diff --git a/components/soc/esp32c5/include/soc/Kconfig.soc_caps.in b/components/soc/esp32c5/include/soc/Kconfig.soc_caps.in index 1f98c027ff8..60155333315 100644 --- a/components/soc/esp32c5/include/soc/Kconfig.soc_caps.in +++ b/components/soc/esp32c5/include/soc/Kconfig.soc_caps.in @@ -1487,10 +1487,22 @@ config SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND bool default y +config SOC_FLASH_ENCRYPTION_PAGE_CONFIGURABLE + bool + default y + config SOC_PSRAM_ENCRYPTION_XTS_AES_128 bool default y +config SOC_PSRAM_ENCRYPTION_SEPARATE_KEY + bool + default y + +config SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE + bool + default y + config SOC_RECOVERY_BOOTLOADER_SUPPORTED bool default y diff --git a/components/soc/esp32c5/include/soc/soc_caps.h b/components/soc/esp32c5/include/soc/soc_caps.h index afee80f6501..960b9ecaad1 100644 --- a/components/soc/esp32c5/include/soc/soc_caps.h +++ b/components/soc/esp32c5/include/soc/soc_caps.h @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2023-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2023-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -564,9 +564,12 @@ #define SOC_FLASH_ENCRYPTION_XTS_AES 1 #define SOC_FLASH_ENCRYPTION_XTS_AES_128 1 #define SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND 1 +#define SOC_FLASH_ENCRYPTION_PAGE_CONFIGURABLE 1 /* Flash encryption can be configured on a MMU page basis */ /*-------------------------- PSRAM Encryption CAPS----------------------------*/ -#define SOC_PSRAM_ENCRYPTION_XTS_AES_128 (1) +#define SOC_PSRAM_ENCRYPTION_XTS_AES_128 1 +#define SOC_PSRAM_ENCRYPTION_SEPARATE_KEY 1 /* PSRAM encryption can use independent key */ +#define SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE 1 /* PSRAM encryption can be configured on a MMU page basis */ /*------------------------Bootloader CAPS---------------------------------*/ /* Support Recovery Bootloader */ diff --git a/components/soc/esp32c6/include/soc/Kconfig.soc_caps.in b/components/soc/esp32c6/include/soc/Kconfig.soc_caps.in index 0134da89cb9..46f397f00bc 100644 --- a/components/soc/esp32c6/include/soc/Kconfig.soc_caps.in +++ b/components/soc/esp32c6/include/soc/Kconfig.soc_caps.in @@ -1279,6 +1279,10 @@ config SOC_FLASH_ENCRYPTION_XTS_AES_128 bool default y +config SOC_FLASH_ENCRYPTION_PAGE_CONFIGURABLE + bool + default y + config SOC_APM_CTRL_FILTER_SUPPORTED bool default y diff --git a/components/soc/esp32c6/include/soc/soc_caps.h b/components/soc/esp32c6/include/soc/soc_caps.h index 1f6b558c5ae..b56885a7898 100644 --- a/components/soc/esp32c6/include/soc/soc_caps.h +++ b/components/soc/esp32c6/include/soc/soc_caps.h @@ -491,6 +491,7 @@ #define SOC_FLASH_ENCRYPTED_XTS_AES_BLOCK_MAX (64) #define SOC_FLASH_ENCRYPTION_XTS_AES 1 #define SOC_FLASH_ENCRYPTION_XTS_AES_128 1 +#define SOC_FLASH_ENCRYPTION_PAGE_CONFIGURABLE 1 /* Flash encryption can be configured on a MMU page basis */ /*-------------------------- APM CAPS ----------------------------------------*/ #define SOC_APM_CTRL_FILTER_SUPPORTED 1 /*!< Support for APM control filter */ diff --git a/components/soc/esp32c61/include/soc/Kconfig.soc_caps.in b/components/soc/esp32c61/include/soc/Kconfig.soc_caps.in index d74e57b7c2d..c2c9ba7a587 100644 --- a/components/soc/esp32c61/include/soc/Kconfig.soc_caps.in +++ b/components/soc/esp32c61/include/soc/Kconfig.soc_caps.in @@ -1019,6 +1019,14 @@ config SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND bool default y +config SOC_FLASH_ENCRYPTION_PAGE_CONFIGURABLE + bool + default y + +config SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE + bool + default y + config SOC_RECOVERY_BOOTLOADER_SUPPORTED bool default y diff --git a/components/soc/esp32c61/include/soc/soc_caps.h b/components/soc/esp32c61/include/soc/soc_caps.h index 4a3790ccb2e..4024c68dfc4 100644 --- a/components/soc/esp32c61/include/soc/soc_caps.h +++ b/components/soc/esp32c61/include/soc/soc_caps.h @@ -403,6 +403,10 @@ #define SOC_FLASH_ENCRYPTION_XTS_AES 1 #define SOC_FLASH_ENCRYPTION_XTS_AES_128 1 #define SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND 1 +#define SOC_FLASH_ENCRYPTION_PAGE_CONFIGURABLE 1 /* Flash encryption can be configured on a MMU page basis */ + +/*-------------------------- PSRAM Encryption CAPS----------------------------*/ +#define SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE 1 /* PSRAM encryption can be configured on a MMU page basis */ /*------------------------Bootloader CAPS---------------------------------*/ /* Support Recovery Bootloader */ diff --git a/components/soc/esp32h2/include/soc/Kconfig.soc_caps.in b/components/soc/esp32h2/include/soc/Kconfig.soc_caps.in index 159e408b275..72c60ab6071 100644 --- a/components/soc/esp32h2/include/soc/Kconfig.soc_caps.in +++ b/components/soc/esp32h2/include/soc/Kconfig.soc_caps.in @@ -1299,6 +1299,10 @@ config SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND bool default y +config SOC_FLASH_ENCRYPTION_PAGE_CONFIGURABLE + bool + default y + config SOC_APM_CTRL_FILTER_SUPPORTED bool default y diff --git a/components/soc/esp32h2/include/soc/soc_caps.h b/components/soc/esp32h2/include/soc/soc_caps.h index 334a3543777..e9fb835d71f 100644 --- a/components/soc/esp32h2/include/soc/soc_caps.h +++ b/components/soc/esp32h2/include/soc/soc_caps.h @@ -512,6 +512,7 @@ #define SOC_FLASH_ENCRYPTION_XTS_AES 1 #define SOC_FLASH_ENCRYPTION_XTS_AES_128 1 #define SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND 1 /*!< Only avliable in chip version above 1.2*/ +#define SOC_FLASH_ENCRYPTION_PAGE_CONFIGURABLE 1 /* Flash encryption can be configured on a MMU page basis */ /*-------------------------- APM CAPS ----------------------------------------*/ #define SOC_APM_CTRL_FILTER_SUPPORTED 1 /*!< Support for APM control filter */ diff --git a/components/soc/esp32p4/include/soc/Kconfig.soc_caps.in b/components/soc/esp32p4/include/soc/Kconfig.soc_caps.in index bc53ce80b0d..dc32061b377 100644 --- a/components/soc/esp32p4/include/soc/Kconfig.soc_caps.in +++ b/components/soc/esp32p4/include/soc/Kconfig.soc_caps.in @@ -1963,6 +1963,18 @@ config SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND bool default y +config SOC_FLASH_ENCRYPTION_PAGE_CONFIGURABLE + bool + default y + +config SOC_PSRAM_ENCRYPTION_SEPARATE_KEY + bool + default y + +config SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE + bool + default y + config SOC_UART_NUM int default 6 diff --git a/components/soc/esp32p4/include/soc/soc_caps.h b/components/soc/esp32p4/include/soc/soc_caps.h index e0074a49c1c..9bb035970fc 100644 --- a/components/soc/esp32p4/include/soc/soc_caps.h +++ b/components/soc/esp32p4/include/soc/soc_caps.h @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2022-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2022-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -712,6 +712,12 @@ #define SOC_FLASH_ENCRYPTION_XTS_AES_128 1 /* SOC_EFUSE_XTS_AES_KEY_128 (1) || SOC_KEY_MANAGER_FE_KEY_DEPLOY_XTS_AES_128 (1) */ #define SOC_FLASH_ENCRYPTION_XTS_AES_256 1 /* SOC_EFUSE_XTS_AES_KEY_256 (1) || SOC_KEY_MANAGER_FE_KEY_DEPLOY_XTS_AES_256 (1) */ #define SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND 1 /*!< Only available in chip version above 3.0 */ +#define SOC_FLASH_ENCRYPTION_PAGE_CONFIGURABLE 1 /* Flash encryption can be configured on a MMU page basis */ + +/*-------------------------- PSRAM Encryption CAPS----------------------------*/ +#define SOC_PSRAM_ENCRYPTION_SEPARATE_KEY 1 /* PSRAM encryption can use independent key */ +#define SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE 1 /* PSRAM encryption can be configured on a MMU page basis */ + /*-------------------------- MEMPROT CAPS ------------------------------------*/ /*-------------------------- UART CAPS ---------------------------------------*/ diff --git a/docs/en/api-guides/external-ram.rst b/docs/en/api-guides/external-ram.rst index c7e74f66d4c..5a35e04ce93 100644 --- a/docs/en/api-guides/external-ram.rst +++ b/docs/en/api-guides/external-ram.rst @@ -241,6 +241,13 @@ By default, failure to initialize external RAM will cause the ESP-IDF startup to This feature is enabled whenever flash encryption is enabled. For more information on how to enable and how it works see :doc:`Flash Encryption `. + .. only:: SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE + + On {IDF_TARGET_NAME}, PSRAM encryption can be controlled on a per-MMU-page basis, allowing individual PSRAM pages to be selectively encrypted or left unencrypted. However, in the default configuration, all PSRAM pages are encrypted when flash encryption is enabled. + + .. only:: SOC_PSRAM_ENCRYPTION_SEPARATE_KEY + + On {IDF_TARGET_NAME}, PSRAM encryption can use an independent encryption key. If the PSRAM encryption key is not programmed, the flash encryption key will be used as the PSRAM encryption key. .. only:: esp32 diff --git a/docs/en/security/flash-encryption.rst b/docs/en/security/flash-encryption.rst index e7cd221d06f..01b866522a4 100644 --- a/docs/en/security/flash-encryption.rst +++ b/docs/en/security/flash-encryption.rst @@ -1039,8 +1039,17 @@ The command ``idf.py decrypt-flash-data`` can be used with the same options (and External RAM ------------ - When Flash Encryption is enabled any data read from and written to external SPI RAM through the cache will also be encrypted/decrypted. This happens the same way and with the same key as for Flash Encryption. If Flash Encryption is enabled then encryption for external SPI RAM is also always enabled, it is not possible to separately control this functionality. + .. only:: SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE + When Flash Encryption is enabled any data read from and written to external SPI RAM through the cache can also be encrypted/decrypted. On {IDF_TARGET_NAME}, PSRAM encryption can be controlled on a per-MMU-page basis, allowing individual PSRAM pages to be selectively encrypted or left unencrypted. However, in the default configuration, all PSRAM pages are encrypted when flash encryption is enabled. + + .. only:: not SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE + + When Flash Encryption is enabled any data read from and written to external SPI RAM through the cache will also be encrypted/decrypted. If Flash Encryption is enabled then encryption for external SPI RAM is also automatically enabled. + + .. only:: SOC_PSRAM_ENCRYPTION_SEPARATE_KEY + + On {IDF_TARGET_NAME}, PSRAM encryption can use an independent encryption key. If the PSRAM encryption key is not programmed, the flash encryption key will be used as the PSRAM encryption key. Technical Details ----------------- diff --git a/docs/zh_CN/api-guides/external-ram.rst b/docs/zh_CN/api-guides/external-ram.rst index d7fd7592a66..7fc7427efd9 100644 --- a/docs/zh_CN/api-guides/external-ram.rst +++ b/docs/zh_CN/api-guides/external-ram.rst @@ -241,6 +241,14 @@ ESP-IDF 启动过程中,片外 RAM 被映射到数据虚拟地址空间,该 只要启用了 flash 加密功能,就会启用这个功能。关于如何启用 flash 加密以及其工作原理,请参考 :doc:`/security/flash-encryption`。 + .. only:: SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE + + 在 {IDF_TARGET_NAME} 上,PSRAM 加密可以按 MMU 页面粒度进行控制,允许对单个 PSRAM 页面选择性地加密或不加密。但在默认配置下,启用 flash 加密时所有 PSRAM 页面都会被加密。 + + .. only:: SOC_PSRAM_ENCRYPTION_SEPARATE_KEY + + 在 {IDF_TARGET_NAME} 上,PSRAM 加密可以使用独立的加密密钥。如果未烧录 PSRAM 加密密钥,则会使用 flash 加密密钥作为 PSRAM 加密密钥。 + .. only:: esp32 diff --git a/docs/zh_CN/security/flash-encryption.rst b/docs/zh_CN/security/flash-encryption.rst index 57f68eaba5b..c3002d633eb 100644 --- a/docs/zh_CN/security/flash-encryption.rst +++ b/docs/zh_CN/security/flash-encryption.rst @@ -1039,7 +1039,17 @@ JTAG 调试 片外 RAM ------------ - 启用 flash 加密后,任何通过缓存从片外 SPI RAM 读取和写入的数据也将被加密/解密。这个实现的方式以及使用的密钥与 flash 加密相同。如果启用 flash 加密,则片外 SPI RAM 的加密也会被启用,无法单独控制此功能。 + .. only:: SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE + + 启用 flash 加密后,任何通过缓存从片外 SPI RAM 读取和写入的数据也可以被加密/解密。在 {IDF_TARGET_NAME} 上,PSRAM 加密可以按 MMU 页面粒度进行控制,允许对单个 PSRAM 页面选择性地加密或不加密。但在默认配置下,启用 flash 加密时所有 PSRAM 页面都会被加密。 + + .. only:: not SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE + + 启用 flash 加密后,任何通过缓存从片外 SPI RAM 读取和写入的数据也将被加密/解密。如果启用 flash 加密,则片外 SPI RAM 的加密也会自动启用。 + + .. only:: SOC_PSRAM_ENCRYPTION_SEPARATE_KEY + + 在 {IDF_TARGET_NAME} 上,PSRAM 加密可以使用独立的加密密钥。如果未烧录 PSRAM 加密密钥,则会使用 flash 加密密钥作为 PSRAM 加密密钥。 技术细节