mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
feat(mbedtls): migrates ESP-TEE with PSA APIs
This commit is contained in:
@@ -230,7 +230,7 @@ static void init_ota_sem(void)
|
||||
static int create_ota_task(const char *url, const char *task_name, void (*ota_task)(void *))
|
||||
{
|
||||
init_ota_sem();
|
||||
if (xTaskCreate(ota_task, task_name, configMINIMAL_STACK_SIZE * 3, (void *)url, 5, NULL) != pdPASS) {
|
||||
if (xTaskCreate(ota_task, task_name, configMINIMAL_STACK_SIZE * 4, (void *)url, 5, NULL) != pdPASS) {
|
||||
ESP_LOGE(TAG, "Task creation failed for %s", task_name);
|
||||
return ESP_FAIL;
|
||||
}
|
||||
|
||||
@@ -14,9 +14,11 @@
|
||||
#include "esp_console.h"
|
||||
#include "argtable3/argtable3.h"
|
||||
|
||||
#include "mbedtls/ecp.h"
|
||||
#include "mbedtls/ecdsa.h"
|
||||
#include "mbedtls/sha256.h"
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
// #include "mbedtls/ecp.h"
|
||||
// #include "mbedtls/ecdsa.h"
|
||||
// #include "mbedtls/sha256.h"
|
||||
#include "psa/crypto.h"
|
||||
|
||||
#include "esp_tee_sec_storage.h"
|
||||
#include "example_tee_srv.h"
|
||||
@@ -91,57 +93,33 @@ static esp_err_t verify_ecdsa_secp256r1_sign(const uint8_t *digest, size_t len,
|
||||
|
||||
esp_err_t err = ESP_FAIL;
|
||||
|
||||
mbedtls_mpi r, s;
|
||||
mbedtls_mpi_init(&r);
|
||||
mbedtls_mpi_init(&s);
|
||||
psa_key_id_t key_id = 0;
|
||||
psa_key_attributes_t key_attributes = PSA_KEY_ATTRIBUTES_INIT;
|
||||
psa_set_key_type(&key_attributes, PSA_KEY_TYPE_ECC_PUBLIC_KEY(PSA_ECC_FAMILY_SECP_R1));
|
||||
psa_set_key_usage_flags(&key_attributes, PSA_KEY_USAGE_SIGN_HASH | PSA_KEY_USAGE_EXPORT | PSA_KEY_USAGE_VERIFY_HASH);
|
||||
psa_set_key_algorithm(&key_attributes, PSA_ALG_ECDSA(PSA_ALG_SHA_256));
|
||||
|
||||
mbedtls_ecdsa_context ecdsa_context;
|
||||
mbedtls_ecdsa_init(&ecdsa_context);
|
||||
uint8_t pub_key[2 * ECDSA_SECP256R1_KEY_LEN + 1];
|
||||
pub_key[0] = 0x04;
|
||||
memcpy(pub_key + 1, pubkey->pub_x, ECDSA_SECP256R1_KEY_LEN);
|
||||
memcpy(pub_key + 1 + ECDSA_SECP256R1_KEY_LEN, pubkey->pub_y, ECDSA_SECP256R1_KEY_LEN);
|
||||
|
||||
int ret = mbedtls_ecp_group_load(&ecdsa_context.MBEDTLS_PRIVATE(grp), MBEDTLS_ECP_DP_SECP256R1);
|
||||
if (ret != 0) {
|
||||
psa_status_t status = psa_import_key(&key_attributes, pub_key, sizeof(pub_key), &key_id);
|
||||
if (status != PSA_SUCCESS) {
|
||||
goto exit;
|
||||
}
|
||||
|
||||
size_t plen = mbedtls_mpi_size(&ecdsa_context.MBEDTLS_PRIVATE(grp).P);
|
||||
|
||||
ret = mbedtls_mpi_read_binary(&r, sign->sign_r, plen);
|
||||
if (ret != 0) {
|
||||
status = psa_verify_hash(key_id, PSA_ALG_ECDSA(PSA_ALG_SHA_256), digest, len, sign->signature, sizeof(sign->signature));
|
||||
if (status != PSA_SUCCESS) {
|
||||
goto exit;
|
||||
}
|
||||
|
||||
ret = mbedtls_mpi_read_binary(&s, sign->sign_s, plen);
|
||||
if (ret != 0) {
|
||||
goto exit;
|
||||
}
|
||||
|
||||
ret = mbedtls_mpi_read_binary(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(X), pubkey->pub_x, plen);
|
||||
if (ret != 0) {
|
||||
goto exit;
|
||||
}
|
||||
|
||||
ret = mbedtls_mpi_read_binary(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Y), pubkey->pub_y, plen);
|
||||
if (ret != 0) {
|
||||
goto exit;
|
||||
}
|
||||
|
||||
ret = mbedtls_mpi_lset(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Z), 1);
|
||||
if (ret != 0) {
|
||||
goto exit;
|
||||
}
|
||||
|
||||
ret = mbedtls_ecdsa_verify(&ecdsa_context.MBEDTLS_PRIVATE(grp), digest, len, &ecdsa_context.MBEDTLS_PRIVATE(Q), &r, &s);
|
||||
if (ret != 0) {
|
||||
goto exit;
|
||||
}
|
||||
psa_destroy_key(key_id);
|
||||
psa_reset_key_attributes(&key_attributes);
|
||||
|
||||
err = ESP_OK;
|
||||
|
||||
exit:
|
||||
mbedtls_mpi_free(&r);
|
||||
mbedtls_mpi_free(&s);
|
||||
mbedtls_ecdsa_free(&ecdsa_context);
|
||||
|
||||
return err;
|
||||
}
|
||||
|
||||
@@ -161,8 +139,10 @@ static int get_msg_sha256(int argc, char **argv)
|
||||
const char *msg = (const char *)cmd_get_msg_sha256_args.msg->sval[0];
|
||||
|
||||
uint8_t msg_digest[SHA256_DIGEST_SZ];
|
||||
int ret = mbedtls_sha256((const unsigned char *)msg, strlen(msg), msg_digest, false);
|
||||
if (ret != 0) {
|
||||
size_t msg_len = strlen(msg);
|
||||
size_t digest_len = 0;
|
||||
psa_status_t status = psa_hash_compute(PSA_ALG_SHA_256, (const uint8_t *)msg, msg_len, msg_digest, sizeof(msg_digest), &digest_len);
|
||||
if (status != PSA_SUCCESS) {
|
||||
ESP_LOGE(TAG, "Failed to calculate message hash!");
|
||||
return ESP_FAIL;
|
||||
}
|
||||
|
||||
@@ -5,8 +5,8 @@ CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
|
||||
# Reducing TEE I/DRAM sizes
|
||||
# 24KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x6000
|
||||
# 12KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x3000
|
||||
# 16KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x4000
|
||||
|
||||
# Disable TEE logs (also disable all panic logs)
|
||||
CONFIG_SECURE_TEE_DEBUG_MODE=n
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
# Reducing TEE I/DRAM sizes
|
||||
# 28KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7000
|
||||
# 16KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x5000
|
||||
|
||||
# TEE Secure Storage: Release mode
|
||||
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
|
||||
|
||||
@@ -18,4 +18,4 @@ CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
|
||||
|
||||
# Increasing TEE DRAM size
|
||||
# 18KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x4800
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x5000
|
||||
|
||||
Reference in New Issue
Block a user