mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 10:40:47 +03:00
fix(esp_security): Stop ECDSA and Key Manager resets from corrupting concurrent crypto
ECDSA enable pulses a reset that also holds SHA in reset, and SHA shares its DMA with AES. Key Manager enable pulses a reset that also covers the XTS-AES flash encryption key-usage selector. Neither path was serialized against those victims, so a hardware ECDSA/HMAC/DS operation could corrupt a concurrent SHA/AES transfer or an in-flight encrypted flash read. - Take the SHA/AES lock inside esp_crypto_ecdsa_lock_acquire(), before MPI, matching the DS lock order (sha_aes < mpi) - Add esp_crypto_key_mgr_enable_periph_clk_no_reset() and switch ECDSA, HMAC and DS to it; they only need the key-usage selector writable - Hold esp_crypto_key_manager_lock across those clock enable/disable pairs so selector writes stay serialized without resetting KM
This commit is contained in:
@@ -110,14 +110,16 @@ void esp_crypto_ecc_lock_release(void);
|
||||
/**
|
||||
* @brief Acquire lock for ECDSA cryptography peripheral
|
||||
*
|
||||
* Internally also locks the ECC and MPI peripheral, as the ECDSA depends on these peripherals
|
||||
* Internally also locks the ECC and MPI peripheral, as the ECDSA depends on these peripherals,
|
||||
* and the SHA/AES peripheral, because the ECDSA reset holds SHA in reset as well
|
||||
*/
|
||||
void esp_crypto_ecdsa_lock_acquire(void);
|
||||
|
||||
/**
|
||||
* @brief Release lock for ECDSA cryptography peripheral
|
||||
*
|
||||
* Internally also releases the ECC and MPI peripheral, as the ECDSA depends on these peripherals
|
||||
* Internally also releases the ECC and MPI peripheral, as the ECDSA depends on these peripherals,
|
||||
* and the SHA/AES peripheral, because the ECDSA reset holds SHA in reset as well
|
||||
*/
|
||||
void esp_crypto_ecdsa_lock_release(void);
|
||||
#endif /* SOC_ECDSA_SUPPORTED */
|
||||
@@ -126,12 +128,16 @@ void esp_crypto_ecdsa_lock_release(void);
|
||||
/**
|
||||
* @brief Acquire lock for Key Manager peripheral
|
||||
*
|
||||
* Must be held across esp_crypto_key_mgr_enable_periph_clk(true/false): that
|
||||
* helper pulses the Key Manager reset, which also covers the XTS-AES flash
|
||||
* encryption key-usage selector on targets that deploy FE keys through KM.
|
||||
*/
|
||||
void esp_crypto_key_manager_lock_acquire(void);
|
||||
|
||||
/**
|
||||
* @brief Release lock for Key Manager peripheral
|
||||
*
|
||||
* Must be released only after the matching esp_crypto_key_mgr_enable_periph_clk(false).
|
||||
*/
|
||||
void esp_crypto_key_manager_lock_release(void);
|
||||
#endif /* SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT */
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -63,10 +63,30 @@ void esp_crypto_ecdsa_enable_periph_clk(bool enable);
|
||||
/**
|
||||
* @brief Enable or disable the Key Manager peripheral clock
|
||||
*
|
||||
* When enable is true this also pulses the Key Manager reset. The caller must
|
||||
* hold esp_crypto_key_manager_lock across the matching true/false pair, because
|
||||
* that reset also covers the XTS-AES flash encryption key-usage selector.
|
||||
*
|
||||
* Prefer esp_crypto_key_mgr_enable_periph_clk_no_reset() when the caller only
|
||||
* needs the key-usage selector writable (ECDSA/HMAC/DS).
|
||||
*
|
||||
* @param enable true: enable; false: disable
|
||||
*/
|
||||
void esp_crypto_key_mgr_enable_periph_clk(bool enable);
|
||||
|
||||
/**
|
||||
* @brief Enable or disable the Key Manager clocks without resetting the peripheral
|
||||
*
|
||||
* Use this when a crypto accelerator only needs to write its own key-usage
|
||||
* selector. Resetting would drop the XTS-AES flash encryption selector that
|
||||
* MSPI may be using, and flash DMA does not take the Key Manager lock.
|
||||
* The caller must still hold esp_crypto_key_manager_lock across the matching
|
||||
* true/false pair to serialize selector writes.
|
||||
*
|
||||
* @param enable true: enable; false: disable
|
||||
*/
|
||||
void esp_crypto_key_mgr_enable_periph_clk_no_reset(bool enable);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user