Merge branch 'feat/esp_tee_hmac_ds_prot' into 'master'

feat(esp_tee): Protect the HMAC, DS and ECC peripherals from REE access

See merge request espressif/esp-idf!38285
This commit is contained in:
Laukik Hase
2025-04-17 13:20:54 +08:00
24 changed files with 620 additions and 195 deletions
+12 -2
View File
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2020-2024 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2020-2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -14,6 +14,8 @@
#ifdef SOC_DIG_SIGN_SUPPORTED
#include "rom/digital_signature.h"
#ifdef __cplusplus
extern "C" {
#endif
@@ -38,7 +40,15 @@ extern "C" {
+ ESP_DS_SIGNATURE_L_BIT_LEN \
+ ESP_DS_SIGNATURE_PADDING_BIT_LEN) / 8))
typedef struct esp_ds_context esp_ds_context_t;
/**
* @brief Context object used for non-blocking digital signature operations
*
* This object is allocated by \c esp_ds_start_sign() and must be passed to
* \c esp_ds_finish_sign() to complete the digital signature operation.
*/
typedef struct esp_ds_context {
const ets_ds_data_t *data; /*!< Pointer to the encrypted private key data */
} esp_ds_context_t;
typedef enum {
ESP_DS_RSA_1024 = (1024 / 32) - 1,