From d771b41400b4eed6f8fc0faa8617a5df0f7e4133 Mon Sep 17 00:00:00 2001 From: renpeiying Date: Wed, 13 May 2026 19:20:47 +0800 Subject: [PATCH] docs: Update translation for security docs --- .../migration-guides/release-6.x/6.0/security.rst | 4 +++- docs/en/security/secure-boot-v2.rst | 3 --- .../migration-guides/release-6.x/6.0/security.rst | 13 +++++++++++-- docs/zh_CN/security/secure-boot-v2.rst | 5 +---- 4 files changed, 15 insertions(+), 10 deletions(-) diff --git a/docs/en/migration-guides/release-6.x/6.0/security.rst b/docs/en/migration-guides/release-6.x/6.0/security.rst index 6ca1c60d3be..0a506603279 100644 --- a/docs/en/migration-guides/release-6.x/6.0/security.rst +++ b/docs/en/migration-guides/release-6.x/6.0/security.rst @@ -61,7 +61,6 @@ ESP-IDF v6.0 updates to Mbed TLS v4.0, where **PSA Crypto is the primary cryptog - 4.97 - Default configuration changes ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ @@ -123,6 +122,7 @@ Note that the new AES functions return error codes for better error handling, un The HMAC peripheral is now used via the **PSA Crypto HMAC driver** instead of the legacy :cpp:func:`esp_hmac_calculate` API. The applications are expected to populate the :cpp:type:`esp_hmac_opaque_key_t` structure and import it via :cpp:func:`psa_import_key` API using the ``PSA_KEY_LIFETIME_ESP_HMAC`` lifetime attribute. Then, they can use the :cpp:func:`psa_mac_compute` API to compute HMAC. + BluFi ----- @@ -137,6 +137,7 @@ BluFi (Wi-Fi provisioning over BLE) is affected by the Mbed TLS v4.x / PSA Crypt - Update the device firmware to ESP-IDF v6.0. - Update the BluFi client application to a version compatible with the updated BluFi protocol and security negotiation used by ESP-IDF v6.0. + Bootloader Support ------------------ @@ -165,6 +166,7 @@ The following deprecated functions have been removed: - When NVS encryption is enabled on SoCs with the HMAC peripheral that have flash encryption enabled, the HMAC-based NVS encryption scheme is now selected as default instead of the flash encryption-based scheme. If your application previously used the flash encryption-based scheme, you need to manually configure the NVS encryption scheme to flash encryption from HMAC through ``menuconfig`` or your project's ``sdkconfig`` (i.e., setting ``CONFIG_NVS_SEC_KEY_PROTECT_USING_FLASH_ENC=y``). + Mbed TLS v4.1 migration ----------------------- diff --git a/docs/en/security/secure-boot-v2.rst b/docs/en/security/secure-boot-v2.rst index f21e721042c..9569138819e 100644 --- a/docs/en/security/secure-boot-v2.rst +++ b/docs/en/security/secure-boot-v2.rst @@ -76,7 +76,6 @@ The Secure Boot process on {IDF_TARGET_NAME} involves the following steps: 2. When the second stage bootloader loads a particular application image, the application's {IDF_TARGET_SBV2_SCHEME} signature is verified. If the verification is successful, the application image is executed. - Advantages ---------- @@ -529,7 +528,6 @@ Restrictions After Secure Boot Is Enabled - After Secure Boot is enabled, further read-protection of eFuse keys is not possible. This is done to prevent an attacker from read-protecting the eFuse block that contains the Secure Boot public key digest, which could result in immediate denial of service and potentially enable a fault injection attack to bypass the signature verification. For further information on read-protected keys, see the details below. - Burning read-protected keys ~~~~~~~~~~~~~~~~~~~~~~~~~~~ @@ -613,7 +611,6 @@ For example, to generate a signing key using the OpenSSL command line: Remember that the strength of the Secure Boot system depends on keeping the signing key private. - .. _remote-sign-v2-image: Remote Signing of Images diff --git a/docs/zh_CN/migration-guides/release-6.x/6.0/security.rst b/docs/zh_CN/migration-guides/release-6.x/6.0/security.rst index 6f70bfad493..c522e69066f 100644 --- a/docs/zh_CN/migration-guides/release-6.x/6.0/security.rst +++ b/docs/zh_CN/migration-guides/release-6.x/6.0/security.rst @@ -61,7 +61,6 @@ ESP-IDF v6.0 已升级至 Mbed TLS v4.0,**PSA Crypto 成为主要加密接口* - 4.97 - 默认配置更改 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ @@ -123,6 +122,7 @@ ESP-IDF 提供了基于 NVS 的 PSA 内部可信存储 (ITS) 实现,因此无 现已通过 **PSA Crypto HMAC 驱动程序** 使用 HMAC 外设,而不是使用旧版 :cpp:func:`esp_hmac_calculate` API。应用需要填写 :cpp:type:`esp_hmac_opaque_key_t` 结构体,并通过 :cpp:func:`psa_import_key` API 使用 ``PSA_KEY_LIFETIME_ESP_HMAC`` 生命周期属性将其导入。然后可以使用 :cpp:func:`psa_mac_compute` API 计算 HMAC。 + BluFi ----- @@ -137,6 +137,7 @@ BluFi(基于 BLE 的 Wi-Fi 配网)功能受到 ESP-IDF v6.0 中 Mbed TLS v4. - 将设备固件升级至 ESP-IDF v6.0。 - 将 BluFi 客户端应用更新至兼容 ESP-IDF v6.0 新版 BluFi 协议和安全协商的版本。 + 引导加载程序支持 ---------------- @@ -151,7 +152,6 @@ BluFi(基于 BLE 的 Wi-Fi 配网)功能受到 ESP-IDF v6.0 中 Mbed TLS v4. - 在 ESP-IDF v6.0 中,用于安全启动的 ECDSA 应为 NISTP256/NISTP384 曲线。 - 对旧版 NISTP192 的支持已弃用,仅当通过 ``CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS`` 显式启用时方可使用。 - 对旧版 NISTP192 的支持可能会在下一个 ESP-IDF 版本中被移除,因此强烈建议迁移至 NISTP256/NISTP384。 -- 从 Mbed TLS 4.1 开始,已移除对旧版 NISTP192 的支持。 **已移除的废弃 API** @@ -165,3 +165,12 @@ BluFi(基于 BLE 的 Wi-Fi 配网)功能受到 ESP-IDF v6.0 中 Mbed TLS v4. ------------ - 当 SoC 具备 HMAC 外设并启用了 flash 加密时,如果同时还启用了 NVS 加密,则默认会选择基于 HMAC 的 NVS 加密方案,而不是基于 flash 加密的方案。如果你的应用程序之前使用基于 flash 加密的方案,则需要通过 ``menuconfig`` 或项目的 ``sdkconfig`` 文件,手动将 NVS 加密方案从 HMAC 配置为 flash 加密(即设置 ``CONFIG_NVS_SEC_KEY_PROTECT_USING_FLASH_ENC=y``)。 + + +Mbed TLS v4.1 迁移 +------------------- + +引导加载程序支持 +~~~~~~~~~~~~~~~~~~ + +- 从 Mbed TLS 4.1 开始,已移除对旧版 NISTP192 的支持。 diff --git a/docs/zh_CN/security/secure-boot-v2.rst b/docs/zh_CN/security/secure-boot-v2.rst index ee049884af5..52d9c1d5a44 100644 --- a/docs/zh_CN/security/secure-boot-v2.rst +++ b/docs/zh_CN/security/secure-boot-v2.rst @@ -76,7 +76,6 @@ 2. 二级引导加载程序加载特定应用程序镜像,并验证应用程序的 {IDF_TARGET_SBV2_SCHEME} 签名。若验证通过,则执行应用程序镜像。 - 优势 ---- @@ -273,7 +272,7 @@ - 仅针对镜像内容的 SHA-256 哈希值,不包括签名块。 * - 36 - 1 - - 曲线 ID。2 代表 NIST256p 曲线。 + - 曲线 ID。2 表示 NIST256p 曲线。 * - 37 - 64 - ECDSA 公钥:32 字节的 X 坐标,后跟 32 字节的 Y 坐标。 @@ -529,7 +528,6 @@ Secure Boot v2 签名验证也可以在 OTA 更新期间验证数据分区镜像 - 一旦启用安全启动,就无法再对 eFuse 密钥进行读保护,这可以避免攻击者对存储公共密钥摘要的 eFuse 块进行读保护,进而导致系统无法验证和处理签名,系统服务无法正常运行。有关读保护密钥的更多信息,请参阅下方详细说明。 - 烧录读保护密钥 ~~~~~~~~~~~~~~ @@ -613,7 +611,6 @@ Secure Boot v2 签名验证也可以在 OTA 更新期间验证数据分区镜像 注意,安全启动系统的强度取决于能否保持签名密钥的私密性。 - .. _remote-sign-v2-image: 远程镜像签名