feat(esp_tee): Added support for PBKDF2-based (HMAC) ECDSA signing

This commit is contained in:
Laukik Hase
2025-09-19 12:06:02 +05:30
parent 333a2c0ebc
commit c152663408
18 changed files with 375 additions and 33 deletions
+4
View File
@@ -280,6 +280,10 @@ target_sources(mbedcrypto PRIVATE
"${COMPONENT_DIR}/port/esp_ds/esp_ds_common.c")
endif()
if(CONFIG_SOC_HMAC_SUPPORTED)
target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/esp_hmac_pbkdf2.c")
endif()
# Note: some mbedTLS hardware acceleration can be enabled/disabled by config.
#
# We don't need to filter aes.c as this uses a different prefix (esp_aes_x) and the
@@ -65,3 +65,6 @@ target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/sha/core/sha.c"
target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/ecc/esp_ecc.c"
"${COMPONENT_DIR}/port/ecc/ecc_alt.c")
# HMAC-based PBKDF2 implementation
target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/esp_hmac_pbkdf2.c")
+82
View File
@@ -0,0 +1,82 @@
/*
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*
*/
#include <string.h>
#include "esp_hmac.h"
#include "sdkconfig.h"
#include "esp_hmac_pbkdf2.h"
#define SHA256_DIGEST_SZ 32
esp_err_t esp_hmac_derive_pbkdf2_key(hmac_key_id_t key_id, const uint8_t *salt, size_t salt_len, int iterations, size_t key_len, uint8_t *out_key)
{
if (!out_key || !salt || key_len == 0 || salt_len == 0 || iterations <= 0) {
return ESP_ERR_INVALID_ARG;
}
if (key_id >= HMAC_KEY_MAX) {
return ESP_ERR_INVALID_ARG;
}
uint8_t U[SHA256_DIGEST_SZ] = {0};
uint8_t T[SHA256_DIGEST_SZ] = {0};
uint8_t counter[4] = {0, 0, 0, 1};
uint8_t *hmac_input = calloc(1, salt_len + sizeof(counter));
if (!hmac_input) {
return ESP_ERR_NO_MEM;
}
esp_err_t err = ESP_FAIL;
size_t remaining = key_len;
uint8_t *out_p = out_key;
while (remaining > 0) {
memcpy(hmac_input, salt, salt_len);
memcpy(hmac_input + salt_len, counter, sizeof(counter));
err = esp_hmac_calculate(key_id, hmac_input, salt_len + sizeof(counter), U);
if (err != ESP_OK) {
goto cleanup;
}
memcpy(T, U, SHA256_DIGEST_SZ);
for (int i = 1; i < iterations; i++) {
err = esp_hmac_calculate(key_id, U, SHA256_DIGEST_SZ, U);
if (err != ESP_OK) {
goto cleanup;
}
for (int j = 0; j < SHA256_DIGEST_SZ; j++) {
T[j] ^= U[j];
}
}
size_t copy_len = (remaining < SHA256_DIGEST_SZ) ? remaining : SHA256_DIGEST_SZ;
memcpy(out_p, T, copy_len);
out_p += copy_len;
remaining -= copy_len;
for (int i = 3; i >= 0; i--) {
if (++counter[i]) {
break;
}
}
}
err = ESP_OK;
cleanup:
memset(U, 0x00, sizeof(U));
memset(T, 0x00, sizeof(T));
if (hmac_input) {
memset(hmac_input, 0x00, salt_len + sizeof(counter));
free(hmac_input);
}
return err;
}
@@ -0,0 +1,41 @@
/*
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
#pragma once
#ifdef __cplusplus
extern "C" {
#endif
#include <stdint.h>
#include "esp_err.h"
#include "hal/hmac_types.h"
/**
* @brief Derive a key using PBKDF2-HMAC-SHA256 algorithm with HMAC peripheral
*
* This function implements PBKDF2 (Password-Based Key Derivation Function 2) using HMAC-SHA256
* to derive a cryptographic key from the efuse key and salt. The function uses the HMAC peripheral
* in upstream mode to perform the underlying HMAC calculations.
*
* @param key_id Determines which of the 6 key blocks in the efuses should be used as the base key.
* The corresponding purpose field of the key block must be set to HMAC upstream purpose.
* @param salt Input salt for the PBKDF2 algorithm
* @param salt_len Length of the salt in bytes (must be > 0)
* @param iterations Number of iterations (recommended >= 2048)
* @param key_len Length of the derived key to generate in bytes (must be > 0)
* @param[out] out_key Buffer to store the derived key. Must be at least key_len bytes.
* @return esp_err_t
* - ESP_OK: Key derivation successful
* - ESP_ERR_INVALID_ARG: Invalid arguments (null pointers, zero lengths, or key_id out of range)
* - ESP_ERR_NO_MEM: Memory allocation failed
* - ESP_FAIL: HMAC calculation failed
*/
esp_err_t esp_hmac_derive_pbkdf2_key(hmac_key_id_t key_id, const uint8_t *salt, size_t salt_len, int iterations, size_t key_len, uint8_t *out_key);
#ifdef __cplusplus
}
#endif