uint8_t
return ESP_ERR_INVALID_ARG;
}
if (len == 0 || tag_len == 0 || iv_len == 0) {
ESP_LOGE(TAG, "Invalid input/tag/iv length");
if (len == 0) {
ESP_LOGE(TAG, "Invalid input length");
return ESP_ERR_INVALID_SIZE;
}
/* Enforce standard AES-GCM parameters */
if (iv_len != AES256_GCM_IV_LEN ||
tag_len < AES256_GCM_TAG_LEN_MIN || tag_len > AES256_GCM_TAG_LEN_MAX) {
ESP_LOGE(TAG, "Non-standard GCM iv_len(%u)/tag_len(%u) rejected",
(unsigned)iv_len, (unsigned)tag_len);
return ESP_ERR_INVALID_SIZE;
}