mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat(bootloader_support): remove P192 curve support
This commit is contained in:
@@ -558,22 +558,13 @@ menu "Security features"
|
||||
depends on SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
|
||||
default SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
|
||||
help
|
||||
Select the ECDSA key size. Three key sizes are supported depending upon on the target:
|
||||
Select the ECDSA key size. Two key sizes are supported depending on the target:
|
||||
|
||||
- 192 bit key using NISTP192 curve (Legacy, not recommended)
|
||||
- 256 bit key using NISTP256 curve (Recommended)
|
||||
- 384 bit key using NISTP384 curve (Recommended)
|
||||
|
||||
The advantage of using 384 and 256 bit keys is the extra randomness which makes it difficult to be
|
||||
bruteforced compared to 192 bit key.
|
||||
At present, both key sizes are practically implausible to bruteforce.
|
||||
|
||||
config SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
|
||||
bool "Using ECC curve NISTP192 (Legacy, not recommended)"
|
||||
depends on SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
|
||||
help
|
||||
This legacy option is not recommended for new designs. Prefer NISTP256 or NISTP384.
|
||||
|
||||
config SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
|
||||
bool "Using ECC curve NISTP256 (Recommended)"
|
||||
depends on SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
|
||||
@@ -708,7 +699,7 @@ menu "Security features"
|
||||
|
||||
Key file is an ECDSA private key (NIST256p curve) in PEM format for Secure Boot V1.
|
||||
Key file is an RSA private key in PEM format for Secure Boot V2 (RSA scheme).
|
||||
Key file is an ECDSA private key (NIST 192p, 256p or 384p) in PEM format for Secure Boot V2 (ECDSA scheme).
|
||||
Key file is an ECDSA private key (256p or 384p) in PEM format for Secure Boot V2 (ECDSA scheme).
|
||||
|
||||
Path is evaluated relative to the project directory.
|
||||
|
||||
|
||||
@@ -43,7 +43,6 @@ if(CONFIG_SECURE_SIGNED_APPS)
|
||||
set(bootloader_binary_files
|
||||
${bootloader_binary_files}
|
||||
"${BOOTLOADER_BUILD_DIR}/bootloader-reflash-digest.bin"
|
||||
"${BOOTLOADER_BUILD_DIR}/secure-bootloader-key-192.bin"
|
||||
"${BOOTLOADER_BUILD_DIR}/secure-bootloader-key-256.bin"
|
||||
)
|
||||
endif()
|
||||
@@ -66,9 +65,7 @@ if(CONFIG_SECURE_SIGNED_APPS)
|
||||
"Secure Boot Signing Key ${CONFIG_SECURE_BOOT_SIGNING_KEY} does not exist. Generate using:"
|
||||
"\tidf.py secure-generate-signing-key ${CONFIG_SECURE_BOOT_SIGNING_KEY}")
|
||||
else()
|
||||
if(CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS)
|
||||
set(scheme "ecdsa192")
|
||||
elseif(CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS)
|
||||
if(CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS)
|
||||
set(scheme "ecdsa256")
|
||||
elseif(CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS)
|
||||
set(scheme "ecdsa384")
|
||||
|
||||
@@ -70,11 +70,9 @@ typedef enum {
|
||||
#define ESP_SECURE_BOOT_SCHEME ESP_SECURE_BOOT_V2_ECDSA
|
||||
#endif
|
||||
|
||||
/* Expected ECDSA curve ID from menuconfig "ECDSA key size" (matches ECDSA_CURVE_P192/P256/P384 in ROM) */
|
||||
/* Expected ECDSA curve ID from menuconfig "ECDSA key size" (matches ECDSA_CURVE_P256/P384 in ROM) */
|
||||
#if CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
|
||||
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
|
||||
#define ESP_SECURE_BOOT_ECDSA_CURVE_ID ECDSA_CURVE_P192
|
||||
#elif CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
|
||||
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
|
||||
#define ESP_SECURE_BOOT_ECDSA_CURVE_ID ECDSA_CURVE_P256
|
||||
#elif CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS
|
||||
#define ESP_SECURE_BOOT_ECDSA_CURVE_ID ECDSA_CURVE_P384
|
||||
|
||||
@@ -13,9 +13,7 @@
|
||||
|
||||
ESP_LOG_ATTR_TAG(TAG, "secure_boot_v2_ecdsa");
|
||||
|
||||
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
|
||||
#define ECDSA_INTEGER_LEN 24
|
||||
#elif CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS
|
||||
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS
|
||||
#define ECDSA_INTEGER_LEN 48
|
||||
#else
|
||||
#define ECDSA_INTEGER_LEN 32
|
||||
@@ -41,13 +39,6 @@ esp_err_t verify_ecdsa_signature_block(const ets_secure_boot_signature_t *sig_bl
|
||||
psa_ecc_family_t curve_family;
|
||||
|
||||
switch(trusted_block->ecdsa.key.curve_id) {
|
||||
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
|
||||
case ECDSA_CURVE_P192:
|
||||
key_size = 24;
|
||||
curve_family = PSA_ECC_FAMILY_SECP_R1;
|
||||
psa_set_key_bits(&key_attributes, PSA_BYTES_TO_BITS(key_size));
|
||||
break;
|
||||
#endif /* CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS */
|
||||
#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
|
||||
case ECDSA_CURVE_P256:
|
||||
key_size = 32;
|
||||
|
||||
@@ -50,17 +50,6 @@ static esp_err_t validate_signature_block(const ets_secure_boot_sig_block_t *blo
|
||||
}
|
||||
#endif
|
||||
|
||||
#if SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED && CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
|
||||
if (block->ecdsa.key.curve_id == ECDSA_CURVE_P192) {
|
||||
// Enabling ECDSA-192 Curve mode
|
||||
esp_err_t err = esp_efuse_enable_ecdsa_p192_curve_mode();
|
||||
if (err != ESP_OK) {
|
||||
ESP_LOGE(TAG, "Failed to enable ECDSA-192 curve mode: %d", err);
|
||||
return err;
|
||||
}
|
||||
}
|
||||
#endif
|
||||
|
||||
return ESP_OK;
|
||||
}
|
||||
|
||||
|
||||
@@ -79,17 +79,6 @@ static esp_err_t validate_signature_block(const ets_secure_boot_sig_block_t *blo
|
||||
}
|
||||
#endif
|
||||
|
||||
#if SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED && CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
|
||||
if (block->ecdsa.key.curve_id == ECDSA_CURVE_P192) {
|
||||
// Enabling ECDSA-192 Curve mode
|
||||
esp_err_t err = esp_efuse_enable_ecdsa_p192_curve_mode();
|
||||
if (err != ESP_OK) {
|
||||
ESP_LOGE(TAG, "Failed to enable ECDSA-192 curve mode: %d", err);
|
||||
return err;
|
||||
}
|
||||
}
|
||||
#endif
|
||||
|
||||
return ESP_OK;
|
||||
}
|
||||
|
||||
|
||||
@@ -277,7 +277,7 @@
|
||||
|
||||
#ifdef CONFIG_MBEDTLS_HARDWARE_ECC
|
||||
#ifdef CONFIG_MBEDTLS_ECC_OTHER_CURVES_SOFT_FALLBACK
|
||||
/* Use hardware accelerator for SECP192R1 and SECP256R1 curves,
|
||||
/* Use hardware accelerator for SECP256R1 curves,
|
||||
* software implementation for rest of the curves
|
||||
*/
|
||||
#define MBEDTLS_ECP_MUL_ALT_SOFT_FALLBACK
|
||||
@@ -525,7 +525,6 @@
|
||||
#endif
|
||||
|
||||
/**
|
||||
* \def MBEDTLS_ECP_DP_SECP192R1_ENABLED
|
||||
*
|
||||
* MBEDTLS_ECP_XXXX_ENABLED: Enables specific curves within the Elliptic Curve
|
||||
* module. By default all supported curves are enabled.
|
||||
@@ -543,11 +542,6 @@
|
||||
#else
|
||||
#undef PSA_WANT_ECC_SECP_R1_384
|
||||
#endif
|
||||
#ifdef CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
|
||||
#define PSA_WANT_ECC_SECP_R1_192 1
|
||||
#else
|
||||
#undef PSA_WANT_ECC_SECP_R1_192
|
||||
#endif
|
||||
#ifdef CONFIG_MBEDTLS_ECP_DP_SECP521R1_ENABLED
|
||||
#define PSA_WANT_ECC_SECP_R1_521 1
|
||||
#else
|
||||
|
||||
Reference in New Issue
Block a user