Commit Graph
100 Commits
Author SHA1 Message Date
harshal.patil 1d4a1e0624 test(mbedtls): add partial-block PSRAM coverage for AES and AES-GCM
Extend the CTR test data length to 6433 bytes so the trailing partial
block is exercised with external RAM buffers (which stalls the ESP32-S2
Crypto DMA on an unfixed driver), and add AES-GCM PSRAM tests verified
against internal RAM references.
2026-08-25 14:50:15 +05:30
harshal.patil 4025a2f8b9 fix(mbedtls/aes): fix ESP32-S2 Crypto DMA stall on PSRAM output with partial blocks
The ESP32-S2 Crypto DMA in-channel stalls silently when a receive
descriptor list transitions from external to internal RAM. The AES
driver hits this when a PSRAM-output operation has a trailing partial
block, as the internal stream descriptor is linked after the external
RAM data descriptors.

- esp_aes_process_dma(): process the block-aligned part and the partial
  block as two separate DMA operations, keeping each descriptor list
  uniform
- crypto_dma_ll_reset(): also reset the in-channel (per the TRM receive
  reset sequence), otherwise stale state from a preceding external-RAM
  operation corrupts the next operation's output

The GCM DMA path is unaffected; it never operates on PSRAM buffers.
2026-08-25 14:50:15 +05:30
harshal.patil 710ce291ac fix(mbedtls): validate cert header extent before reading it in bundle check
esp_crt_check_bundle() read the 4-byte certificate header (name_len,
key_len) via esp_crt_get_len() after only checking that the cert's
start offset lies inside the bundle, so a crafted bundle whose first
or last certificate starts within the final 3 bytes caused a transient
out-of-bounds read of up to 3 bytes before the extent check rejected
it. Require the whole header to lie inside the bundle before reading
it.
2026-08-24 20:56:43 +05:30
harshal.patil 516e849636 change(security): disable Key Manager support on ESP32-C5/P4/S31
The Key Manager hardware peripheral in its current form needs further
design changes before it can be offered as a production feature.
Until a revised peripheral design is available, withdraw ESP-IDF
support for it on all Key Manager capable targets.
2026-08-11 09:41:38 +05:30
harshal.patil 6dd847c8dd refactor(esp_system): deduplicate ROM fast wake RTC digest reservation
The digest length and the condition that reserves it at the end of RTC RAM were
duplicated in seven places. Hold the reservation in a hidden Kconfig value that
is zero when the feature does not apply, so every consumer subtracts it
unconditionally, and derive ESP_SECURE_BOOT_DIGEST_LEN from it.
2026-07-31 10:54:32 +08:00
harshal.patil 275587ea02 feat(mbedtls/psa_esp_rsa_ds): Expose persistent key buffer format/parse helpers 2026-07-03 10:25:49 +05:30
harshal.patil bac955ae9d feat(examples/security): Add example to demonstrate the usage of custom key storages with PSA 2026-07-03 10:25:49 +05:30
harshal.patil 3c4586abff feat(mbedtls): Support custom storage backend for persistent PSA keys 2026-07-03 10:25:48 +05:30
harshal.patil bb5025d983 test(mbedtls): move AES test vectors to a dedicated header 2026-07-01 16:32:18 +05:30
harshal.patil 64570337aa fix(mbedtls/aes): Fix AES-DMA over encrypted PSRAM on ESP32-S31
esp_crypto_shared_gdma_done() polled the AXI RX raw interrupt status
(in_done) but never cleared it, so after the first transfer the set bit
made every subsequent call return immediately without waiting.
2026-07-01 16:32:09 +05:30
harshal.patil d11534bfa1 fix(panic): handle absent IROM/DROM alignment gap in spiram-xip memprot tests
The spiram-xip IROM/DROM alignment tests assumed the XIP region always
leaves an alignment gap before the next MMU page: they executed into the
gap and expected an instruction access fault followed by a register dump.
When the section ends exactly on an MMU page boundary there is no gap - the
device prints "<IROM/DROM> alignment gap not added into heap" and returns,
the framework restarts cleanly (esp_restart_noos, no panic), and the test
timed out waiting for a register dump.
2026-07-01 11:00:05 +05:30
harshal.patil a9b74b5219 fix(soc): Remove non-existent crypto registers (ESP32-C61) 2026-06-29 12:27:50 +05:30
harshal.patil 1c351b4650 fix(mbedtls/port): align ESP PSA hardware drivers with software references
Audited every esp_* PSA driver against its corresponding software driver in
mbedtls/library (psa_crypto_cipher.c, psa_crypto_aead.c, psa_crypto_mac.c,
psa_crypto_hash.c, psa_crypto_ecp.c, psa_crypto_rsa.c) and fixed gaps in
workflow ownership, error-path cleanup, sensitive-data wiping, and BAD_STATE
gating per the PSA Crypto API spec.

esp_aes (cipher): fix padding oracle in cipher_finish by replacing leaky
branches with mbedtls_ct_* primitives; abort wipes the driver-level ctx,
not just the inner mbedtls_aes_context; setup routes errors through abort.

esp_aes_gcm (AEAD): zeroize the 16-byte full_tag scratch; restore the
*output_length = finish_output_size assignment that the SW reference keeps
for future ciphers; NULL the inner ctx pointer after free in abort; gate
update/finish on a live ctx with PSA_ERROR_BAD_STATE.

esp_ecdsa: keep abort-at-exit in the one-shot wrappers so the stack-copy
of the hash (needed for little-endian byte order on HW) is wiped per
PSA spec 6.3.3, drop the over-defensive public-key qx/qy wipes that the
SW driver does not perform.

esp_cmac / esp_hmac_transparent / esp_hmac_opaque (MAC): make abort
idempotent, route setup errors through abort, gate update/finish/
verify_finish on PSA_ERROR_BAD_STATE, wipe M_last and intermediate hmac[]
buffers on completion or HW failure. HMAC opaque gains alg + computed
fields to mirror the SW psa_crypto_mac.c state machine. HMAC transparent
explicitly aborts the inner SHA context before reusing it for the outer
hash.

esp_sha: switch the per-op live indicator to (sha_ctx != NULL) so the
public esp_sha_operation_type_t enum keeps its original ordinal values;
free + NULL sha_ctx on every error path; gate update/finish/clone on a
live ctx; wipe per-algorithm core/parallel-engine scratch buffers
(W[], A[], state) on HW-engine failure.

esp_md5: replace bare memset in abort with mbedtls_platform_zeroize.

esp_rsa_ds: complete() no longer frees sig_buffer (abort owns that);
start() routes failures through abort; asymmetric_decrypt funnels all
cleanup through a single exit: label. RSA-DS utilities wipe the
decrypted-plaintext scratch on v15 / OAEP unpad failure.
2026-06-29 14:22:40 +08:00
harshal.patil 5ed711bc06 fix(esp_common/esp_fault): make ESP_FAULT_ASSERT survive optimization
ESP_FAULT_ASSERT(C) was silently deleted by the optimizer when C is a cached
flag/status already proven by a preceding `if (!C) return/goto`: the compiler
folds C to a constant and drops all three checks, removing the fault-injection
protection with no warning.
2026-06-18 19:41:56 +05:30
harshal.patil 5f824c8683 fix(secure_boot): range-check ECDSA r,s in bootloader before ROM verify 2026-06-12 17:32:38 +05:30
harshal.patil b420f20040 test(esp_hal_security): warm up ECC const-time loop before measuring 2026-06-09 15:07:55 +05:30
harshal.patil 6b8f830991 fix(esp_tee): Reset crypto peripherals before the panic-induced reset 2026-06-09 15:07:55 +05:30
harshal.patil c1f70a4cb5 fix(esp_rom): Patch ets_ecdsa_verify() to include signature bounds check 2026-06-09 15:07:53 +05:30
harshal.patil 3195c942da fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down 2026-06-09 15:02:59 +05:30
harshal.patil 40de3df854 test(mbedtls): Add out-of-bounds test for the ECDSA hardware driver 2026-05-27 11:38:14 +05:30
harshal.patil d1d45ff256 change(esp_psram): Consider all PSRAM regions in PMP protection 2026-05-21 20:54:30 +05:30
harshal.patil d8808f90b9 test(mbedtls/persistent_storage_format): Add ESP ITS NVS format-stability test app 2026-05-15 09:28:47 +05:30
harshal.patil 513efdf89a refactor(mbedtls/test): Move the mbedtls test app to support multiple test apps 2026-05-15 09:28:42 +05:30
harshal.patil 1d6b5f219e feat(mbedtls/psa_esp_rsa_ds): Support persistent ESP-RSA DS driver 2026-05-15 09:17:09 +05:30
harshal.patil 98bbe26aea feat(esp_security): add ECDH1 deployment mode to Key Manager driver 2026-05-11 09:38:00 +05:30
harshal.patil 1141c48750 change(mbedtls): Add tee key id length validation in the ESP-ECDSA PSA driver 2026-05-04 18:21:01 +05:30
harshal.patil 4f0915d7f6 test(mbedtls): Add a test for opaque HMAC driver verification 2026-05-04 18:21:01 +05:30
harshal.patil c923685b0f fix(mbedtls): Flash compatibility across multiple key sources (ECDSA, HMAC) 2026-05-04 18:21:00 +05:30
harshal.patil 7da92d6f82 test(esp_security): Update the Key Manager test to support ESP32-P4 2026-05-04 18:18:20 +05:30
harshal.patil ba5fdc77fd fix(esp_security): guard key manager APIs against unsupported chip revs
On ESP32-P4 rev < 3.0, Key Manager is software-disabled, but the public
esp_key_mgr.h APIs had no runtime check.
Calls using HMAC/DS/PSRAM key types fell through to
HAL_ASSERT("Unsupported ...") paths in key_mgr_ll.h. Gate
each public API with key_mgr_ll_is_supported() and return
ESP_ERR_NOT_SUPPORTED cleanly instead.
2026-05-04 18:18:20 +05:30
harshal.patil 63b2f2c8e8 fix(esp_security): Fix the flipped key info slot when deploying a Key Manager-based key 2026-05-04 15:42:30 +05:30
harshal.patil 1caafa9e2b fix(esp_security): Enable ECC clock while using the Key Manager's ECDH key deployment mode 2026-05-04 15:42:30 +05:30
harshal.patil 257eccc7ec fix(cpu_region_protect): Fix incorrect definition of ALIGN_UP macro 2026-04-30 10:45:28 +05:30
harshal.patil d0aa4f1524 fix(esp_hw_support): reset stale PMP gap entries on P4 v3 before app memprot setup 2026-04-30 10:45:13 +05:30
harshal.patil ca3b9ca7d3 fix(mbedtls/rsa_ds): Preserve compatibility by reverting the modified esp_ds_data_ctx_t size 2026-03-26 14:06:07 +05:30
harshal.patil 1db26df63d fix(esp_security): Fixes incorrect key manager configuration for ESP32-P4 rev < 3 2026-03-24 16:33:25 +05:30
harshal.patil 2339834e4a fix(esp_security): Enable Key Manager clocks even for efuse key operations
The Key Manager holds a key usage register, thus, the Key Manager peripheral
clock must be enabled even for efuses-based key operations to route the
crypto operations to correctly to the efuses (default is Key Manager)
2026-03-24 16:23:16 +05:30
harshal.patil fe3b5ca898 fix(esp_security): Add more validation checks 2026-03-23 10:46:23 +05:30
harshal.patil 45d5ef45a5 feat(esp_ds): Support using the AES key used by DS peripheral for encrypting params 2026-03-23 10:46:22 +05:30
harshal.patil 629a4e2444 docs(key-manager): Add Key-Manager peripheral related documentation 2026-03-18 16:42:21 +05:30
harshal.patil bc2c857bc9 test(examples/security): Extend the flash enc example to flash enc enabled using KM targets 2026-03-18 16:41:03 +05:30
harshal.patil 8b26fb150b test(examples/security): Add an example to demonstrate signing using Key Manager keys 2026-03-18 16:39:07 +05:30
harshal.patil e0b444281c change(mbedtls): Change the ESP-DS-RSA key lifetime name to include the VOLATILE keyword 2026-03-18 16:38:24 +05:30
harshal.patil ca0daf01c6 fix(esp-tls): Remove the legacy use_km_key option 2026-03-18 16:38:24 +05:30
harshal.patil 155d88ed0e feat(mbedtls/esp_rsa_ds): Support Key Manager key using the ESP-RSA-DS PSA interface 2026-03-18 16:38:24 +05:30
harshal.patil 1daa847feb feat(mbedtls/esp_mac): Support Key Manager key using the ESP-HMAC PSA interface 2026-03-18 16:38:24 +05:30
harshal.patil 79e92e076a feat(mbedtls/esp_ecdsa): Support Key Manager key using the ESP-ECDSA PSA interface 2026-03-18 16:38:24 +05:30
harshal.patil 37a73ff5a4 change(mbedtls/psa_driver_esp_hmac): Use efuse key block instead of efuse block
- Maintains compatibility of the older esp_hmac_ APIs and the PSA driver
2026-03-18 16:38:23 +05:30
harshal.patil 96f5317806 feat(mbedtls/esp_rsa_ds): Introduce ESP-RSA DS opaque key context 2026-03-18 16:38:23 +05:30
harshal.patilandZhang Shu Xian 96e8b85577 docs: Adds a migration guide entry for HMAC peripheral's PSA interface
Co-authored-by: Zhang Shu Xian <zhangshuxian@espressif.com>
2026-03-17 10:28:39 +08:00
harshal.patil 9253fbadbc fix(nvs_flash): Use h/w accelerated AES-ECB for XTS-AES operations 2026-02-11 15:40:10 +05:30
harshal.patil aabf35b41b change(mbedtls): Disable MBEDTLS_SHA3_C by default 2026-02-11 18:04:56 +08:00
harshal.patil 51956d766e fix(mbedtls): Support truncated HMAC 2026-02-10 14:09:33 +05:30
harshal.patil 91c3738e81 test(mbedtls): Re-introduce the extensive AES, AES-GCM and the SHA tests
- Also extend the PSRAM encryption test to ESP32-S3
2026-02-03 13:04:32 +05:30
harshal.patil 00127bce0b fix(mbedtls/sha): Fix SHA-512 parallel engine driver to the use h/w engine 2026-02-03 11:46:51 +05:30
harshal.patil 2d386e2f6f fix(examples/tee): Remove dead code and fix unintialised scalar usage 2026-02-02 10:57:02 +05:30
harshal.patil d495ffb491 feat(esp_tee/tee_sec_storage): Use PSA interface internally 2026-02-02 10:51:31 +05:30
harshal.patil 4122e0e041 fix(mbedtls/psa_driver_aes_gcm): Support shortened tag length for AES-GCM 2026-02-02 10:51:31 +05:30
harshal.patil 556350eea9 fix(mbedtls/include): Fix include libs in the driver's public headers 2026-02-02 10:51:31 +05:30
harshal.patil de7f8c88b2 fix(mbedtls): Make the driver define macros public to allow application access
- Also, use the PSA HMAC opaque key interface for HMAC-PBKDF2
2026-02-02 10:51:31 +05:30
harshal.patil 82ff76eb41 feat(mbedlts/hmac): Support HMAC(MD5) using the MD5 driver 2026-02-02 10:51:31 +05:30
harshal.patil 086ba86c98 change(mbedtls): Remove legacy headers 2026-02-02 10:51:30 +05:30
harshal.patil 3163ed4167 feat(mbedtls): Introduce ESP-HMAC PSA opaque driver 2026-02-02 10:51:30 +05:30
harshal.patil 4d2e7fb4d3 fix(mbedtls): Enable h/w accel for CMAC and HMAC operations
- Refactor ESP-MAC drivers
2026-02-02 10:51:30 +05:30
harshal.patil 4bf3c3d20f fix(mbedtls/ecdsa): Improve build time efuse validation checks in the ecdsa driver 2026-01-31 10:59:22 +05:30
harshal.patil a9598b3304 feat(esp_tee): Support deterministic ECDSA signatures for ESP-TEE based keys 2026-01-31 10:59:16 +05:30
harshal.patil 5c55790f54 feat(mbedtls/ecdsa): Introduce PSA ECDSA driver 2026-01-31 10:59:11 +05:30
harshal.patil f8d81bf701 fix(mbedtls/aes): Cache invalidate the output buffer before the AES-DMA operation
Instead of performing the cache-to-memory (C2M) operation on the output buffer,
even a cache invalidate (M2C) is sufficient to ensure that no write-back occurs
during the DMA write operation
2026-01-19 07:22:19 +00:00
harshal.patil 3c4dadff0b fix(mbedtls): Support partial hardware AES-GCM and s/w fallback for non-AES ciphers
- Support software-fallback for unsupported hardware AES lengths
2026-01-09 13:55:51 +05:30
harshal.patil 9773691ca2 fix(mbedlts/aes): Ensure cache coherency when DMA writes to cacheable PSRAM buffers 2026-01-08 16:24:31 +05:30
harshal.patil 88fc8952e5 test(ota): Add tests for verifying app build's SBv2 ECDSA signature verify APIs 2025-12-26 11:49:15 +05:30
harshal.patil c2dffd77fa fix(mbedtls/aes): Reallocate buffers only if in external RAM 2025-12-12 14:17:06 +05:30
harshal.patil 4504fa267b fix(secure_boot): Application's Secure Boot verify API support ECDSA-P384 2025-12-12 12:37:48 +05:30
harshal.patil b2dabf6f86 test(mbedtls): add more tests for alignment, buffer size related
- Also, enabled Flash Encryption enabled tests for ESP32-C5
- Removed ESP32-P4 specific configs, as those configs are set as default now
2025-12-11 16:48:25 +05:30
harshal.patil bb0354aecf fix(mbedtls/port): Use internal buffers to perform chunkwise operations
when the external input and output buffers are unaligned.
This also fixes as a recursion loop that occurs when the size of the input
buffer is not aligned to dcache_line_size but is aligned to AES_BLOCK_BYTES
2025-12-11 16:48:16 +05:30
harshal.patil 71084705c9 fix(key_mgr): Correct XTS-AES key length register configuration
The key_mgr_ll_set_xts_aes_key_len() function was incorrectly using
REG_SET_FIELD() with the key_len enum value directly. Since
KEYMNG_FLASH_KEY_LEN is a 1-bit register field (0=128-bit, 1=256-bit),
writing ESP_KEY_MGR_XTS_AES_LEN_128 (value 3) resulted in the LSB (1)
being stored, incorrectly configuring 256-bit mode.

Fixed by using a switch statement to properly map:
- ESP_KEY_MGR_XTS_AES_LEN_128 → REG_CLR_BIT (0)
- ESP_KEY_MGR_XTS_AES_LEN_256 → REG_SET_BIT (1)

Thus, matching the correct ESP32-C5 implementation.
2025-11-26 15:40:09 +05:30
harshal.patil 9a18386202 feat(esp_security): Support ECDSA-P384 key deployment using Key Manager 2025-11-20 11:37:07 +05:30
harshal.patil 792c93c597 change(mbedtls): Generalize key source union for the hardware ECDSA context 2025-11-20 11:37:07 +05:30
harshal.patil cd0770cd39 change(esp_key_mgr): Store key_len field in the key_info
- Update the Key Manager key types to be generic
- Define a new enum to determine the length of the keys
- Refactor the Key Manager driver support generic key types and key lengths
- Also store key deployment mode in the key recovery info
2025-11-20 11:37:07 +05:30
harshal.patil 172f904e23 feat(bootloader_support): Support FE XTS-AES-256 using Key Manager for ESP32-C5 2025-11-20 11:37:07 +05:30
harshal.patil 9c823cdf38 fix(hal): Force HUK power up when configuring HUK for ESP32-C5 2025-11-20 11:37:07 +05:30
harshal.patil 7cefae573a feat(flash_encryption): Remove mspi reset when switching the XTS-AES key source 2025-11-20 11:37:07 +05:30
harshal.patil 92e5cfa47e change(bootloader_support): Rename the esp_flash_encryption_enable_key_mgr() API 2025-11-20 11:37:07 +05:30
harshal.patil 7212b517d4 change(esp_key_mgr): Make Key Manager driver bootloader compatible
- Independent of heap
2025-11-20 11:37:07 +05:30
harshal.patil c1503cd847 feat(bootloader_support): Support Flash Encryption using Key Manager 2025-11-20 11:37:05 +05:30
harshal.patil 46e2cd21d4 fix(esp_security/esp_key_mgr): Fix missed error codes and some cleanup 2025-11-20 11:35:22 +05:30
harshal.patil 6815f7a71b test(examples): Fix cert bundle stress test 2025-11-14 09:46:28 +05:30
harshal.patil 3e7602a2e4 feat(cpu_region_protect): Extend PMP memprot for ESP32-P4 V3 2025-11-11 17:54:17 +05:30
harshal.patil 54c5c760ba fix(esp_security): Set WR_DIS_SECURE_BOOT_SHA384_EN by default when
Flash Encryption Release mode is enabled and Secure Boot P384 scheme not is enabled.
2025-11-11 17:52:21 +05:30
harshal.patil 488dcb58e1 fix(esp_security): Fix undefined efuse build failure in case of ESP32-P4
- The `wr_dis` efuse bit corresponding to `SECURE_BOOT_SHA384_EN` is absent in P4
2025-11-11 17:52:21 +05:30
harshal.patil 10cefdd975 fix(mbedtls/port): Align AES and SHA DMA buffers to 16 when SPIRAM encryption is enabled
- Targets that support GDMA and MSPI encryption module need data and addresses aligned to 16
2025-11-11 17:39:39 +05:30
harshal.patil beb0303ad6 fix(hal): Fix MMU PSRAM anti-fi MMU target check
In case of ESP32-C5 and ESP32-C61, mmu_ids for PSRAM and Flash
MMU are the same due to their shared memory space. Thus, instead of
mmu_id we should use mmu_target_t.
2025-11-03 11:29:27 +05:30
harshal.patil 7338c5179b fix(build_system): Add Bootloader and Partition Table as dependencies for encrypted-flash
- If ESP-TEE is enabled, also add it as the dependency for the encrypted-flash target
2025-11-03 11:15:25 +05:30
harshal.patil 609d52c6bf feat(esp32p4): Support newer Key Manager key sources for ESP32-P4 V3 2025-10-15 15:49:20 +05:30
Harshal Patil f088a128ac Merge branch 'test/set_minimal_build_for_security_test_apps' into 'master'
test(security): Use minimal build in the security test apps

Closes IDF-14203

See merge request espressif/esp-idf!42292
2025-09-30 11:38:21 +05:30
harshal.patil 1d4a634b98 test(security): Use minimal build in the security test apps 2025-09-30 10:52:03 +05:30
Harshal Patil fd7d9c9ee9 Merge branch 'fix/key_mgr_use_default_efuse_key' into 'master'
Configure the Key Manager to use XTS-AES efuse key by-default

Closes IDFCI-3135 and IDFCI-3136

See merge request espressif/esp-idf!42032
2025-09-26 12:34:19 +05:30
Harshal Patil c6e65586e3 Merge branch 'feat/support_aes_block_and_dma_modes_during_runtime' into 'master'
Support AES block and DMA modes during runtime

Closes IDFGH-15251 and IDF-2594

See merge request espressif/esp-idf!40917
2025-09-23 19:46:49 +05:30
harshal.patil 8b663ebe4d fix(esp_security): Configure the Key Manager to use XTS-AES efuse key by-default 2025-09-22 12:22:07 +05:30
harshal.patil ade76189c5 test(hal/crypto): Update AES test app to remove redundant block operation 2025-09-20 10:55:07 +05:30