feat(hal): add ECDSA low-level driver for esp32s31

Co-authored-by: Nilesh Kale <nilesh.kale@espressif.com>
This commit is contained in:
Aditya Patwardhan
2026-05-20 10:17:34 +05:30
committed by nilesh.kale
co-authored by Nilesh Kale
parent e9a9091b59
commit e1d429ba30
10 changed files with 540 additions and 32 deletions
@@ -77,9 +77,9 @@ This contains tests for the following features of the crypto peripherals:
The HMAC tests need an HMAC key to be burned in the `BLOCK_KEY4` and `BLOCK_KEY5` of the efuses. As this verification application is independent of the efuse component, the user needs to manually burn the keys and their key purposes using `espefuse`.
```bash
espefuse -p $ESPPORT burn-key BLOCK_KEY4 main/hmac/hmac_key.bin HMAC_DOWN_JTAG
espefuse -p $ESPPORT burn-key BLOCK_KEY3 main/hmac/hmac_key.bin HMAC_DOWN_JTAG
espefuse -p $ESPPORT burn-key BLOCK_KEY5 main/hmac/hmac_key.bin HMAC_UP
espefuse -p $ESPPORT burn-key BLOCK_KEY4 main/hmac/hmac_key.bin HMAC_UP
```
# Burning the HMAC keys for Digital Signature tests
@@ -108,12 +108,25 @@ espefuse -p $ESPPORT burn-key BLOCK_KEY2 main/ds/keys/4096/ds_key3.bin HMAC_DOWN
By default, ECDSA tests are disabled. You can enable it after disabling HMAC & DS tests using `idf.py menuconfig -> Test App Configuration -> Enable ECDSA Peripheral test cases`
The ECDSA tests need some ECDSA keys to be burned in the `BLOCK_KEY3` and `BLOCK_KEY4` of the efuses. As this verification application is independent of the efuse component, the user needs to manually burn the keys and their key purposes using `espefuse`.
The ECDSA tests need ECDSA private keys burned in efuse key blocks. This application does not use the efuse component, so you must burn the keys and their key purposes manually with `espefuse`.
**When curve-specific key purposes are supported** (e.g. chips with `SOC_ECDSA_SUPPORT_CURVE_SPECIFIC_KEY_PURPOSES`):
```bash
espefuse -p $ESPPORT burn-key BLOCK_KEY3 main/ecdsa/ecdsa192_priv_key.pem ECDSA_KEY
espefuse -p $ESPPORT burn-key BLOCK_KEY0 main/ecdsa/ecdsa192_priv_key.pem ECDSA_KEY_P192
espefuse -p $ESPPORT burn-key BLOCK_KEY4 main/ecdsa/ecdsa256_priv_key.pem ECDSA_KEY
espefuse -p $ESPPORT burn-key BLOCK_KEY1 main/ecdsa/ecdsa256_priv_key.pem ECDSA_KEY_P256
espefuse -p $ESPPORT burn-key BLOCK_KEY2 main/ecdsa/ecdsa384_priv_key.pem ECDSA_KEY_P384
```
The ECDSA-P384 key will be burned in two parts, with the lower portion programmed into BLOCK_KEY2 using the key purpose ECDSA_KEY_P384_L and the upper portion programmed into the next available eFuse block using the key purpose ECDSA_KEY_P384_H.
**When curve-specific key purposes are not supported**
```bash
espefuse -p $ESPPORT burn-key BLOCK_KEY0 main/ecdsa/ecdsa192_priv_key.pem ECDSA_KEY
espefuse -p $ESPPORT burn-key BLOCK_KEY1 main/ecdsa/ecdsa256_priv_key.pem ECDSA_KEY
```
# Burning the XTS-AES key
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2023-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2023-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Unlicense OR CC0-1.0
*/
@@ -11,12 +11,8 @@
#define DS_KEY_BLOCK_3 2
// efuse key blocks for HMAC
#define HMAC_KEY_BLOCK_1 4
#if CONFIG_IDF_TARGET_ESP32S31
#define HMAC_KEY_BLOCK_2 3 // S31 has only KEY0-KEY4, KEY3 is free
#else
#define HMAC_KEY_BLOCK_2 5
#endif
#define HMAC_KEY_BLOCK_1 3
#define HMAC_KEY_BLOCK_2 4
/*
* ECDSA and other peripheral testcases cannot run together as block used for burning keys are overlapped