feat(esp_security): make esp32s31 on-demand crypto clock management optional

This commit is contained in:
wuzhenghui
2026-09-02 19:20:15 +08:00
parent 0f5ec4d261
commit d25d49d307
3 changed files with 54 additions and 4 deletions
+17
View File
@@ -1,5 +1,22 @@
menu "ESP Security Specific"
config ESP_CRYPTO_CLK_ON_DEMAND
bool "Enable on-demand crypto clock management"
depends on IDF_TARGET_ESP32S31
default y if PM_ENABLE
default n
help
When enabled, crypto/security peripheral clocks and their parent
(PLL_F240M) are enabled only while crypto operations are in
progress and disabled afterwards, reducing power consumption.
Enabling and disabling these clocks has a noticeable performance
cost for crypto operations. When this option is disabled (default),
crypto clocks remain always on after initialization for better
crypto performance.
Defaults to enabled when Power Management (CONFIG_PM_ENABLE) is on.
menu "Crypto DPA Protection"
depends on SOC_CRYPTO_DPA_PROTECTION_SUPPORTED
config ESP_CRYPTO_DPA_PROTECTION_AT_STARTUP
@@ -4,6 +4,7 @@
* SPDX-License-Identifier: Apache-2.0
*/
#include "sdkconfig.h"
#include "esp_attr.h"
#include "esp_crypto_clk.h"
#include "soc/clk_tree_defs.h"
@@ -23,8 +24,6 @@ DEFINE_CRIT_SECTION_LOCK_STATIC(s_crypto_common_clk_mux);
#define CRYPTO_CLK_UNLOCK()
#endif
static int s_crypto_common_clk_ref_cnt;
static void esp_crypto_pll_f240m_enable(bool enable)
{
#if !NON_OS_BUILD
@@ -41,6 +40,10 @@ FORCE_INLINE_ATTR void esp_crypto_periph_clk_enable(bool enable)
HP_SYS_CLKRST.crypto_ctrl0.reg_crypto_sec_clk_en = enable;
}
#if CONFIG_ESP_CRYPTO_CLK_ON_DEMAND
static int s_crypto_common_clk_ref_cnt;
void esp_crypto_common_clk_enable(bool enable)
{
CRYPTO_CLK_LOCK();
@@ -56,3 +59,28 @@ void esp_crypto_common_clk_enable(bool enable)
}
CRYPTO_CLK_UNLOCK();
}
#else /* !CONFIG_ESP_CRYPTO_CLK_ON_DEMAND */
static bool s_crypto_clk_always_on_done;
static void esp_crypto_clk_always_on(void)
{
CRYPTO_CLK_LOCK();
if (!s_crypto_clk_always_on_done) {
esp_crypto_pll_f240m_enable(true);
esp_crypto_periph_clk_enable(true);
s_crypto_clk_always_on_done = true;
}
CRYPTO_CLK_UNLOCK();
}
void esp_crypto_common_clk_enable(bool enable)
{
/* Keep clocks always on: enable once, ignore disable. */
if (enable) {
esp_crypto_clk_always_on();
}
}
#endif /* CONFIG_ESP_CRYPTO_CLK_ON_DEMAND */
@@ -7,13 +7,18 @@
#pragma once
#include <stdbool.h>
#include "sdkconfig.h"
#include "hal/sec_ll.h"
#include "soc/clk_tree_defs.h"
void esp_crypto_common_clk_enable(bool enable);
static inline void esp_crypto_clk_init(void)
{
// Set crypto clock (`clk_sec`) to use 240M PLL clock
sec_ll_crypto_clk_src_sel(SOC_MOD_CLK_PLL_F240M);
#if !CONFIG_ESP_CRYPTO_CLK_ON_DEMAND
/* Keep crypto clocks always on for better crypto performance. */
esp_crypto_common_clk_enable(true);
#endif
}
void esp_crypto_common_clk_enable(bool enable);