fix(wpa_supplicant): Only use fastpsk/fastpbkdf2 when hw available

This commit is contained in:
Kapil Gupta
2026-04-23 12:23:47 +05:30
parent a39e3035cf
commit e372a52e8f
3 changed files with 64 additions and 24 deletions
+12 -7
View File
@@ -118,8 +118,12 @@ if(CONFIG_ESP_WIFI_MBEDTLS_CRYPTO)
"esp_supplicant/src/crypto/crypto_mbedtls-bignum.c"
"esp_supplicant/src/crypto/crypto_mbedtls-rsa.c"
"esp_supplicant/src/crypto/crypto_mbedtls-ec.c")
if(NOT CONFIG_IDF_TARGET_ESP32 AND NOT CONFIG_IDF_TARGET_ESP32S31) # TDOD IDF-14630
list(APPEND crypto_src "esp_supplicant/src/crypto/fastpsk.c")
if(CONFIG_MBEDTLS_HARDWARE_SHA)
if(NOT CONFIG_SOC_SHA_SUPPORT_PARALLEL_ENG)
list(APPEND crypto_src "esp_supplicant/src/crypto/fastpsk.c")
else()
list(APPEND crypto_src "esp_supplicant/src/crypto/fastpbkdf2.c")
endif()
endif()
# Add internal RC4 as RC4 has been removed from mbedtls
set(crypto_src ${crypto_src} "src/crypto/rc4.c")
@@ -130,9 +134,6 @@ if(CONFIG_ESP_WIFI_MBEDTLS_CRYPTO)
set(crypto_src ${crypto_src} "src/crypto/sha1-pbkdf2.c"
${crypto_src} "src/crypto/sha1.c"
${crypto_src} "src/crypto/sha1-internal.c")
elseif(NOT CONFIG_IDF_TARGET_ESP32S31)
#TDOD IDF-14630: use mbedtls_pkcs5_pbkdf2_hmac (software) instead of fastpbkdf2.
set(crypto_src ${crypto_src} "esp_supplicant/src/crypto/fastpbkdf2.c")
endif()
if(NOT CONFIG_MBEDTLS_SHA1_C AND CONFIG_MBEDTLS_HARDWARE_SHA)
set(crypto_src ${crypto_src} "src/crypto/sha1.c")
@@ -282,8 +283,12 @@ target_compile_definitions(${COMPONENT_LIB} PRIVATE
CONFIG_NO_RADIUS
)
if((CONFIG_MBEDTLS_SHA1_C OR CONFIG_MBEDTLS_HARDWARE_SHA) AND NOT CONFIG_IDF_TARGET_ESP32S31) # TDOD IDF-14630
target_compile_definitions(${COMPONENT_LIB} PRIVATE CONFIG_FAST_PBKDF2)
if(CONFIG_MBEDTLS_HARDWARE_SHA)
if(NOT CONFIG_SOC_SHA_SUPPORT_PARALLEL_ENG)
target_compile_definitions(${COMPONENT_LIB} PRIVATE CONFIG_FAST_PSK)
else()
target_compile_definitions(${COMPONENT_LIB} PRIVATE CONFIG_FAST_PBKDF2)
endif()
endif()
if(CONFIG_ESP_WIFI_ENABLE_WPA3_SAE)
@@ -30,16 +30,17 @@
#include "aes_wrap.h"
#include "crypto.h"
#include "mbedtls/esp_config.h"
#include "mbedtls/private/pkcs5.h"
#include "psa/crypto.h"
#include "mbedtls/psa_util.h"
#define WPA_HEX_ERR(err) ((err) < 0 ? "-" : ""), (unsigned int) ((err) < 0 ? -(err) : (err))
#ifdef CONFIG_FAST_PSK
#include "fastpsk.h"
#endif
#ifdef CONFIG_FAST_PBKDF2
#include "fastpbkdf2.h"
#include "fastpsk.h"
#endif
struct crypto_hash {
@@ -1058,26 +1059,60 @@ cleanup:
return ret;
}
#ifdef CONFIG_TLS_INTERNAL_CLIENT
static int pbkdf2_sha1_psa(const char *passphrase, const u8 *ssid, size_t ssid_len,
int iterations, u8 *buf, size_t buflen)
{
psa_key_derivation_operation_t op = PSA_KEY_DERIVATION_OPERATION_INIT;
psa_status_t status;
status = psa_key_derivation_setup(&op, PSA_ALG_PBKDF2_HMAC(PSA_ALG_SHA_1));
if (status != PSA_SUCCESS) {
goto cleanup;
}
status = psa_key_derivation_input_integer(&op, PSA_KEY_DERIVATION_INPUT_COST, iterations);
if (status != PSA_SUCCESS) {
goto cleanup;
}
status = psa_key_derivation_input_bytes(&op, PSA_KEY_DERIVATION_INPUT_SALT, ssid, ssid_len);
if (status != PSA_SUCCESS) {
goto cleanup;
}
status = psa_key_derivation_input_bytes(&op, PSA_KEY_DERIVATION_INPUT_PASSWORD,
(const u8 *) passphrase, os_strlen(passphrase));
if (status != PSA_SUCCESS) {
goto cleanup;
}
status = psa_key_derivation_output_bytes(&op, buf, buflen);
cleanup:
psa_key_derivation_abort(&op);
return status == PSA_SUCCESS ? 0 : -1;
}
#endif
#if defined(CONFIG_MBEDTLS_SHA1_C) || defined(CONFIG_MBEDTLS_HARDWARE_SHA)
int pbkdf2_sha1(const char *passphrase, const u8 *ssid, size_t ssid_len,
int iterations, u8 *buf, size_t buflen)
{
#ifdef CONFIG_FAST_PBKDF2
/* For ESP32: Using pbkdf2_hmac_sha1() because esp_fast_psk() utilizes hardware,
* but for ESP32, the SHA1 hardware implementation is slower than the software implementation.
*/
#if defined(CONFIG_IDF_TARGET_ESP32) || !defined(CONFIG_SOC_SHA_SUPPORTED)
fastpbkdf2_hmac_sha1((const u8 *) passphrase, os_strlen(passphrase),
ssid, ssid_len, iterations, buf, buflen);
return 0;
#else
return esp_fast_psk(passphrase, os_strlen(passphrase), ssid, ssid_len, iterations, buf, buflen);
if (ssid_len <= 32 && os_strlen(passphrase) <= 63 &&
iterations == 4096 && buflen == 32) {
#if defined(CONFIG_FAST_PSK)
return esp_fast_psk(passphrase, os_strlen(passphrase), ssid, ssid_len, iterations, buf, buflen);
#elif defined(CONFIG_FAST_PBKDF2)
fastpbkdf2_hmac_sha1((const u8 *) passphrase, os_strlen(passphrase),
ssid, ssid_len, iterations, buf, buflen);
return 0;
#endif
}
#ifdef CONFIG_TLS_INTERNAL_CLIENT
return pbkdf2_sha1_psa(passphrase, ssid, ssid_len, iterations, buf, buflen);
#else
int ret = mbedtls_pkcs5_pbkdf2_hmac_ext(MBEDTLS_MD_SHA1, (const u8 *) passphrase,
os_strlen(passphrase), ssid,
ssid_len, iterations, buflen, buf);
return ret == 0 ? 0 : -1;
return -1;
#endif
}
#endif /* defined(CONFIG_MBEDTLS_SHA1_C) || defined(CONFIG_MBEDTLS_HARDWARE_SHA) */
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2023-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2023-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Unlicense OR CC0-1.0
*/