feat(mbedtls): migrates ESP-TEE with PSA APIs

This commit is contained in:
Ashish Sharma
2025-12-19 07:28:33 +08:00
parent c47caf4f0a
commit f306dbea84
175 changed files with 4213 additions and 2038 deletions
@@ -5,15 +5,85 @@
*/
#include "esp_log.h"
#include "esp_secure_boot.h"
#include "mbedtls/pk.h"
#include "psa/crypto.h"
#include "mbedtls/pk.h"
#include "mbedtls/rsa.h"
#include "mbedtls/asn1.h"
#include "mbedtls/asn1write.h"
#include "secure_boot_signature_priv.h"
ESP_LOG_ATTR_TAG(TAG, "secure_boot_v2_rsa");
/*
* Helper function to encode RSA public key (N, e) into DER format manually
* This creates a PKCS#1 RSAPublicKey structure:
*
* RSAPublicKey ::= SEQUENCE {
* modulus INTEGER, -- n
* publicExponent INTEGER -- e
* }
*/
static int encode_rsa_pubkey_der(const uint8_t *modulus, size_t modulus_len,
const uint8_t *exponent, size_t exponent_len,
uint8_t *der_buf, size_t der_buf_size,
uint8_t **der_start, size_t *der_len)
{
if (!der_buf || !der_start || !der_len || der_buf_size == 0) {
return -1;
}
int ret;
unsigned char *c = der_buf + der_buf_size;
size_t len = 0;
/* Write the exponent (e) as an INTEGER */
/* Skip leading zeros in exponent */
while (exponent_len > 0 && *exponent == 0) {
exponent++;
exponent_len--;
}
/* Write exponent */
MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_raw_buffer(&c, der_buf, exponent, exponent_len));
/* Add padding byte if MSB is set (to keep it positive) */
if (exponent_len > 0 && (exponent[0] & 0x80)) {
MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_raw_buffer(&c, der_buf, (const unsigned char *)"\x00", 1));
}
MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_len(&c, der_buf, exponent_len + ((exponent[0] & 0x80) ? 1 : 0)));
MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_tag(&c, der_buf, MBEDTLS_ASN1_INTEGER));
/* Write the modulus (N) as an INTEGER */
/* Skip leading zeros in modulus */
const uint8_t *mod_ptr = modulus;
size_t mod_len = modulus_len;
while (mod_len > 0 && *mod_ptr == 0) {
mod_ptr++;
mod_len--;
}
/* Write modulus */
MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_raw_buffer(&c, der_buf, mod_ptr, mod_len));
/* Add padding byte if MSB is set */
if (mod_len > 0 && (mod_ptr[0] & 0x80)) {
MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_raw_buffer(&c, der_buf, (const unsigned char *)"\x00", 1));
}
MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_len(&c, der_buf, mod_len + ((mod_ptr[0] & 0x80) ? 1 : 0)));
MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_tag(&c, der_buf, MBEDTLS_ASN1_INTEGER));
/* Write SEQUENCE header */
MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_len(&c, der_buf, len));
MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_tag(&c, der_buf,
MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE));
*der_start = c;
*der_len = len;
return 0;
}
esp_err_t verify_rsa_signature_block(const ets_secure_boot_signature_t *sig_block, const uint8_t *image_digest, const ets_secure_boot_sig_block_t *trusted_block)
{
if (!sig_block || !image_digest || !trusted_block) {
@@ -23,8 +93,10 @@ esp_err_t verify_rsa_signature_block(const ets_secure_boot_signature_t *sig_bloc
esp_err_t ret = ESP_OK;
psa_status_t status;
const unsigned rsa_key_size = sizeof(sig_block->block[0].signature);
unsigned char *sig_be = calloc(1, rsa_key_size);
unsigned char *sig_be = NULL;
unsigned char *pubkey_der_buf = NULL;
sig_be = calloc(1, rsa_key_size);
if (sig_be == NULL) {
return ESP_ERR_NO_MEM;
}
@@ -33,41 +105,47 @@ esp_err_t verify_rsa_signature_block(const ets_secure_boot_signature_t *sig_bloc
psa_key_attributes_t key_attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_id_t key_id = 0;
/* Prepare the RSA public key data */
const mbedtls_mpi N = { .MBEDTLS_PRIVATE(s) = 1,
.MBEDTLS_PRIVATE(n) = sizeof(trusted_block->key.n)/sizeof(mbedtls_mpi_uint),
.MBEDTLS_PRIVATE(p) = (void *)trusted_block->key.n,
};
const mbedtls_mpi e = { .MBEDTLS_PRIVATE(s) = 1,
.MBEDTLS_PRIVATE(n) = sizeof(trusted_block->key.e)/sizeof(mbedtls_mpi_uint), // 1
.MBEDTLS_PRIVATE(p) = (void *)&trusted_block->key.e,
};
mbedtls_pk_context pk;
mbedtls_pk_init(&pk);
mbedtls_pk_setup(&pk, mbedtls_pk_info_from_type(MBEDTLS_PK_RSA));
mbedtls_rsa_context *rsa = mbedtls_pk_rsa(pk);
ret = mbedtls_rsa_import(rsa, &N, NULL, NULL, NULL, &e);
if (ret != 0) {
ESP_LOGE(TAG, "Failed to import RSA public key, err: %d", ret);
mbedtls_pk_free(&pk);
goto cleanup;
}
ret = mbedtls_rsa_complete(rsa);
if (ret != 0) {
ESP_LOGE(TAG, "Failed to complete RSA context, err: %d", ret);
mbedtls_pk_free(&pk);
goto cleanup;
/* Allocate buffer for DER-encoded public key */
size_t pubkey_der_buf_size = PSA_KEY_EXPORT_RSA_PUBLIC_KEY_MAX_SIZE(3072);
pubkey_der_buf = calloc(1, pubkey_der_buf_size);
if (pubkey_der_buf == NULL) {
free(sig_be);
return ESP_ERR_NO_MEM;
}
// Load the public key into PSA
ret = mbedtls_pk_get_psa_attributes(&pk, PSA_KEY_USAGE_VERIFY_HASH, &key_attributes);
/* Convert raw N and e to DER format manually */
uint8_t *der_start = NULL;
size_t der_len = 0;
/* Convert modulus from little-endian to big-endian */
uint8_t *n_be = calloc(1, rsa_key_size);
if (n_be == NULL) {
free(sig_be);
free(pubkey_der_buf);
return ESP_ERR_NO_MEM;
}
for (size_t i = 0; i < rsa_key_size; i++) {
n_be[i] = trusted_block->key.n[rsa_key_size - 1 - i];
}
/* Convert e from uint32_t to byte array (big-endian) */
uint8_t e_bytes[4];
e_bytes[0] = (trusted_block->key.e >> 24) & 0xFF;
e_bytes[1] = (trusted_block->key.e >> 16) & 0xFF;
e_bytes[2] = (trusted_block->key.e >> 8) & 0xFF;
e_bytes[3] = trusted_block->key.e & 0xFF;
ret = encode_rsa_pubkey_der(
n_be, rsa_key_size,
e_bytes, sizeof(e_bytes),
pubkey_der_buf, pubkey_der_buf_size,
&der_start, &der_len
);
free(n_be);
if (ret != 0) {
ESP_LOGE(TAG, "Failed to get key attributes, err: %d", ret);
mbedtls_pk_free(&pk);
ESP_LOGE(TAG, "Failed to encode RSA public key to DER, err: %d", ret);
goto cleanup;
}
@@ -76,16 +154,14 @@ esp_err_t verify_rsa_signature_block(const ets_secure_boot_signature_t *sig_bloc
psa_set_key_algorithm(&key_attributes, PSA_ALG_RSA_PSS(PSA_ALG_SHA_256));
psa_set_key_type(&key_attributes, PSA_KEY_TYPE_RSA_PUBLIC_KEY);
ret = mbedtls_pk_import_into_psa(&pk, &key_attributes, &key_id);
if (ret != 0) {
ESP_LOGE(TAG, "Failed to import key into PSA, err: %d", ret);
mbedtls_pk_free(&pk);
/* Import DER-encoded public key into PSA */
status = psa_import_key(&key_attributes, der_start, der_len, &key_id);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "Failed to import key into PSA, err: %d", status);
ret = ESP_FAIL;
goto cleanup;
}
mbedtls_rsa_free(rsa);
mbedtls_pk_free(&pk);
/* Signature needs to be byte swapped into BE representation */
for (int j = 0; j < rsa_key_size; j++) {
sig_be[rsa_key_size - j - 1] = trusted_block->signature[j];
@@ -111,6 +187,7 @@ cleanup:
}
psa_reset_key_attributes(&key_attributes);
free(sig_be);
free(pubkey_der_buf);
return ret;
}
@@ -1,4 +1,4 @@
idf_component_register(SRCS "test_app_main.c" "test_verify_image.c"
INCLUDE_DIRS "."
REQUIRES unity bootloader_support esp_partition app_update
REQUIRES unity bootloader_support esp_partition app_update mbedtls
WHOLE_ARCHIVE)
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2021-2022 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -21,6 +21,9 @@
#include "esp_partition.h"
#include "esp_ota_ops.h"
#include "esp_image_format.h"
#include "psa/crypto.h"
#include "mbedtls/asn1.h"
#include "mbedtls/asn1write.h"
TEST_CASE("Verify bootloader image in flash", "[bootloader_support]")
{
+3 -5
View File
@@ -1443,13 +1443,11 @@ uint8_t esp_ble_get_chip_rev_version(void)
#if (!CONFIG_BT_NIMBLE_ENABLED) && (CONFIG_BT_CONTROLLER_ENABLED)
#if CONFIG_BT_LE_SM_LEGACY || CONFIG_BT_LE_SM_SC
#define BLE_SM_KEY_ERR 0x17
#define BLE_PUB_KEY_LEN 65
#if CONFIG_BT_LE_CRYPTO_STACK_MBEDTLS
#if CONFIG_BT_LE_SM_SC
#include "psa/crypto.h"
#define BLE_PUB_KEY_LEN 65
#endif // CONFIG_BT_LE_SM_SC
#else
#include "tinycrypt/aes.h"
#include "tinycrypt/constants.h"
@@ -1590,7 +1588,7 @@ exit:
#endif // CONFIG_BT_LE_CRYPTO_STACK_MBEDTLS
/**
* pub: 64 bytes
* pub: BLE_PUB_KEY_LEN bytes
* priv: 32 bytes
*/
int ble_sm_alg_gen_key_pair(uint8_t *pub, uint8_t *priv)
@@ -1600,7 +1598,7 @@ int ble_sm_alg_gen_key_pair(uint8_t *pub, uint8_t *priv)
swap_buf(&pub[32], &ble_sm_alg_dbg_pub_key[32], 32);
swap_buf(priv, ble_sm_alg_dbg_priv_key, 32);
#else
uint8_t pk[64];
uint8_t pk[BLE_PUB_KEY_LEN];
do {
#if CONFIG_BT_LE_CRYPTO_STACK_MBEDTLS
+1 -3
View File
@@ -1585,13 +1585,11 @@ void esp_ble_controller_log_dump_all(bool output)
#if (!CONFIG_BT_NIMBLE_ENABLED) && (CONFIG_BT_CONTROLLER_ENABLED)
#if CONFIG_BT_LE_SM_LEGACY || CONFIG_BT_LE_SM_SC
#define BLE_SM_KEY_ERR 0x17
#define BLE_PUB_KEY_LEN 65
#if CONFIG_BT_LE_CRYPTO_STACK_MBEDTLS
#if CONFIG_BT_LE_SM_SC
#include "psa/crypto.h"
#define BLE_PUB_KEY_LEN 65
#endif // CONFIG_BT_LE_SM_SC
#else
#include "tinycrypt/aes.h"
#include "tinycrypt/constants.h"
+1 -4
View File
@@ -1655,18 +1655,15 @@ void esp_ble_controller_log_dump_all(bool output)
#if (!CONFIG_BT_NIMBLE_ENABLED) && (CONFIG_BT_CONTROLLER_ENABLED)
#if CONFIG_BT_LE_SM_LEGACY || CONFIG_BT_LE_SM_SC
#define BLE_SM_KEY_ERR 0x17
#define BLE_PUB_KEY_LEN 65
#if CONFIG_BT_LE_CRYPTO_STACK_MBEDTLS
#if CONFIG_BT_LE_SM_SC
#include "psa/crypto.h"
#define BLE_PUB_KEY_LEN 65
#endif // CONFIG_BT_LE_SM_SC
#else
#include "tinycrypt/aes.h"
#include "tinycrypt/constants.h"
#include "tinycrypt/utils.h"
#if CONFIG_BT_LE_SM_SC
#include "tinycrypt/cmac_mode.h"
#include "tinycrypt/ecc_dh.h"
+3 -5
View File
@@ -1605,14 +1605,12 @@ void esp_ble_controller_log_dump_all(bool output)
#if (!CONFIG_BT_NIMBLE_ENABLED) && (CONFIG_BT_CONTROLLER_ENABLED)
#if CONFIG_BT_LE_SM_LEGACY || CONFIG_BT_LE_SM_SC
#define BLE_SM_KEY_ERR 0x17
#define BLE_PUB_KEY_LEN 65
#if CONFIG_BT_LE_CRYPTO_STACK_MBEDTLS
#include "mbedtls/aes.h"
// #include "mbedtls/aes.h"
#if CONFIG_BT_LE_SM_SC
#include "psa/crypto.h"
#define BLE_PUB_KEY_LEN 65
#endif // CONFIG_BT_LE_SM_SC
#else
#include "tinycrypt/aes.h"
#include "tinycrypt/constants.h"
@@ -1762,7 +1760,7 @@ int ble_sm_alg_gen_key_pair(uint8_t *pub, uint8_t *priv)
swap_buf(&pub[32], &ble_sm_alg_dbg_pub_key[32], 32);
swap_buf(priv, ble_sm_alg_dbg_priv_key, 32);
#else
uint8_t pk[64];
uint8_t pk[BLE_PUB_KEY_LEN];
do {
#if CONFIG_BT_LE_CRYPTO_STACK_MBEDTLS
+2 -4
View File
@@ -26,8 +26,8 @@ menu "ESP-TLS"
config ESP_TLS_USE_DS_PERIPHERAL
bool "Use Digital Signature (DS) Peripheral with ESP-TLS"
depends on ESP_TLS_USING_MBEDTLS && SOC_DIG_SIGN_SUPPORTED && MBEDTLS_PK_RSA_ALT_SUPPORT
default y
depends on ESP_TLS_USING_MBEDTLS && SOC_DIG_SIGN_SUPPORTED
default n
help
Enable use of the Digital Signature Peripheral for ESP-TLS.The DS peripheral
can only be used when it is appropriately configured for TLS.
@@ -76,9 +76,7 @@ menu "ESP-TLS"
bool "Enable PSK verification"
select MBEDTLS_PSK_MODES if ESP_TLS_USING_MBEDTLS
select MBEDTLS_KEY_EXCHANGE_PSK if ESP_TLS_USING_MBEDTLS
select MBEDTLS_KEY_EXCHANGE_DHE_PSK if ESP_TLS_USING_MBEDTLS && MBEDTLS_DHM_C
select MBEDTLS_KEY_EXCHANGE_ECDHE_PSK if ESP_TLS_USING_MBEDTLS && MBEDTLS_ECDH_C
select MBEDTLS_KEY_EXCHANGE_RSA_PSK if ESP_TLS_USING_MBEDTLS
help
Enable support for pre shared key ciphers, supported for both mbedTLS as well as
wolfSSL TLS library.
+6 -6
View File
@@ -15,8 +15,8 @@
#include "mbedtls/x509_crt.h"
#ifdef CONFIG_ESP_TLS_SERVER_SESSION_TICKETS
#include "mbedtls/ssl_ticket.h"
#include "mbedtls/entropy.h"
#include "mbedtls/ctr_drbg.h"
// #include "mbedtls/entropy.h"
// #include "mbedtls/ctr_drbg.h"
#endif
#elif CONFIG_ESP_TLS_USING_WOLFSSL
#include "wolfssl/wolfcrypt/settings.h"
@@ -246,11 +246,11 @@ typedef struct esp_tls_cfg {
* @brief Data structures necessary to support TLS session tickets according to RFC5077
*/
typedef struct esp_tls_server_session_ticket_ctx {
mbedtls_entropy_context entropy; /*!< mbedTLS entropy context structure */
// mbedtls_entropy_context entropy; /*!< mbedTLS entropy context structure */
mbedtls_ctr_drbg_context ctr_drbg; /*!< mbedTLS ctr drbg context structure.
CTR_DRBG is deterministic random
bit generation based on AES-256 */
// mbedtls_ctr_drbg_context ctr_drbg; /*!< mbedTLS ctr drbg context structure.
// CTR_DRBG is deterministic random
// bit generation based on AES-256 */
mbedtls_ssl_ticket_context ticket_ctx; /*!< Session ticket generation context */
} esp_tls_server_session_ticket_ctx_t;
#endif
+68 -19
View File
@@ -488,23 +488,49 @@ void esp_mbedtls_cleanup(esp_tls_t *tls)
mbedtls_x509_crt_free(&tls->clientcert);
#ifdef CONFIG_ESP_TLS_USE_DS_PERIPHERAL
if (mbedtls_pk_get_type(&tls->clientkey) == MBEDTLS_PK_RSA_ALT) {
mbedtls_rsa_alt_context *rsa_alt = tls->clientkey.MBEDTLS_PRIVATE(pk_ctx);
if (rsa_alt && rsa_alt->key != NULL) {
mbedtls_rsa_free(rsa_alt->key);
mbedtls_free(rsa_alt->key);
rsa_alt->key = NULL;
if (mbedtls_pk_get_type(&tls->clientkey) == MBEDTLS_PK_RSASSA_PSS) {
mbedtls_rsa_context *rsa = tls->clientkey.MBEDTLS_PRIVATE(pk_ctx);
if (rsa != NULL) {
mbedtls_rsa_free(rsa);
mbedtls_free(rsa);
rsa = NULL;
}
tls->clientkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
}
// Similar cleanup for server key
if (mbedtls_pk_get_type(&tls->serverkey) == MBEDTLS_PK_RSA_ALT) {
mbedtls_rsa_alt_context *rsa_alt = tls->serverkey.MBEDTLS_PRIVATE(pk_ctx);
if (rsa_alt && rsa_alt->key != NULL) {
mbedtls_rsa_free(rsa_alt->key);
mbedtls_free(rsa_alt->key);
rsa_alt->key = NULL;
if (mbedtls_pk_get_type(&tls->serverkey) == MBEDTLS_PK_RSASSA_PSS) {
mbedtls_rsa_context *rsa = tls->serverkey.MBEDTLS_PRIVATE(pk_ctx);
if (rsa != NULL) {
mbedtls_rsa_free(rsa);
mbedtls_free(rsa);
rsa = NULL;
}
tls->serverkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
}
#endif
#ifdef CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN
/* In mbedtls v4.0, ECDSA keys require manual cleanup of the keypair structure */
if (mbedtls_pk_get_type(&tls->clientkey) == MBEDTLS_PK_ECDSA) {
mbedtls_ecp_keypair *keypair = tls->clientkey.MBEDTLS_PRIVATE(pk_ctx);
if (keypair != NULL) {
mbedtls_ecp_keypair_free(keypair);
mbedtls_free(keypair);
keypair = NULL;
}
tls->clientkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
}
// Similar cleanup for server key
if (mbedtls_pk_get_type(&tls->serverkey) == MBEDTLS_PK_ECDSA) {
mbedtls_ecp_keypair *keypair = tls->serverkey.MBEDTLS_PRIVATE(pk_ctx);
if (keypair != NULL) {
mbedtls_ecp_keypair_free(keypair);
mbedtls_free(keypair);
keypair = NULL;
}
tls->serverkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
}
#endif
@@ -1347,6 +1373,13 @@ static esp_err_t esp_set_atecc608a_pki_context(esp_tls_t *tls, const void *pki)
#endif /* CONFIG_ESP_TLS_USE_SECURE_ELEMENT */
#ifdef CONFIG_ESP_TLS_USE_DS_PERIPHERAL
int esp_mbedtls_ds_can_do(mbedtls_pk_type_t type)
{
ESP_LOGI(TAG, "esp_mbedtls_ds_can_do called with type %d", type);
return type == MBEDTLS_PK_RSA || type == MBEDTLS_PK_RSASSA_PSS;
}
static esp_err_t esp_mbedtls_init_pk_ctx_for_ds(const void *pki)
{
int ret = -1;
@@ -1357,15 +1390,31 @@ static esp_err_t esp_mbedtls_init_pk_ctx_for_ds(const void *pki)
return ESP_ERR_NO_MEM;
}
mbedtls_rsa_init(rsakey);
if ((ret = mbedtls_pk_setup_rsa_alt(((const esp_tls_pki_t*)pki)->pk_key, rsakey, NULL, esp_ds_rsa_sign,
esp_ds_get_keylen )) != 0) {
ESP_LOGE(TAG, "Error in mbedtls_pk_setup_rsa_alt, returned -0x%04X", -ret);
mbedtls_print_error_msg(ret);
mbedtls_rsa_free(rsakey);
free(rsakey);
ret = ESP_FAIL;
esp_tls_pki_t *pki_l = (esp_tls_pki_t *) pki;
mbedtls_pk_context *pk_context = (mbedtls_pk_context *) pki_l->pk_key;
// const mbedtls_pk_info_t *pk_info = mbedtls_pk_info_from_type(MBEDTLS_PK_RSA);
mbedtls_pk_info_t *esp_ds_pk_info = calloc(1, sizeof(mbedtls_pk_info_t));
if (esp_ds_pk_info == NULL) {
ESP_LOGE(TAG, "Failed to allocate memory for mbedtls_pk_info_t");
ret = ESP_ERR_NO_MEM;
goto exit;
}
esp_ds_pk_info->sign_func = esp_ds_rsa_sign_alt;
esp_ds_pk_info->get_bitlen = esp_ds_get_keylen_alt;
esp_ds_pk_info->can_do = esp_mbedtls_ds_can_do;
esp_ds_pk_info->type = MBEDTLS_PK_RSASSA_PSS;
pk_context->pk_info = esp_ds_pk_info;
pk_context->pk_ctx = rsakey;
// if ((ret = mbedtls_pk_setup_rsa_alt(((const esp_tls_pki_t*)pki)->pk_key, rsakey, NULL, esp_ds_rsa_sign,
// esp_ds_get_keylen )) != 0) {
// ESP_LOGE(TAG, "Error in mbedtls_pk_setup_rsa_alt, returned -0x%04X", -ret);
// mbedtls_print_error_msg(ret);
// mbedtls_rsa_free(rsakey);
// free(rsakey);
// ret = ESP_FAIL;
// goto exit;
// }
ret = esp_ds_init_data_ctx(((const esp_tls_pki_t*)pki)->esp_ds_data);
if (ret != ESP_OK) {
ESP_LOGE(TAG, "Failed to initialize DS parameters from nvs");
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2021-2023 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -20,8 +20,8 @@
#include "mbedtls/net_sockets.h"
#include "mbedtls/esp_debug.h"
#include "mbedtls/ssl.h"
#include "mbedtls/entropy.h"
#include "mbedtls/ctr_drbg.h"
// #include "mbedtls/entropy.h"
// #include "mbedtls/ctr_drbg.h"
#include "mbedtls/error.h"
#ifdef CONFIG_ESP_TLS_SERVER_SESSION_TICKETS
#include "mbedtls/ssl_ticket.h"
@@ -38,11 +38,11 @@ struct esp_tls {
#ifdef CONFIG_ESP_TLS_USING_MBEDTLS
mbedtls_ssl_context ssl; /*!< TLS/SSL context */
mbedtls_entropy_context entropy; /*!< mbedTLS entropy context structure */
// mbedtls_entropy_context entropy; /*!< mbedTLS entropy context structure */
mbedtls_ctr_drbg_context ctr_drbg; /*!< mbedTLS ctr drbg context structure.
CTR_DRBG is deterministic random
bit generation based on AES-256 */
// mbedtls_ctr_drbg_context ctr_drbg; /*!< mbedTLS ctr drbg context structure.
// CTR_DRBG is deterministic random
// bit generation based on AES-256 */
mbedtls_ssl_config conf; /*!< TLS/SSL configuration to be shared
between mbedtls_ssl_context
+35 -20
View File
@@ -7,7 +7,7 @@
#include "freertos/FreeRTOS.h"
#include "freertos/task.h"
#include "unity.h"
#include "mbedtls/aes.h"
// #include "mbedtls/aes.h"
#include "memory_checks.h"
#include "soc/soc_caps.h"
#if SOC_SHA_SUPPORT_PARALLEL_ENG
@@ -22,30 +22,45 @@
#else
#define SHA_TYPE SHA2_256
#endif //SOC_SHA_SUPPORT_SHA512
#include <string.h>
#define CALL_SZ (32 * 1024)
/* setUp runs before every test */
void setUp(void)
{
// #if SOC_SHA_SUPPORTED
// // Execute esp_sha operation to allocate internal SHA semaphore (in case of ESP32)
// // and initial DMA setup memory which is considered as leaked otherwise
// const uint8_t input_buffer[64] = {0};
// uint8_t output_buffer[64];
// esp_sha(SHA_TYPE, input_buffer, sizeof(input_buffer), output_buffer);
// #endif // SOC_SHA_SUPPORTED
#if SOC_SHA_SUPPORTED
// Execute esp_sha operation to allocate internal SHA semaphore (in case of ESP32)
// and initial DMA setup memory which is considered as leaked otherwise
const uint8_t input_buffer[64] = {0};
uint8_t output_buffer[64];
esp_sha(SHA_TYPE, input_buffer, sizeof(input_buffer), output_buffer);
#endif // SOC_SHA_SUPPORTED
// #if SOC_AES_SUPPORTED
// // Execute mbedtls_aes_init operation to allocate AES interrupt
// // allocation memory which is considered as leak otherwise
// const uint8_t plaintext[16] = {0};
// uint8_t ciphertext[16];
// const uint8_t key[16] = { 0 };
// mbedtls_aes_context ctx;
// mbedtls_aes_init(&ctx);
// mbedtls_aes_setkey_enc(&ctx, key, 128);
// mbedtls_aes_crypt_ecb(&ctx, MBEDTLS_AES_ENCRYPT, plaintext, ciphertext);
// mbedtls_aes_free(&ctx);
// #endif // SOC_AES_SUPPORTED
// Execute mbedtls_aes_init operation to allocate AES interrupt
// allocation memory which is considered as leak otherwise
uint8_t iv[16];
uint8_t key[16];
memset(iv, 0xEE, 16);
memset(key, 0x44, 16);
uint8_t *buf = heap_caps_malloc(CALL_SZ, MALLOC_CAP_DMA | MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL);
TEST_ASSERT_NOT_NULL(buf);
psa_key_id_t key_id;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT);
psa_set_key_algorithm(&attributes, PSA_ALG_ECB_NO_PADDING);
psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
psa_set_key_bits(&attributes, 128);
psa_import_key(&attributes, key, sizeof(key), &key_id);
size_t output_length = 0;
psa_cipher_encrypt(key_id, PSA_ALG_ECB_NO_PADDING, buf, CALL_SZ, buf, CALL_SZ, &output_length);
heap_caps_free(buf);
psa_destroy_key(key_id);
#endif // SOC_AES_SUPPORTED
test_utils_record_free_mem();
TEST_ESP_OK(test_utils_set_leak_level(0, ESP_LEAK_TYPE_CRITICAL, ESP_COMP_LEAK_GENERAL));
@@ -61,7 +76,7 @@ void tearDown(void)
/* clean up some of the newlib's lazy allocations */
esp_reent_cleanup();
mbedtls_psa_crypto_free();
// mbedtls_psa_crypto_free();
/* check if unit test has caused heap corruption in any heap */
TEST_ASSERT_MESSAGE( heap_caps_check_integrity(MALLOC_CAP_INVALID, true), "The test has corrupted the heap");
+3
View File
@@ -79,6 +79,9 @@ SECONDARY: 102: init_rng in components/esp_hw_support/hw_random.c on BIT(0)
# Security specific initializations
SECONDARY: 103: esp_security_init in components/esp_security/src/init.c on BIT(0)
# PSA Crypto initialization (must happen after esp_security_init for hardware crypto support)
SECONDARY: 104: mbedtls_psa_crypto_init_fn in components/mbedtls/port/esp_psa_crypto_init.c on BIT(0)
# esp_sleep doesn't have init dependencies
SECONDARY: 105: esp_sleep_startup_init in components/esp_hw_support/sleep_gpio.c on BIT(0)
SECONDARY: 106: sleep_clock_startup_init in components/esp_hw_support/lowpower/port/esp32c5/sleep_clock.c on BIT(0)
+3 -3
View File
@@ -12,14 +12,14 @@ menu "ESP-TEE (Trusted Execution Environment)"
config SECURE_TEE_IRAM_SIZE
hex "IRAM region size"
default 0x8000
range 0x5000 0xA000
range 0x5000 0xF000
help
This configuration sets the IRAM size for the TEE module.
This should be 256-byte (0x100) aligned.
config SECURE_TEE_DRAM_SIZE
hex "DRAM region size"
default 0x4000
default 0x5000
range 0x3000 0x7000
help
This configuration sets the DRAM size for the TEE module.
@@ -45,7 +45,7 @@ menu "ESP-TEE (Trusted Execution Environment)"
config SECURE_TEE_IROM_SIZE
hex
default 0x10000
default 0x20000
help
This should be a multiple of MMU_PAGE_SIZE.
@@ -14,12 +14,8 @@
#include "bootloader_sha.h"
#include "esp_tee_sec_storage.h"
#endif
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include "esp_random.h"
#include "mbedtls/ecdh.h"
#include "mbedtls/ecdsa.h"
#include "mbedtls/sha256.h"
#include "psa/crypto.h"
#include "esp_attestation_utils.h"
#define ECDSA_PUBKEY_PREFIX_SZ (0x02)
@@ -91,8 +87,8 @@ static esp_err_t get_ecdsa_sign_secp256r1(const esp_att_ecdsa_keypair_t *keypair
return err;
}
memcpy(sign_r, sign.sign_r, sign_r_len);
memcpy(sign_s, sign.sign_s, sign_s_len);
memcpy(sign_r, sign.signature, sign_r_len);
memcpy(sign_s, sign.signature + sign_r_len, sign_s_len);
return ESP_OK;
}
@@ -113,44 +109,34 @@ static esp_err_t gen_ecdsa_keypair_secp256r1(esp_att_ecdsa_keypair_t *keypair)
memset(keypair, 0x00, sizeof(esp_att_ecdsa_keypair_t));
int ret = -1;
esp_err_t err = ESP_FAIL;
mbedtls_ecdsa_context ecdsa_ctx;
mbedtls_ecdsa_init(&ecdsa_ctx);
ret = mbedtls_ecdsa_genkey(&ecdsa_ctx, MBEDTLS_ECP_DP_SECP256R1, rng_func, NULL);
if (ret != 0) {
goto exit;
psa_key_attributes_t key_attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_set_key_type(&key_attributes, PSA_KEY_TYPE_ECC_KEY_PAIR(PSA_ECC_FAMILY_SECP_R1));
psa_set_key_bits(&key_attributes, 256);
psa_set_key_usage_flags(&key_attributes, PSA_KEY_USAGE_SIGN | PSA_KEY_USAGE_VERIFY);
psa_set_key_algorithm(&key_attributes, PSA_ALG_ECDSA);
psa_status_t status = psa_generate_key(&key_attributes, &keypair->key_id);
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
size_t pvt_len = mbedtls_mpi_size(&ecdsa_ctx.MBEDTLS_PRIVATE(d));
ret = mbedtls_mpi_write_binary(&ecdsa_ctx.MBEDTLS_PRIVATE(d), (unsigned char *)keypair->pvt_key, pvt_len);
if (ret != 0) {
goto exit;
size_t pub_key_len = 0;
uint8_t pub_key[2 * SECP256R1_ECDSA_KEY_LEN + 1] = {0};
status = psa_export_public_key(keypair->key_id, pub_key, sizeof(pub_key), &pub_key_len);
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
size_t pubx_len = mbedtls_mpi_size(&(ecdsa_ctx.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(X)));
ret = mbedtls_mpi_write_binary(&(ecdsa_ctx.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(X)), (unsigned char *)(keypair->pub_key_x), pubx_len);
if (ret != 0) {
goto exit;
if (pub_key_len != sizeof(pub_key)) {
return ESP_ERR_INVALID_SIZE;
}
size_t puby_len = mbedtls_mpi_size(&(ecdsa_ctx.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Y)));
ret = mbedtls_mpi_write_binary(&(ecdsa_ctx.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Y)), (unsigned char *)(keypair->pub_key_y), puby_len);
if (ret != 0) {
goto exit;
}
memcpy(keypair->pub_key_x, pub_key + 1, SECP256R1_ECDSA_KEY_LEN);
memcpy(keypair->pub_key_y, pub_key + 1 + SECP256R1_ECDSA_KEY_LEN, SECP256R1_ECDSA_KEY_LEN);
psa_reset_key_attributes(&key_attributes);
keypair->curve = 0;
err = ESP_OK;
exit:
if (ret != 0) {
ESP_LOGE(TAG, "Failed to generate ECDSA keypair (-0x%X)", -ret);
}
mbedtls_ecdsa_free(&ecdsa_ctx);
return err;
return ESP_OK;
}
static esp_err_t get_ecdsa_sign_secp256r1(const esp_att_ecdsa_keypair_t *keypair, const uint8_t *digest, const size_t len,
@@ -164,67 +150,21 @@ static esp_err_t get_ecdsa_sign_secp256r1(const esp_att_ecdsa_keypair_t *keypair
return ESP_ERR_INVALID_SIZE;
}
esp_err_t err = ESP_FAIL;
mbedtls_ecp_keypair pvt_key;
mbedtls_mpi r, s;
mbedtls_mpi_init(&r);
mbedtls_mpi_init(&s);
mbedtls_ecp_keypair_init(&pvt_key);
int ret = mbedtls_ecp_read_key(MBEDTLS_ECP_DP_SECP256R1, &pvt_key, keypair->pvt_key, sizeof(keypair->pvt_key));
if (ret != 0) {
goto exit;
size_t signature_len = 0;
uint8_t signature[sign_r_len + sign_s_len];
psa_status_t status = psa_sign_hash(keypair->key_id, PSA_ALG_ECDSA(PSA_ALG_SHA_256), digest, len, signature, sign_r_len + sign_s_len, &signature_len);
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
mbedtls_ecdsa_context ecdsa_ctx;
mbedtls_ecdsa_init(&ecdsa_ctx);
ret = mbedtls_ecdsa_from_keypair(&ecdsa_ctx, &pvt_key);
if (ret != 0) {
goto exit;
if (signature_len != sign_r_len + sign_s_len) {
return ESP_ERR_INVALID_SIZE;
}
ret = mbedtls_ecdsa_sign(&ecdsa_ctx.MBEDTLS_PRIVATE(grp), &r, &s, &ecdsa_ctx.MBEDTLS_PRIVATE(d),
digest, len, rng_func, NULL);
if (ret != 0) {
return ret;
}
memcpy(sign_r, signature, sign_r_len);
memcpy(sign_s, signature + sign_r_len, sign_s_len);
size_t r_len = mbedtls_mpi_size(&r);
if (r_len > sign_s_len) {
goto exit;
}
ret = mbedtls_mpi_write_binary(&r, (unsigned char *)(sign_r), r_len);
if (ret != 0) {
goto exit;
}
size_t s_len = mbedtls_mpi_size(&s);
if (s_len > sign_s_len) {
goto exit;
}
ret = mbedtls_mpi_write_binary(&s, (unsigned char *)(sign_s), s_len);
if (ret != 0) {
goto exit;
}
err = ESP_OK;
exit:
if (ret != 0) {
ESP_LOGE(TAG, "Failed to generate ECDSA signature (-0x%X)", -ret);
}
mbedtls_ecdsa_free(&ecdsa_ctx);
mbedtls_ecp_keypair_free(&pvt_key);
mbedtls_mpi_free(&s);
mbedtls_mpi_free(&r);
return err;
return ESP_OK;
}
#endif
@@ -241,33 +181,23 @@ esp_err_t esp_att_utils_ecdsa_get_pubkey(const esp_att_ecdsa_keypair_t *keypair,
return ESP_ERR_INVALID_ARG;
}
esp_err_t err = ESP_FAIL;
size_t hexstr_len = sizeof(keypair->pub_key_x) * 2 + ECDSA_PUBKEY_PREFIX_SZ + 1;
char *hexstr = calloc(hexstr_len, sizeof(uint8_t));
if (hexstr == NULL) {
err = ESP_ERR_NO_MEM;
goto exit;
size_t pubkey_hexstr_size = sizeof(keypair->pub_key_x) * 2 + ECDSA_PUBKEY_PREFIX_SZ + 1;
*pubkey_hexstr = calloc(pubkey_hexstr_size, sizeof(char));
if (*pubkey_hexstr == NULL) {
return ESP_ERR_NO_MEM;
}
/* Checking the parity of the y-component of the public key */
char *pubkey_prefix = (keypair->pub_key_y[SECP256R1_ECDSA_KEY_LEN - 1] & 1)
? ECDSA_COMPRESSED_KEY_ODD_PREFIX
: ECDSA_COMPRESSED_KEY_EVEN_PREFIX;
memcpy(hexstr, pubkey_prefix, ECDSA_PUBKEY_PREFIX_SZ);
char *pubkey_prefix = (keypair->pub_key_y[SECP256R1_ECDSA_KEY_LEN - 1] & 1) ? ECDSA_COMPRESSED_KEY_ODD_PREFIX : ECDSA_COMPRESSED_KEY_EVEN_PREFIX;
memcpy(*pubkey_hexstr, pubkey_prefix, ECDSA_PUBKEY_PREFIX_SZ);
err = esp_att_utils_hexbuf_to_hexstr(keypair->pub_key_x, sizeof(keypair->pub_key_x),
&hexstr[ECDSA_PUBKEY_PREFIX_SZ], hexstr_len - ECDSA_PUBKEY_PREFIX_SZ);
int err = esp_att_utils_hexbuf_to_hexstr(keypair->pub_key_x, sizeof(keypair->pub_key_x), *pubkey_hexstr + ECDSA_PUBKEY_PREFIX_SZ, pubkey_hexstr_size - ECDSA_PUBKEY_PREFIX_SZ);
if (err != ESP_OK) {
goto exit;
free(*pubkey_hexstr);
*pubkey_hexstr = NULL;
return err;
}
*pubkey_hexstr = hexstr;
return ESP_OK;
exit:
free(hexstr);
return err;
}
esp_err_t esp_att_utils_ecdsa_get_pubkey_digest(const esp_att_ecdsa_keypair_t *keypair, uint8_t *digest, const size_t len)
@@ -276,17 +206,44 @@ esp_err_t esp_att_utils_ecdsa_get_pubkey_digest(const esp_att_ecdsa_keypair_t *k
return ESP_ERR_INVALID_ARG;
}
// Check if the public key is available in the keypair struct
// We already export the public key in the gen_ecdsa_keypair_secp256r1 function
// If not, we need to export it again
if (keypair->pub_key_x[0] != 0) {
memcpy(digest, keypair->pub_key_x, len);
return ESP_OK;
}
if (keypair->pub_key_y[0] != 0) {
memcpy(digest, keypair->pub_key_y, len);
return ESP_OK;
}
uint8_t pubkey_c[SECP256R1_ECDSA_KEY_LEN * 2] = {0};
memcpy(pubkey_c, keypair->pub_key_x, SECP256R1_ECDSA_KEY_LEN);
memcpy(pubkey_c + SECP256R1_ECDSA_KEY_LEN, keypair->pub_key_y, SECP256R1_ECDSA_KEY_LEN);
memcpy(pubkey_c, keypair->pub_key_x, sizeof(keypair->pub_key_x));
memcpy(pubkey_c + SECP256R1_ECDSA_KEY_LEN, keypair->pub_key_y, sizeof(keypair->pub_key_y));
uint8_t pubkey_digest[SHA256_DIGEST_SZ];
int ret = mbedtls_sha256((const unsigned char *)pubkey_c, sizeof(pubkey_c), pubkey_digest, false);
if (ret != 0) {
ESP_LOGE(TAG, "Failed to calculate pubkey digest (-%X)", -ret);
psa_hash_operation_t hash_op = PSA_HASH_OPERATION_INIT;
psa_status_t status = psa_hash_setup(&hash_op, PSA_ALG_SHA_256);
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
status = psa_hash_update(&hash_op, pubkey_c, sizeof(pubkey_c));
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
size_t pubkey_digest_len = 0;
status = psa_hash_finish(&hash_op, pubkey_digest, len, &pubkey_digest_len);
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
if (pubkey_digest_len != len) {
return ESP_ERR_INVALID_SIZE;
}
memcpy(digest, pubkey_digest, len);
return ESP_OK;
}
@@ -14,11 +14,7 @@
#include "bootloader_sha.h"
#include "esp_tee_sec_storage.h"
#endif
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include "esp_random.h"
#include "mbedtls/ecdh.h"
#include "mbedtls/ecdsa.h"
#include "mbedtls/sha256.h"
#include "json_generator.h"
#include "esp_attestation_utils.h"
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -37,9 +37,9 @@
#include "esp32c6/rom/secure_boot.h"
#endif
#endif
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include "mbedtls/sha256.h"
#define DECLARE_PRIVATE_IDENTIFIERS
// // #include "mbedtls/sha256.h"
#include "psa/crypto.h"
#include "bootloader_flash_priv.h"
#include "esp_attestation_utils.h"
@@ -50,7 +50,7 @@ static const char *TAG = "esp_att_utils";
/* Forward declaration */
static esp_err_t read_partition(uint32_t offset, void *buf, size_t size);
esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t *digest);
esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t *digest, size_t digest_len);
static esp_err_t get_active_app_part_pos(esp_partition_pos_t *pos);
static esp_err_t get_active_tee_part_pos(esp_partition_pos_t *pos);
@@ -78,7 +78,7 @@ static esp_err_t read_partition(uint32_t offset, void *buf, size_t size)
return (esp_err_t)esp_tee_flash_read(offset, buf, size, true);
}
esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t *digest)
esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t *digest, size_t digest_len)
{
if (digest == NULL) {
return ESP_ERR_INVALID_ARG;
@@ -87,12 +87,9 @@ esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t
uint32_t mmu_free_pages_count = esp_tee_flash_mmap_get_free_pages();
uint32_t partial_image_len = mmu_free_pages_count * CONFIG_MMU_PAGE_SIZE;
mbedtls_sha256_context ctx;
mbedtls_sha256_init(&ctx);
int ret = mbedtls_sha256_starts(&ctx, false);
if (ret != 0) {
mbedtls_sha256_free(&ctx);
psa_hash_operation_t hash_op = PSA_HASH_OPERATION_INIT;
psa_status_t status = psa_hash_setup(&hash_op, PSA_ALG_SHA_256);
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
@@ -100,18 +97,27 @@ esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t
uint32_t mmap_len = MIN(len, partial_image_len);
const void *image = esp_tee_flash_mmap(flash_offset, mmap_len);
if (image == NULL) {
mbedtls_sha256_free(&ctx);
psa_hash_abort(&hash_op);
return ESP_FAIL;
}
status = psa_hash_update(&hash_op, image, mmap_len);
if (status != PSA_SUCCESS) {
psa_hash_abort(&hash_op);
return ESP_FAIL;
}
mbedtls_sha256_update(&ctx, image, mmap_len);
esp_tee_flash_munmap(image);
flash_offset += mmap_len;
len -= mmap_len;
}
mbedtls_sha256_finish(&ctx, digest);
mbedtls_sha256_free(&ctx);
size_t digest_size = 0;
status = psa_hash_finish(&hash_op, digest, digest_len, &digest_size);
if (status != PSA_SUCCESS) {
psa_hash_abort(&hash_op);
return ESP_FAIL;
}
return ESP_OK;
}
@@ -154,7 +160,7 @@ static esp_err_t read_partition(uint32_t offset, void *buf, size_t size)
return esp_flash_read(NULL, buf, offset, size);
}
esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t *digest)
esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t *digest, size_t digest_len)
{
if (digest == NULL) {
return ESP_ERR_INVALID_ARG;
@@ -165,11 +171,10 @@ esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t
uint32_t mmu_free_pages_count = bootloader_mmap_get_free_pages();
uint32_t partial_image_len = mmu_free_pages_count * CONFIG_MMU_PAGE_SIZE;
mbedtls_sha256_context sha256_ctx;
mbedtls_sha256_init(&sha256_ctx);
if (mbedtls_sha256_starts(&sha256_ctx, false) != 0) {
goto exit;
psa_hash_operation_t hash_op = PSA_HASH_OPERATION_INIT;
psa_status_t status = psa_hash_setup(&hash_op, PSA_ALG_SHA_256);
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
while (len > 0) {
@@ -178,7 +183,9 @@ esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t
if (image == NULL) {
goto exit;
}
if (mbedtls_sha256_update(&sha256_ctx, image, mmap_len) != 0) {
status = psa_hash_update(&hash_op, image, mmap_len);
if (status != PSA_SUCCESS) {
psa_hash_abort(&hash_op);
goto exit;
}
bootloader_munmap(image);
@@ -187,13 +194,16 @@ esp_err_t get_flash_contents_sha256(uint32_t flash_offset, uint32_t len, uint8_t
len -= mmap_len;
}
if (mbedtls_sha256_finish(&sha256_ctx, digest) != 0) {
size_t digest_len = 0;
status = psa_hash_finish(&hash_op, digest, digest_len, &digest_len);
if (status != PSA_SUCCESS) {
psa_hash_abort(&hash_op);
goto exit;
}
err = ESP_OK;
exit:
mbedtls_sha256_free(&sha256_ctx);
psa_hash_abort(&hash_op);
return err;
}
@@ -283,7 +293,7 @@ static esp_err_t get_part_digest(const esp_partition_pos_t *pos, esp_att_part_di
return ESP_ERR_NO_MEM;
}
err = get_flash_contents_sha256(pos->offset, image_len, digest);
err = get_flash_contents_sha256(pos->offset, image_len, digest, digest_len);
if (err != ESP_OK) {
goto exit;
}
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -14,9 +14,7 @@
#include "esp_efuse.h"
#include "esp_efuse_table.h"
#include "hal/efuse_hal.h"
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include "mbedtls/sha256.h"
#include "psa/crypto.h"
#include "esp_attestation.h"
#include "esp_attestation_utils.h"
@@ -63,33 +61,28 @@ static esp_err_t fetch_device_id(uint8_t *devid_buf)
goto exit;
}
mbedtls_sha256_context ctx;
mbedtls_sha256_init(&ctx);
int ret = mbedtls_sha256_starts(&ctx, false);
if (ret != 0) {
mbedtls_sha256_free(&ctx);
err = ESP_FAIL;
goto exit;
psa_hash_operation_t hash_op = PSA_HASH_OPERATION_INIT;
psa_status_t status = psa_hash_setup(&hash_op, PSA_ALG_SHA_256);
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
ret = mbedtls_sha256_update(&ctx, (const unsigned char *)mac_addr, sizeof(mac_addr));
if (ret != 0) {
mbedtls_sha256_free(&ctx);
err = ESP_FAIL;
goto exit;
status = psa_hash_update(&hash_op, mac_addr, sizeof(mac_addr));
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
uint8_t digest[SHA256_DIGEST_SZ] = {0};
ret = mbedtls_sha256_finish(&ctx, digest);
if (ret != 0) {
mbedtls_sha256_free(&ctx);
err = ESP_FAIL;
goto exit;
size_t digest_len = 0;
status = psa_hash_finish(&hash_op, devid_buf, SHA256_DIGEST_SZ, &digest_len);
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
memcpy(devid_buf, digest, SHA256_DIGEST_SZ);
mbedtls_sha256_free(&ctx);
if (digest_len != SHA256_DIGEST_SZ) {
return ESP_ERR_INVALID_SIZE;
}
return ESP_OK;
exit:
return err;
@@ -179,6 +172,8 @@ esp_err_t esp_att_generate_token(const uint32_t nonce, const uint32_t client_id,
return ESP_ERR_INVALID_ARG;
}
ESP_LOGI(TAG, "Generating attestation token");
if (token_buf_size < ESP_ATT_TK_MIN_SIZE) {
ESP_LOGE(TAG, "EAT buffer too small: got %luB, need > %dB", token_buf_size, ESP_ATT_TK_MIN_SIZE);
return ESP_ERR_INVALID_SIZE;
@@ -211,12 +206,9 @@ esp_err_t esp_att_generate_token(const uint32_t nonce, const uint32_t client_id,
memset(token_buf, 0x00, token_buf_size);
mbedtls_sha256_context ctx;
mbedtls_sha256_init(&ctx);
int ret = mbedtls_sha256_starts(&ctx, false);
if (ret != 0) {
mbedtls_sha256_free(&ctx);
psa_hash_operation_t hash_op = PSA_HASH_OPERATION_INIT;
psa_status_t status = psa_hash_setup(&hash_op, PSA_ALG_SHA_256);
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
@@ -236,9 +228,9 @@ esp_err_t esp_att_generate_token(const uint32_t nonce, const uint32_t client_id,
}
json_gen_push_object_str(&jstr, "header", hdr_json);
ret = mbedtls_sha256_update(&ctx, (const unsigned char *)hdr_json, hdr_len - 1);
if (ret != 0) {
mbedtls_sha256_free(&ctx);
status = psa_hash_update(&hash_op, (const unsigned char *)hdr_json, hdr_len - 1);
if (status != PSA_SUCCESS) {
psa_hash_abort(&hash_op);
return ESP_FAIL;
}
free(hdr_json);
@@ -253,9 +245,9 @@ esp_err_t esp_att_generate_token(const uint32_t nonce, const uint32_t client_id,
}
json_gen_push_object_str(&jstr, "eat", eat_json);
ret = mbedtls_sha256_update(&ctx, (const unsigned char *)eat_json, eat_len - 1);
if (ret != 0) {
mbedtls_sha256_free(&ctx);
status = psa_hash_update(&hash_op, (const unsigned char *)eat_json, eat_len - 1);
if (status != PSA_SUCCESS) {
psa_hash_abort(&hash_op);
return ESP_FAIL;
}
free(eat_json);
@@ -269,20 +261,20 @@ esp_err_t esp_att_generate_token(const uint32_t nonce, const uint32_t client_id,
}
json_gen_push_object_str(&jstr, "public_key", pubkey_json);
ret = mbedtls_sha256_update(&ctx, (const unsigned char *)pubkey_json, pubkey_len - 1);
if (ret != 0) {
mbedtls_sha256_free(&ctx);
status = psa_hash_update(&hash_op, (const unsigned char *)pubkey_json, pubkey_len - 1);
if (status != PSA_SUCCESS) {
psa_hash_abort(&hash_op);
return ESP_FAIL;
}
free(pubkey_json);
uint8_t digest[SHA256_DIGEST_SZ] = {0};
ret = mbedtls_sha256_finish(&ctx, digest);
if (ret != 0) {
mbedtls_sha256_free(&ctx);
size_t digest_len = 0;
status = psa_hash_finish(&hash_op, digest, sizeof(digest), &digest_len);
if (status != PSA_SUCCESS) {
psa_hash_abort(&hash_op);
return ESP_FAIL;
}
mbedtls_sha256_free(&ctx);
char *sign_json = NULL;
int sign_len = -1;
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -13,6 +13,8 @@
#include "esp_attestation.h"
#include "psa/crypto.h"
#ifdef __cplusplus
extern "C" {
#endif
@@ -79,8 +79,7 @@ typedef struct {
*
*/
typedef struct {
uint8_t sign_r[MAX_ECDSA_SUPPORTED_KEY_LEN]; /*!< R component */
uint8_t sign_s[MAX_ECDSA_SUPPORTED_KEY_LEN]; /*!< S component */
uint8_t signature[MAX_ECDSA_SUPPORTED_KEY_LEN * 2]; /*!< Signature */
} __attribute__((__packed__)) esp_tee_sec_storage_ecdsa_sign_t;
#if ESP_TEE_BUILD && !(__DOXYGEN__)
@@ -13,11 +13,18 @@
#include "esp_efuse_chip.h"
#include "esp_random.h"
#include "spi_flash_mmap.h"
#if SOC_HMAC_SUPPORTED
#include "esp_hmac.h"
#endif
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include "mbedtls/aes.h"
#include "mbedtls/gcm.h"
#include "mbedtls/sha256.h"
#include "mbedtls/ecdsa.h"
// #include "mbedtls/aes.h"
// #include "mbedtls/gcm.h"
// #include "mbedtls/sha256.h"
// #include "mbedtls/ecdsa.h"
// #include "mbedtls/error.h"
#include "esp_hmac_pbkdf2.h"
#include "psa/crypto.h"
#include "mbedtls/psa_util.h"
#include "esp_rom_sys.h"
#include "nvs.h"
@@ -45,13 +52,13 @@
/* Structure to hold ECDSA SECP256R1 key pair */
typedef struct {
uint8_t priv_key[ECDSA_SECP256R1_KEY_LEN]; /* Private key for ECDSA SECP256R1 */
uint8_t pub_key[2 * ECDSA_SECP256R1_KEY_LEN]; /* Public key for ECDSA SECP256R1 (X and Y coordinates) */
uint8_t pub_key[(2 * ECDSA_SECP256R1_KEY_LEN) + 1]; /* Public key for ECDSA SECP256R1 (X and Y coordinates) */
} __attribute__((aligned(4))) __attribute__((__packed__)) sec_stg_ecdsa_secp256r1_t;
/* Structure to hold ECDSA SECP192R1 key pair */
typedef struct {
uint8_t priv_key[ECDSA_SECP192R1_KEY_LEN]; /* Private key for ECDSA SECP192R1 */
uint8_t pub_key[2 * ECDSA_SECP192R1_KEY_LEN]; /* Public key for ECDSA SECP192R1 (X and Y coordinates) */
uint8_t pub_key[(2 * ECDSA_SECP192R1_KEY_LEN) + 1]; /* Public key for ECDSA SECP192R1 (X and Y coordinates) */
} __attribute__((aligned(4))) __attribute__((__packed__)) sec_stg_ecdsa_secp192r1_t;
/* Structure to hold AES-256 key and IV */
@@ -72,7 +79,7 @@ typedef struct {
uint32_t reserved[38]; /* Reserved space for future use */
} __attribute__((aligned(4))) __attribute__((__packed__)) sec_stg_key_t;
_Static_assert(sizeof(sec_stg_key_t) == 256, "Incorrect sec_stg_key_t size");
_Static_assert(sizeof(sec_stg_key_t) == 260, "Incorrect sec_stg_key_t size");
static nvs_handle_t tee_nvs_hdl;
@@ -128,12 +135,6 @@ static int buffer_hexdump(const char *label, const void *buffer, size_t length)
return 0;
}
static int rand_func(void *rng_state, unsigned char *output, size_t len)
{
esp_fill_random(output, len);
return 0;
}
#if CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE
static esp_err_t compute_nvs_keys_with_hmac(esp_efuse_block_t key_blk, nvs_sec_cfg_t *cfg)
{
@@ -269,6 +270,8 @@ esp_err_t esp_tee_sec_storage_init(void)
ESP_LOGW(TAG, "TEE Secure Storage enabled in insecure DEVELOPMENT mode");
#endif
psa_crypto_init();
return ESP_OK;
}
@@ -306,66 +309,75 @@ static int generate_ecdsa_key(sec_stg_key_t *keyctx, esp_tee_sec_storage_type_t
return -1;
}
mbedtls_ecp_group_id curve_id = MBEDTLS_ECP_DP_SECP256R1;
size_t key_len = ECDSA_SECP256R1_KEY_LEN;
psa_status_t status = psa_crypto_init();
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "Failed to initialize PSA Crypto: %ld", status);
return -1;
}
psa_key_id_t key_id = 0;
psa_key_attributes_t key_attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_set_key_bits(&key_attributes, ECDSA_SECP256R1_KEY_LEN * 8);
psa_set_key_type(&key_attributes, PSA_KEY_TYPE_ECC_KEY_PAIR(PSA_ECC_FAMILY_SECP_R1));
psa_set_key_usage_flags(&key_attributes, PSA_KEY_USAGE_SIGN_HASH | PSA_KEY_USAGE_EXPORT | PSA_KEY_USAGE_VERIFY_HASH);
psa_set_key_algorithm(&key_attributes, PSA_ALG_ECDSA(PSA_ALG_SHA_256));
if (key_type == ESP_SEC_STG_KEY_ECDSA_SECP192R1) {
#if CONFIG_SECURE_TEE_SEC_STG_SUPPORT_SECP192R1_SIGN
curve_id = MBEDTLS_ECP_DP_SECP192R1;
key_len = ECDSA_SECP192R1_KEY_LEN;
psa_set_key_bits(&key_attributes, ECDSA_SECP192R1_KEY_LEN * 8);
#else
ESP_LOGE(TAG, "Unsupported key-type!");
return -1;
#endif
}
ESP_LOGD(TAG, "Generating ECDSA key for curve %d...", curve_id);
mbedtls_ecdsa_context ctxECDSA;
mbedtls_ecdsa_init(&ctxECDSA);
int ret = mbedtls_ecdsa_genkey(&ctxECDSA, curve_id, rand_func, NULL);
if (ret != 0) {
status = psa_generate_key(&key_attributes, &key_id);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "Failed to generate ECDSA key: %ld", status);
goto exit;
}
uint8_t *priv_key = (key_type == ESP_SEC_STG_KEY_ECDSA_SECP256R1) ?
keyctx->ecdsa_secp256r1.priv_key :
size_t priv_key_len = 0;
size_t pub_key_len = 0;
/* Use the correct union member based on key type */
uint8_t *priv_key_buf = NULL;
size_t priv_key_buf_size = 0;
uint8_t *pub_key_buf = NULL;
size_t pub_key_buf_size = 0;
if (key_type == ESP_SEC_STG_KEY_ECDSA_SECP192R1) {
#if CONFIG_SECURE_TEE_SEC_STG_SUPPORT_SECP192R1_SIGN
keyctx->ecdsa_secp192r1.priv_key;
#else
NULL;
priv_key_buf = keyctx->ecdsa_secp192r1.priv_key;
priv_key_buf_size = sizeof(keyctx->ecdsa_secp192r1.priv_key);
pub_key_buf = keyctx->ecdsa_secp192r1.pub_key;
pub_key_buf_size = sizeof(keyctx->ecdsa_secp192r1.pub_key);
#endif
} else {
priv_key_buf = keyctx->ecdsa_secp256r1.priv_key;
priv_key_buf_size = sizeof(keyctx->ecdsa_secp256r1.priv_key);
pub_key_buf = keyctx->ecdsa_secp256r1.pub_key;
pub_key_buf_size = sizeof(keyctx->ecdsa_secp256r1.pub_key);
}
uint8_t *pub_key = (key_type == ESP_SEC_STG_KEY_ECDSA_SECP256R1) ?
keyctx->ecdsa_secp256r1.pub_key :
#if CONFIG_SECURE_TEE_SEC_STG_SUPPORT_SECP192R1_SIGN
keyctx->ecdsa_secp192r1.pub_key;
#else
NULL;
#endif
ret = mbedtls_mpi_write_binary(&(ctxECDSA.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(X)), pub_key, key_len);
if (ret != 0) {
status = psa_export_key(key_id, priv_key_buf, priv_key_buf_size, &priv_key_len);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "Failed to export ECDSA private key: %ld", status);
goto exit;
}
ret = mbedtls_mpi_write_binary(&(ctxECDSA.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Y)), pub_key + key_len, key_len);
if (ret != 0) {
status = psa_export_public_key(key_id, pub_key_buf, pub_key_buf_size, &pub_key_len);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "Failed to export ECDSA public key: %ld", status);
goto exit;
}
ret = mbedtls_mpi_write_binary(&ctxECDSA.MBEDTLS_PRIVATE(d), priv_key, key_len);
if (ret != 0) {
goto exit;
}
buffer_hexdump("Private key", priv_key, key_len);
buffer_hexdump("Public key", pub_key, key_len * 2);
buffer_hexdump("Private key", priv_key_buf, priv_key_len);
buffer_hexdump("Public key", pub_key_buf, pub_key_len);
exit:
mbedtls_ecdsa_free(&ctxECDSA);
return ret;
psa_destroy_key(key_id);
psa_reset_key_attributes(&key_attributes);
return status == PSA_SUCCESS ? 0 : -1;
}
static int generate_aes256_key(sec_stg_key_t *keyctx)
@@ -454,68 +466,47 @@ esp_err_t esp_tee_sec_storage_ecdsa_sign(const esp_tee_sec_storage_key_cfg_t *cf
return ESP_ERR_INVALID_STATE;
}
mbedtls_mpi r, s;
mbedtls_ecp_keypair priv_key;
mbedtls_ecdsa_context sign_ctx;
mbedtls_mpi_init(&r);
mbedtls_mpi_init(&s);
mbedtls_ecp_keypair_init(&priv_key);
mbedtls_ecdsa_init(&sign_ctx);
size_t key_len = 0;
int ret = -1;
psa_key_id_t key_id = 0;
psa_key_attributes_t key_attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_set_key_type(&key_attributes, PSA_KEY_TYPE_ECC_KEY_PAIR(PSA_ECC_FAMILY_SECP_R1));
psa_set_key_usage_flags(&key_attributes, PSA_KEY_USAGE_SIGN_HASH | PSA_KEY_USAGE_EXPORT | PSA_KEY_USAGE_VERIFY_HASH);
psa_set_key_algorithm(&key_attributes, PSA_ALG_ECDSA(PSA_ALG_SHA_256));
uint8_t *priv_key = NULL;
size_t priv_key_len = 0;
if (cfg->type == ESP_SEC_STG_KEY_ECDSA_SECP256R1) {
ret = mbedtls_ecp_read_key(MBEDTLS_ECP_DP_SECP256R1, &priv_key, keyctx.ecdsa_secp256r1.priv_key, sizeof(keyctx.ecdsa_secp256r1.priv_key));
key_len = ECDSA_SECP256R1_KEY_LEN;
psa_set_key_bits(&key_attributes, ECDSA_SECP256R1_KEY_LEN * 8);
priv_key = keyctx.ecdsa_secp256r1.priv_key;
priv_key_len = sizeof(keyctx.ecdsa_secp256r1.priv_key);
#if CONFIG_SECURE_TEE_SEC_STG_SUPPORT_SECP192R1_SIGN
} else if (cfg->type == ESP_SEC_STG_KEY_ECDSA_SECP192R1) {
ret = mbedtls_ecp_read_key(MBEDTLS_ECP_DP_SECP192R1, &priv_key, keyctx.ecdsa_secp192r1.priv_key, sizeof(keyctx.ecdsa_secp192r1.priv_key));
key_len = ECDSA_SECP192R1_KEY_LEN;
psa_set_key_bits(&key_attributes, ECDSA_SECP192R1_KEY_LEN * 8);
priv_key = keyctx.ecdsa_secp192r1.priv_key;
priv_key_len = sizeof(keyctx.ecdsa_secp192r1.priv_key);
#endif
}
if (ret != 0) {
err = ESP_FAIL;
goto exit;
}
ret = mbedtls_ecdsa_from_keypair(&sign_ctx, &priv_key);
if (ret != 0) {
psa_status_t status = psa_import_key(&key_attributes, priv_key, priv_key_len, &key_id);
if (status != PSA_SUCCESS) {
err = ESP_FAIL;
ESP_LOGE(TAG, "Failed to import ECDSA private key: %ld", status);
goto exit;
}
ESP_LOGD(TAG, "Generating ECDSA signature...");
ret = mbedtls_ecdsa_sign(&sign_ctx.MBEDTLS_PRIVATE(grp), &r, &s, &sign_ctx.MBEDTLS_PRIVATE(d), hash, hlen,
rand_func, NULL);
if (ret != 0) {
ESP_LOGE(TAG, "Error generating signature: %d", ret);
err = ESP_FAIL;
goto exit;
}
memset(out_sign, 0x00, sizeof(esp_tee_sec_storage_ecdsa_sign_t));
ret = mbedtls_mpi_write_binary(&r, out_sign->sign_r, key_len);
if (ret == 0) {
ret = mbedtls_mpi_write_binary(&s, out_sign->sign_s, key_len);
}
if (ret != 0) {
memset(out_sign, 0x00, sizeof(esp_tee_sec_storage_ecdsa_sign_t));
size_t signature_len = 0;
status = psa_sign_hash(key_id, PSA_ALG_ECDSA(PSA_ALG_SHA_256), hash, hlen, out_sign->signature, sizeof(out_sign->signature), &signature_len);
if (status != PSA_SUCCESS) {
err = ESP_FAIL;
ESP_LOGE(TAG, "Failed to generate ECDSA signature: %ld", status);
goto exit;
}
err = ESP_OK;
exit:
mbedtls_ecdsa_free(&sign_ctx);
mbedtls_ecp_keypair_free(&priv_key);
mbedtls_mpi_free(&s);
mbedtls_mpi_free(&r);
psa_destroy_key(key_id);
psa_reset_key_attributes(&key_attributes);
return err;
}
@@ -534,6 +525,20 @@ esp_err_t esp_tee_sec_storage_ecdsa_get_pubkey(const esp_tee_sec_storage_key_cfg
sec_stg_key_t keyctx;
size_t keyctx_len = sizeof(keyctx);
/* Read key from storage first before accessing its fields */
err = secure_storage_read(cfg->id, (void *)&keyctx, &keyctx_len);
if (err != ESP_OK) {
ESP_LOGE(TAG, "Failed to read key from secure storage");
return err;
}
if (keyctx.type != cfg->type) {
ESP_LOGE(TAG, "Key type mismatch");
return ESP_ERR_INVALID_STATE;
}
/* Now determine the public key source and length based on key type */
uint8_t *pub_key_src = NULL;
size_t pub_key_len = 0;
@@ -553,20 +558,18 @@ esp_err_t esp_tee_sec_storage_ecdsa_get_pubkey(const esp_tee_sec_storage_key_cfg
return ESP_ERR_INVALID_ARG;
}
err = secure_storage_read(cfg->id, (void *)&keyctx, &keyctx_len);
if (err != ESP_OK) {
ESP_LOGE(TAG, "Failed to read key from secure storage");
return err;
// If pub_key_src[0] is 0x04, then it is compressed format
// This is what we save when exporting the public key from PSA
if (pub_key_src[0] == 0x04) {
memcpy(out_pubkey->pub_x, pub_key_src + 1, pub_key_len);
memcpy(out_pubkey->pub_y, pub_key_src + pub_key_len + 1, pub_key_len);
} else {
// This case is when the keys are host generated
// In this case the public key is stored as X and Y concatenated without 0x04 prefix
memcpy(out_pubkey->pub_x, pub_key_src, pub_key_len);
memcpy(out_pubkey->pub_y, pub_key_src + pub_key_len, pub_key_len);
}
if (keyctx.type != cfg->type) {
ESP_LOGE(TAG, "Key type mismatch");
return ESP_ERR_INVALID_STATE;
}
memcpy(out_pubkey->pub_x, pub_key_src, pub_key_len);
memcpy(out_pubkey->pub_y, pub_key_src + pub_key_len, pub_key_len);
return ESP_OK;
}
@@ -731,7 +734,7 @@ esp_err_t esp_tee_sec_storage_ecdsa_sign_pbkdf2(const esp_tee_sec_storage_pbkdf2
goto exit;
}
ret = mbedtls_ecp_keypair_calc_public(&keypair, rand_func, NULL);
ret = mbedtls_ecp_keypair_calc_public(&keypair, mbedtls_psa_get_random, MBEDTLS_PSA_RANDOM_STATE);
if (ret != 0) {
err = ESP_FAIL;
goto exit;
@@ -739,16 +742,16 @@ esp_err_t esp_tee_sec_storage_ecdsa_sign_pbkdf2(const esp_tee_sec_storage_pbkdf2
ret = mbedtls_ecdsa_sign(&keypair.MBEDTLS_PRIVATE(grp), &r, &s,
&keypair.MBEDTLS_PRIVATE(d), hash, hlen,
rand_func, NULL);
mbedtls_psa_get_random, MBEDTLS_PSA_RANDOM_STATE);
if (ret != 0) {
err = ESP_FAIL;
goto exit;
}
memset(out_sign, 0x00, sizeof(esp_tee_sec_storage_ecdsa_sign_t));
ret = mbedtls_mpi_write_binary(&r, out_sign->sign_r, key_len);
ret = mbedtls_mpi_write_binary(&r, out_sign->signature, key_len);
if (ret == 0) {
ret = mbedtls_mpi_write_binary(&s, out_sign->sign_s, key_len);
ret = mbedtls_mpi_write_binary(&s, out_sign->signature + key_len, key_len);
}
if (ret != 0) {
@@ -54,6 +54,12 @@ ssize_t _write_r(struct _reent *r, int fd, const void *ptr, size_t len)
return -1;
}
ssize_t _open_r(struct _reent *r, const char *path, int flags, int mode)
{
errno = ENOSYS;
return -1;
}
int _getpid_r(struct _reent *r)
{
return 1;
@@ -180,14 +186,26 @@ int __cxa_thread_atexit(void (*func)(void *), void *arg, void *dso)
return 0;
}
#if CONFIG_IDF_TARGET_ESP32H2 || CONFIG_IDF_TARGET_ESP32C61
// #if CONFIG_IDF_TARGET_ESP32H2
void *_sbrk(ptrdiff_t incr)
{
return (void *) -1;
}
#endif
// #endif
void esp_tee_include_syscalls_impl(void)
{
}
int _unlink_r(struct _reent *r, const char *path)
{
errno = ENOSYS;
return -1;
}
int _rename_r(struct _reent *r, const char *src, const char *dst)
{
errno = ENOSYS;
return -1;
}
@@ -214,3 +214,8 @@ ASSERT ((_tee_iram_end <= _tee_dram_start),
"Error: TEE IRAM segment overflowed into the DRAM segment! Increase CONFIG_SECURE_TEE_IRAM_SIZE as required.");
ASSERT((_tee_heap_end >= _tee_heap_start + 0x2000),
"Error: TEE heap size is too small - minimum is 8KB (0x2000)! Increase CONFIG_SECURE_TEE_DRAM_SIZE as required.");
/* MMU Page Alignment Checks */
ASSERT ((CONFIG_SECURE_TEE_IROM_SIZE % 0x10000) == 0,
"Error: SECURE_TEE_IROM_SIZE must be a multiple of MMU_PAGE_SIZE (0x10000/64KB)!");
ASSERT ((CONFIG_SECURE_TEE_DROM_SIZE % 0x10000) == 0,
"Error: SECURE_TEE_DROM_SIZE must be a multiple of MMU_PAGE_SIZE (0x10000/64KB)!");
@@ -219,3 +219,8 @@ ASSERT ((_tee_iram_end <= _tee_dram_start),
"Error: TEE IRAM segment overflowed into the DRAM segment! Increase CONFIG_SECURE_TEE_IRAM_SIZE as required.");
ASSERT((_tee_heap_end >= _tee_heap_start + 0x2000),
"Error: TEE heap size is too small - minimum is 8KB (0x2000)! Increase CONFIG_SECURE_TEE_DRAM_SIZE as required.");
/* MMU Page Alignment Checks */
ASSERT ((CONFIG_SECURE_TEE_IROM_SIZE % CONFIG_MMU_PAGE_SIZE) == 0,
"Error: SECURE_TEE_IROM_SIZE must be a multiple of MMU_PAGE_SIZE (CONFIG_MMU_PAGE_SIZE)!");
ASSERT ((CONFIG_SECURE_TEE_DROM_SIZE % CONFIG_MMU_PAGE_SIZE) == 0,
"Error: SECURE_TEE_DROM_SIZE must be a multiple of MMU_PAGE_SIZE (CONFIG_MMU_PAGE_SIZE)!");
@@ -230,7 +230,7 @@ static void init_ota_sem(void)
static int create_ota_task(const char *url, const char *task_name, void (*ota_task)(void *))
{
init_ota_sem();
if (xTaskCreate(ota_task, task_name, configMINIMAL_STACK_SIZE * 3, (void *)url, 5, NULL) != pdPASS) {
if (xTaskCreate(ota_task, task_name, configMINIMAL_STACK_SIZE * 4, (void *)url, 5, NULL) != pdPASS) {
ESP_LOGE(TAG, "Task creation failed for %s", task_name);
return ESP_FAIL;
}
@@ -14,9 +14,11 @@
#include "esp_console.h"
#include "argtable3/argtable3.h"
#include "mbedtls/ecp.h"
#include "mbedtls/ecdsa.h"
#include "mbedtls/sha256.h"
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
// #include "mbedtls/ecp.h"
// #include "mbedtls/ecdsa.h"
// #include "mbedtls/sha256.h"
#include "psa/crypto.h"
#include "esp_tee_sec_storage.h"
#include "example_tee_srv.h"
@@ -91,57 +93,33 @@ static esp_err_t verify_ecdsa_secp256r1_sign(const uint8_t *digest, size_t len,
esp_err_t err = ESP_FAIL;
mbedtls_mpi r, s;
mbedtls_mpi_init(&r);
mbedtls_mpi_init(&s);
psa_key_id_t key_id = 0;
psa_key_attributes_t key_attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_set_key_type(&key_attributes, PSA_KEY_TYPE_ECC_PUBLIC_KEY(PSA_ECC_FAMILY_SECP_R1));
psa_set_key_usage_flags(&key_attributes, PSA_KEY_USAGE_SIGN_HASH | PSA_KEY_USAGE_EXPORT | PSA_KEY_USAGE_VERIFY_HASH);
psa_set_key_algorithm(&key_attributes, PSA_ALG_ECDSA(PSA_ALG_SHA_256));
mbedtls_ecdsa_context ecdsa_context;
mbedtls_ecdsa_init(&ecdsa_context);
uint8_t pub_key[2 * ECDSA_SECP256R1_KEY_LEN + 1];
pub_key[0] = 0x04;
memcpy(pub_key + 1, pubkey->pub_x, ECDSA_SECP256R1_KEY_LEN);
memcpy(pub_key + 1 + ECDSA_SECP256R1_KEY_LEN, pubkey->pub_y, ECDSA_SECP256R1_KEY_LEN);
int ret = mbedtls_ecp_group_load(&ecdsa_context.MBEDTLS_PRIVATE(grp), MBEDTLS_ECP_DP_SECP256R1);
if (ret != 0) {
psa_status_t status = psa_import_key(&key_attributes, pub_key, sizeof(pub_key), &key_id);
if (status != PSA_SUCCESS) {
goto exit;
}
size_t plen = mbedtls_mpi_size(&ecdsa_context.MBEDTLS_PRIVATE(grp).P);
ret = mbedtls_mpi_read_binary(&r, sign->sign_r, plen);
if (ret != 0) {
status = psa_verify_hash(key_id, PSA_ALG_ECDSA(PSA_ALG_SHA_256), digest, len, sign->signature, sizeof(sign->signature));
if (status != PSA_SUCCESS) {
goto exit;
}
ret = mbedtls_mpi_read_binary(&s, sign->sign_s, plen);
if (ret != 0) {
goto exit;
}
ret = mbedtls_mpi_read_binary(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(X), pubkey->pub_x, plen);
if (ret != 0) {
goto exit;
}
ret = mbedtls_mpi_read_binary(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Y), pubkey->pub_y, plen);
if (ret != 0) {
goto exit;
}
ret = mbedtls_mpi_lset(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Z), 1);
if (ret != 0) {
goto exit;
}
ret = mbedtls_ecdsa_verify(&ecdsa_context.MBEDTLS_PRIVATE(grp), digest, len, &ecdsa_context.MBEDTLS_PRIVATE(Q), &r, &s);
if (ret != 0) {
goto exit;
}
psa_destroy_key(key_id);
psa_reset_key_attributes(&key_attributes);
err = ESP_OK;
exit:
mbedtls_mpi_free(&r);
mbedtls_mpi_free(&s);
mbedtls_ecdsa_free(&ecdsa_context);
return err;
}
@@ -161,8 +139,10 @@ static int get_msg_sha256(int argc, char **argv)
const char *msg = (const char *)cmd_get_msg_sha256_args.msg->sval[0];
uint8_t msg_digest[SHA256_DIGEST_SZ];
int ret = mbedtls_sha256((const unsigned char *)msg, strlen(msg), msg_digest, false);
if (ret != 0) {
size_t msg_len = strlen(msg);
size_t digest_len = 0;
psa_status_t status = psa_hash_compute(PSA_ALG_SHA_256, (const uint8_t *)msg, msg_len, msg_digest, sizeof(msg_digest), &digest_len);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "Failed to calculate message hash!");
return ESP_FAIL;
}
@@ -5,8 +5,8 @@ CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
# Reducing TEE I/DRAM sizes
# 24KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x6000
# 12KB
CONFIG_SECURE_TEE_DRAM_SIZE=0x3000
# 16KB
CONFIG_SECURE_TEE_DRAM_SIZE=0x4000
# Disable TEE logs (also disable all panic logs)
CONFIG_SECURE_TEE_DEBUG_MODE=n
@@ -1,6 +1,8 @@
# Reducing TEE I/DRAM sizes
# 28KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x7000
# 16KB
CONFIG_SECURE_TEE_DRAM_SIZE=0x5000
# TEE Secure Storage: Release mode
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
@@ -18,4 +18,4 @@ CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
# Increasing TEE DRAM size
# 18KB
CONFIG_SECURE_TEE_DRAM_SIZE=0x4800
CONFIG_SECURE_TEE_DRAM_SIZE=0x5000
@@ -22,25 +22,21 @@ endif()
set(mbedtls_test_srcs_dir "${idf_path}/components/mbedtls/test_apps/main")
# AES
if(CONFIG_SOC_AES_SUPPORTED)
list(APPEND srcs "${mbedtls_test_srcs_dir}/test_aes.c"
"${mbedtls_test_srcs_dir}/test_aes_gcm.c"
"${mbedtls_test_srcs_dir}/test_aes_perf.c")
endif()
# SHA
if(CONFIG_SOC_SHA_SUPPORTED)
list(APPEND srcs "${mbedtls_test_srcs_dir}/test_mbedtls_sha.c"
"${mbedtls_test_srcs_dir}/test_sha.c"
"${mbedtls_test_srcs_dir}/test_sha_perf.c")
endif()
# list(APPEND srcs "${mbedtls_test_srcs_dir}/test_aes.c"
# "${mbedtls_test_srcs_dir}/test_aes_gcm.c"
# "${mbedtls_test_srcs_dir}/test_aes_perf.c")
# # SHA
list(APPEND srcs "${mbedtls_test_srcs_dir}/test_mbedtls_sha.c"
"${mbedtls_test_srcs_dir}/test_sha.c"
"${mbedtls_test_srcs_dir}/test_sha_perf.c")
# Mixed
if(CONFIG_SOC_AES_SUPPORTED AND CONFIG_SOC_SHA_SUPPORTED)
list(APPEND srcs "${mbedtls_test_srcs_dir}/test_aes_sha_parallel.c")
endif()
# ECC
if(CONFIG_SOC_ECC_SUPPORTED)
list(APPEND srcs "${mbedtls_test_srcs_dir}/test_ecp.c")
endif()
# list(APPEND srcs "${mbedtls_test_srcs_dir}/test_ecp.c")
# Utility
list(APPEND srcs "${mbedtls_test_srcs_dir}/test_apb_dport_access.c"
"${mbedtls_test_srcs_dir}/test_mbedtls_utils.c")
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -9,10 +9,64 @@
#include "nvs_flash.h"
#include "unity.h"
#include "memory_checks.h"
#include "psa/crypto.h"
#if SOC_SHA_SUPPORT_PARALLEL_ENG
#include "sha/sha_parallel_engine.h"
#else
#include "sha/sha_core.h"
#endif
#include "bignum_impl.h"
/* setUp runs before every test */
void setUp(void)
{
#if SOC_SHA_SUPPORTED
// Execute esp_sha operation to allocate internal SHA semaphore (in case of ESP32)
// and initial DMA setup memory which is considered as leaked otherwise
const uint8_t input_buffer[64] = {0};
uint8_t output_buffer[64];
#if SOC_SHA_SUPPORT_SHA1
esp_sha(SHA1, input_buffer, sizeof(input_buffer), output_buffer);
#endif // SOC_SHA_SUPPORT_SHA1
#if SOC_SHA_SUPPORT_SHA256
esp_sha(SHA2_256, input_buffer, sizeof(input_buffer), output_buffer);
#endif // SOC_SHA_SUPPORT_SHA256
#if SOC_SHA_SUPPORT_SHA512
esp_sha(SHA2_512, input_buffer, sizeof(input_buffer), output_buffer);
#endif // SOC_SHA_SUPPORT_SHA512
#endif // SOC_SHA_SUPPORTED
#if defined(CONFIG_MBEDTLS_HARDWARE_MPI)
esp_mpi_enable_hardware_hw_op();
esp_mpi_disable_hardware_hw_op();
#endif // CONFIG_MBEDTLS_HARDWARE_MPI
#if SOC_AES_SUPPORTED
// Execute mbedtls_aes_init operation to allocate AES interrupt
// allocation memory which is considered as leak otherwise
const uint8_t plaintext[16] = {0};
uint8_t ciphertext[32];
const uint8_t key[16] = { 0 };
psa_status_t status;
psa_key_id_t key_id = 0;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT);
psa_set_key_algorithm(&attributes, PSA_ALG_CBC_NO_PADDING);
psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
psa_set_key_bits(&attributes, 128);
status = psa_import_key(&attributes, key, sizeof(key), &key_id);
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
size_t output_len = 0;
status = psa_cipher_encrypt(key_id, PSA_ALG_CBC_NO_PADDING, plaintext, sizeof(plaintext), ciphertext, sizeof(ciphertext), &output_len);
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
const uint8_t plaintext_long[256] = {0};
uint8_t ciphertext_long[272];
output_len = 0;
status = psa_cipher_encrypt(key_id, PSA_ALG_CBC_NO_PADDING, plaintext_long, sizeof(plaintext_long), ciphertext_long, sizeof(ciphertext_long), &output_len);
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
psa_destroy_key(key_id);
#endif // SOC_AES_SUPPORTED
test_utils_record_free_mem();
test_utils_set_leak_level(CONFIG_UNITY_CRITICAL_LEAK_LEVEL_GENERAL, ESP_LEAK_TYPE_CRITICAL, ESP_COMP_LEAK_GENERAL);
test_utils_set_leak_level(CONFIG_UNITY_WARN_LEAK_LEVEL_GENERAL, ESP_LEAK_TYPE_WARNING, ESP_COMP_LEAK_GENERAL);
@@ -7,10 +7,11 @@
#include "esp_log.h"
#include "esp_heap_caps.h"
#include "mbedtls/ecp.h"
#include "mbedtls/ecdsa.h"
#include "mbedtls/sha256.h"
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
// #include "mbedtls/ecp.h"
// #include "mbedtls/ecdsa.h"
// #include "mbedtls/sha256.h"
#include "psa/crypto.h"
#include "esp_tee.h"
#include "esp_tee_attestation.h"
@@ -24,6 +25,7 @@
/* Note: negative value here so that assert message prints a grep-able
error hex value (mbedTLS uses -N for error codes) */
#define TEST_ASSERT_MBEDTLS_OK(X) TEST_ASSERT_EQUAL_HEX32(0, -(X))
#define TEST_ASSERT_PSA_OK(X) TEST_ASSERT_EQUAL_HEX32(0, -(X))
#define SHA256_DIGEST_SZ (32)
#define ECDSA_SECP256R1_KEY_LEN (32)
@@ -165,19 +167,13 @@ static void prehash_token_data(const char *token_json, uint8_t *digest, size_t l
char *eat_str = cJSON_PrintUnformatted(eat);
char *public_key_str = cJSON_PrintUnformatted(public_key);
mbedtls_sha256_context sha256_ctx;
mbedtls_sha256_init(&sha256_ctx);
TEST_ASSERT_MBEDTLS_OK(mbedtls_sha256_starts(&sha256_ctx, false));
TEST_ASSERT_MBEDTLS_OK(mbedtls_sha256_update(&sha256_ctx, (const unsigned char *)header_str, strlen(header_str)));
TEST_ASSERT_MBEDTLS_OK(mbedtls_sha256_update(&sha256_ctx, (const unsigned char *)eat_str, strlen(eat_str)));
TEST_ASSERT_MBEDTLS_OK(mbedtls_sha256_update(&sha256_ctx, (const unsigned char *)public_key_str, strlen(public_key_str)));
TEST_ASSERT_MBEDTLS_OK(mbedtls_sha256_finish(&sha256_ctx, digest));
mbedtls_sha256_free(&sha256_ctx);
psa_hash_operation_t operation = PSA_HASH_OPERATION_INIT;
TEST_ASSERT_PSA_OK(psa_hash_setup(&operation, PSA_ALG_SHA_256));
size_t digest_len = 0;
TEST_ASSERT_PSA_OK(psa_hash_update(&operation, (const unsigned char *)header_str, strlen(header_str)));
TEST_ASSERT_PSA_OK(psa_hash_update(&operation, (const unsigned char *)eat_str, strlen(eat_str)));
TEST_ASSERT_PSA_OK(psa_hash_update(&operation, (const unsigned char *)public_key_str, strlen(public_key_str)));
TEST_ASSERT_PSA_OK(psa_hash_finish(&operation, digest, SHA256_DIGEST_SZ, &digest_len));
free(public_key_str);
free(eat_str);
@@ -239,13 +235,13 @@ static void fetch_signature(const char *token_json, esp_tee_sec_storage_ecdsa_si
uint8_t *sign_r_buf = NULL;
size_t sign_r_buf_sz = 0;
hexstr_to_bytes(sign_r->valuestring, &sign_r_buf, &sign_r_buf_sz);
memcpy(sign_ctx->sign_r, sign_r_buf, sign_r_buf_sz);
memcpy(sign_ctx->signature, sign_r_buf, sign_r_buf_sz);
free(sign_r_buf);
uint8_t *sign_s_buf = NULL;
size_t sign_s_buf_sz = 0;
hexstr_to_bytes(sign_s->valuestring, &sign_s_buf, &sign_s_buf_sz);
memcpy(sign_ctx->sign_s, sign_s_buf, sign_s_buf_sz);
memcpy(sign_ctx->signature + sign_r_buf_sz, sign_s_buf, sign_s_buf_sz);
free(sign_s_buf);
cJSON_Delete(root);
@@ -8,10 +8,10 @@
#include "esp_log.h"
#include "esp_heap_caps.h"
#include "esp_partition.h"
#include "mbedtls/ecp.h"
#include "mbedtls/ecdsa.h"
#include "mbedtls/sha256.h"
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
// #include "mbedtls/ecp.h"
// #include "mbedtls/ecdsa.h"
// #include "mbedtls/sha256.h"
#include "ecdsa/ecdsa_alt.h"
#include "esp_tee.h"
@@ -25,6 +25,7 @@
#include "nvs.h"
#include "unity.h"
#include "sdkconfig.h"
#include "ecdsa/ecdsa_alt.h"
/* Note: negative value here so that assert message prints a grep-able
error hex value (mbedTLS uses -N for error codes) */
@@ -52,33 +53,52 @@ int verify_ecdsa_sign(const uint8_t *digest, size_t len, const esp_tee_sec_stora
TEST_ASSERT_NOT_NULL(sign);
TEST_ASSERT_NOT_EQUAL(0, len);
mbedtls_mpi r, s;
mbedtls_mpi_init(&r);
mbedtls_mpi_init(&s);
int err = ESP_FAIL;
mbedtls_ecdsa_context ecdsa_context;
mbedtls_ecdsa_init(&ecdsa_context);
psa_key_id_t key_id = 0;
psa_key_attributes_t key_attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_set_key_type(&key_attributes, PSA_KEY_TYPE_ECC_PUBLIC_KEY(PSA_ECC_FAMILY_SECP_R1));
psa_set_key_usage_flags(&key_attributes, PSA_KEY_USAGE_VERIFY_HASH);
psa_set_key_algorithm(&key_attributes, PSA_ALG_ECDSA(PSA_ALG_SHA_256));
mbedtls_ecp_group_id curve_id = MBEDTLS_ECP_DP_SECP256R1;
size_t pub_key_len;
size_t signature_size;
if (is_crv_p192) {
curve_id = MBEDTLS_ECP_DP_SECP192R1;
psa_set_key_bits(&key_attributes, ECDSA_SECP192R1_KEY_LEN * 8);
pub_key_len = ECDSA_SECP192R1_KEY_LEN;
signature_size = ECDSA_SECP192R1_KEY_LEN * 2;
} else {
psa_set_key_bits(&key_attributes, ECDSA_SECP256R1_KEY_LEN * 8);
pub_key_len = ECDSA_SECP256R1_KEY_LEN;
signature_size = ECDSA_SECP256R1_KEY_LEN * 2;
}
TEST_ASSERT_MBEDTLS_OK(mbedtls_ecp_group_load(&ecdsa_context.MBEDTLS_PRIVATE(grp), curve_id));
size_t plen = mbedtls_mpi_size(&ecdsa_context.MBEDTLS_PRIVATE(grp).P);
uint8_t pub_key[2 * pub_key_len + 1];
pub_key[0] = 0x04;
memcpy(pub_key + 1, pubkey->pub_x, pub_key_len);
memcpy(pub_key + 1 + pub_key_len, pubkey->pub_y, pub_key_len);
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_read_binary(&r, sign->sign_r, plen));
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_read_binary(&s, sign->sign_s, plen));
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_read_binary(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(X), pubkey->pub_x, plen));
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_read_binary(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Y), pubkey->pub_y, plen));
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_lset(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Z), 1));
TEST_ASSERT_MBEDTLS_OK(mbedtls_ecdsa_verify(&ecdsa_context.MBEDTLS_PRIVATE(grp), digest, len, &ecdsa_context.MBEDTLS_PRIVATE(Q), &r, &s));
psa_status_t status = psa_import_key(&key_attributes, pub_key, sizeof(pub_key), &key_id);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "Failed to import ECDSA public key: %ld", status);
err = ESP_ERR_INVALID_ARG;
goto exit;
}
mbedtls_mpi_free(&r);
mbedtls_mpi_free(&s);
mbedtls_ecdsa_free(&ecdsa_context);
status = psa_verify_hash(key_id, PSA_ALG_ECDSA(PSA_ALG_SHA_256), digest, len, sign->signature, signature_size);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "Failed to verify ECDSA signature: %ld", status);
err = ESP_ERR_INVALID_ARG;
goto exit;
}
return 0;
psa_destroy_key(key_id);
psa_reset_key_attributes(&key_attributes);
err = ESP_OK;
exit:
return err;
}
TEST_CASE("Test TEE Secure Storage - Sign-verify (ecdsa_secp256r1)", "[sec_storage]")
@@ -90,7 +110,9 @@ TEST_CASE("Test TEE Secure Storage - Sign-verify (ecdsa_secp256r1)", "[sec_stora
esp_fill_random(message, buf_sz);
uint8_t msg_digest[SHA256_DIGEST_SZ];
TEST_ASSERT_MBEDTLS_OK(mbedtls_sha256(message, buf_sz, msg_digest, false));
size_t msg_digest_len = 0;
psa_status_t status = psa_hash_compute(PSA_ALG_SHA_256, message, buf_sz, msg_digest, sizeof(msg_digest), &msg_digest_len);
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
free(message);
esp_tee_sec_storage_key_cfg_t key_cfg = {
@@ -108,12 +130,12 @@ TEST_CASE("Test TEE Secure Storage - Sign-verify (ecdsa_secp256r1)", "[sec_stora
TEST_ESP_OK(esp_tee_sec_storage_gen_key(&key_cfg));
esp_tee_sec_storage_ecdsa_sign_t sign = {};
TEST_ESP_OK(esp_tee_sec_storage_ecdsa_sign(&key_cfg, msg_digest, sizeof(msg_digest), &sign));
TEST_ESP_OK(esp_tee_sec_storage_ecdsa_sign(&key_cfg, msg_digest, msg_digest_len, &sign));
esp_tee_sec_storage_ecdsa_pubkey_t pubkey = {};
TEST_ESP_OK(esp_tee_sec_storage_ecdsa_get_pubkey(&key_cfg, &pubkey));
TEST_ESP_OK(verify_ecdsa_sign(msg_digest, sizeof(msg_digest), &pubkey, &sign, false));
TEST_ESP_OK(verify_ecdsa_sign(msg_digest, msg_digest_len, &pubkey, &sign, false));
TEST_ESP_OK(esp_tee_sec_storage_clear_key(key_cfg.id));
}
@@ -129,7 +151,10 @@ TEST_CASE("Test TEE Secure Storage - Sign-verify (ecdsa_secp192r1)", "[sec_stora
esp_fill_random(message, buf_sz);
uint8_t msg_digest[SHA256_DIGEST_SZ];
TEST_ASSERT_MBEDTLS_OK(mbedtls_sha256(message, buf_sz, msg_digest, false));
size_t msg_digest_len = 0;
psa_status_t status = psa_hash_compute(PSA_ALG_SHA_256, message, buf_sz, msg_digest, sizeof(msg_digest), &msg_digest_len);
(void)msg_digest_len;
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
free(message);
esp_tee_sec_storage_key_cfg_t key_cfg = {
@@ -222,7 +247,9 @@ TEST_CASE("Test TEE Secure Storage - Operations with invalid/non-existent keys",
TEST_ASSERT_NOT_NULL(message);
esp_fill_random(message, SZ);
uint8_t msg_digest[SHA256_DIGEST_SZ];
TEST_ASSERT_MBEDTLS_OK(mbedtls_sha256(message, SZ, msg_digest, false));
size_t msg_digest_len = 0;
psa_status_t status = psa_hash_compute(PSA_ALG_SHA_256, message, SZ, msg_digest, sizeof(msg_digest), &msg_digest_len);
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
free(message);
const char *key_id = "key_id_misc";
@@ -483,18 +510,18 @@ static void test_ecdsa_sign(mbedtls_ecp_group_id gid)
};
TEST_ASSERT_EQUAL(0, esp_ecdsa_tee_set_pk_context(&key_ctx, &conf));
mbedtls_ecp_keypair *keypair = mbedtls_pk_ec(key_ctx);
mbedtls_ecp_keypair *keypair = key_ctx.MBEDTLS_PRIVATE(pk_ctx); //mbedtls_pk_ec(key_ctx);
mbedtls_mpi key_mpi = keypair->MBEDTLS_PRIVATE(d);
TEST_ASSERT_MBEDTLS_OK(mbedtls_ecdsa_sign(&ecdsa_context.MBEDTLS_PRIVATE(grp), &r, &s, &key_mpi, sha, SHA256_DIGEST_SZ, NULL, NULL));
esp_tee_sec_storage_ecdsa_sign_t sign = {};
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_write_binary(&r, sign.sign_r, key_len));
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_write_binary(&s, sign.sign_s, key_len));
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_write_binary(&r, sign.signature, key_len));
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_write_binary(&s, sign.signature + key_len, key_len));
TEST_ESP_OK(verify_ecdsa_sign(sha, sizeof(sha), &pubkey, &sign, is_crv_p192));
mbedtls_pk_free(&key_ctx);
esp_ecdsa_free_pk_context(&key_ctx);
mbedtls_ecdsa_free(&ecdsa_context);
mbedtls_mpi_free(&r);
mbedtls_mpi_free(&s);
@@ -11,3 +11,6 @@ CONFIG_SECURE_TEE_TEST_MODE=y
# Setting partition table
CONFIG_PARTITION_TABLE_SINGLE_APP_TEE=y
CONFIG_PARTITION_TABLE_OFFSET=0xF000
# TEE IRAM size
CONFIG_SECURE_TEE_IRAM_SIZE=0xC400
@@ -0,0 +1 @@
©œ_¶Ý“òc©/ !û¨Ž¹²º�Ʋm YÃSÌ+)vÅ—¤ רƒeS›
@@ -13,7 +13,7 @@
#include "esp_heap_caps.h"
// Some resources are lazy allocated in wifi and lwip
#define TEST_MEMORY_LEAK_THRESHOLD (-1536)
#define TEST_MEMORY_LEAK_THRESHOLD (-1596)
static size_t before_free_8bit;
static size_t before_free_32bit;
@@ -1,4 +1,3 @@
CONFIG_ESP_COREDUMP_ENABLE_TO_UART=y
CONFIG_ESP_COREDUMP_CHECKSUM_SHA256=y
CONFIG_ESP_COREDUMP_ENABLE_TO_UART=y
@@ -54,30 +54,16 @@ static void test_cbc_aes(size_t buffer_size, const uint8_t expected_cipher_end[3
// Encrypt
memcpy(nonce, iv, 16);
#ifdef SOC_AES_SUPPORT_DMA
if (is_dma) {
esp_aes_crypt_cbc(&ctx, ESP_AES_ENCRYPT, buffer_size, nonce, plaintext, ciphertext);
}
else
#endif
{
aes_crypt_cbc_block(ESP_AES_ENCRYPT, key_bits / 8, key_256, buffer_size, nonce, plaintext, ciphertext);
}
TEST_ASSERT_EQUAL(0, esp_aes_crypt_cbc(&ctx, ESP_AES_ENCRYPT, buffer_size, nonce, plaintext, ciphertext));
TEST_ASSERT_EQUAL_HEX8_ARRAY(expected_cipher_end, ciphertext + buffer_size - 32, 32);
// Decrypt
memcpy(nonce, iv, 16);
#ifdef SOC_AES_SUPPORT_DMA
if (is_dma) {
esp_aes_crypt_cbc(&ctx, ESP_AES_DECRYPT, buffer_size, nonce, ciphertext, decryptedtext);
}
else
#endif
{
aes_crypt_cbc_block(ESP_AES_DECRYPT, key_bits / 8, key_256, buffer_size, nonce, ciphertext, decryptedtext);
}
TEST_ASSERT_EQUAL(0, esp_aes_crypt_cbc(&ctx, ESP_AES_DECRYPT, buffer_size, nonce, ciphertext, decryptedtext));
TEST_ASSERT_EQUAL_HEX8_ARRAY(plaintext, decryptedtext, buffer_size);
esp_aes_free(&ctx);
// Free dynamically allocated memory
@@ -108,29 +94,13 @@ static void test_ctr_aes(size_t buffer_size, const uint8_t expected_cipher_end[3
// Encrypt
memcpy(nonce, iv, 16);
#ifdef SOC_AES_SUPPORT_DMA
if (is_dma) {
esp_aes_crypt_ctr(&ctx, buffer_size, &nc_off, nonce, stream_block, plaintext, ciphertext);
}
else
#endif
{
aes_crypt_ctr_block(key_bits / 8, key_256, buffer_size, &nc_off, nonce, stream_block, plaintext, ciphertext);
}
TEST_ASSERT_EQUAL(0, esp_aes_crypt_ctr(&ctx, buffer_size, &nc_off, nonce, stream_block, plaintext, ciphertext));
TEST_ASSERT_EQUAL_HEX8_ARRAY(expected_cipher_end, ciphertext + buffer_size - 32, 32);
// Decrypt
memcpy(nonce, iv, 16);
nc_off = 0;
#ifdef SOC_AES_SUPPORT_DMA
if (is_dma) {
esp_aes_crypt_ctr(&ctx, buffer_size, &nc_off, nonce, stream_block, ciphertext, decryptedtext);
}
else
#endif
{
aes_crypt_ctr_block(key_bits / 8, key_256, buffer_size, &nc_off, nonce, stream_block, ciphertext, decryptedtext);
}
TEST_ASSERT_EQUAL(0, esp_aes_crypt_ctr(&ctx, buffer_size, &nc_off, nonce, stream_block, ciphertext, decryptedtext));
TEST_ASSERT_EQUAL_HEX8_ARRAY(plaintext, decryptedtext, buffer_size);
esp_aes_free(&ctx);
@@ -163,13 +133,13 @@ static void test_ofb_aes(size_t buffer_size, const uint8_t expected_cipher_end[3
// Encrypt
memcpy(nonce, iv, 16);
esp_aes_crypt_ofb(&ctx, buffer_size, &nc_off, nonce, plaintext, ciphertext);
TEST_ASSERT_EQUAL(0, esp_aes_crypt_ofb(&ctx, buffer_size, &nc_off, nonce, plaintext, ciphertext));
TEST_ASSERT_EQUAL_HEX8_ARRAY(expected_cipher_end, ciphertext + buffer_size - 32, 32);
// Decrypt
memcpy(nonce, iv, 16);
nc_off = 0;
esp_aes_crypt_ofb(&ctx, buffer_size, &nc_off, nonce, ciphertext, decryptedtext);
TEST_ASSERT_EQUAL(0, esp_aes_crypt_ofb(&ctx, buffer_size, &nc_off, nonce, ciphertext, decryptedtext));
TEST_ASSERT_EQUAL_HEX8_ARRAY(plaintext, decryptedtext, buffer_size);
esp_aes_free(&ctx);
@@ -200,12 +170,12 @@ static void test_cfb8_aes(size_t buffer_size, const uint8_t expected_cipher_end[
// Encrypt
memcpy(nonce, iv, 16);
esp_aes_crypt_cfb8(&ctx, ESP_AES_ENCRYPT, buffer_size, nonce, plaintext, ciphertext);
TEST_ASSERT_EQUAL(0, esp_aes_crypt_cfb8(&ctx, ESP_AES_ENCRYPT, buffer_size, nonce, plaintext, ciphertext));
TEST_ASSERT_EQUAL_HEX8_ARRAY(expected_cipher_end, ciphertext + buffer_size - 32, 32);
// Decrypt
memcpy(nonce, iv, 16);
esp_aes_crypt_cfb8(&ctx, ESP_AES_DECRYPT, buffer_size, nonce, ciphertext, decryptedtext);
TEST_ASSERT_EQUAL(0, esp_aes_crypt_cfb8(&ctx, ESP_AES_DECRYPT, buffer_size, nonce, ciphertext, decryptedtext));
TEST_ASSERT_EQUAL_HEX8_ARRAY(plaintext, decryptedtext, buffer_size);
esp_aes_free(&ctx);
@@ -237,13 +207,13 @@ static void test_cfb128_aes(size_t buffer_size, const uint8_t expected_cipher_en
// Encrypt
memcpy(nonce, iv, 16);
esp_aes_crypt_cfb128(&ctx, ESP_AES_ENCRYPT, buffer_size, &nc_off, nonce, plaintext, ciphertext);
TEST_ASSERT_EQUAL(0, esp_aes_crypt_cfb128(&ctx, ESP_AES_ENCRYPT, buffer_size, &nc_off, nonce, plaintext, ciphertext));
TEST_ASSERT_EQUAL_HEX8_ARRAY(expected_cipher_end, ciphertext + buffer_size - 32, 32);
// Decrypt
nc_off = 0;
memcpy(nonce, iv, 16);
esp_aes_crypt_cfb128(&ctx, ESP_AES_DECRYPT, buffer_size, &nc_off, nonce, ciphertext, decryptedtext);
TEST_ASSERT_EQUAL(0, esp_aes_crypt_cfb128(&ctx, ESP_AES_DECRYPT, buffer_size, &nc_off, nonce, ciphertext, decryptedtext));
TEST_ASSERT_EQUAL_HEX8_ARRAY(plaintext, decryptedtext, buffer_size);
esp_aes_free(&ctx);
@@ -305,7 +275,6 @@ static void test_gcm_aes(size_t length, const uint8_t expected_last_block[16], c
}
#endif /* SOC_GCM_SUPPORTED */
#endif /* SOC_AES_SUPPORT_DMA */
#endif // CONFIG_SOC_AES_SUPPORT_GCM
TEST(aes, cbc_aes_256_block_test)
{
@@ -405,7 +374,6 @@ TEST(aes, gcm_aes_long_dma_test)
#endif /* CONFIG_CRYPTO_TESTAPP_USE_AES_INTERRUPT */
#endif /* SOC_GCM_SUPPORTED */
#endif /* SOC_AES_SUPPORT_DMA */
#endif /* CONFIG_SOC_AES_SUPPORT_GCM */
TEST_GROUP_RUNNER(aes)
{
@@ -252,7 +252,7 @@ _test_panic_handler:
/* Executing the panic handler */
li t0, 0xDEADC0DE
csrr t0, mscratch
csrw mscratch, t0
mv a0, sp
csrr a1, mcause
li t0, VECTORS_MCAUSE_REASON_MASK
@@ -76,35 +76,29 @@ static const uint32_t test_peri_apm_lp_peri_reg[] = {
BIT64(APM_TEE_LP_PERIPH_LP_PERI) | \
BIT64(APM_TEE_LP_PERIPH_LP_APM))
IRAM_ATTR static uint32_t reg_read(uint32_t addr)
FORCE_INLINE_ATTR uint32_t reg_read(uint32_t addr)
{
uint32_t val;
asm volatile (
"li t0, 0x100\n"
"lw %0, 0(%1)\n"
"1:\n"
"nop\n"
"addi t0, t0, -1\n"
"bnez t0, 1b\n"
: "=r"(val)
uint32_t value;
__asm__ volatile (
"lw %0, 0(%1)\n"
"fence\n"
"nop\nnop\nnop\nnop\n"
: "=r"(value)
: "r"(addr)
: "t0", "memory"
: "memory"
);
return val;
return value;
}
IRAM_ATTR static void reg_write(uint32_t addr, uint32_t value)
FORCE_INLINE_ATTR void reg_write(uint32_t addr, uint32_t value)
{
asm volatile (
"li t0, 0x100\n"
"sw %1, 0(%0)\n"
"1:\n"
"nop\n"
"addi t0, t0, -1\n"
"bnez t0, 1b\n"
__asm__ volatile (
"sw %1, 0(%0)\n"
"fence\n"
"nop\nnop\nnop\nnop\n"
:
: "r"(addr), "r"(value)
: "t0", "memory"
: "memory"
);
}
@@ -58,4 +58,4 @@ def test_tee_peri_apm(dut: IdfDut) -> None:
indirect=['config', 'target'],
)
def test_tee_interrupts(dut: IdfDut) -> None:
dut.run_all_single_board_cases()
dut.run_all_single_board_cases(group='CPU')
+40 -23
View File
@@ -28,7 +28,12 @@ if(NOT ${IDF_TARGET} STREQUAL "linux")
endif()
set(mbedtls_srcs "")
set(mbedtls_include_dirs "port/include" "mbedtls/include" "mbedtls/library")
set(mbedtls_include_dirs
"port/include"
"mbedtls/include"
"mbedtls/library"
"mbedtls/tf-psa-crypto/core"
"mbedtls/tf-psa-crypto/drivers/builtin/src/")
if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL)
list(APPEND mbedtls_include_dirs "port/mbedtls_rom")
@@ -177,6 +182,8 @@ endif()
# Core libraries from the mbedTLS project
set(mbedtls_targets mbedtls mbedx509 tfpsacrypto builtin)
target_include_directories(tfpsacrypto PUBLIC "port/include")
if(CONFIG_MBEDTLS_HARDWARE_SHA OR CONFIG_MBEDTLS_HARDWARE_AES)
list(APPEND include_dirs "${COMPONENT_DIR}/port/psa_driver/include")
target_include_directories(tfpsacrypto PUBLIC "${COMPONENT_DIR}/port/psa_driver/include")
@@ -203,6 +210,10 @@ list(APPEND mbedtls_targets everest p256m)
set(mbedtls_target_sources "${COMPONENT_DIR}/port/mbedtls_debug.c"
"${COMPONENT_DIR}/port/esp_platform_time.c")
if(CONFIG_MBEDTLS_VER_4_X_SUPPORT)
list(APPEND mbedtls_target_sources "${COMPONENT_DIR}/port/esp_psa_crypto_init.c")
endif()
if(CONFIG_MBEDTLS_DYNAMIC_BUFFER)
set(mbedtls_target_sources ${mbedtls_target_sources}
"${COMPONENT_DIR}/port/dynamic/esp_mbedtls_dynamic_impl.c"
@@ -309,7 +320,7 @@ if(CONFIG_SOC_AES_SUPPORTED)
target_include_directories(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/aes/include")
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/aes/esp_aes_xts.c"
"${COMPONENT_DIR}/port/aes/esp_aes_common.c"
"${COMPONENT_DIR}/port/aes/${AES_PERIPHERAL_TYPE}/esp_aes.c"
"${COMPONENT_DIR}/port/aes/esp_aes.c"
)
endif()
@@ -329,19 +340,19 @@ if(CONFIG_SOC_SHA_SUPPORTED)
endif()
endif()
# if(CONFIG_SOC_DIG_SIGN_SUPPORTED)
# target_sources(mbedcrypto PRIVATE
# "${COMPONENT_DIR}/port/esp_ds/esp_rsa_sign_alt.c"
# "${COMPONENT_DIR}/port/esp_ds/esp_rsa_dec_alt.c"
# "${COMPONENT_DIR}/port/esp_ds/esp_ds_common.c")
# endif()
if(CONFIG_SOC_DIG_SIGN_SUPPORTED)
target_sources(tfpsacrypto PRIVATE
"${COMPONENT_DIR}/port/esp_ds/esp_rsa_sign_alt.c"
"${COMPONENT_DIR}/port/esp_ds/esp_rsa_dec_alt.c"
"${COMPONENT_DIR}/port/esp_ds/esp_ds_common.c")
endif()
# # CONFIG_ESP_TLS_USE_DS_PERIPHERAL can be enabled only for the supported targets.
# if(CONFIG_ESP_TLS_USE_DS_PERIPHERAL)
# target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/esp_ds/esp_rsa_sign_alt.c")
# endif()
if(CONFIG_ESP_TLS_USE_DS_PERIPHERAL)
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/esp_ds/esp_rsa_sign_alt.c")
endif()
if(CONFIG_SOC_HMAC_SUPPORTED)
target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/esp_hmac_pbkdf2.c")
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/esp_hmac_pbkdf2.c")
endif()
# Note: some mbedTLS hardware acceleration can be enabled/disabled by config.
@@ -366,9 +377,11 @@ endif()
if(CONFIG_MBEDTLS_HARDWARE_GCM OR CONFIG_MBEDTLS_HARDWARE_AES)
target_compile_definitions(tfpsacrypto PRIVATE ESP_AES_DRIVER_ENABLED)
target_include_directories(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/include/aes")
target_sources(tfpsacrypto PRIVATE
"${COMPONENT_DIR}/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes.c"
)
if(CONFIG_MBEDTLS_HARDWARE_SHA)
target_sources(tfpsacrypto PRIVATE
"${COMPONENT_DIR}/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes.c"
"${COMPONENT_DIR}/port/psa_driver/esp_aes/psa_crypto_driver_esp_cmac.c"
)
endif()
@@ -481,23 +494,27 @@ endif()
target_link_libraries(${COMPONENT_LIB} ${linkage_type} ${mbedtls_targets})
# Ensure PSA crypto initialization is included in the build
if(NOT ${IDF_TARGET} STREQUAL "linux")
target_link_libraries(${COMPONENT_LIB} ${linkage_type} "-u mbedtls_psa_crypto_init_include_impl")
endif()
# if(CONFIG_ESP_TLS_USE_DS_PERIPHERAL)
# # The linker seems to be unable to resolve all the dependencies without increasing this
# set_property(TARGET mbedcrypto APPEND PROPERTY LINK_INTERFACE_MULTIPLICITY 6)
# endif()
# Additional optional dependencies for the mbedcrypto library
# function(mbedcrypto_optional_deps component_name)
# idf_build_get_property(components BUILD_COMPONENTS)
# if(${component_name} IN_LIST components)
# idf_component_get_property(lib_name ${component_name} COMPONENT_LIB)
# target_link_libraries(mbedcrypto PRIVATE ${lib_name})
# endif()
# endfunction()
function(builtin_optional_deps component_name)
idf_build_get_property(components BUILD_COMPONENTS)
if(${component_name} IN_LIST components)
idf_component_get_property(lib_name ${component_name} COMPONENT_LIB)
target_link_libraries(builtin PRIVATE ${lib_name})
endif()
endfunction()
# if(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN_CONSTANT_TIME_CM)
# mbedcrypto_optional_deps(esp_timer idf::esp_timer)
# endif()
if(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN_CONSTANT_TIME_CM)
builtin_optional_deps(esp_timer idf::esp_timer)
endif()
# # Link esp-cryptoauthlib to mbedtls
# if(CONFIG_ATCA_MBEDTLS_ECDSA)
+25 -16
View File
@@ -1,6 +1,15 @@
menu "mbedTLS"
menu "Core Configuration"
config MBEDTLS_VER_4_X_SUPPORT
depends on IDF_EXPERIMENTAL_FEATURES
bool "Enable support for mbedTLS version 4.x and the PSA cryptography API for ESP-IDF"
default y
help
Enable support for mbedTLS version 4.x and the PSA cryptography API for ESP-IDF.
This option migrates from mbedtls API to PSA Crypto API. This increases code size and is experimental.
choice MBEDTLS_COMPILER_OPTIMIZATION
prompt "Compiler optimization level"
default MBEDTLS_COMPILER_OPTIMIZATION_SIZE
@@ -693,7 +702,7 @@ menu "mbedTLS"
config MBEDTLS_KEY_EXCHANGE_DHE_PSK
bool "Enable DHE-PSK based ciphersuite modes"
depends on MBEDTLS_PSK_MODES && MBEDTLS_DHM_C
default y
default n
help
Enable to support Diffie-Hellman PSK (pre-shared-key) TLS authentication modes.
@@ -707,7 +716,7 @@ menu "mbedTLS"
config MBEDTLS_KEY_EXCHANGE_RSA_PSK
bool "Enable RSA-PSK based ciphersuite modes"
depends on MBEDTLS_PSK_MODES
default y
default n
help
Enable to support RSA PSK (pre-shared-key) TLS authentication modes.
@@ -719,7 +728,7 @@ menu "mbedTLS"
config MBEDTLS_KEY_EXCHANGE_DHE_RSA
bool "Enable DHE-RSA based ciphersuite modes"
default y
default n
depends on MBEDTLS_DHM_C
help
Enable to support ciphersuites with prefix TLS-DHE-RSA-WITH-
@@ -1411,7 +1420,7 @@ menu "mbedTLS"
menu "Hardware Acceleration"
config MBEDTLS_HARDWARE_ECDSA_VERIFY
bool "Enable ECDSA signature verification using on-chip ECDSA peripheral"
default n
default y
depends on SOC_ECDSA_SUPPORTED
help
Enable hardware accelerated ECDSA peripheral to verify signature
@@ -1423,7 +1432,7 @@ menu "mbedTLS"
config MBEDTLS_HARDWARE_ECDSA_SIGN_MASKING_CM
bool "Mask original ECDSA sign operation under dummy sign operations"
select HAL_ECDSA_GEN_SIG_CM
default n
default y
help
The ECDSA peripheral before ESP32-H2 v1.2 does not offer constant time ECDSA sign operation.
This time can be observed through power profiling of the device,
@@ -1436,7 +1445,7 @@ menu "mbedTLS"
config MBEDTLS_HARDWARE_ECDSA_SIGN_CONSTANT_TIME_CM
bool "Make ECDSA signature operation pseudo constant time for software"
default n
default y
help
This option adds a delay after the actual ECDSA signature operation
so that the entire operation appears to be constant  time for the software.
@@ -1466,12 +1475,12 @@ menu "mbedTLS"
config MBEDTLS_TEE_SEC_STG_ECDSA_SIGN
bool "Enable ECDSA signing using TEE secure storage"
default n
default y
depends on SECURE_ENABLE_TEE
config MBEDTLS_HARDWARE_ECC
bool "Enable hardware ECC acceleration"
default n
default y
depends on SOC_ECC_SUPPORTED
help
Enable hardware accelerated ECC point multiplication and point verification for points
@@ -1480,7 +1489,7 @@ menu "mbedTLS"
config MBEDTLS_ECC_OTHER_CURVES_SOFT_FALLBACK
bool "Fallback to software implementation for curves not supported in hardware"
depends on MBEDTLS_HARDWARE_ECC
default n
default y
help
Fallback to software implementation of ECC point multiplication and point verification
for curves not supported in hardware.
@@ -1517,7 +1526,7 @@ menu "mbedTLS"
bool "Fallback to software implementation for larger MPI values"
depends on MBEDTLS_HARDWARE_MPI
default y if SOC_RSA_MAX_BIT_LEN <= 3072 # HW max 3072 bits
default n
default y
help
Fallback to software implementation for RSA key lengths
larger than SOC_RSA_MAX_BIT_LEN. If this is not active
@@ -1527,7 +1536,7 @@ menu "mbedTLS"
config MBEDTLS_MPI_USE_INTERRUPT
bool "Use interrupt for MPI exp-mod operations"
depends on !IDF_TARGET_ESP32 && MBEDTLS_HARDWARE_MPI
default n
default y
help
Use an interrupt to coordinate long MPI operations.
@@ -1558,7 +1567,7 @@ menu "mbedTLS"
config MBEDTLS_HARDWARE_GCM
bool "Enable partially hardware accelerated GCM"
depends on SOC_AES_SUPPORT_GCM && MBEDTLS_HARDWARE_AES
default n
default y
help
Enable partially hardware accelerated GCM. GHASH calculation is still done
in software.
@@ -1570,7 +1579,7 @@ menu "mbedTLS"
config MBEDTLS_GCM_SUPPORT_NON_AES_CIPHER
bool "Enable support for non-AES ciphers in GCM operation"
depends on MBEDTLS_HARDWARE_AES
default n
default y
help
Enable this config to support fallback to software definitions for a non-AES
cipher GCM operation as we support hardware acceleration only for AES cipher.
@@ -1593,7 +1602,7 @@ menu "mbedTLS"
config MBEDTLS_AES_USE_INTERRUPT
bool "Use interrupt for long AES operations"
depends on !IDF_TARGET_ESP32 && MBEDTLS_HARDWARE_AES
default n
default y
help
Use an interrupt to coordinate long AES operations.
@@ -1776,7 +1785,7 @@ menu "mbedTLS"
config MBEDTLS_USE_CRYPTO_ROM_IMPL_BOOTLOADER
bool "Use ROM implementation of the crypto algorithm in the bootloader"
depends on ESP_ROM_HAS_MBEDTLS_CRYPTO_LIB
depends on ESP_ROM_HAS_MBEDTLS_CRYPTO_LIB && !MBEDTLS_VER_4_X_SUPPORT
default "n"
select MBEDTLS_AES_C
help
@@ -1787,7 +1796,7 @@ menu "mbedTLS"
config MBEDTLS_USE_CRYPTO_ROM_IMPL
bool "Use ROM implementation of the crypto algorithm"
depends on ESP_ROM_HAS_MBEDTLS_CRYPTO_LIB
depends on ESP_ROM_HAS_MBEDTLS_CRYPTO_LIB && !MBEDTLS_VER_4_X_SUPPORT
default "n"
select MBEDTLS_SHA512_C
select MBEDTLS_AES_C
@@ -60,7 +60,7 @@ CONFIG_MBEDTLS_CIPHER_PADDING_ZEROS=n
CONFIG_MBEDTLS_AES_FEWER_TABLES=y
# Elliptic Curve Ciphers Configuration
CONFIG_MBEDTLS_ECP_NIST_OPTIM=n
CONFIG_MBEDTLS_ECP_NIST_OPTIM=y
CONFIG_MBEDTLS_DHM_C=n
CONFIG_MBEDTLS_ECDSA_C=y
CONFIG_MBEDTLS_PK_PARSE_EC_EXTENDED=n
@@ -89,7 +89,7 @@ CONFIG_MBEDTLS_GENPRIME=y
CONFIG_MBEDTLS_PKCS12_C=n
CONFIG_MBEDTLS_PKCS1_V21=n
CONFIG_MBEDTLS_ENTROPY_FORCE_SHA256=y
CONFIG_MBEDTLS_ENTROPY_FORCE_SHA256=n
CONFIG_MBEDTLS_CTR_DRBG_C=y
CONFIG_ESP_WIFI_MBEDTLS_TLS_CLIENT=n
@@ -166,15 +166,15 @@ CONFIG_MBEDTLS_GCM_SUPPORT_NON_AES_CIPHER=y
CONFIG_MBEDTLS_HARDWARE_AES=y
CONFIG_MBEDTLS_AES_USE_INTERRUPT=y
CONFIG_MBEDTLS_AES_INTERRUPT_LEVEL=0
CONFIG_MBEDTLS_PK_RSA_ALT_SUPPORT=y
CONFIG_MBEDTLS_HARDWARE_MPI=y
CONFIG_MBEDTLS_PK_RSA_ALT_SUPPORT=n
CONFIG_MBEDTLS_HARDWARE_MPI=n
# CONFIG_MBEDTLS_LARGE_KEY_SOFTWARE_MPI=n
CONFIG_MBEDTLS_MPI_USE_INTERRUPT=y
CONFIG_MBEDTLS_MPI_INTERRUPT_LEVEL=0
CONFIG_MBEDTLS_HARDWARE_ECC=y
CONFIG_MBEDTLS_ECC_OTHER_CURVES_SOFT_FALLBACK=y
CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN=n
CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY=y
CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY=n
CONFIG_MBEDTLS_ATCA_HW_ECDSA_SIGN=n
CONFIG_MBEDTLS_ATCA_HW_ECDSA_VERIFY=n
@@ -17,6 +17,9 @@
#include "sdkconfig.h"
#include "psa/crypto.h"
#include "mbedtls/psa_util.h"
/*
Format of certificate bundle:
First, n uint32 "offset" entries, each describing the start of one certificate's data in terms of
@@ -131,6 +134,10 @@ static int esp_crt_check_signature(const mbedtls_x509_crt* child, const uint8_t*
int ret = 0;
mbedtls_pk_context pubkey;
const mbedtls_md_info_t *md_info;
psa_key_id_t key_id = 0;
psa_status_t status;
psa_key_attributes_t key_attr = PSA_KEY_ATTRIBUTES_INIT;
bool key_imported = false;
mbedtls_pk_init(&pubkey);
@@ -139,37 +146,125 @@ static int esp_crt_check_signature(const mbedtls_x509_crt* child, const uint8_t*
goto cleanup;
}
// Fast check to avoid expensive computations when not necessary
if (unlikely(!mbedtls_pk_can_do(&pubkey, child->MBEDTLS_PRIVATE(sig_pk)))) {
ESP_LOGE(TAG, "Unsuitable public key");
ret = MBEDTLS_ERR_PK_TYPE_MISMATCH;
goto cleanup;
}
// Get the message digest info for the hash algorithm used in the certificate
// We need to know this BEFORE importing the key so we can set the correct algorithm
md_info = mbedtls_md_info_from_type(child->MBEDTLS_PRIVATE(sig_md));
if (unlikely(md_info == NULL)) {
ESP_LOGE(TAG, "Unknown message digest");
ESP_LOGE(TAG, "Unknown message digest type: %d", child->MBEDTLS_PRIVATE(sig_md));
ret = MBEDTLS_ERR_X509_FEATURE_UNAVAILABLE;
goto cleanup;
}
// Map mbedTLS MD type to PSA hash algorithm
psa_algorithm_t psa_hash_alg;
switch (child->MBEDTLS_PRIVATE(sig_md)) {
case MBEDTLS_MD_SHA256:
psa_hash_alg = PSA_ALG_SHA_256;
break;
case MBEDTLS_MD_SHA384:
psa_hash_alg = PSA_ALG_SHA_384;
break;
case MBEDTLS_MD_SHA512:
psa_hash_alg = PSA_ALG_SHA_512;
break;
case MBEDTLS_MD_SHA1:
psa_hash_alg = PSA_ALG_SHA_1;
break;
default:
ESP_LOGE(TAG, "Unsupported hash algorithm: %d", child->MBEDTLS_PRIVATE(sig_md));
ret = MBEDTLS_ERR_X509_FEATURE_UNAVAILABLE;
goto cleanup;
}
// Get the appropriate key attributes for signature verification
ret = mbedtls_pk_get_psa_attributes(&pubkey, PSA_KEY_USAGE_VERIFY_HASH, &key_attr);
if (unlikely(ret != 0)) {
ESP_LOGE(TAG, "Failed to get PSA key attributes with error 0x%x", -ret);
goto cleanup;
}
// Determine the PSA algorithm based on the key type and hash type
// We need to set this BEFORE importing the key
psa_algorithm_t psa_alg;
psa_key_type_t key_type = psa_get_key_type(&key_attr);
ESP_LOGD(TAG, "Key type: 0x%x, Hash alg: 0x%x",
(unsigned int)key_type, (unsigned int)psa_hash_alg);
if (PSA_KEY_TYPE_IS_RSA(key_type)) {
// For RSA keys, use PKCS#1 v1.5 with the specific hash algorithm
psa_alg = PSA_ALG_RSA_PKCS1V15_SIGN(psa_hash_alg);
ESP_LOGD(TAG, "Using RSA PKCS1V15 SIGN algorithm with hash");
} else if (PSA_KEY_TYPE_IS_ECC(key_type)) {
// For ECC keys, use ECDSA_ANY which works with psa_verify_hash
// and doesn't constrain the hash length
psa_alg = PSA_ALG_ECDSA_ANY;
ESP_LOGD(TAG, "Using ECDSA_ANY algorithm (no hash constraint)");
} else {
ESP_LOGE(TAG, "Unsupported key type: 0x%x", (unsigned int)key_type);
ret = MBEDTLS_ERR_PK_TYPE_MISMATCH;
goto cleanup;
}
// Override the algorithm in key attributes with the specific hash algorithm
// This is required because PSA_ALG_ANY_HASH wildcard doesn't work for verification
psa_set_key_algorithm(&key_attr, psa_alg);
// Import the public key into PSA
ret = mbedtls_pk_import_into_psa(&pubkey, &key_attr, &key_id);
if (unlikely(ret != 0)) {
ESP_LOGE(TAG, "Failed to import key into PSA with error 0x%x", -ret);
goto cleanup;
}
key_imported = true;
unsigned char hash[MBEDTLS_MD_MAX_SIZE];
const unsigned char md_size = mbedtls_md_get_size(md_info);
if ((ret = mbedtls_md(md_info, child->tbs.p, child->tbs.len, hash)) != 0) {
ESP_LOGE(TAG, "MD failed with error 0x%x", -ret);
size_t hash_len = 0;
status = psa_hash_compute(psa_hash_alg, child->tbs.p, child->tbs.len, hash, sizeof(hash), &hash_len);
unsigned char *sig_ptr = child->MBEDTLS_PRIVATE(sig).p;
size_t sig_len = child->MBEDTLS_PRIVATE(sig).len;
unsigned char raw_sig[MBEDTLS_ECDSA_MAX_LEN];
if (PSA_KEY_TYPE_IS_ECC(key_type)) {
// Convert DER-encoded ECDSA signature to raw (r||s) format for PSA
// Get the key size in bits from PSA attributes
size_t key_bits = psa_get_key_bits(&key_attr);
ret = mbedtls_ecdsa_der_to_raw(key_bits,
child->MBEDTLS_PRIVATE(sig).p,
child->MBEDTLS_PRIVATE(sig).len,
raw_sig, sizeof(raw_sig), &sig_len);
if (ret != 0) {
ESP_LOGE(TAG, "Failed to convert ECDSA signature to raw format: 0x%x (returned %d)", -ret, ret);
ret = MBEDTLS_ERR_X509_INVALID_SIGNATURE;
goto cleanup;
}
sig_ptr = raw_sig;
ESP_LOGD(TAG, "Converted DER signature (len=%zu) to raw format (len=%zu) for %zu-bit key",
child->MBEDTLS_PRIVATE(sig).len, sig_len, key_bits);
}
// Verify the signature using PSA with the correct algorithm
ESP_LOGD(TAG, "Verifying signature: alg=0x%08x, hash_len=%d, sig_len=%zu",
(unsigned int)psa_alg, md_size, sig_len);
status = psa_verify_hash(key_id, psa_alg, hash, md_size, sig_ptr, sig_len);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "PSA signature verification failed with error 0x%x (decimal: %d)",
(unsigned int)status, (int)status);
ret = MBEDTLS_ERR_X509_INVALID_SIGNATURE;
goto cleanup;
}
if (unlikely((ret = mbedtls_pk_verify_ext(child->MBEDTLS_PRIVATE(sig_pk), NULL, &pubkey,
child->MBEDTLS_PRIVATE(sig_md), hash, md_size,
child->MBEDTLS_PRIVATE(sig).p, child->MBEDTLS_PRIVATE(sig).len)) != 0)) {
ESP_LOGE(TAG, "PK verify failed with error 0x%x", -ret);
goto cleanup;
}
ret = 0;
ESP_LOGD(TAG, "Certificate signature verified successfully");
cleanup:
if (key_imported) {
psa_destroy_key(key_id);
}
psa_reset_key_attributes(&key_attr);
mbedtls_pk_free(&pubkey);
return ret;
}
@@ -229,7 +324,6 @@ int esp_crt_verify_callback(void *buf, mbedtls_x509_crt* const crt, const int de
return 0;
}
if (unlikely(s_crt_bundle == NULL)) {
ESP_LOGE(TAG, "No certificates in bundle");
return MBEDTLS_ERR_X509_FATAL_ERROR;
@@ -405,7 +499,8 @@ static int esp_crt_ca_cb_callback(void *ctx, mbedtls_x509_crt const *child, mbed
uint16_t cert_key_len = esp_crt_get_key_len(cert);
// Set the public key in the new certificate
mbedtls_pk_init(&new_cert->pk);
int ret = mbedtls_pk_parse_subpubkey((unsigned char **)&cert_key, cert_key + cert_key_len, &new_cert->pk);
// Use mbedtls_pk_parse_public_key() instead of deprecated mbedtls_pk_parse_subpubkey()
int ret = mbedtls_pk_parse_public_key(&new_cert->pk, cert_key, cert_key_len);
if (ret != 0) {
ESP_LOGE(TAG, "Failed to parse public key from certificate: %d", ret);
mbedtls_x509_crt_free(new_cert);
@@ -7,7 +7,7 @@
#include "esp_err.h"
#include "mbedtls/aes.h"
// #include "mbedtls/aes.h"
#include "esp_crypto_dma.h"
#include "soc/soc_caps.h"
@@ -31,11 +31,35 @@ include_directories("${COMPONENT_DIR}/port/include")
# Import mbedtls library targets
add_subdirectory(mbedtls)
set(mbedtls_targets tfpsacrypto builtin)
# Set TF_PSA_CRYPTO_CONFIG_FILE before processing subdirectories to prevent override
set(
TF_PSA_CRYPTO_USER_CONFIG_FILE "${COMPONENT_DIR}/esp_tee/esp_tee_mbedtls_config.h"
CACHE STRING "Path to the PSA Crypto configuration file"
FORCE
)
set(mbedtls_targets mbedtls tfpsacrypto builtin mbedx509 everest p256m)
if(NOT ${IDF_TARGET} STREQUAL "linux")
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/esp_hardware.c")
else()
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/linux_hardware.c")
endif()
foreach(target ${mbedtls_targets})
target_compile_definitions(${target} PUBLIC
-DMBEDTLS_CONFIG_FILE="${COMPONENT_DIR}/esp_tee/esp_tee_mbedtls_config.h")
set_config_files_compile_definitions(${target})
target_compile_definitions(${target} PUBLIC MBEDTLS_MAJOR_VERSION=4)
if(CONFIG_COMPILER_STATIC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU") # TODO IDF-10087
target_compile_options(${target} PRIVATE "-fno-analyzer")
endif()
if(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SIZE)
message(STATUS "Setting -Os for ${target}")
target_compile_options(${target} PRIVATE "-Os")
elseif(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_PERF)
target_compile_options(${target} PRIVATE "-O2")
endif()
endforeach()
target_link_libraries(${COMPONENT_LIB} INTERFACE ${mbedtls_targets})
@@ -46,27 +70,54 @@ target_include_directories(tfpsacrypto PRIVATE ${crypto_port_inc_dirs})
# Shared GDMA layer for TEE
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/esp_tee/esp_tee_crypto_shared_gdma.c")
target_include_directories(tfpsacrypto PUBLIC "${COMPONENT_DIR}/port/psa_driver/include")
# AES implementation
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/aes/dma/esp_aes.c"
"${COMPONENT_DIR}/port/aes/dma/esp_aes_dma_core.c")
if(CONFIG_SOC_AES_SUPPORTED)
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/aes/esp_aes.c"
"${COMPONENT_DIR}/port/aes/dma/esp_aes_dma_core.c")
if(CONFIG_MBEDTLS_HARDWARE_GCM OR CONFIG_MBEDTLS_HARDWARE_AES)
target_compile_definitions(tfpsacrypto PRIVATE ESP_AES_DRIVER_ENABLED)
target_include_directories(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/include/aes")
if(CONFIG_MBEDTLS_HARDWARE_SHA)
target_sources(tfpsacrypto PRIVATE
"${COMPONENT_DIR}/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes.c"
"${COMPONENT_DIR}/port/psa_driver/esp_aes/psa_crypto_driver_esp_cmac.c"
)
endif()
if(CONFIG_SOC_AES_SUPPORT_GCM)
target_sources(tfpsacrypto PRIVATE "$ENV{IDF_PATH}/components/mbedtls/port/aes/esp_aes_gcm.c"
"${COMPONENT_DIR}/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes_gcm.c")
endif()
endif()
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/aes/esp_aes_common.c"
"${COMPONENT_DIR}/port/aes/esp_aes_xts.c"
"${COMPONENT_DIR}/port/aes/esp_aes_gcm.c")
# SHA implementation
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/sha/core/esp_sha1.c"
"${COMPONENT_DIR}/port/sha/core/esp_sha256.c"
"${COMPONENT_DIR}/port/sha/core/esp_sha512.c")
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/sha/core/sha.c"
"${COMPONENT_DIR}/port/sha/esp_sha.c")
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/ecc/esp_ecc.c"
"${COMPONENT_DIR}/port/ecc/ecc_alt.c")
# HMAC-based PBKDF2 implementation
if(CONFIG_SOC_HMAC_SUPPORTED)
target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/esp_hmac_pbkdf2.c")
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/aes/esp_aes_common.c"
"${COMPONENT_DIR}/port/aes/esp_aes_xts.c"
"${COMPONENT_DIR}/port/aes/esp_aes_gcm.c")
endif()
# SHA implementation
if(CONFIG_SOC_SHA_SUPPORTED)
target_compile_definitions(tfpsacrypto PRIVATE ESP_SHA_DRIVER_ENABLED)
target_sources(tfpsacrypto PRIVATE
"${COMPONENT_DIR}/port/psa_driver/esp_sha/psa_crypto_driver_esp_sha.c"
"${COMPONENT_DIR}/port/psa_driver/esp_sha/core/psa_crypto_driver_esp_sha1.c"
"${COMPONENT_DIR}/port/psa_driver/esp_sha/core/psa_crypto_driver_esp_sha256.c"
"${COMPONENT_DIR}/port/psa_driver/esp_sha/core/psa_crypto_driver_esp_sha512.c"
"${COMPONENT_DIR}/port/sha/core/sha.c"
"${COMPONENT_DIR}/port/sha/esp_sha.c")
endif()
# target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/sha/core/esp_sha1.c"
# "${COMPONENT_DIR}/port/sha/core/esp_sha256.c"
# "${COMPONENT_DIR}/port/sha/core/esp_sha512.c")
# target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/sha/core/sha.c"
# "${COMPONENT_DIR}/port/sha/esp_sha.c")
if(CONFIG_SOC_ECC_SUPPORTED)
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/ecc/esp_ecc.c"
"${COMPONENT_DIR}/port/ecc/ecc_alt.c")
endif()
if(CONFIG_SOC_HMAC_SUPPORTED)
# HMAC-based PBKDF2 implementation
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/esp_hmac_pbkdf2.c")
endif()
@@ -28,21 +28,27 @@
#ifndef ESP_TEE_MBEDTLS_CONFIG_H
#define ESP_TEE_MBEDTLS_CONFIG_H
#define MBEDTLS_NO_PLATFORM_ENTROPY
#define MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS
#ifndef CONFIG_IDF_TARGET_LINUX
#undef MBEDTLS_PSA_BUILTIN_GET_ENTROPY
#define MBEDTLS_PSA_DRIVER_GET_ENTROPY
#define MBEDTLS_PLATFORM_GET_ENTROPY_ALT
#define MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG
#endif // !CONFIG_IDF_TARGET_LINUX
#undef MBEDTLS_PSA_KEY_STORE_DYNAMIC
// #define MBEDTLS_NO_PLATFORM_ENTROPY
#define MBEDTLS_HAVE_TIME
#define MBEDTLS_PLATFORM_MS_TIME_ALT
#undef MBEDTLS_TIMING_C
#define MBEDTLS_PLATFORM_C
#define MBEDTLS_CIPHER_C
#define MBEDTLS_AES_C
#define MBEDTLS_GCM_C
#if SOC_AES_SUPPORTED
#define MBEDTLS_AES_ALT
#define MBEDTLS_GCM_ALT
#else
#define MBEDTLS_AES_ROM_TABLES
#endif
// #define MBEDTLS_CIPHER_C
// #define MBEDTLS_AES_C
// #define MBEDTLS_GCM_C
// #define MBEDTLS_AES_ALT
#define MBEDTLS_PSA_ACCEL_KEY_TYPE_AES
// #define MBEDTLS_GCM_ALT
#define MBEDTLS_CIPHER_MODE_XTS
#define MBEDTLS_ASN1_WRITE_C
@@ -61,18 +67,43 @@
#define MBEDTLS_SHA224_C
#define MBEDTLS_SHA256_C
#if SOC_SHA_SUPPORT_SHA512 && CONFIG_MBEDTLS_SHA512_C
#define MBEDTLS_SHA384_C
#define MBEDTLS_SHA512_C
// #define MBEDTLS_SHA384_C
// #define MBEDTLS_SHA512_C
#endif
#if SOC_SHA_SUPPORTED
#if CONFIG_MBEDTLS_SHA1_C
#define MBEDTLS_SHA1_ALT
#endif
#define MBEDTLS_SHA256_ALT
#if SOC_SHA_SUPPORT_SHA512 && CONFIG_MBEDTLS_SHA512_C
#define MBEDTLS_SHA512_ALT
// #define MBEDTLS_SHA1_ALT
#define MBEDTLS_PSA_ACCEL_ALG_SHA_1
#undef MBEDTLS_PSA_BUILTIN_ALG_SHA_1
#undef MBEDTLS_SHA1_C
#endif
// #define MBEDTLS_SHA256_ALT
#undef MBEDTLS_PSA_BUILTIN_ALG_SHA_224
#undef MBEDTLS_SHA224_C
#define MBEDTLS_PSA_ACCEL_ALG_SHA_224
#undef MBEDTLS_PSA_BUILTIN_ALG_SHA_256
#define MBEDTLS_PSA_ACCEL_ALG_SHA_256
#undef MBEDTLS_SHA256_C
// #if SOC_SHA_SUPPORT_SHA512 && CONFIG_MBEDTLS_SHA512_C
// #define MBEDTLS_SHA512_ALT
// #undef MBEDTLS_PSA_BUILTIN_ALG_SHA_384
// #undef MBEDTLS_SHA384_C
// #define MBEDTLS_PSA_ACCEL_ALG_SHA_384
// #undef MBEDTLS_PSA_BUILTIN_ALG_SHA_512
// #define MBEDTLS_PSA_ACCEL_ALG_SHA_512
// #undef MBEDTLS_SHA512_C
// #else
// #undef MBEDTLS_SHA512_ALT
// #undef MBEDTLS_SHA384_ALT
// #define MBEDTLS_SHA512_C
// #define MBEDTLS_SHA384_C
// #define PSA_WANT_ALG_SHA_384 1
// #define PSA_WANT_ALG_SHA_512 1
// #define MBEDTLS_PSA_BUILTIN_ALG_SHA_384 1
// #define MBEDTLS_PSA_BUILTIN_ALG_SHA_512 1
// #endif
#endif
#if SOC_ECC_SUPPORTED
@@ -80,10 +111,72 @@
#define MBEDTLS_ECP_VERIFY_ALT
#endif
#if !SOC_HMAC_SUPPORTED
#define MBEDTLS_MD_C
#endif
// #define MBEDTLS_ENTROPY_C
#define MBEDTLS_ENTROPY_C
#undef PSA_WANT_ECC_SECP_K1_192
#undef PSA_WANT_ECC_SECP_K1_256
// #define PSA_WANT_ECC_SECP_R1_192
#undef PSA_WANT_ECC_SECP_R1_224
#undef PSA_WANT_ECC_SECP_R1_384
#undef PSA_WANT_ECC_SECP_R1_521
#undef PSA_WANT_ECC_BRAINPOOL_P_R1_256
#undef PSA_WANT_ECC_BRAINPOOL_P_R1_384
#undef PSA_WANT_ECC_BRAINPOOL_P_R1_512
#undef MBEDTLS_ECP_DP_BP256R1_ENABLED
#undef MBEDTLS_ECP_DP_BP384R1_ENABLED
#undef MBEDTLS_ECP_DP_BP512R1_ENABLED
#undef MBEDTLS_ECP_DP_SECP192K1_ENABLED
#undef MBEDTLS_ECP_DP_SECP224K1_ENABLED
#undef MBEDTLS_ECP_DP_SECP256K1_ENABLED
#undef PSA_WANT_KEY_TYPE_HMAC
#undef PSA_WANT_KEY_TYPE_ARIA
#undef PSA_WANT_KEY_TYPE_CAMELLIA
#undef MBEDTLS_CAMELLIA_C
#undef MBEDTLS_DES_C
#undef PSA_WANT_ALG_RIPEMD160
#undef MBEDTLS_RIPEMD160_C
#undef PSA_WANT_ALG_MD5
#undef MBEDTLS_MD5_C
#undef PSA_WANT_ALG_CHACHA20
#undef MBEDTLS_CHACHA20_C
#undef PSA_WANT_ALG_SHA3_224
#undef MBEDTLS_SHA3_224_C
#undef PSA_WANT_ALG_SHA3_256
#undef MBEDTLS_SHA3_256_C
#undef PSA_WANT_ALG_SHA3_384
#undef MBEDTLS_SHA3_384_C
#undef PSA_WANT_ALG_SHA3_512
#undef MBEDTLS_SHA3_512_C
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_BASIC
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_IMPORT
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_EXPORT
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE
#undef MBEDTLS_RSA_C
#undef PSA_WANT_ALG_FFDH
#undef MBEDTLS_ARIA_C
#undef MBEDTLS_CCM_C
#undef MBEDTLS_CHACHA20_C
#undef MBEDTLS_CHACHAPOLY_C
#undef MBEDTLS_DEBUG_C
// #undef MBEDTLS_SSL_CLI_C
#define MBEDTLS_SSL_CLI_C
#undef MBEDTLS_SSL_SRV_C
// #undef MBEDTLS_SSL_TLS_C
// #undef MBEDTLS_X509_USE_C
#undef PSA_WANT_ALG_PBKDF2_HMAC
#undef PSA_WANT_ALG_TLS12_PRF
#undef PSA_WANT_ALG_PBKDF2_AES_CMAC_PRF_128
#undef PSA_WANT_ALG_CCM
#undef PSA_WANT_ALG_CMAC
#undef PSA_WANT_KEY_TYPE_DES
#undef MBEDTLS_AES_C
#define MBEDTLS_AES_ROM_TABLES
#endif /* ESP_TEE_MBEDTLS_CONFIG_H */
@@ -24,7 +24,7 @@
#include "esp_aes_internal.h"
#include "esp_crypto_dma.h"
#include "mbedtls/aes.h"
// // #include "mbedtls/aes.h"
#include "mbedtls/platform_util.h"
#if !ESP_TEE_BUILD
@@ -546,7 +546,7 @@ int esp_aes_process_dma(esp_aes_context *ctx, const unsigned char *input, unsign
*/
if (ctx->key_in_hardware != ctx->key_bytes) {
mbedtls_platform_zeroize(output, len);
return MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH;
return -1;
}
#ifdef SOC_GDMA_EXT_MEM_ENC_ALIGNMENT
@@ -736,7 +736,7 @@ int esp_aes_process_dma_gcm(esp_aes_context *ctx, const unsigned char *input, un
*/
if (ctx->key_in_hardware != ctx->key_bytes) {
mbedtls_platform_zeroize(output, len);
return MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH;
return -1;
}
unsigned stream_bytes = len % AES_BLOCK_BYTES; // bytes which aren't in a full block
@@ -1014,7 +1014,7 @@ int esp_aes_process_dma(esp_aes_context *ctx, const unsigned char *input, unsign
*/
if (ctx->key_in_hardware != ctx->key_bytes) {
mbedtls_platform_zeroize(output, len);
return MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH;
return -1;
}
if (block_bytes > 0) {
@@ -1249,7 +1249,7 @@ int esp_aes_process_dma_gcm(esp_aes_context *ctx, const unsigned char *input, un
*/
if (ctx->key_in_hardware != ctx->key_bytes) {
mbedtls_platform_zeroize(output, len);
return MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH;
return -1;
}
/* Set up dma descriptors for input and output */
+9 -3
View File
@@ -16,7 +16,7 @@
*/
#include <string.h>
#include "mbedtls/aes.h"
// #include "mbedtls/aes.h"
#include "esp_log.h"
#include "esp_crypto_lock.h"
#include "hal/aes_hal.h"
@@ -34,6 +34,10 @@
#include "hal/crypto_dma_ll.h"
#endif
#define MBEDTLS_ERR_AES_BAD_INPUT_DATA -0x0021 /**< Invalid input data. */
#define MBEDTLS_ERR_AES_INVALID_KEY_LENGTH -0x0020 /**< Invalid key length. */
#define MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH -0x0022 /**< Invalid data input length. */
static const char *TAG = "esp-aes";
#if CONFIG_MBEDTLS_AES_HW_SMALL_DATA_LEN_OPTIM
@@ -131,7 +135,8 @@ static int esp_aes_block(esp_aes_context *ctx, const void *input, void *output)
key write to hardware. Treat this as a fatal error and zero the output block.
*/
if (ctx->key_in_hardware != ctx->key_bytes) {
mbedtls_platform_zeroize(output, 16);
// mbedtls_platform_zeroize(output, 16);
memset(output, 0, 16);
return MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH;
}
i0 = input_words[0];
@@ -156,7 +161,8 @@ static int esp_aes_block(esp_aes_context *ctx, const void *input, void *output)
// calling zeroing functions to narrow the
// window for a double-fault of the abort step, here
memset(output, 0, 16);
mbedtls_platform_zeroize(output, 16);
// mbedtls_platform_zeroize(output, 16);
memset(output, 0, 16);
abort();
}
+2 -2
View File
@@ -17,7 +17,7 @@
#include "sdkconfig.h"
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include "esp_aes_internal.h"
#include "mbedtls/aes.h"
// // #include "mbedtls/aes.h"
#include "hal/aes_hal.h"
#include "hal/aes_types.h"
#include "soc/soc_caps.h"
@@ -70,7 +70,7 @@ int esp_aes_setkey( esp_aes_context *ctx, const unsigned char *key,
}
#endif
if (keybits != 128 && keybits != 192 && keybits != 256) {
return MBEDTLS_ERR_AES_INVALID_KEY_LENGTH;
return -1;
}
ctx->key_bytes = keybits / 8;
memcpy(ctx->key, key, ctx->key_bytes);
+22 -22
View File
@@ -21,7 +21,7 @@
#include "esp_aes_internal.h"
#include "hal/aes_hal.h"
#include "mbedtls/aes.h"
// #include "mbedtls/aes.h"
// #include "mbedtls/error.h"
#include "mbedtls/gcm.h"
@@ -252,7 +252,7 @@ static void gcm_mult( esp_gcm_context *ctx, const unsigned char x[16],
/* Update the key value in gcm context */
int esp_aes_gcm_setkey( esp_gcm_context *ctx,
mbedtls_cipher_id_t cipher,
int cipher,
const unsigned char *key,
unsigned int keybits )
{
@@ -283,7 +283,7 @@ int esp_aes_gcm_setkey( esp_gcm_context *ctx,
}
#endif
if (keybits != 128 && keybits != 192 && keybits != 256) {
return MBEDTLS_ERR_AES_INVALID_KEY_LENGTH;
return -1;
}
@@ -377,7 +377,7 @@ int esp_aes_gcm_starts( esp_gcm_context *ctx,
{
if (!ctx) {
ESP_LOGE(TAG, "No AES context supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0
@@ -390,12 +390,12 @@ int esp_aes_gcm_starts( esp_gcm_context *ctx,
/* IV is not allowed to be zero length */
if ( iv_len == 0 ||
( (uint32_t) iv_len ) >> 29 != 0 ) {
return ( MBEDTLS_ERR_GCM_BAD_INPUT );
return ( -1 );
}
if (!iv) {
ESP_LOGE(TAG, "No IV supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
/* Initialize AES-GCM context */
@@ -421,7 +421,7 @@ int esp_aes_gcm_starts( esp_gcm_context *ctx,
esp_aes_release_hardware();
#else
memset(ctx->H, 0, sizeof(ctx->H));
int ret = esp_aes_crypt_ecb(&ctx->aes_ctx, MBEDTLS_AES_ENCRYPT, ctx->H, ctx->H);
int ret = esp_aes_crypt_ecb(&ctx->aes_ctx, ESP_AES_ENCRYPT, ctx->H, ctx->H);
if (ret != 0) {
return ret;
}
@@ -449,7 +449,7 @@ int esp_aes_gcm_update_ad( esp_gcm_context *ctx,
{
if (!ctx) {
ESP_LOGE(TAG, "No AES context supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0
@@ -460,12 +460,12 @@ int esp_aes_gcm_update_ad( esp_gcm_context *ctx,
/* AD are limited to 2^32 bits, so 2^29 bytes */
if ( ( (uint32_t) aad_len ) >> 29 != 0 ) {
return ( MBEDTLS_ERR_GCM_BAD_INPUT );
return ( -1 );
}
if ( (aad_len > 0) && !aad) {
ESP_LOGE(TAG, "No aad supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
if (ctx->gcm_state != ESP_AES_GCM_STATE_START) {
@@ -490,7 +490,7 @@ int esp_aes_gcm_update( esp_gcm_context *ctx,
{
if (!ctx) {
ESP_LOGE(TAG, "No GCM context supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0
@@ -505,21 +505,21 @@ int esp_aes_gcm_update( esp_gcm_context *ctx,
if (!output_length) {
ESP_LOGE(TAG, "No output length supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
*output_length = input_length;
if (!input) {
ESP_LOGE(TAG, "No input supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
if (!output) {
ESP_LOGE(TAG, "No output supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
if ( output > input && (size_t) ( output - input ) < input_length ) {
return ( MBEDTLS_ERR_GCM_BAD_INPUT );
return ( -1 );
}
/* If this is the first time esp_gcm_update is getting called
* calculate GHASH on aad and preincrement the ICB
@@ -575,7 +575,7 @@ int esp_aes_gcm_finish( esp_gcm_context *ctx,
uint8_t stream[AES_BLOCK_BYTES] = {0};
if ( tag_len > 16 || tag_len < 4 ) {
return ( MBEDTLS_ERR_GCM_BAD_INPUT );
return ( -1 );
}
/* Calculate final GHASH on aad_len, data length */
@@ -663,7 +663,7 @@ int esp_aes_gcm_crypt_and_tag( esp_gcm_context *ctx,
{
if (!ctx) {
ESP_LOGE(TAG, "No AES context supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0
@@ -687,24 +687,24 @@ int esp_aes_gcm_crypt_and_tag( esp_gcm_context *ctx,
Maximum size of data in the buffer that a DMA descriptor can hold.
*/
if (aad_len > DMA_DESCRIPTOR_BUFFER_MAX_SIZE_4B_ALIGNED) {
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
/* IV and AD are limited to 2^32 bits, so 2^29 bytes */
/* IV is not allowed to be zero length */
if ( iv_len == 0 ||
( (uint32_t) iv_len ) >> 29 != 0 ||
( (uint32_t) aad_len ) >> 29 != 0 ) {
return ( MBEDTLS_ERR_GCM_BAD_INPUT );
return ( -1 );
}
if (!iv) {
ESP_LOGE(TAG, "No IV supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
if ( (aad_len > 0) && !aad) {
ESP_LOGE(TAG, "No aad supplied");
return MBEDTLS_ERR_GCM_BAD_INPUT;
return -1;
}
/* Initialize AES-GCM context */
@@ -784,7 +784,7 @@ int esp_aes_gcm_auth_decrypt( esp_gcm_context *ctx,
if ( diff != 0 ) {
bzero( output, length );
return ( MBEDTLS_ERR_GCM_AUTH_FAILED );
return ( -1 );
}
return ( 0 );
+8 -7
View File
@@ -37,9 +37,10 @@
#include <string.h>
#include <sys/lock.h>
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include "mbedtls/aes.h"
// #include "mbedtls/aes.h"
#include "aes/esp_aes.h"
#include "psa/crypto.h"
void esp_aes_xts_init( esp_aes_xts_context *ctx )
{
@@ -66,7 +67,7 @@ static int esp_aes_xts_decode_keys( const unsigned char *key,
switch ( keybits ) {
case 256: break;
case 512: break;
default : return ( MBEDTLS_ERR_AES_INVALID_KEY_LENGTH );
default : return ( PSA_ERROR_NOT_SUPPORTED );
}
*key1bits = half_keybits;
@@ -196,16 +197,16 @@ int esp_aes_crypt_xts( esp_aes_xts_context *ctx,
/* Sectors must be at least 16 bytes. */
if ( length < 16 ) {
return MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH;
return PSA_ERROR_DATA_INVALID;
}
/* NIST SP 80-38E disallows data units larger than 2**20 blocks. */
if ( length > ( 1 << 20 ) * 16 ) {
return MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH;
return PSA_ERROR_DATA_INVALID;
}
/* Compute the tweak. */
ret = esp_aes_crypt_ecb( &ctx->tweak, MBEDTLS_AES_ENCRYPT,
ret = esp_aes_crypt_ecb( &ctx->tweak, ESP_AES_ENCRYPT,
data_unit, tweak );
if ( ret != 0 ) {
return ( ret );
@@ -214,7 +215,7 @@ int esp_aes_crypt_xts( esp_aes_xts_context *ctx,
while ( blocks-- ) {
size_t i;
if ( leftover && ( mode == MBEDTLS_AES_DECRYPT ) && blocks == 0 ) {
if ( leftover && ( mode == ESP_AES_DECRYPT ) && blocks == 0 ) {
/* We are on the last block in a decrypt operation that has
* leftover bytes, so we need to use the next tweak for this block,
* and this tweak for the lefover bytes. Save the current tweak for
@@ -247,7 +248,7 @@ int esp_aes_crypt_xts( esp_aes_xts_context *ctx,
if ( leftover ) {
/* If we are on the leftover bytes in a decrypt operation, we need to
* use the previous tweak for these bytes (as saved in prev_tweak). */
unsigned char *t = mode == MBEDTLS_AES_DECRYPT ? prev_tweak : tweak;
unsigned char *t = mode == ESP_AES_DECRYPT ? prev_tweak : tweak;
/* We are now on the final part of the data unit, which doesn't divide
* evenly by 16. It's time for ciphertext stealing. */
@@ -494,7 +494,6 @@ int mbedtls_mpi_mul_mpi( mbedtls_mpi *Z, const mbedtls_mpi *X, const mbedtls_mpi
size_t y_words = bits_to_words(y_bits);
size_t z_words = bits_to_words(x_bits + y_bits);
size_t hw_words = mpi_hal_calc_hardware_words(MAX(x_words, y_words)); // length of one operand in hardware
/* Short-circuit eval if either argument is 0 or 1.
This is needed as the mpi modular division
@@ -526,9 +526,9 @@ size_t esp_mbedtls_get_crt_size(mbedtls_x509_crt *cert, size_t *num)
void esp_mbedtls_free_dhm(mbedtls_ssl_context *ssl)
{
#ifdef CONFIG_MBEDTLS_DHM_C
const mbedtls_ssl_config *conf = mbedtls_ssl_context_get_config(ssl);
mbedtls_mpi_free((mbedtls_mpi *)&conf->MBEDTLS_PRIVATE(dhm_P));
mbedtls_mpi_free((mbedtls_mpi *)&conf->MBEDTLS_PRIVATE(dhm_G));
// const mbedtls_ssl_config *conf = mbedtls_ssl_context_get_config(ssl);
// mbedtls_mpi_free((mbedtls_mpi *)&conf->MBEDTLS_PRIVATE(dhm_P));
// mbedtls_mpi_free((mbedtls_mpi *)&conf->MBEDTLS_PRIVATE(dhm_G));
#endif /* CONFIG_MBEDTLS_DHM_C */
}
@@ -21,8 +21,7 @@ static bool ssl_ciphersuite_uses_rsa_key_ex(mbedtls_ssl_context *ssl)
const mbedtls_ssl_ciphersuite_t *ciphersuite_info =
ssl->MBEDTLS_PRIVATE(handshake)->ciphersuite_info;
if (ciphersuite_info->MBEDTLS_PRIVATE(key_exchange) == MBEDTLS_KEY_EXCHANGE_RSA ||
ciphersuite_info->MBEDTLS_PRIVATE(key_exchange) == MBEDTLS_KEY_EXCHANGE_RSA_PSK) {
if (ciphersuite_info->MBEDTLS_PRIVATE(key_exchange) == MBEDTLS_KEY_EXCHANGE_ECDHE_RSA) {
return true;
} else {
return false;
+28 -29
View File
@@ -47,43 +47,42 @@ static int ssl_update_checksum_start( mbedtls_ssl_context *ssl,
const unsigned char *buf, size_t len )
{
int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
#if defined(MBEDTLS_SHA256_C)
ret = mbedtls_md_update( &ssl->handshake->fin_sha256, buf, len );
psa_status_t status;
#if defined(PSA_WANT_ALG_SHA_256)
status = psa_hash_update(
&ssl->handshake->fin_sha256_psa, buf, len);
if (status != PSA_SUCCESS) {
ret = psa_status_to_mbedtls(status, psa_to_md_errors, ARRAY_LENGTH(psa_to_md_errors), psa_generic_status_to_mbedtls);
return ret;
}
#endif
#if defined(MBEDTLS_SHA512_C)
ret = mbedtls_md_update( &ssl->handshake->fin_sha384, buf, len );
#if defined(PSA_WANT_ALG_SHA_384)
status = psa_hash_update(
&ssl->handshake->fin_sha384_psa, buf, len);
if (status != PSA_SUCCESS) {
ret = psa_status_to_mbedtls(status, psa_to_md_errors, ARRAY_LENGTH(psa_to_md_errors), psa_generic_status_to_mbedtls);
return ret;
}
#endif
return ret;
return 0;
}
static int ssl_handshake_params_init( mbedtls_ssl_handshake_params *handshake )
{
memset( handshake, 0, sizeof( mbedtls_ssl_handshake_params ) );
#if defined(MBEDTLS_SHA256_C)
mbedtls_md_init( &handshake->fin_sha256 );
int ret = mbedtls_md_setup( &handshake->fin_sha256,
mbedtls_md_info_from_type(MBEDTLS_MD_SHA256),
0 );
if (ret != 0) {
return ret;
}
ret = mbedtls_md_starts( &handshake->fin_sha256 );
if (ret != 0) {
return ret;
psa_status_t status;
#if defined(PSA_WANT_ALG_SHA_256)
handshake->fin_sha256_psa = psa_hash_operation_init();
status = psa_hash_setup( &handshake->fin_sha256_psa, PSA_ALG_SHA_256 );
if (status != PSA_SUCCESS) {
return psa_status_to_mbedtls(status, psa_to_md_errors, ARRAY_LENGTH(psa_to_md_errors), psa_generic_status_to_mbedtls);
}
#endif
#if defined(MBEDTLS_SHA512_C)
mbedtls_md_init( &handshake->fin_sha384 );
ret = mbedtls_md_setup( &handshake->fin_sha384,
mbedtls_md_info_from_type(MBEDTLS_MD_SHA384),
0 );
if (ret != 0) {
return ret;
}
ret = mbedtls_md_starts( &handshake->fin_sha384 );
if (ret != 0) {
return ret;
#if defined(PSA_WANT_ALG_SHA_384)
handshake->fin_sha384_psa = psa_hash_operation_init();
status = psa_hash_setup( &handshake->fin_sha384_psa, PSA_ALG_SHA_384 );
if (status != PSA_SUCCESS) {
return psa_status_to_mbedtls(status, psa_to_md_errors, ARRAY_LENGTH(psa_to_md_errors), psa_generic_status_to_mbedtls);
}
#endif
@@ -92,7 +91,7 @@ static int ssl_handshake_params_init( mbedtls_ssl_handshake_params *handshake )
#if defined(MBEDTLS_DHM_C)
mbedtls_dhm_init( &handshake->dhm_ctx );
#endif
#if defined(MBEDTLS_ECDH_C) && \
#if !defined(MBEDTLS_USE_PSA_CRYPTO) && \
defined(MBEDTLS_KEY_EXCHANGE_SOME_ECDH_OR_ECDHE_1_2_ENABLED)
mbedtls_ecdh_init( &handshake->ecdh_ctx );
#endif
+45 -6
View File
@@ -16,7 +16,8 @@
#include "esp_crypto_periph_clk.h"
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
// #include "mbedtls/error.h"
#include "mbedtls/ecdsa.h"
#include "mbedtls/private/ecdsa.h"
#include "mbedtls/private/pk_private.h"
#include "mbedtls/asn1.h"
#include "mbedtls/asn1write.h"
#include "mbedtls/platform_util.h"
@@ -389,7 +390,20 @@ int esp_ecdsa_privkey_load_pk_context(mbedtls_pk_context *key_ctx, int efuse_blk
if (mbedtls_pk_setup(key_ctx, pk_info) != 0) {
return -1;
}
keypair = mbedtls_pk_ec(*key_ctx);
/* In mbedtls v4.0, MBEDTLS_PK_ECDSA doesn't allocate pk_ctx (ctx_alloc_func = NULL)
* because EC keys are managed through PSA. For hardware ECDSA, we need to manually
* allocate an mbedtls_ecp_keypair structure to store the magic values. */
keypair = calloc(1, sizeof(mbedtls_ecp_keypair));
if (keypair == NULL) {
return MBEDTLS_ERR_ECP_ALLOC_FAILED;
}
/* Initialize the keypair structure */
mbedtls_ecp_keypair_init(keypair);
/* Manually assign to pk_ctx since mbedtls_pk_setup didn't do it */
key_ctx->MBEDTLS_PRIVATE(pk_ctx) = keypair;
return esp_ecdsa_privkey_load_mpi(&(keypair->MBEDTLS_PRIVATE(d)), efuse_blk);
}
@@ -432,7 +446,6 @@ int esp_ecdsa_set_pk_context(mbedtls_pk_context *key_ctx, esp_ecdsa_pk_conf_t *c
return 0;
}
static int esp_ecdsa_sign(mbedtls_ecp_group *grp, mbedtls_mpi* r, mbedtls_mpi* s,
const mbedtls_mpi *d, const unsigned char* msg, size_t msg_len,
ecdsa_sign_type_t k_type)
@@ -549,6 +562,23 @@ static int esp_ecdsa_sign(mbedtls_ecp_group *grp, mbedtls_mpi* r, mbedtls_mpi* s
}
#endif
void esp_ecdsa_free_pk_context(mbedtls_pk_context *key_ctx)
{
if (key_ctx == NULL) {
return;
}
/* In mbedtls v4.0, we manually allocated the keypair structure for hardware ECDSA.
* We need to free it manually since ctx_free_func is NULL for MBEDTLS_PK_ECDSA. */
mbedtls_ecp_keypair *keypair = mbedtls_pk_ec(*key_ctx);
if (keypair != NULL) {
mbedtls_ecp_keypair_free(keypair);
free(keypair);
key_ctx->MBEDTLS_PRIVATE(pk_ctx) = NULL;
}
mbedtls_pk_free(key_ctx);
}
#if CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN
int esp_ecdsa_tee_load_pubkey(mbedtls_ecp_keypair *keypair, const char *tee_key_id)
@@ -619,7 +649,16 @@ int esp_ecdsa_tee_set_pk_context(mbedtls_pk_context *key_ctx, esp_ecdsa_pk_conf_
ESP_LOGE(TAG, "Failed to setup pk context, mbedtls_pk_setup() returned %d", ret);
return ret;
}
keypair = mbedtls_pk_ec(*key_ctx);
// keypair = mbedtls_pk_ec(*key_ctx);
keypair = calloc(1, sizeof(mbedtls_ecp_keypair));
if (keypair == NULL) {
ESP_LOGE(TAG, "Failed to allocate memory for ecp_keypair");
return MBEDTLS_ERR_ECP_ALLOC_FAILED;
}
mbedtls_ecp_keypair_init(keypair);
key_ctx->MBEDTLS_PRIVATE(pk_ctx) = keypair;
mbedtls_mpi_init(&(keypair->MBEDTLS_PRIVATE(d)));
keypair->MBEDTLS_PRIVATE(d).MBEDTLS_PRIVATE(s) = ECDSA_KEY_MAGIC_TEE;
@@ -696,8 +735,8 @@ static int esp_ecdsa_tee_sign(mbedtls_ecp_group *grp, mbedtls_mpi* r, mbedtls_mp
return MBEDTLS_ERR_ECP_BAD_INPUT_DATA;
}
mbedtls_mpi_read_binary(r, sign.sign_r, len);
mbedtls_mpi_read_binary(s, sign.sign_s, len);
mbedtls_mpi_read_binary(r, sign.signature, len);
mbedtls_mpi_read_binary(s, sign.signature + len, len);
return 0;
}
+15 -4
View File
@@ -12,7 +12,8 @@
#include "esp_ds/esp_ds_rsa.h"
#include "freertos/FreeRTOS.h"
#include "freertos/semphr.h"
#include "mbedtls/rsa.h"
// #include "mbedtls/rsa.h"
#include "psa/crypto.h"
#ifdef SOC_DIG_SIGN_SUPPORTED
#include "rom/digital_signature.h"
@@ -49,6 +50,16 @@ size_t esp_ds_get_keylen(void *ctx)
return ((s_ds_data->rsa_length + 1) * FACTOR_KEYLEN_IN_BYTES);
}
size_t esp_ds_get_keylen_alt(mbedtls_pk_context *ctx)
{
if (s_ds_data == NULL) {
ESP_LOGE(TAG, "s_ds_data is NULL, cannot get key length");
return 0;
}
/* calculating the rsa_length in bytes */
return ((s_ds_data->rsa_length + 1) * FACTOR_KEYLEN_IN_BYTES);
}
/* Lock for the DS session, other TLS connections trying to use the DS peripheral will be blocked
* till this DS session is completed (i.e. TLS handshake for this connection is completed) */
static void __attribute__((constructor)) esp_ds_conn_lock(void)
@@ -134,7 +145,7 @@ int esp_ds_mgf_mask(unsigned char *dst, size_t dlen, unsigned char *src,
mbedtls_md_init(&md_ctx);
md_info = mbedtls_md_info_from_type(md_alg);
if (md_info == NULL) {
return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
return PSA_ERROR_INVALID_ARGUMENT;
}
if ((ret = mbedtls_md_setup(&md_ctx, md_info, 0)) != 0) {
@@ -191,11 +202,11 @@ int esp_ds_hash_mprime(const unsigned char *hash, size_t hlen,
const unsigned char zeros[8] = { 0, 0, 0, 0, 0, 0, 0, 0 };
mbedtls_md_context_t md_ctx;
int ret = MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
int ret = PSA_ERROR_INVALID_ARGUMENT;
const mbedtls_md_info_t *md_info = mbedtls_md_info_from_type(md_alg);
if (md_info == NULL) {
return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
return PSA_ERROR_INVALID_ARGUMENT;
}
mbedtls_md_init(&md_ctx);
@@ -9,7 +9,8 @@
#include "sdkconfig.h"
#include "esp_ds.h"
#include "rsa_dec_alt.h"
#include "mbedtls/rsa.h"
#include "mbedtls/private/rsa.h"
#include "psa/crypto.h"
#include "esp_ds_common.h"
#include "esp_log.h"
@@ -24,7 +25,7 @@ static int esp_ds_rsaes_pkcs1_v15_unpadding(unsigned char *input,
size_t *olen)
{
if (ilen < MIN_V15_PADDING_LEN) {
return MBEDTLS_ERR_RSA_INVALID_PADDING;
return MBEDTLS_ERR_CIPHER_INVALID_PADDING;
}
unsigned char bad = 0;
@@ -39,7 +40,7 @@ static int esp_ds_rsaes_pkcs1_v15_unpadding(unsigned char *input,
bad |= input[0];
/* Check the padding type */
bad |= input[1] ^ MBEDTLS_RSA_CRYPT;
bad |= input[1] ^ 2; // MBEDTLS_RSA_CRYPT;
/* Scan for separator (0x00) and count padding bytes in constant time */
for (size_t i = 2; i < ilen; i++) {
@@ -72,7 +73,7 @@ static int esp_ds_rsaes_pkcs1_v15_unpadding(unsigned char *input,
}
if (bad) {
return MBEDTLS_ERR_RSA_INVALID_PADDING;
return PSA_ERROR_INVALID_ARGUMENT;
}
*olen = msg_len;
@@ -88,7 +89,7 @@ static int esp_ds_compute_hash(mbedtls_md_type_t md_alg,
{
const mbedtls_md_info_t *md_info = mbedtls_md_info_from_type(md_alg);
if (md_info == NULL) {
return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
return PSA_ERROR_INVALID_ARGUMENT;
}
return mbedtls_md(md_info, input, ilen, output);
}
@@ -165,7 +166,7 @@ static int esp_ds_rsaes_pkcs1_v21_unpadding(unsigned char *input,
bad |= (output_max_len < msg_len);
if (bad) {
return MBEDTLS_ERR_RSA_INVALID_PADDING;
return PSA_ERROR_INVALID_ARGUMENT;
}
/* Copy message in constant time */
@@ -181,7 +182,7 @@ int esp_ds_rsa_decrypt(void *ctx, size_t *olen,
const unsigned char *input, unsigned char *output,
size_t output_max_len)
{
int padding = MBEDTLS_RSA_PKCS_V15;
int padding = MBEDTLS_PK_RSA_PKCS_V15;
if (ctx != NULL) {
mbedtls_rsa_context *rsa_ctx = (mbedtls_rsa_context *)ctx;
@@ -256,12 +257,12 @@ int esp_ds_rsa_decrypt(void *ctx, size_t *olen,
}
// Unpad the decrypted data
if (padding == MBEDTLS_RSA_PKCS_V15) {
if (padding == MBEDTLS_PK_RSA_PKCS_V15) {
if (esp_ds_rsaes_pkcs1_v15_unpadding((uint8_t *)output_tmp, ilen, (uint8_t *)output_tmp, ilen, olen) != 0) {
ESP_LOGE(TAG, "Error in v15 unpadding");
goto exit;
}
} else if (padding == MBEDTLS_RSA_PKCS_V21) {
} else if (padding == MBEDTLS_PK_RSA_PKCS_V21) {
if (esp_ds_rsaes_pkcs1_v21_unpadding((uint8_t *)output_tmp, ilen, (uint8_t *)output_tmp, ilen, olen) != 0) {
ESP_LOGE(TAG, "Error in v21 unpadding");
goto exit;
+105 -29
View File
@@ -14,14 +14,76 @@
#include "esp_heap_caps.h"
#include "freertos/FreeRTOS.h"
#include "freertos/semphr.h"
#include "mbedtls/build_info.h"
#include "mbedtls/rsa.h"
#include "mbedtls/oid.h"
#include "psa/crypto.h"
#include "mbedtls/psa_util.h"
// #include "mbedtls/build_info.h"
#include "mbedtls/private/rsa.h"
// #include "mbedtls/oid.h"
#include "mbedtls/pk.h"
#include "mbedtls/platform_util.h"
#include "mbedtls/asn1.h"
#include "mbedtls/md.h"
#include <string.h>
static const char *TAG = "ESP_RSA_SIGN_ALT";
/*
* Local OID lookup table for hash algorithms
* This replicates the OID data needed for PKCS#1 v1.5 DigestInfo encoding
* Since OID access has moved to internal driver headers in PSA transition,
* we maintain this local table for the hardware accelerator implementation.
*/
typedef struct {
mbedtls_md_type_t md_alg;
const char *oid;
size_t oid_len;
} oid_md_mapping_t;
static const oid_md_mapping_t oid_md_table[] = {
#if defined(PSA_WANT_ALG_MD5)
{ MBEDTLS_MD_MD5, "\x2a\x86\x48\x86\xf7\x0d\x02\x05", 8 },
#endif
#if defined(PSA_WANT_ALG_SHA_1)
{ MBEDTLS_MD_SHA1, "\x2b\x0e\x03\x02\x1a", 5 },
#endif
#if defined(PSA_WANT_ALG_SHA_224)
{ MBEDTLS_MD_SHA224, "\x60\x86\x48\x01\x65\x03\x04\x02\x04", 9 },
#endif
#if defined(PSA_WANT_ALG_SHA_256)
{ MBEDTLS_MD_SHA256, "\x60\x86\x48\x01\x65\x03\x04\x02\x01", 9 },
#endif
#if defined(PSA_WANT_ALG_SHA_384)
{ MBEDTLS_MD_SHA384, "\x60\x86\x48\x01\x65\x03\x04\x02\x02", 9 },
#endif
#if defined(PSA_WANT_ALG_SHA_512)
{ MBEDTLS_MD_SHA512, "\x60\x86\x48\x01\x65\x03\x04\x02\x03", 9 },
#endif
#if defined(PSA_WANT_ALG_RIPEMD160)
{ MBEDTLS_MD_RIPEMD160, "\x2b\x24\x03\x02\x01", 5 },
#endif
{ MBEDTLS_MD_NONE, NULL, 0 }
};
/**
* @brief Get OID for hash algorithm (local implementation)
*
* @param md_alg Hash algorithm type
* @param oid Output pointer for OID string
* @param olen Output pointer for OID length
* @return 0 on success, PSA_ERROR_NOT_SUPPORTED if not found
*/
static int esp_ds_get_oid_by_md(mbedtls_md_type_t md_alg, const char **oid, size_t *olen)
{
for (size_t i = 0; oid_md_table[i].md_alg != MBEDTLS_MD_NONE; i++) {
if (oid_md_table[i].md_alg == md_alg) {
*oid = oid_md_table[i].oid;
*olen = oid_md_table[i].oid_len;
return 0;
}
}
return PSA_ERROR_NOT_SUPPORTED;
}
static int rsa_rsassa_pkcs1_v15_encode( mbedtls_md_type_t md_alg,
unsigned int hashlen,
const unsigned char *hash,
@@ -37,11 +99,11 @@ static int rsa_rsassa_pkcs1_v15_encode( mbedtls_md_type_t md_alg,
if ( md_alg != MBEDTLS_MD_NONE ) {
const mbedtls_md_info_t *md_info = mbedtls_md_info_from_type( md_alg );
if ( md_info == NULL ) {
return ( MBEDTLS_ERR_RSA_BAD_INPUT_DATA );
return ( PSA_ERROR_INVALID_ARGUMENT );
}
if ( mbedtls_oid_get_oid_by_md( md_alg, &oid, &oid_size ) != 0 ) {
return ( MBEDTLS_ERR_RSA_BAD_INPUT_DATA );
if ( esp_ds_get_oid_by_md( md_alg, &oid, &oid_size ) != 0 ) {
return ( PSA_ERROR_INVALID_ARGUMENT );
}
hashlen = mbedtls_md_get_size( md_info );
@@ -51,7 +113,7 @@ static int rsa_rsassa_pkcs1_v15_encode( mbedtls_md_type_t md_alg,
if ( 8 + hashlen + oid_size >= 0x80 ||
10 + hashlen < hashlen ||
10 + hashlen + oid_size < 10 + hashlen ) {
return ( MBEDTLS_ERR_RSA_BAD_INPUT_DATA );
return ( PSA_ERROR_INVALID_ARGUMENT );
}
/*
@@ -63,12 +125,12 @@ static int rsa_rsassa_pkcs1_v15_encode( mbedtls_md_type_t md_alg,
* - Need oid_size bytes for hash alg OID.
*/
if ( nb_pad < 10 + hashlen + oid_size ) {
return ( MBEDTLS_ERR_RSA_BAD_INPUT_DATA );
return ( PSA_ERROR_INVALID_ARGUMENT );
}
nb_pad -= 10 + hashlen + oid_size;
} else {
if ( nb_pad < hashlen ) {
return ( MBEDTLS_ERR_RSA_BAD_INPUT_DATA );
return ( PSA_ERROR_INVALID_ARGUMENT );
}
nb_pad -= hashlen;
@@ -77,7 +139,7 @@ static int rsa_rsassa_pkcs1_v15_encode( mbedtls_md_type_t md_alg,
/* Need space for signature header and padding delimiter (3 bytes),
* and 8 bytes for the minimal padding */
if ( nb_pad < 3 + 8 ) {
return ( MBEDTLS_ERR_RSA_BAD_INPUT_DATA );
return ( PSA_ERROR_INVALID_ARGUMENT );
}
nb_pad -= 3;
@@ -86,7 +148,7 @@ static int rsa_rsassa_pkcs1_v15_encode( mbedtls_md_type_t md_alg,
/* Write signature header and padding */
*p++ = 0;
*p++ = MBEDTLS_RSA_SIGN;
*p++ = 1; //MBEDTLS_RSA_SIGN;
memset( p, 0xFF, nb_pad );
p += nb_pad;
*p++ = 0;
@@ -129,7 +191,7 @@ static int rsa_rsassa_pkcs1_v15_encode( mbedtls_md_type_t md_alg,
* after the initial bounds check. */
if ( p != dst + dst_len ) {
mbedtls_platform_zeroize( dst, dst_len );
return ( MBEDTLS_ERR_RSA_BAD_INPUT_DATA );
return ( PSA_ERROR_INVALID_ARGUMENT );
}
return ( 0 );
@@ -147,15 +209,15 @@ static int rsa_rsassa_pss_pkcs1_v21_encode( int (*f_rng)(void *, unsigned char *
unsigned char *p = sig;
unsigned char *salt = NULL;
size_t slen, min_slen, hlen, offset = 0;
int ret = MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
int ret = PSA_ERROR_INVALID_ARGUMENT;
size_t msb;
if ((md_alg != MBEDTLS_MD_NONE || hashlen != 0) && hash == NULL) {
return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
return PSA_ERROR_INVALID_ARGUMENT;
}
if (f_rng == NULL) {
return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
return PSA_ERROR_INVALID_ARGUMENT;
}
olen = dst_len;
@@ -164,20 +226,20 @@ static int rsa_rsassa_pss_pkcs1_v21_encode( int (*f_rng)(void *, unsigned char *
/* Gather length of hash to sign */
size_t exp_hashlen = mbedtls_md_get_size_from_type(md_alg);
if (exp_hashlen == 0) {
return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
return PSA_ERROR_INVALID_ARGUMENT;
}
if (hashlen != exp_hashlen) {
return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
return PSA_ERROR_INVALID_ARGUMENT;
}
}
hlen = mbedtls_md_get_size_from_type(md_alg);
if (hlen == 0) {
return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
return PSA_ERROR_INVALID_ARGUMENT;
}
if (saltlen == MBEDTLS_RSA_SALT_LEN_ANY) {
if (saltlen == -1) {
/* Calculate the largest possible salt length, up to the hash size.
* Normally this is the hash length, which is the maximum salt length
* according to FIPS 185-4 �5.5 (e) and common practice. If there is not
@@ -187,14 +249,14 @@ static int rsa_rsassa_pss_pkcs1_v21_encode( int (*f_rng)(void *, unsigned char *
* (PKCS#1 v2.2) �9.1.1 step 3. */
min_slen = hlen - 2;
if (olen < hlen + min_slen + 2) {
return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
return PSA_ERROR_INVALID_ARGUMENT;
} else if (olen >= hlen + hlen + 2) {
slen = hlen;
} else {
slen = olen - hlen - 2;
}
} else if ((saltlen < 0) || (saltlen + hlen + 2 > olen)) {
return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
return PSA_ERROR_INVALID_ARGUMENT;
} else {
slen = (size_t) saltlen;
}
@@ -210,7 +272,7 @@ static int rsa_rsassa_pss_pkcs1_v21_encode( int (*f_rng)(void *, unsigned char *
/* Generate salt of length slen in place in the encoded message */
salt = p;
if ((ret = f_rng(p_rng, salt, slen)) != 0) {
return MBEDTLS_ERR_RSA_RNG_FAILED;
return PSA_ERROR_INVALID_ARGUMENT;
}
p += slen;
@@ -246,7 +308,7 @@ static int rsa_rsassa_pkcs1_v21_encode(int (*f_rng)(void *, unsigned char *, siz
size_t dst_len,
unsigned char *dst )
{
return rsa_rsassa_pss_pkcs1_v21_encode(f_rng, p_rng, md_alg, hashlen, hash, MBEDTLS_RSA_SALT_LEN_ANY, dst, dst_len);
return rsa_rsassa_pss_pkcs1_v21_encode(f_rng, p_rng, md_alg, hashlen, hash, -1, dst, dst_len);
}
#endif /* CONFIG_MBEDTLS_SSL_PROTO_TLS1_3 */
@@ -254,6 +316,15 @@ int esp_ds_rsa_sign( void *ctx,
int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
mbedtls_md_type_t md_alg, unsigned int hashlen,
const unsigned char *hash, unsigned char *sig )
{
mbedtls_pk_context *pk = (mbedtls_pk_context *)ctx;
size_t sig_len = 0;
return esp_ds_rsa_sign_alt(pk, md_alg, hash, hashlen, sig, 0, &sig_len);
}
int esp_ds_rsa_sign_alt(mbedtls_pk_context *pk, mbedtls_md_type_t md_alg,
const unsigned char *hash, size_t hash_len,
unsigned char *sig, size_t sig_size, size_t *sig_len)
{
esp_ds_context_t *esp_ds_ctx = NULL;
esp_err_t ds_r;
@@ -263,7 +334,11 @@ int esp_ds_rsa_sign( void *ctx,
* which allows NULL ctx. If ctx is NULL, then the default padding
* MBEDTLS_RSA_PKCS_V15 is used.
*/
int padding = MBEDTLS_RSA_PKCS_V15;
int padding = MBEDTLS_PK_RSA_PKCS_V15;
void *ctx = NULL;
if (pk != NULL) {
ctx = pk->MBEDTLS_PRIVATE(pk_ctx);
}
if (ctx != NULL) {
mbedtls_rsa_context *rsa_ctx = (mbedtls_rsa_context *)ctx;
padding = rsa_ctx->MBEDTLS_PRIVATE(padding);
@@ -274,11 +349,11 @@ int esp_ds_rsa_sign( void *ctx,
return -1;
}
const size_t data_len = s_ds_data->rsa_length + 1;
const size_t sig_len = data_len * FACTOR_KEYLEN_IN_BYTES;
const size_t _sig_len = data_len * FACTOR_KEYLEN_IN_BYTES;
if (padding == MBEDTLS_RSA_PKCS_V21) {
if (padding == MBEDTLS_PK_RSA_PKCS_V21) {
#ifdef CONFIG_MBEDTLS_SSL_PROTO_TLS1_3
if ((ret = (rsa_rsassa_pkcs1_v21_encode(f_rng, p_rng ,md_alg, hashlen, hash, sig_len, sig ))) != 0) {
if ((ret = (rsa_rsassa_pkcs1_v21_encode(mbedtls_psa_get_random, MBEDTLS_PSA_RANDOM_STATE ,md_alg, hash_len, hash, _sig_len, sig ))) != 0) {
ESP_LOGE(TAG, "Error in pkcs1_v21 encoding, returned %d", ret);
return -1;
}
@@ -287,13 +362,13 @@ int esp_ds_rsa_sign( void *ctx,
return -1;
#endif /* CONFIG_MBEDTLS_SSL_PROTO_TLS1_3 */
} else {
if ((ret = (rsa_rsassa_pkcs1_v15_encode(md_alg, hashlen, hash, sig_len, sig ))) != 0) {
if ((ret = (rsa_rsassa_pkcs1_v15_encode(md_alg, hash_len, hash, _sig_len, sig ))) != 0) {
ESP_LOGE(TAG, "Error in pkcs1_v15 encoding, returned %d", ret);
return -1;
}
}
uint32_t *signature = heap_caps_malloc_prefer(sig_len, 2, MALLOC_CAP_32BIT | MALLOC_CAP_INTERNAL, MALLOC_CAP_DEFAULT | MALLOC_CAP_INTERNAL);
uint32_t *signature = heap_caps_malloc_prefer(_sig_len, 2, MALLOC_CAP_32BIT | MALLOC_CAP_INTERNAL, MALLOC_CAP_DEFAULT | MALLOC_CAP_INTERNAL);
if (signature == NULL) {
ESP_LOGE(TAG, "Could not allocate memory for internal DS operations");
return -1;
@@ -330,5 +405,6 @@ int esp_ds_rsa_sign( void *ctx,
((uint32_t *)sig)[i] = SWAP_INT32(((uint32_t *)signature)[(data_len) - (i + 1)]);
}
heap_caps_free(signature);
*sig_len = _sig_len;
return 0;
}
@@ -0,0 +1,34 @@
/*
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
#include "esp_private/startup_internal.h"
#include "psa/crypto.h"
#include "esp_err.h"
#include "esp_log.h"
#include "sdkconfig.h"
void mbedtls_psa_crypto_init_include_impl(void);
/**
* @brief Initialize PSA Crypto library at system startup
*
* This function is called during the SECONDARY initialization stage with priority 104,
* which ensures it runs after esp_security_init (priority 104). This ordering guarantees
* that hardware crypto support is fully initialized before PSA crypto initialization.
*/
ESP_SYSTEM_INIT_FN(mbedtls_psa_crypto_init_fn, SECONDARY, BIT(0), 104)
{
psa_status_t status = psa_crypto_init();
if (status != PSA_SUCCESS) {
return ESP_FAIL;
}
return ESP_OK;
}
void mbedtls_psa_crypto_init_include_impl(void)
{
// Linker hook, exists for no other purpose
}
@@ -11,7 +11,7 @@
#pragma once
#include "aes/esp_aes.h"
#include "mbedtls/cipher.h"
// #include "mbedtls/cipher.h"
#ifdef __cplusplus
extern "C" {
@@ -69,7 +69,7 @@ void esp_aes_gcm_init( esp_gcm_context *ctx);
* \return A cipher-specific error code on failure.
*/
int esp_aes_gcm_setkey( esp_gcm_context *ctx,
mbedtls_cipher_id_t cipher,
int cipher,
const unsigned char *key,
unsigned int keybits );
@@ -110,6 +110,20 @@ int esp_ecdsa_set_pk_context(mbedtls_pk_context *key_ctx, esp_ecdsa_pk_conf_t *c
#endif // CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN || __DOXYGEN__
/**
* @brief Free the PK context initialized with hardware ECDSA key.
* This function properly cleans up the manually allocated mbedtls_ecp_keypair
* structure and then frees the PK context.
*
* Note: In mbedtls v4.0, ECDSA keys are managed through PSA, so the standard
* mbedtls_pk_free() does not deallocate the manually created keypair structure.
* Always use this function instead of mbedtls_pk_free() for contexts initialized
* with esp_ecdsa_set_pk_context().
*
* @param key_ctx The PK context to free (initialized with esp_ecdsa_set_pk_context)
*/
void esp_ecdsa_free_pk_context(mbedtls_pk_context *key_ctx);
#if CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN || __DOXYGEN__
/**
@@ -12,7 +12,7 @@ extern "C" {
#include "esp_ds.h"
#include "mbedtls/md.h"
#include "mbedtls/pk.h"
/**
* @brief ESP-DS data context
*
@@ -67,7 +67,9 @@ int esp_ds_rsa_sign( void *ctx,
int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
mbedtls_md_type_t md_alg, unsigned int hashlen,
const unsigned char *hash, unsigned char *sig );
int esp_ds_rsa_sign_alt(mbedtls_pk_context *pk, mbedtls_md_type_t md_alg,
const unsigned char *hash, size_t hash_len,
unsigned char *sig, size_t sig_size, size_t *sig_len);
/*
* @brief Get RSA key length in bytes from internal DS context
*
@@ -75,6 +77,8 @@ int esp_ds_rsa_sign( void *ctx,
*/
size_t esp_ds_get_keylen(void *ctx);
size_t esp_ds_get_keylen_alt(mbedtls_pk_context *ctx);
/*
* @brief Set timeout (equal to TLS session timeout), so that DS module usage can be synchronized in case of multiple TLS connections using DS module,
*/
@@ -15,6 +15,7 @@ extern "C" {
#include "esp_ds.h"
#include "mbedtls/md.h"
#include "mbedtls/pk.h"
/**
* @brief ESP-DS data context
@@ -60,6 +61,10 @@ int esp_ds_rsa_sign(void *ctx,
mbedtls_md_type_t md_alg, unsigned int hashlen,
const unsigned char *hash, unsigned char *sig);
int esp_ds_rsa_sign_alt(mbedtls_pk_context *pk, mbedtls_md_type_t md_alg,
const unsigned char *hash, size_t hash_len,
unsigned char *sig, size_t sig_size, size_t *sig_len)
/*
* @brief Get RSA key length in bytes from internal DS context
*
@@ -5,7 +5,8 @@
*/
#pragma once
#include_next "mbedtls/bignum.h"
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include_next "mbedtls/private/bignum.h"
#include "sdkconfig.h"
/**
@@ -5,7 +5,8 @@
*/
#pragma once
#include_next "mbedtls/ecp.h"
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include_next "mbedtls/private/ecp.h"
#include "sdkconfig.h"
#ifdef __cplusplus
@@ -33,8 +33,13 @@
#endif // MBEDTLS_MAJOR_VERSION < 4
#include "soc/soc_caps.h"
#ifndef CONFIG_IDF_TARGET_LINUX
#undef MBEDTLS_PSA_BUILTIN_GET_ENTROPY
#define MBEDTLS_PSA_DRIVER_GET_ENTROPY
#define MBEDTLS_PLATFORM_GET_ENTROPY_ALT
#define MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG
#endif // !CONFIG_IDF_TARGET_LINUX
/**
* \def MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS
@@ -173,7 +178,7 @@
*/
#ifdef CONFIG_MBEDTLS_HARDWARE_AES
#define MBEDTLS_GCM_ALT
// #define MBEDTLS_GCM_ALT
#ifdef CONFIG_MBEDTLS_GCM_SUPPORT_NON_AES_CIPHER
/* Prefer hardware and fallback to software */
#define MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK
@@ -186,15 +191,17 @@
with software fallback.
*/
#ifdef CONFIG_MBEDTLS_HARDWARE_SHA
#define MBEDTLS_SHA1_ALT
#define MBEDTLS_SHA256_ALT
// #define MBEDTLS_SHA1_ALT
// #define MBEDTLS_SHA256_ALT
#define MBEDTLS_PSA_ACCEL_ALG_SHA_1
#define MBEDTLS_PSA_ACCEL_ALG_SHA_224
#define MBEDTLS_PSA_ACCEL_ALG_SHA_256
#if SOC_SHA_SUPPORT_SHA512
#define MBEDTLS_PSA_ACCEL_ALG_SHA_384
#define MBEDTLS_PSA_ACCEL_ALG_SHA_512
#endif
#if SOC_SHA_SUPPORT_SHA512
#define MBEDTLS_SHA512_ALT
// #define MBEDTLS_SHA512_ALT
#else
#undef MBEDTLS_SHA512_ALT
#endif
@@ -208,11 +215,13 @@
/* MBEDTLS_MDx_ALT to enable ROM MD support
with software fallback.
*/
#ifdef CONFIG_MBEDTLS_ROM_MD5
#define MBEDTLS_MD5_ALT
#else
#undef MBEDTLS_MD5_ALT
#endif
/* TODO: With PSA we probably need to handle this
under the driver abstraction layer */
// #ifdef CONFIG_MBEDTLS_ROM_MD5
// #define MBEDTLS_MD5_ALT
// #else
// #undef MBEDTLS_MD5_ALT
// #endif
/* The following MPI (bignum) functions have hardware support.
* Uncommenting these macros will use the hardware-accelerated
@@ -222,6 +231,7 @@
#ifdef CONFIG_MBEDTLS_LARGE_KEY_SOFTWARE_MPI
/* Prefer hardware and fallback to software */
#define MBEDTLS_MPI_EXP_MOD_ALT_FALLBACK
#define MBEDTLS_MPI_EXP_MOD_ALT
#else
/* Hardware only mode */
#define MBEDTLS_MPI_EXP_MOD_ALT
@@ -273,7 +283,7 @@
*
* Uncomment to use your own hardware entropy collector.
*/
#define MBEDTLS_ENTROPY_HARDWARE_ALT
// #define MBEDTLS_ENTROPY_HARDWARE_ALT
#endif // !CONFIG_IDF_TARGET_LINUX
/**
@@ -337,9 +347,13 @@
* Enable Cipher Block Chaining mode (CBC) for symmetric ciphers.
*/
#ifdef CONFIG_MBEDTLS_CIPHER_MODE_CBC
#define MBEDTLS_CIPHER_MODE_CBC
// #define MBEDTLS_CIPHER_MODE_CBC
#define PSA_WANT_ALG_CBC_NO_PADDING 1
#define PSA_WANT_ALG_CBC_PKCS7 1
#else
#undef MBEDTLS_CIPHER_MODE_CBC
// #undef MBEDTLS_CIPHER_MODE_CBC
#undef PSA_WANT_ALG_CBC_NO_PADDING
#undef PSA_WANT_ALG_CBC_PKCS7
#endif
/**
@@ -348,9 +362,11 @@
* Enable Cipher Feedback mode (CFB) for symmetric ciphers.
*/
#ifdef CONFIG_MBEDTLS_CIPHER_MODE_CFB
#define MBEDTLS_CIPHER_MODE_CFB
// #define MBEDTLS_CIPHER_MODE_CFB
#define PSA_WANT_ALG_CFB 1
#else
#undef MBEDTLS_CIPHER_MODE_CFB
// #undef MBEDTLS_CIPHER_MODE_CFB
#undef PSA_WANT_ALG_CFB
#endif
/**
@@ -359,9 +375,11 @@
* Enable Counter Block Cipher mode (CTR) for symmetric ciphers.
*/
#ifdef CONFIG_MBEDTLS_CIPHER_MODE_CTR
#define MBEDTLS_CIPHER_MODE_CTR
// #define MBEDTLS_CIPHER_MODE_CTR
#define PSA_WANT_ALG_CTR 1
#else
#undef MBEDTLS_CIPHER_MODE_CTR
// #undef MBEDTLS_CIPHER_MODE_CTR
#undef PSA_WANT_ALG_CTR
#endif
/**
* \def MBEDTLS_CIPHER_MODE_OFB
@@ -369,9 +387,11 @@
* Enable Output Feedback mode (OFB) for symmetric ciphers.
*/
#ifdef CONFIG_MBEDTLS_CIPHER_MODE_OFB
#define MBEDTLS_CIPHER_MODE_OFB
// #define MBEDTLS_CIPHER_MODE_OFB
#define PSA_WANT_ALG_OFB 1
#else
#undef MBEDTLS_CIPHER_MODE_OFB
// #undef MBEDTLS_CIPHER_M ODE_OFB
#undef PSA_WANT_ALG_OFB
#endif
/**
@@ -396,29 +416,29 @@
*
* Enable padding modes in the cipher layer.
*/
#ifdef CONFIG_MBEDTLS_CIPHER_PADDING_PKCS7
#define MBEDTLS_CIPHER_PADDING_PKCS7
#else
#undef MBEDTLS_CIPHER_PADDING_PKCS7
#endif
// #ifdef CONFIG_MBEDTLS_CIPHER_PADDING_PKCS7
// #define MBEDTLS_CIPHER_PADDING_PKCS7
// #else
// #undef MBEDTLS_CIPHER_PADDING_PKCS7
// #endif
#ifdef CONFIG_MBEDTLS_CIPHER_PADDING_ONE_AND_ZEROS
#define MBEDTLS_CIPHER_PADDING_ONE_AND_ZEROS
#else
#undef MBEDTLS_CIPHER_PADDING_ONE_AND_ZEROS
#endif
// #ifdef CONFIG_MBEDTLS_CIPHER_PADDING_ONE_AND_ZEROS
// #define MBEDTLS_CIPHER_PADDING_ONE_AND_ZEROS
// #else
// #undef MBEDTLS_CIPHER_PADDING_ONE_AND_ZEROS
// #endif
#ifdef CONFIG_MBEDTLS_CIPHER_PADDING_ZEROS_AND_LEN
#define MBEDTLS_CIPHER_PADDING_ZEROS_AND_LEN
#else
#undef MBEDTLS_CIPHER_PADDING_ZEROS_AND_LEN
#endif
// #ifdef CONFIG_MBEDTLS_CIPHER_PADDING_ZEROS_AND_LEN
// #define MBEDTLS_CIPHER_PADDING_ZEROS_AND_LEN
// #else
// #undef MBEDTLS_CIPHER_PADDING_ZEROS_AND_LEN
// #endif
#ifdef CONFIG_MBEDTLS_CIPHER_PADDING_ZEROS
#define MBEDTLS_CIPHER_PADDING_ZEROS
#else
#undef MBEDTLS_CIPHER_PADDING_ZEROS
#endif
// #ifdef CONFIG_MBEDTLS_CIPHER_PADDING_ZEROS
// #define MBEDTLS_CIPHER_PADDING_ZEROS
// #else
// #undef MBEDTLS_CIPHER_PADDING_ZEROS
// #endif
/**
* \def MBEDTLS_ECP_RESTARTABLE
@@ -520,7 +540,8 @@
*
*/
#ifdef CONFIG_MBEDTLS_CMAC_C
#define MBEDTLS_CMAC_C
// #define MBEDTLS_CMAC_C
#define PSA_WANT_ALG_CMAC 1
#else
#ifdef CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL
/* The mbedtls present in ROM is built with the MBEDTLS_CMAC_C symbol being enabled,
@@ -528,7 +549,8 @@
*/
#error "CONFIG_MBEDTLS_CMAC_C cannot be disabled when CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL is enabled"
#endif
#undef MBEDTLS_CMAC_C
// #undef MBEDTLS_CMAC_C
#undef PSA_WANT_ALG_CMAC
#endif
/**
@@ -545,11 +567,11 @@
#else
#undef MBEDTLS_ECP_DP_SECP192R1_ENABLED
#endif
#ifdef CONFIG_MBEDTLS_ECP_DP_SECP224R1_ENABLED
#define MBEDTLS_ECP_DP_SECP224R1_ENABLED
#else
#undef MBEDTLS_ECP_DP_SECP224R1_ENABLED
#endif
// #ifdef CONFIG_MBEDTLS_ECP_DP_SECP224R1_ENABLED
// #define MBEDTLS_ECP_DP_SECP224R1_ENABLED
// #else
// #undef MBEDTLS_ECP_DP_SECP224R1_ENABLED
// #endif
#ifdef CONFIG_MBEDTLS_ECP_DP_SECP256R1_ENABLED
#define MBEDTLS_ECP_DP_SECP256R1_ENABLED
#else
@@ -571,11 +593,11 @@
#else
#undef MBEDTLS_ECP_DP_SECP192K1_ENABLED
#endif
#ifdef CONFIG_MBEDTLS_ECP_DP_SECP224K1_ENABLED
#define MBEDTLS_ECP_DP_SECP224K1_ENABLED
#else
#undef MBEDTLS_ECP_DP_SECP224K1_ENABLED
#endif
// #ifdef CONFIG_MBEDTLS_ECP_DP_SECP224K1_ENABLED
// #define MBEDTLS_ECP_DP_SECP224K1_ENABLED
// #else
// #undef MBEDTLS_ECP_DP_SECP224K1_ENABLED
// #endif
#ifdef CONFIG_MBEDTLS_ECP_DP_SECP256K1_ENABLED
#define MBEDTLS_ECP_DP_SECP256K1_ENABLED
#else
@@ -647,9 +669,11 @@
* Comment this macro to disable deterministic ECDSA.
*/
#ifdef CONFIG_MBEDTLS_ECDSA_DETERMINISTIC
#define MBEDTLS_ECDSA_DETERMINISTIC
// #define MBEDTLS_ECDSA_DETERMINISTIC
#define PSA_WANT_ALG_DETERMINISTIC_ECDSA 1
#else
#undef MBEDTLS_ECDSA_DETERMINISTIC
// #undef MBEDTLS_ECDSA_DETERMINISTIC
#undef PSA_WANT_ALG_DETERMINISTIC_ECDSA
#endif
/**
@@ -779,11 +803,11 @@
* MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
* MBEDTLS_TLS_RSA_WITH_3DES_EDE_CBC_SHA
*/
#ifdef CONFIG_MBEDTLS_KEY_EXCHANGE_RSA
#define MBEDTLS_KEY_EXCHANGE_RSA_ENABLED
#else
#undef MBEDTLS_KEY_EXCHANGE_RSA_ENABLED
#endif
// #ifdef CONFIG_MBEDTLS_KEY_EXCHANGE_RSA
// #define MBEDTLS_KEY_EXCHANGE_RSA_ENABLED
// #else
// #undef MBEDTLS_KEY_EXCHANGE_RSA_ENABLED
// #endif
/**
* \def MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED
@@ -809,11 +833,11 @@
* MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
* MBEDTLS_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA
*/
#ifdef CONFIG_MBEDTLS_KEY_EXCHANGE_DHE_RSA
#define MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED
#else
#undef MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED
#endif
// #ifdef CONFIG_MBEDTLS_KEY_EXCHANGE_DHE_RSA
// #define MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED
// #else
// #undef MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED
// #endif
/**
* \def MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED
@@ -891,11 +915,11 @@
* MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256
* MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384
*/
#ifdef CONFIG_MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA
#define MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED
#else
#undef MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED
#endif
// #ifdef CONFIG_MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA
// #define MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED
// #else
// #undef MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED
// #endif
/**
* \def MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED
@@ -918,11 +942,11 @@
* MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256
* MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_GCM_SHA384
*/
#ifdef CONFIG_MBEDTLS_KEY_EXCHANGE_ECDH_RSA
#define MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED
#else
#undef MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED
#endif
// #ifdef CONFIG_MBEDTLS_KEY_EXCHANGE_ECDH_RSA
// #define MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED
// #else
// #undef MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED
// #endif
/**
* \def MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED
@@ -1008,11 +1032,11 @@
*
* Requires: MBEDTLS_BIGNUM_C
*/
#ifdef CONFIG_MBEDTLS_GENPRIME
#define MBEDTLS_GENPRIME
#else
#undef MBEDTLS_GENPRIME
#endif
// #ifdef CONFIG_MBEDTLS_GENPRIME
// #define MBEDTLS_GENPRIME
// #else
// #undef MBEDTLS_GENPRIME
// #endif
/**
* \def MBEDTLS_FS_IO
@@ -1037,7 +1061,7 @@
*
* Uncomment this macro to disable the built-in platform entropy functions.
*/
#define MBEDTLS_NO_PLATFORM_ENTROPY
// #define MBEDTLS_NO_PLATFORM_ENTROPY
#endif // !CONFIG_IDF_TARGET_LINUX
/**
@@ -1083,9 +1107,13 @@
* This enables support for PKCS#1 v1.5 operations.
*/
#ifdef CONFIG_MBEDTLS_PKCS1_V15
#define MBEDTLS_PKCS1_V15
// #define MBEDTLS_PKCS1_V15
#define PSA_WANT_ALG_RSA_PKCS1V15_CRYPT 1
#define PSA_WANT_ALG_RSA_PKCS1V15_SIGN 1
#else
#undef MBEDTLS_PKCS1_V15
// #undef MBEDTLS_PKCS1_V15
#undef PSA_WANT_ALG_RSA_PKCS1V15_CRYPT
#undef PSA_WANT_ALG_RSA_PKCS1V15_SIGN
#endif
/**
@@ -1098,9 +1126,11 @@
* This enables support for RSAES-OAEP and RSASSA-PSS operations.
*/
#ifdef CONFIG_MBEDTLS_PKCS1_V21
#define MBEDTLS_PKCS1_V21
// #define MBEDTLS_PKCS1_V21
#define PSA_WANT_ALG_RSA_OAEP 1
#else
#undef MBEDTLS_PKCS1_V21
// #undef MBEDTLS_PKCS1_V21
#undef PSA_WANT_ALG_RSA_OAEP
#endif
/**
@@ -1954,16 +1984,18 @@
* PEM_PARSE uses AES for decrypting encrypted keys.
*/
#ifdef CONFIG_MBEDTLS_AES_C
#define MBEDTLS_AES_C
// #define MBEDTLS_AES_C
#define PSA_WANT_KEY_TYPE_AES 1
#else
#undef MBEDTLS_AES_C
// #undef MBEDTLS_AES_C
#undef PSA_WANT_KEY_TYPE_AES
#endif
/* The following units have ESP32 hardware support,
uncommenting each _ALT macro will use the
hardware-accelerated implementation. */
#ifdef CONFIG_MBEDTLS_HARDWARE_AES
#define MBEDTLS_AES_ALT
// #define MBEDTLS_AES_ALT
#define MBEDTLS_PSA_ACCEL_ALG_CBC_NO_PADDING
#undef MBEDTLS_PSA_BUILTIN_ALG_CBC_NO_PADDING
#define MBEDTLS_PSA_ACCEL_ALG_CBC_PKCS7
@@ -2184,9 +2216,11 @@
* MBEDTLS_TLS_ECDHE_PSK_WITH_ARIA_256_CBC_SHA384
*/
#ifdef CONFIG_MBEDTLS_ARIA_C
#define MBEDTLS_ARIA_C
// #define MBEDTLS_ARIA_C
#define PSA_WANT_KEY_TYPE_ARIA 1
#else
#undef MBEDTLS_ARIA_C
// #undef MBEDTLS_ARIA_C
#undef PSA_WANT_KEY_TYPE_ARIA
#endif
/**
@@ -2203,9 +2237,11 @@
* enabled as well.
*/
#ifdef CONFIG_MBEDTLS_CCM_C
#define MBEDTLS_CCM_C
// #define MBEDTLS_CCM_C
#define PSA_WANT_ALG_CCM 1
#else
#undef MBEDTLS_CCM_C
// #undef MBEDTLS_CCM_C
#undef PSA_WANT_ALG_CCM
#endif
/**
@@ -2268,11 +2304,11 @@
*
* Uncomment to enable generic cipher wrappers.
*/
#ifdef CONFIG_MBEDTLS_CIPHER_C
#define MBEDTLS_CIPHER_C
#else
#undef MBEDTLS_CIPHER_C
#endif
// #ifdef CONFIG_MBEDTLS_CIPHER_C
// #define MBEDTLS_CIPHER_C
// #else
// #undef MBEDTLS_CIPHER_C
// #endif
/**
* \def MBEDTLS_CTR_DRBG_C
@@ -2354,11 +2390,11 @@
* This module is used by the following key exchanges:
* DHE-RSA, DHE-PSK
*/
#ifdef CONFIG_MBEDTLS_DHM_C
#define MBEDTLS_DHM_C
#else
#undef MBEDTLS_DHM_C
#endif
// #ifdef CONFIG_MBEDTLS_DHM_C
// #define MBEDTLS_DHM_C
// #else
// #undef MBEDTLS_DHM_C
// #endif
/**
* \def MBEDTLS_ECDH_C
@@ -2457,11 +2493,11 @@
*
* This module provides a generic entropy pool
*/
#ifdef CONFIG_MBEDTLS_ENTROPY_C
#define MBEDTLS_ENTROPY_C
#else
#undef MBEDTLS_ENTROPY_C
#endif
// #ifdef CONFIG_MBEDTLS_ENTROPY_C
// #define MBEDTLS_ENTROPY_C
// #else
// #undef MBEDTLS_ENTROPY_C
// #endif
/**
* \def MBEDTLS_ERROR_C
@@ -2508,9 +2544,11 @@
* requisites are enabled as well.
*/
#ifdef CONFIG_MBEDTLS_GCM_C
#define MBEDTLS_GCM_C
// #define MBEDTLS_GCM_C
#define PSA_WANT_ALG_GCM 1
#else
#undef MBEDTLS_GCM_C
// #undef MBEDTLS_GCM_C
#undef PSA_WANT_ALG_GCM
#endif
/**
@@ -2526,11 +2564,11 @@
* This module enables support for the Hashed Message Authentication Code
* (HMAC)-based key derivation function (HKDF).
*/
#ifdef CONFIG_MBEDTLS_HKDF_C
#define MBEDTLS_HKDF_C
#else
#undef MBEDTLS_HKDF_C
#endif
// #ifdef CONFIG_MBEDTLS_HKDF_C
// #define MBEDTLS_HKDF_C
// #else
// #undef MBEDTLS_HKDF_C
// #endif
/**
* \def MBEDTLS_HMAC_DRBG_C
@@ -2617,7 +2655,8 @@
* PEM_PARSE uses MD5 for decrypting encrypted keys.
*/
#ifdef CONFIG_MBEDTLS_MD5_C
#define MBEDTLS_MD5_C
// #define MBEDTLS_MD5_C
#define PSA_WANT_ALG_MD5 1
#else
#undef MBEDTLS_MD5_C
#undef PSA_WANT_ALG_MD5
@@ -2665,11 +2704,11 @@
*
* This modules translates between OIDs and internal values.
*/
#ifdef CONFIG_MBEDTLS_OID_C
#define MBEDTLS_OID_C
#else
#undef MBEDTLS_OID_C
#endif
// #ifdef CONFIG_MBEDTLS_OID_C
// #define MBEDTLS_OID_C
// #else
// #undef MBEDTLS_OID_C
// #endif
/**
* \def MBEDTLS_PADLOCK_C
@@ -2842,11 +2881,11 @@
*
* This module enables PKCS#12 functions.
*/
#ifdef CONFIG_MBEDTLS_PKCS12_C
#define MBEDTLS_PKCS12_C
#else
#undef MBEDTLS_PKCS12_C
#endif
// #ifdef CONFIG_MBEDTLS_PKCS12_C
// #define MBEDTLS_PKCS12_C
// #else
// #undef MBEDTLS_PKCS12_C
// #endif
/**
* \def MBEDTLS_PLATFORM_C
@@ -2917,9 +2956,13 @@
* Requires: MBEDTLS_BIGNUM_C, MBEDTLS_OID_C
*/
#ifdef CONFIG_MBEDTLS_RSA_C
#define MBEDTLS_RSA_C
// #define MBEDTLS_RSA_C
#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR 1
#define PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY 1
#else
#undef MBEDTLS_RSA_C
// #undef MBEDTLS_RSA_C
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR
#undef PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY
#endif
/**
@@ -2940,9 +2983,10 @@
*
*/
#if CONFIG_MBEDTLS_SHA1_C
#define MBEDTLS_SHA1_C
// #define MBEDTLS_SHA1_C
#define PSA_WANT_ALG_SHA_1 1
#else
#undef MBEDTLS_SHA1_C
// #undef MBEDTLS_SHA1_C
#undef PSA_WANT_ALG_SHA_1
#endif
/**
@@ -2979,9 +3023,10 @@
* This module adds support for SHA-384 and SHA-512.
*/
#ifdef CONFIG_MBEDTLS_SHA512_C
#define MBEDTLS_SHA512_C
// #define MBEDTLS_SHA512_C
#define PSA_WANT_ALG_SHA_512 1
#else
#undef MBEDTLS_SHA512_C
// #undef MBEDTLS_SHA512_C
#undef PSA_WANT_ALG_SHA_512
#endif
@@ -3000,9 +3045,10 @@
* Comment to disable SHA-384
*/
#ifdef CONFIG_MBEDTLS_SHA384_C
#define MBEDTLS_SHA384_C
// #define MBEDTLS_SHA384_C
#define PSA_WANT_ALG_SHA_384 1
#else
#undef MBEDTLS_SHA384_C
// #undef MBEDTLS_SHA384_C
#undef PSA_WANT_ALG_SHA_384
#endif
@@ -3022,17 +3068,19 @@
* This module is required for the SSL/TLS 1.2 PRF function.
*/
#ifdef CONFIG_MBEDTLS_SHA256_C
#define MBEDTLS_SHA256_C
// #define MBEDTLS_SHA256_C
#define PSA_WANT_ALG_SHA_256 1
#else
#undef MBEDTLS_SHA256_C
// #undef MBEDTLS_SHA256_C
#undef PSA_WANT_ALG_SHA_256
#endif
/* MBEDTLS_SHAxx_ALT to enable hardware SHA support
with software fallback.
*/
#ifdef CONFIG_MBEDTLS_HARDWARE_SHA
#define MBEDTLS_SHA1_ALT
#define MBEDTLS_SHA256_ALT
// #define MBEDTLS_SHA1_ALT
// #define MBEDTLS_SHA256_ALT
#define MBEDTLS_PSA_ACCEL_ALG_SHA_1
#undef MBEDTLS_PSA_BUILTIN_ALG_SHA_1
#define MBEDTLS_PSA_ACCEL_ALG_SHA_224
@@ -3049,7 +3097,7 @@
#undef MBEDTLS_PSA_BUILTIN_ALG_SHA_384
#undef MBEDTLS_SHA512_C
#undef MBEDTLS_SHA384_C
#define MBEDTLS_SHA512_ALT
// #define MBEDTLS_SHA512_ALT
#else
#undef MBEDTLS_SHA512_ALT
#endif
@@ -3069,9 +3117,17 @@
* This module adds support for SHA3.
*/
#ifdef CONFIG_MBEDTLS_SHA3_C
#define MBEDTLS_SHA3_C
// #define MBEDTLS_SHA3_C
#define PSA_WANT_ALG_SHA3_224 1
#define PSA_WANT_ALG_SHA3_256 1
#define PSA_WANT_ALG_SHA3_384 1
#define PSA_WANT_ALG_SHA3_512 1
#else
#undef MBEDTLS_SHA3_C
// #undef MBEDTLS_SHA3_C
#undef PSA_WANT_ALG_SHA3_224
#undef PSA_WANT_ALG_SHA3_256
#undef PSA_WANT_ALG_SHA3_384
#undef PSA_WANT_ALG_SHA3_512
#endif
/**
@@ -5,7 +5,7 @@
*/
#pragma once
#include_next "mbedtls/gcm.h"
// #include_next "mbedtls/gcm.h"
#include "sdkconfig.h"
#ifdef __cplusplus
+21 -21
View File
@@ -9,29 +9,29 @@
#include <stdlib.h>
#include "psa/crypto.h"
psa_status_t mbedtls_psa_external_get_random(
mbedtls_psa_external_random_context_t *context,
uint8_t *output, size_t output_size, size_t *output_length)
{
(void) context; // Unused parameter
// psa_status_t mbedtls_psa_external_get_random(
// mbedtls_psa_external_random_context_t *context,
// uint8_t *output, size_t output_size, size_t *output_length)
// {
// (void) context; // Unused parameter
if (output == NULL || output_length == NULL) {
return PSA_ERROR_INVALID_ARGUMENT;
}
// if (output == NULL || output_length == NULL) {
// return PSA_ERROR_INVALID_ARGUMENT;
// }
if (output_size == 0) {
*output_length = 0;
return PSA_SUCCESS;
}
// if (output_size == 0) {
// *output_length = 0;
// return PSA_SUCCESS;
// }
// Try to use getrandom() first (more secure)
ssize_t result = getrandom(output, output_size, 0);
if (result == (ssize_t)output_size) {
*output_length = output_size;
return PSA_SUCCESS;
}
// // Try to use getrandom() first (more secure)
// ssize_t result = getrandom(output, output_size, 0);
// if (result == (ssize_t)output_size) {
// *output_length = output_size;
// return PSA_SUCCESS;
// }
*output_length = output_size;
// *output_length = output_size;
return PSA_SUCCESS;
}
// return PSA_SUCCESS;
// }
@@ -8,21 +8,21 @@
#include <stddef.h>
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include "mbedtls/aes.h"
// #include "mbedtls/aes.h"
#include "mbedtls/asn1.h"
#include "mbedtls/asn1write.h"
#include "mbedtls/base64.h"
#include "mbedtls/bignum.h"
#include "mbedtls/ccm.h"
// #include "mbedtls/ccm.h"
#include "mbedtls/cipher.h"
#include "mbedtls/cmac.h"
#include "mbedtls/ctr_drbg.h"
// #include "mbedtls/cmac.h"
// #include "mbedtls/ctr_drbg.h"
#include "mbedtls/dhm.h"
#include "mbedtls/ecdh.h"
// #include "mbedtls/ecdh.h"
#include "mbedtls/ecdsa.h"
#include "mbedtls/ecjpake.h"
#include "mbedtls/ecp.h"
#include "mbedtls/entropy.h"
// #include "mbedtls/entropy.h"
#include "mbedtls/hmac_drbg.h"
#include "mbedtls/md.h"
#include "mbedtls/md5.h"
@@ -33,8 +33,8 @@
#include "mbedtls/pk.h"
#include "mbedtls/platform.h"
#include "mbedtls/rsa.h"
#include "mbedtls/sha1.h"
#include "mbedtls/sha256.h"
// #include "mbedtls/sha1.h"
// #include "mbedtls/sha256.h"
#include "mbedtls/sha512.h"
#include "mbedtls/ssl_ciphersuites.h"
#include "mbedtls/ssl.h"
@@ -12,6 +12,7 @@
#include "esp_aes.h"
#include "psa_crypto_core.h"
#include "constant_time_internal.h"
#include "esp_log.h"
static psa_status_t esp_crypto_aes_ecb_update(
esp_aes_operation_t *esp_aes_driver_ctx,
@@ -186,6 +187,7 @@ psa_status_t esp_crypto_aes_update(
}
if (output_size < expected_output_size) {
ESP_LOGE("TAG", "Output buffer too small: have %zu, need %zu", output_size, expected_output_size);
return PSA_ERROR_BUFFER_TOO_SMALL;
}
@@ -341,9 +343,10 @@ psa_status_t esp_crypto_aes_finish(
break;
case PSA_ALG_CBC_PKCS7:
if (esp_aes_driver_ctx->mode == PSA_CRYPTO_DRIVER_ENCRYPT) {
if (esp_aes_driver_ctx->unprocessed_len != 0) {
add_pkcs_padding(esp_aes_driver_ctx->unprocessed_data, esp_aes_driver_ctx->block_length, esp_aes_driver_ctx->unprocessed_len);
}
/* PKCS7 padding: always add padding, even if data is block-aligned.
* If unprocessed_len == 0, we add a full padding block.
* Otherwise, we pad the partial block. */
add_pkcs_padding(esp_aes_driver_ctx->unprocessed_data, esp_aes_driver_ctx->block_length, esp_aes_driver_ctx->unprocessed_len);
} else if (esp_aes_driver_ctx->unprocessed_len != esp_aes_driver_ctx->block_length) {
/*
* For decrypt operations, expect a full block,
@@ -525,16 +528,20 @@ psa_status_t esp_aes_cipher_encrypt(
memset(&esp_aes_driver_ctx, 0, sizeof(esp_aes_operation_t));
size_t update_output_length, finish_output_length;
// ESP_LOGI("esp_aes_cipher_encrypt", "Starting encryption");
status = esp_aes_cipher_encrypt_setup(&esp_aes_driver_ctx, attributes,
key_buffer, key_buffer_size,
alg);
if (status != PSA_SUCCESS) {
ESP_LOGE("esp_aes_cipher_encrypt", "Failed to setup encryption: %ld", status);
goto exit;
}
if (iv_length > 0) {
status = esp_crypto_aes_set_iv(&esp_aes_driver_ctx, iv, iv_length);
if (status != PSA_SUCCESS) {
ESP_LOGE("esp_aes_cipher_encrypt", "Failed to set IV: %ld", status);
goto exit;
}
}
@@ -543,6 +550,7 @@ psa_status_t esp_aes_cipher_encrypt(
output, output_size,
&update_output_length);
if (status != PSA_SUCCESS) {
ESP_LOGE("esp_aes_cipher_encrypt", "Failed to update: %ld", status);
goto exit;
}
@@ -550,6 +558,7 @@ psa_status_t esp_aes_cipher_encrypt(
mbedtls_buffer_offset(output, update_output_length),
output_size - update_output_length, &finish_output_length);
if (status != PSA_SUCCESS) {
ESP_LOGE("esp_aes_cipher_encrypt", "Failed to finish: %ld", status);
goto exit;
}
@@ -559,6 +568,7 @@ exit:
if (status == PSA_SUCCESS) {
status = esp_crypto_aes_abort(&esp_aes_driver_ctx);
} else {
ESP_LOGE("esp_aes_cipher_encrypt", "Failed to abort: %ld", status);
esp_crypto_aes_abort(&esp_aes_driver_ctx);
}
@@ -5,7 +5,7 @@
*/
#include <string.h>
#include "esp_log.h"
#include "mbedtls/aes.h"
// #include "mbedtls/aes.h"
#include "psa_crypto_core.h"
// #include "mbedtls/cipher.h"
@@ -44,7 +44,7 @@ static psa_status_t esp_crypto_aes_gcm_setup(
esp_aes_gcm_init(ctx);
status = mbedtls_to_psa_error(esp_aes_gcm_setkey(ctx, MBEDTLS_CIPHER_ID_AES, key_buffer, key_buffer_size * 8));
status = mbedtls_to_psa_error(esp_aes_gcm_setkey(ctx, 2, key_buffer, key_buffer_size * 8));
if (status != PSA_SUCCESS) {
goto exit;
@@ -46,7 +46,7 @@ static void esp_internal_sha_update_state(esp_sha256_context *ctx)
ctx->sha_state = ESP_SHA256_STATE_IN_PROCESS;
} else if (ctx->sha_state == ESP_SHA256_STATE_IN_PROCESS) {
ctx->first_block = false;
esp_sha_write_digest_state(ctx->mode, ctx->state);
esp_sha_write_digest_state(ctx->mode, ctx->state);
}
}
@@ -54,7 +54,7 @@ psa_status_t esp_sha512_starts(esp_sha512_context *ctx, int mode) {
static int esp_internal_sha_update_state(esp_sha512_context *ctx)
{
if (ctx->sha_state == ESP_SHA512_STATE_INIT) {
if (ctx->mode == SHA2_512) {
if (ctx->mode == SHA2_512T) {
int ret = -1;
if ((ret = esp_sha_512_t_init_hash(ctx->t_val)) != 0) {
return ret;
@@ -52,11 +52,11 @@ psa_status_t esp_sha1_starts(esp_sha1_context *ctx)
ctx->state[2] = 0x98BADCFE;
ctx->state[3] = 0x10325476;
ctx->state[4] = 0xC3D2E1F0;
if (ctx->operation_mode == ESP_SHA_MODE_HARDWARE) {
esp_sha_unlock_engine(SHA1);
}
ctx->sha_state = ESP_SHA1_STATE_INIT;
return ESP_OK;
ctx->first_block = false;
ctx->operation_mode = ESP_SHA_MODE_SOFTWARE;
return PSA_SUCCESS;
}
static void esp_sha1_software_process( esp_sha1_context *ctx, const unsigned char data[64] )
@@ -97,11 +97,13 @@ psa_status_t esp_sha512_starts(esp_sha512_context *ctx, int mode)
ctx->mode = mode;
ctx->sha_state = ESP_SHA512_STATE_INIT;
if (ctx->operation_mode == ESP_SHA_MODE_HARDWARE) {
esp_sha_unlock_engine(sha_type(ctx));
}
ctx->operation_mode = ESP_SHA_MODE_SOFTWARE;
ctx->first_block = false;
// if (ctx->operation_mode == ESP_SHA_MODE_HARDWARE) {
// esp_sha_unlock_engine(sha_type(ctx));
// }
return ESP_OK;
return PSA_SUCCESS;
}
/*
@@ -283,6 +285,10 @@ static int esp_sha512_update(esp_sha512_context *ctx, const unsigned char *input
ilen -= 128;
}
if (ctx->operation_mode == ESP_SHA_MODE_HARDWARE) {
esp_sha_read_digest_state(sha_type(ctx), ctx->state);
}
if ( ilen > 0 ) {
memcpy( (void *) (ctx->buffer + left), input, ilen );
}
@@ -451,7 +457,7 @@ psa_status_t esp_sha512_driver_clone(const esp_sha512_context *source_ctx, esp_s
// If the source context is in hardware mode, we need to read the digest state
// from the hardware engine to ensure the target context has the correct state
if (source_ctx->operation_mode == ESP_SHA_MODE_HARDWARE) {
esp_sha_read_digest_state(sha_type(source_ctx), target_ctx->state);
esp_sha_read_digest_state(SHA2_512, target_ctx->state);
target_ctx->operation_mode = ESP_SHA_MODE_SOFTWARE; // Cloned context operates in software mode
}
return PSA_SUCCESS;
@@ -13,6 +13,7 @@
#include "psa/crypto.h"
#include "psa/crypto_sizes.h"
#include "esp_log.h"
#include "esp_heap_caps.h"
#if CONFIG_SOC_SHA_GDMA
#include "esp_sha_internal.h"
@@ -30,7 +31,7 @@ static int esp_sha_driver_check_supported_algorithm(psa_algorithm_t alg) {
}
static int esp_sha_validate_args(psa_algorithm_t alg, const uint8_t *input, size_t input_length, uint8_t *hash, size_t hash_size) {
if (!input || !hash) {
if (!hash) {
return ESP_ERR_INVALID_ARG;
}
@@ -113,7 +114,11 @@ psa_status_t esp_sha_hash_setup(esp_sha_hash_operation_t *operation, psa_algorit
}
#if CONFIG_SOC_SHA_SUPPORT_SHA1
if (alg == PSA_ALG_SHA_1) {
esp_sha1_context *sha1_ctx = calloc(1, sizeof(esp_sha1_context));
esp_sha1_context *sha1_ctx = heap_caps_malloc(sizeof(esp_sha1_context), MALLOC_CAP_DMA | MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL);
if (!sha1_ctx) {
return PSA_ERROR_INSUFFICIENT_MEMORY;
}
memset(sha1_ctx, 0, sizeof(esp_sha1_context));
operation->sha_ctx = sha1_ctx;
operation->sha_type = ESP_SHA_OPERATION_TYPE_SHA1;
return esp_sha1_starts(sha1_ctx);
@@ -125,7 +130,11 @@ psa_status_t esp_sha_hash_setup(esp_sha_hash_operation_t *operation, psa_algorit
alg == PSA_ALG_SHA_224 ||
#endif // CONFIG_SOC_SHA_SUPPORT_SHA224
alg == PSA_ALG_SHA_256) {
esp_sha256_context *sha256_ctx = calloc(1, sizeof(esp_sha256_context));
esp_sha256_context *sha256_ctx = heap_caps_malloc(sizeof(esp_sha256_context), MALLOC_CAP_DMA | MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL);
if (!sha256_ctx) {
return PSA_ERROR_INSUFFICIENT_MEMORY;
}
memset(sha256_ctx, 0, sizeof(esp_sha256_context));
operation->sha_ctx = sha256_ctx;
int mode = SHA2_256;
operation->sha_type = ESP_SHA_OPERATION_TYPE_SHA256;
@@ -142,7 +151,11 @@ psa_status_t esp_sha_hash_setup(esp_sha_hash_operation_t *operation, psa_algorit
alg == PSA_ALG_SHA_384 ||
#endif // CONFIG_SOC_SHA_SUPPORT_SHA384
alg == PSA_ALG_SHA_512) {
esp_sha512_context *sha512_ctx = calloc(1, sizeof(esp_sha512_context));
esp_sha512_context *sha512_ctx = heap_caps_malloc(sizeof(esp_sha512_context), MALLOC_CAP_DMA | MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL);
if (!sha512_ctx) {
return PSA_ERROR_INSUFFICIENT_MEMORY;
}
memset(sha512_ctx, 0, sizeof(esp_sha512_context));
operation->sha_ctx = sha512_ctx;
int mode = SHA2_512;
operation->sha_type = ESP_SHA_OPERATION_TYPE_SHA512;
@@ -277,7 +290,12 @@ psa_status_t esp_sha_hash_clone(
target_operation->sha_type = source_operation->sha_type;
#if CONFIG_SOC_SHA_SUPPORT_SHA1
if (target_operation->sha_type == ESP_SHA_OPERATION_TYPE_SHA1) {
target_operation->sha_ctx = calloc(1, sizeof(esp_sha1_context));
esp_sha1_context *sha1_ctx = heap_caps_malloc(sizeof(esp_sha1_context), MALLOC_CAP_DMA | MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL);
if (!sha1_ctx) {
return PSA_ERROR_INSUFFICIENT_MEMORY;
}
memset(sha1_ctx, 0, sizeof(esp_sha1_context));
target_operation->sha_ctx = sha1_ctx;
if (!target_operation->sha_ctx) {
return PSA_ERROR_INSUFFICIENT_MEMORY;
}
@@ -287,7 +305,12 @@ psa_status_t esp_sha_hash_clone(
#if CONFIG_SOC_SHA_SUPPORT_SHA224 || CONFIG_SOC_SHA_SUPPORT_SHA256
if (target_operation->sha_type == ESP_SHA_OPERATION_TYPE_SHA256 ||
target_operation->sha_type == ESP_SHA_OPERATION_TYPE_SHA224) {
target_operation->sha_ctx = calloc(1, sizeof(esp_sha256_context));
esp_sha256_context *sha256_ctx = heap_caps_malloc(sizeof(esp_sha256_context), MALLOC_CAP_DMA | MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL);
if (!sha256_ctx) {
return PSA_ERROR_INSUFFICIENT_MEMORY;
}
memset(sha256_ctx, 0, sizeof(esp_sha256_context));
target_operation->sha_ctx = sha256_ctx;
if (!target_operation->sha_ctx) {
return PSA_ERROR_INSUFFICIENT_MEMORY;
}
@@ -297,7 +320,12 @@ psa_status_t esp_sha_hash_clone(
#if CONFIG_SOC_SHA_SUPPORT_SHA384 || CONFIG_SOC_SHA_SUPPORT_SHA512
if (target_operation->sha_type == ESP_SHA_OPERATION_TYPE_SHA384 ||
target_operation->sha_type == ESP_SHA_OPERATION_TYPE_SHA512) {
target_operation->sha_ctx = calloc(1, sizeof(esp_sha512_context));
esp_sha512_context *sha512_ctx = heap_caps_malloc(sizeof(esp_sha512_context), MALLOC_CAP_DMA | MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL);
if (!sha512_ctx) {
return PSA_ERROR_INSUFFICIENT_MEMORY;
}
memset(sha512_ctx, 0, sizeof(esp_sha512_context));
target_operation->sha_ctx = sha512_ctx;
if (!target_operation->sha_ctx) {
return PSA_ERROR_INSUFFICIENT_MEMORY;
}
@@ -5,6 +5,10 @@
*/
#pragma once
#ifdef __cplusplus
extern "C" {
#endif
#if defined(ESP_AES_DRIVER_ENABLED)
#ifndef PSA_CRYPTO_ACCELERATOR_DRIVER_PRESENT
#define PSA_CRYPTO_ACCELERATOR_DRIVER_PRESENT
@@ -90,3 +94,7 @@ psa_status_t esp_aes_cipher_finish(
psa_status_t esp_aes_cipher_abort(
esp_aes_operation_t *operation);
#endif /* ESP_AES_DRIVER_ENABLED */
#ifdef __cplusplus
}
#endif
@@ -6,6 +6,10 @@
#pragma once
#ifdef __cplusplus
extern "C" {
#endif
/**
* \file psa_crypto_driver_esp_sha_contexts.h
*
@@ -43,3 +47,7 @@ typedef struct {
} esp_aes_gcm_operation_t;
#endif /* ESP_AES_DRIVER_ENABLED */
#ifdef __cplusplus
}
#endif
@@ -5,6 +5,10 @@
*/
#pragma once
#ifdef __cplusplus
extern "C" {
#endif
#if defined(ESP_AES_DRIVER_ENABLED)
#include "psa/crypto.h"
@@ -45,3 +49,7 @@ psa_status_t esp_cmac_mac_verify_finish(
const uint8_t *mac,
size_t mac_length);
#endif /* ESP_AES_DRIVER_ENABLED */
#ifdef __cplusplus
}
#endif
@@ -6,7 +6,9 @@
#pragma once
#ifdef __cplusplus
extern "C" {
#endif
#if defined(ESP_AES_DRIVER_ENABLED) || defined(PSA_CRYPTO_DRIVER_TEST)
@@ -50,3 +52,7 @@ typedef struct {
} esp_cmac_operation_t;
#endif /* ESP_AES_DRIVER_ENABLED */
#ifdef __cplusplus
}
#endif
@@ -5,6 +5,10 @@
*/
#pragma once
#ifdef __cplusplus
extern "C" {
#endif
#if defined(ESP_SHA_DRIVER_ENABLED)
#ifndef PSA_CRYPTO_ACCELERATOR_DRIVER_PRESENT
#define PSA_CRYPTO_ACCELERATOR_DRIVER_PRESENT
@@ -61,3 +65,7 @@ psa_status_t esp_sha_hash_clone(
const esp_sha_hash_operation_t *source_operation,
esp_sha_hash_operation_t *target_operation);
#endif
#ifdef __cplusplus
}
#endif
@@ -6,6 +6,10 @@
#pragma once
#ifdef __cplusplus
extern "C" {
#endif
/**
* \file psa_crypto_driver_esp_sha_contexts.h
*
@@ -117,3 +121,7 @@ typedef struct {
} esp_sha_hash_operation_t;
#endif /* ESP_SHA_DRIVER_ENABLED */
#ifdef __cplusplus
}
#endif
+1 -1
View File
@@ -17,7 +17,7 @@
#if defined(MBEDTLS_SHA1_ALT)
#include "mbedtls/sha1.h"
// #include "mbedtls/sha1.h"
#include <string.h>
#include <stdbool.h>
@@ -17,7 +17,7 @@
#if defined(MBEDTLS_SHA256_C) && defined(MBEDTLS_SHA256_ALT)
#include "mbedtls/sha256.h"
// #include "mbedtls/sha256.h"
#include <string.h>
#include <stdbool.h>
+3 -3
View File
@@ -16,9 +16,9 @@
#include "soc/soc_caps.h"
#include "esp_log.h"
#include <mbedtls/sha1.h>
#include <mbedtls/sha256.h>
#include <mbedtls/sha512.h>
// #include <mbedtls/sha1.h>
// #include <mbedtls/sha256.h>
// #include <mbedtls/sha512.h>
#if SOC_SHA_SUPPORT_PARALLEL_ENG
#include "sha/sha_parallel_engine.h"
@@ -19,7 +19,7 @@
#if defined(MBEDTLS_SHA1_ALT)
#include "mbedtls/sha1.h"
// #include "mbedtls/sha1.h"
#include <string.h>
@@ -19,7 +19,7 @@
#if defined(MBEDTLS_SHA256_C) && defined(MBEDTLS_SHA256_ALT)
#include "mbedtls/sha256.h"
// #include "mbedtls/sha256.h"
#include <string.h>
@@ -3,7 +3,10 @@ set(TEST_CRTS "crts/server_cert_chain.pem"
"crts/server_cert_bundle"
"crts/bad_md_crt.pem"
"crts/wrong_sig_crt_esp32_com.pem"
"crts/correct_sig_crt_esp32_com.pem")
"crts/correct_sig_crt_esp32_com.pem"
"crts/ecdsa_cert_bundle"
"crts/ecdsa_correct_sig_crt.pem"
"crts/ecdsa_wrong_sig_crt.pem")
idf_component_register(
SRC_DIRS "."
+26 -2
View File
@@ -3,22 +3,46 @@
*
* SPDX-License-Identifier: Unlicense OR CC0-1.0
*/
#include <string.h>
#include "psa/crypto.h"
#include "freertos/FreeRTOS.h"
#include "freertos/task.h"
#include "unity.h"
#include "mbedtls/aes.h"
// // #include "mbedtls/aes.h"
#include "memory_checks.h"
#include "soc/soc_caps.h"
#include "esp_newlib.h"
#include "esp_random.h"
#include "mbedtls/entropy.h"
// // #include "mbedtls/entropy.h"
#define CALL_SZ (32 * 1024)
/* setUp runs before every test */
void setUp(void)
{
// psa_crypto_init();
// Execute mbedtls_aes_init operation to allocate AES interrupt
// allocation memory which is considered as leak otherwise
#if SOC_AES_SUPPORTED
uint8_t iv[16];
uint8_t key[16];
memset(iv, 0xEE, 16);
memset(key, 0x44, 16);
uint8_t *buf = heap_caps_malloc(CALL_SZ, MALLOC_CAP_DMA | MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL);
TEST_ASSERT_NOT_NULL(buf);
psa_key_id_t key_id;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT);
psa_set_key_algorithm(&attributes, PSA_ALG_ECB_NO_PADDING);
psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
psa_set_key_bits(&attributes, 128);
psa_import_key(&attributes, key, sizeof(key), &key_id);
size_t output_length = 0;
psa_cipher_encrypt(key_id, PSA_ALG_ECB_NO_PADDING, buf, CALL_SZ, buf, CALL_SZ, &output_length);
heap_caps_free(buf);
psa_destroy_key(key_id);
// mbedtls_aes_context ctx;
// mbedtls_aes_init(&ctx);
#endif // SOC_AES_SUPPORTED
@@ -0,0 +1,15 @@
-----BEGIN CERTIFICATE-----
MIICQjCCAcmgAwIBAgIUTbvKUa+55zFxQhgDIQ91RdGXEXIwCgYIKoZIzj0EAwQw
YDELMAkGA1UEBhMCVVMxDTALBgNVBAgMBFRlc3QxDTALBgNVBAcMBFRlc3QxFjAU
BgNVBAoMDVRlc3QgRUNEU0EgQ0ExGzAZBgNVBAMMElRlc3QgRUNEU0EgUm9vdCBD
QTAeFw0yNTExMDMwODAzNTdaFw0yNjExMDMwODAzNTdaMGIxCzAJBgNVBAYTAlVT
MQ0wCwYDVQQIDARUZXN0MQ0wCwYDVQQHDARUZXN0MRQwEgYDVQQKDAtUZXN0IFNl
cnZlcjEfMB0GA1UEAwwWZWNkc2EtdGVzdC5leGFtcGxlLmNvbTB2MBAGByqGSM49
AgEGBSuBBAAiA2IABFd+Bd6HtASMpEytx+QfDk8I0DX73EKQ3tR2TUJuhg7B2epc
qqmMXZ5KQpOY/+V0kv1WyLCDisw7vP6d4yQjokSJqEnaO3af5TJh0WCjWJsVtNZy
VAQMS9lxSZW1a1lle6NCMEAwHQYDVR0OBBYEFNJ2LzJjqMZXRjY0NNvVTS3Crsjh
MB8GA1UdIwQYMBaAFElMhoUHf0Loi7Kzcpp0t4AfUBsuMAoGCCqGSM49BAMEA2cA
MGQCMCiXh9m1BOkedod4lVzKLx535sLbFM7OxnYFxYOCK4Q3djtgxjy0OFmlyD5I
YLUfxAIwO35NHh06OMyOI85NJbOYD2oPDiju/1JYHhER9rPAFrJJtwKGhNlMufqk
V+9SwUK2
-----END CERTIFICATE-----
@@ -0,0 +1,15 @@
-----BEGIN CERTIFICATE-----
MIICQjCCAcmgAwIBAgIUTbvKUa+55zFxQhgDIQ91RdGXEXIwCgYIKoZIzj0EAwQw
YDELMAkGA1UEBhMCVVMxDTALBgNVBAgMBFRlc3QxDTALBgNVBAcMBFRlc3QxFjAU
BgNVBAoMDVRlc3QgRUNEU0EgQ0ExGzAZBgNVBAMMElRlc3QgRUNEU0EgUm9vdCBD
QTAeFw0yNTExMDMwODAzNTdaFw0yNjExMDMwODAzNTdaMGIxCzAJBgNVBAYTAlVT
MQ0wCwYDVQQIDARUZXN0MQ0wCwYDVQQHDARUZXN0MRQwEgYDVQQKDAtUZXN0IFNl
cnZlcjEfMB0GA1UEAwwWZWNkc2EtdGVzdC5leGFtcGxlLmNvbTB2MBAGByqGSM49
AgEGBSuBBAAiA2IABFd+Bd6HtASMpEytx+QfDk8I0DX73EKQ3tR2TUJuhg7B2epc
qqmMXZ5KQpOY/+V0kv1WyLCDisw7vP6d4yQjokSJqEnaO3af5TJh0WCjWJsVtNZy
VAQMS9lxSZW1a1lle6NCMEAwHQYDVR0OBBYEFNJ2LzJjqMZXRjY0NNvVTS3Crsjh
MB8GA1UdIwQYMBaAFElMhoUHf0Loi7Kzcpp0t4AfUBsuMAoGCCqGSM49BAMEA2cA
MGQCMCiXh9m1BOkedod4lVzKMx535sLbFM7OxnYFxYOCK4Q3djtgxjy0OFmlyD5I
YLUfxAIwO35NHh06OMyOI85NJbOYD2oPDiju/1JYHhER9rPAFrJJtwKGhNlMufqk
V+9SwUK2
-----END CERTIFICATE-----
@@ -11,7 +11,7 @@
#include <stdio.h>
#include <stdbool.h>
#include <esp_system.h>
#include "mbedtls/aes.h"
// #include "mbedtls/aes.h"
#include "mbedtls/gcm.h"
#include "unity.h"
#include "sdkconfig.h"
@@ -9,7 +9,7 @@
#include <stdbool.h>
#include <esp_system.h>
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
#include "mbedtls/aes.h"
// #include "mbedtls/aes.h"
#include "mbedtls/gcm.h"
#include "unity.h"
#include "sdkconfig.h"
@@ -25,10 +25,7 @@ TEST_CASE("mbedtls AES performance", "[aes][timeout=60]")
uint8_t iv[16];
uint8_t key[16];
psa_status_t status = PSA_SUCCESS;
// if (status != PSA_SUCCESS) {
// TEST_FAIL_MESSAGE("PSA crypto initialization failed");
// }
psa_status_t status;
memset(iv, 0xEE, 16);
memset(key, 0x44, 16);
@@ -65,7 +62,7 @@ TEST_CASE("mbedtls AES performance", "[aes][timeout=60]")
memset(buf, 0xAA, CALL_SZ);
psa_cipher_update(&operation, buf, CALL_SZ, buf, CALL_SZ, &output_length);
}
psa_cipher_finish(&operation, buf + CALL_SZ - 16, 16, &output_length);
psa_cipher_finish(&operation, buf + output_length, CALL_SZ - output_length, &output_length);
elapsed_usec = ccomp_timer_stop();
/* Sanity check: make sure the last ciphertext block matches

Some files were not shown because too many files have changed in this diff Show More