From d25d49d307ff04ec88bcf68e3ddd915e17984c47 Mon Sep 17 00:00:00 2001 From: wuzhenghui Date: Tue, 21 Jul 2026 21:29:36 +0800 Subject: [PATCH] feat(esp_security): make esp32s31 on-demand crypto clock management optional --- components/esp_security/Kconfig | 17 ++++++++++ .../src/esp32s31/esp_crypto_clk.c | 32 +++++++++++++++++-- .../src/esp32s31/esp_crypto_clk.h | 9 ++++-- 3 files changed, 54 insertions(+), 4 deletions(-) diff --git a/components/esp_security/Kconfig b/components/esp_security/Kconfig index feadfe56a2f..c9784ffdf41 100644 --- a/components/esp_security/Kconfig +++ b/components/esp_security/Kconfig @@ -1,5 +1,22 @@ menu "ESP Security Specific" + config ESP_CRYPTO_CLK_ON_DEMAND + bool "Enable on-demand crypto clock management" + depends on IDF_TARGET_ESP32S31 + default y if PM_ENABLE + default n + help + When enabled, crypto/security peripheral clocks and their parent + (PLL_F240M) are enabled only while crypto operations are in + progress and disabled afterwards, reducing power consumption. + + Enabling and disabling these clocks has a noticeable performance + cost for crypto operations. When this option is disabled (default), + crypto clocks remain always on after initialization for better + crypto performance. + + Defaults to enabled when Power Management (CONFIG_PM_ENABLE) is on. + menu "Crypto DPA Protection" depends on SOC_CRYPTO_DPA_PROTECTION_SUPPORTED config ESP_CRYPTO_DPA_PROTECTION_AT_STARTUP diff --git a/components/esp_security/src/esp32s31/esp_crypto_clk.c b/components/esp_security/src/esp32s31/esp_crypto_clk.c index d54eb26627a..a12cb869886 100644 --- a/components/esp_security/src/esp32s31/esp_crypto_clk.c +++ b/components/esp_security/src/esp32s31/esp_crypto_clk.c @@ -4,6 +4,7 @@ * SPDX-License-Identifier: Apache-2.0 */ +#include "sdkconfig.h" #include "esp_attr.h" #include "esp_crypto_clk.h" #include "soc/clk_tree_defs.h" @@ -23,8 +24,6 @@ DEFINE_CRIT_SECTION_LOCK_STATIC(s_crypto_common_clk_mux); #define CRYPTO_CLK_UNLOCK() #endif -static int s_crypto_common_clk_ref_cnt; - static void esp_crypto_pll_f240m_enable(bool enable) { #if !NON_OS_BUILD @@ -41,6 +40,10 @@ FORCE_INLINE_ATTR void esp_crypto_periph_clk_enable(bool enable) HP_SYS_CLKRST.crypto_ctrl0.reg_crypto_sec_clk_en = enable; } +#if CONFIG_ESP_CRYPTO_CLK_ON_DEMAND + +static int s_crypto_common_clk_ref_cnt; + void esp_crypto_common_clk_enable(bool enable) { CRYPTO_CLK_LOCK(); @@ -56,3 +59,28 @@ void esp_crypto_common_clk_enable(bool enable) } CRYPTO_CLK_UNLOCK(); } + +#else /* !CONFIG_ESP_CRYPTO_CLK_ON_DEMAND */ + +static bool s_crypto_clk_always_on_done; + +static void esp_crypto_clk_always_on(void) +{ + CRYPTO_CLK_LOCK(); + if (!s_crypto_clk_always_on_done) { + esp_crypto_pll_f240m_enable(true); + esp_crypto_periph_clk_enable(true); + s_crypto_clk_always_on_done = true; + } + CRYPTO_CLK_UNLOCK(); +} + +void esp_crypto_common_clk_enable(bool enable) +{ + /* Keep clocks always on: enable once, ignore disable. */ + if (enable) { + esp_crypto_clk_always_on(); + } +} + +#endif /* CONFIG_ESP_CRYPTO_CLK_ON_DEMAND */ diff --git a/components/esp_security/src/esp32s31/esp_crypto_clk.h b/components/esp_security/src/esp32s31/esp_crypto_clk.h index 89a44dbf4e4..25c3b3f80c2 100644 --- a/components/esp_security/src/esp32s31/esp_crypto_clk.h +++ b/components/esp_security/src/esp32s31/esp_crypto_clk.h @@ -7,13 +7,18 @@ #pragma once #include +#include "sdkconfig.h" #include "hal/sec_ll.h" #include "soc/clk_tree_defs.h" +void esp_crypto_common_clk_enable(bool enable); + static inline void esp_crypto_clk_init(void) { // Set crypto clock (`clk_sec`) to use 240M PLL clock sec_ll_crypto_clk_src_sel(SOC_MOD_CLK_PLL_F240M); +#if !CONFIG_ESP_CRYPTO_CLK_ON_DEMAND + /* Keep crypto clocks always on for better crypto performance. */ + esp_crypto_common_clk_enable(true); +#endif } - -void esp_crypto_common_clk_enable(bool enable);