feat(bootloader_support): Support Flash Encryption using Key Manager

This commit is contained in:
harshal.patil
2025-11-20 11:37:05 +05:30
parent 46e2cd21d4
commit c1503cd847
19 changed files with 378 additions and 29 deletions
@@ -20,6 +20,7 @@
#include "soc/keymng_reg.h"
#include "soc/pcr_struct.h"
#include "soc/pcr_reg.h"
#include "hal/efuse_hal.h"
#ifdef __cplusplus
extern "C" {
@@ -443,6 +444,14 @@ static inline bool key_mgr_ll_is_supported(void)
return true;
}
static inline bool key_mgr_ll_flash_encryption_supported(void)
{
if (!key_mgr_ll_is_supported() || efuse_hal_chip_revision() <= 100) {
return false;
}
return true;
}
#ifdef __cplusplus
}
#endif
@@ -484,6 +484,14 @@ static inline bool key_mgr_ll_is_supported(void)
#endif
}
static inline bool key_mgr_ll_flash_encryption_supported(void)
{
if (!key_mgr_ll_is_supported()) {
return false;
}
return true;
}
#ifdef __cplusplus
}
#endif
@@ -110,6 +110,17 @@ typedef enum {
ESP_KEY_MGR_INT_POST_DONE,
} esp_key_mgr_interrupt_type_t;
/**
* @brief Force use key manager key type
* @note This is used to force the key manager to use a specific key type.
*/
typedef enum {
ESP_KEY_MGR_FORCE_USE_KM_ECDSA_KEY = 0,
ESP_KEY_MGR_FORCE_USE_KM_XTS_AES_KEY = 1,
ESP_KEY_MGR_FORCE_USE_KM_HMAC_KEY = 2,
ESP_KEY_MGR_FORCE_USE_KM_DS_KEY = 3,
} esp_key_mgr_force_use_km_key_t;
// store huk info, occupy 96 words
typedef struct PACKED_ATTR {
#define HUK_INFO_LEN 660