Commit Graph
100 Commits
Author SHA1 Message Date
harshal.patil d6f41cac35 feat(mbedtls/psa_esp_rsa_ds): Expose persistent key buffer format/parse helpers 2026-06-18 09:42:54 +05:30
harshal.patil 505bab1267 feat(examples/security): Add example to demonstrate the usage of custom key storages with PSA 2026-06-18 09:42:54 +05:30
harshal.patil 3494df8c85 feat(mbedtls): Support custom storage backend for persistent PSA keys 2026-06-18 09:37:15 +05:30
harshal.patil 6b417e9d47 fix(esp_common/esp_fault): make ESP_FAULT_ASSERT survive optimization
ESP_FAULT_ASSERT(C) was silently deleted by the optimizer when C is a cached
flag/status already proven by a preceding `if (!C) return/goto`: the compiler
folds C to a constant and drops all three checks, removing the fault-injection
protection with no warning.
2026-06-17 16:45:29 +05:30
harshal.patil 9172417c13 fix(mbedtls/port): align ESP PSA hardware drivers with software references
Audited every esp_* PSA driver against its corresponding software driver in
mbedtls/library (psa_crypto_cipher.c, psa_crypto_aead.c, psa_crypto_mac.c,
psa_crypto_hash.c, psa_crypto_ecp.c, psa_crypto_rsa.c) and fixed gaps in
workflow ownership, error-path cleanup, sensitive-data wiping, and BAD_STATE
gating per the PSA Crypto API spec.

esp_aes (cipher): fix padding oracle in cipher_finish by replacing leaky
branches with mbedtls_ct_* primitives; abort wipes the driver-level ctx,
not just the inner mbedtls_aes_context; setup routes errors through abort.

esp_aes_gcm (AEAD): zeroize the 16-byte full_tag scratch; restore the
*output_length = finish_output_size assignment that the SW reference keeps
for future ciphers; NULL the inner ctx pointer after free in abort; gate
update/finish on a live ctx with PSA_ERROR_BAD_STATE.

esp_ecdsa: keep abort-at-exit in the one-shot wrappers so the stack-copy
of the hash (needed for little-endian byte order on HW) is wiped per
PSA spec 6.3.3, drop the over-defensive public-key qx/qy wipes that the
SW driver does not perform.

esp_cmac / esp_hmac_transparent / esp_hmac_opaque (MAC): make abort
idempotent, route setup errors through abort, gate update/finish/
verify_finish on PSA_ERROR_BAD_STATE, wipe M_last and intermediate hmac[]
buffers on completion or HW failure. HMAC opaque gains alg + computed
fields to mirror the SW psa_crypto_mac.c state machine. HMAC transparent
explicitly aborts the inner SHA context before reusing it for the outer
hash.

esp_sha: switch the per-op live indicator to (sha_ctx != NULL) so the
public esp_sha_operation_type_t enum keeps its original ordinal values;
free + NULL sha_ctx on every error path; gate update/finish/clone on a
live ctx; wipe per-algorithm core/parallel-engine scratch buffers
(W[], A[], state) on HW-engine failure.

esp_md5: replace bare memset in abort with mbedtls_platform_zeroize.

esp_rsa_ds: complete() no longer frees sig_buffer (abort owns that);
start() routes failures through abort; asymmetric_decrypt funnels all
cleanup through a single exit: label. RSA-DS utilities wipe the
decrypted-plaintext scratch on v15 / OAEP unpad failure.
2026-06-15 16:10:09 +05:30
harshal.patil f68bc1ba9f fix(secure_boot): range-check ECDSA r,s in bootloader before ROM verify 2026-06-12 14:38:47 +05:30
Harshal Patil c753716f5a Merge branch 'fix/partitions_ota_sb_esp32c2_c61' into 'master'
Use ECDSA Secure Boot V2 scheme for partitions_ota on C2/C61

See merge request espressif/esp-idf!49527
2026-06-10 16:08:18 +05:30
harshal.patil d8b7df4aa2 fix(examples/partitions_ota): use ECDSA Secure Boot V2 scheme for partitions_ota on C2/C61
ESP32-C2 and ESP32-C61 have no RSA based Secure Boot V2 support
so the virt_sb_v2_and_fe configs cannot use the default RSA signing key.
Add target-specific sdkconfig overlays that switch to the ECDSA P-256 key;
on ESP32-C61 the ECDSA scheme must additionally be force-enabled
SECURE_BOOT_V2_ECDSA_INSECURE).
2026-06-10 15:30:06 +05:30
Harshal Patil a5591852c5 Merge branch 'fix/remove_nonexistent_crypto_registers_c61' into 'master'
Remove non-existent crypto registers (ESP32-C61)

See merge request espressif/esp-idf!49241
2026-06-09 18:16:01 +05:30
harshal.patil 81ffe04323 fix(soc): Remove non-existent crypto registers (ESP32-C61) 2026-06-09 13:33:25 +05:30
harshal.patil f9642ccad4 test(esp_hal_security): warm up ECC const-time loop before measuring 2026-06-09 10:59:12 +05:30
harshal.patil dec9ce8263 fix(esp_tee): Reset crypto peripherals before the panic-induced reset 2026-06-09 10:59:12 +05:30
harshal.patil c5e03fd55c fix(esp_rom): Patch ets_ecdsa_verify() to include signature bounds check 2026-06-09 10:59:12 +05:30
harshal.patil 554cce6937 fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down 2026-06-09 10:59:11 +05:30
harshal.patil 3cbd175d2b test(mbedtls/crt_bundle): Make weak-hash test self-contained
The "custom certificate bundle - weak hash" test relied on DigiCert
Global Root CA being present as a trust anchor in cacrt_all.pem (the
only SHA-1-self-signed root in the chain it loaded). The recent
cacrt_all.pem refresh moved that root to cacrt_deprecated.pem, so the
chain could no longer anchor and the test started failing.
2026-06-02 10:06:43 +05:30
harshal.patil a24bd0bf10 test(mbedtls): Add out-of-bounds test for the ECDSA hardware driver 2026-05-26 11:01:57 +05:30
harshal.patil b4517542ae change(esp_psram): Consider all PSRAM regions in PMP protection 2026-05-19 21:32:29 +05:30
harshal.patil 83ebd475c3 test(mbedtls/persistent_storage_format): Add ESP ITS NVS format-stability test app 2026-05-15 09:12:20 +05:30
harshal.patil 4821f331fe refactor(mbedtls/test): Move the mbedtls test app to support multiple test apps 2026-05-15 09:09:15 +05:30
harshal.patil d7c9c3bc10 feat(mbedtls/psa_esp_rsa_ds): Support persistent ESP-RSA DS driver 2026-05-15 09:09:15 +05:30
harshal.patil 9aba184c43 feat(esp_security): add ECDH1 deployment mode to Key Manager driver 2026-04-30 09:29:40 +05:30
harshal.patil c9366ac4b5 fix(esp_security): Fix the flipped key info slot when deploying a Key Manager-based key 2026-04-30 09:17:38 +05:30
harshal.patil 8ce8d8919b fix(esp_security): Enable ECC clock while using the Key Manager's ECDH key deployment mode 2026-04-30 09:17:31 +05:30
Harshal Patil a860d18878 Merge branch 'change/add_tee_key_len_validation_psa_ecdsa_driver' into 'master'
Add tee key id length validation in the ESP-ECDSA PSA driver

See merge request espressif/esp-idf!48054
2026-04-29 23:57:22 +05:30
harshal.patil 63992372fb change(mbedtls): Add tee key id length validation in the ESP-ECDSA PSA driver 2026-04-28 22:17:25 +05:30
harshal.patil c13403aea6 fix(cpu_region_protect): Fix incorrect definition of ALIGN_UP macro 2026-04-28 18:12:46 +05:30
harshal.patil ca480e0199 fix(esp_hw_support): reset stale PMP gap entries on P4 v3 before app memprot setup 2026-04-28 18:12:11 +05:30
Harshal Patil 8f254a2056 Merge branch 'fix/supported_key_mgr_key_types_check' into 'master'
fix(esp_security): guard key manager APIs against unsupported chip revs

Closes IDF-15621

See merge request espressif/esp-idf!47946
2026-04-27 18:40:06 +05:30
harshal.patil 8bfc4f7255 fix(esp_security): guard key manager APIs against unsupported chip revs
On ESP32-P4 rev < 3.0, Key Manager is software-disabled, but the public
esp_key_mgr.h APIs had no runtime check.
Calls using HMAC/DS/PSRAM key types fell through to
HAL_ASSERT("Unsupported ...") paths in key_mgr_ll.h. Gate
each public API with key_mgr_ll_is_supported() and return
ESP_ERR_NOT_SUPPORTED cleanly instead.
2026-04-27 15:18:34 +05:30
harshal.patil 7eb44576be test(mbedtls): Add a test for opaque HMAC driver verification 2026-04-22 10:11:27 +05:30
harshal.patil f195d183be fix(mbedtls): Flash compatibility across multiple key sources (ECDSA, HMAC) 2026-04-22 10:11:12 +05:30
Harshal Patil 876b9581bd Merge branch 'fix/enable_key_mgr_clk_for_efuse_key_ops' into 'master'
Enable Key Manager clock even for efuses-based key operations

See merge request espressif/esp-idf!46740
2026-03-25 21:37:53 +05:30
harshal.patil 2b77826e06 fix(mbedtls/rsa_ds): Preserve compatibility by reverting the modified esp_ds_data_ctx_t size 2026-03-25 18:54:04 +05:30
harshal.patil 28736a81fa fix(esp_security): Enable Key Manager clocks even for efuse key operations
The Key Manager holds a key usage register, thus, the Key Manager peripheral
clock must be enabled even for efuses-based key operations to route the
crypto operations to correctly to the efuses (default is Key Manager)
2026-03-25 10:38:44 +05:30
harshal.patil ccc48c3980 fix(esp_security): Fixes incorrect key manager configuration for ESP32-P4 rev < 3 2026-03-24 15:23:23 +05:30
harshal.patil 48e7d44ce1 fix(esp-tls): Remove the legacy use_km_key option 2026-03-20 11:15:23 +05:30
harshal.patil 398d9ea9cd fix(esp_security): Add more validation checks 2026-03-20 11:15:23 +05:30
harshal.patil 0db717b9ec feat(esp_ds): Support using the AES key used by DS peripheral for encrypting params 2026-03-20 11:15:23 +05:30
harshal.patil 5f647c0ba3 docs(key-manager): Add Key-Manager peripheral related documentation 2026-03-18 16:27:39 +05:30
harshal.patil a1b52eb8ba test(examples/security): Extend the flash enc example to flash enc enabled using KM targets 2026-03-18 16:27:39 +05:30
harshal.patil a8ffefe096 test(examples/security): Add an example to demonstrate signing using Key Manager keys 2026-03-18 16:27:39 +05:30
harshal.patilandZhang Shu Xian 269b90323f docs: Adds a migration guide entry for HMAC peripheral's PSA interface
Co-authored-by: Zhang Shu Xian <zhangshuxian@espressif.com>
2026-03-16 16:38:26 +08:00
Harshal Patil 05b75b76bc Merge branch 'change/fix_convention_for_esp_ds_psa_lifetime' into 'master'
Rename the ESP DS-RSA key lifetime name to include the VOLATILE keyword

See merge request espressif/esp-idf!46351
2026-03-09 08:32:39 +05:30
harshal.patil b5550281b9 change(mbedtls): Change the ESP-DS-RSA key lifetime name to include the VOLATILE keyword 2026-03-06 15:00:38 +05:30
Harshal Patil efbe83bd21 Merge branch 'feat/introduce_esp_rsa_ds_opaque_key_context' into 'master'
Introduce ESP-RSA DS opaque key context

See merge request espressif/esp-idf!45953
2026-03-04 11:19:43 +05:30
harshal.patil a1bbab43fe feat(mbedtls/esp_rsa_ds): Support Key Manager key using the ESP-RSA-DS PSA interface 2026-03-03 18:42:07 +05:30
harshal.patil 8036017951 feat(mbedtls/esp_mac): Support Key Manager key using the ESP-HMAC PSA interface 2026-03-03 18:40:31 +05:30
harshal.patil 30a120c7cb feat(mbedtls/esp_ecdsa): Support Key Manager key using the ESP-ECDSA PSA interface 2026-03-03 18:40:31 +05:30
harshal.patil 163e0974b3 change(mbedtls/psa_driver_esp_hmac): Use efuse key block instead of efuse block
- Maintains compatibility of the older esp_hmac_ APIs and the PSA driver
2026-03-03 18:36:18 +05:30
harshal.patil aa63487d9f feat(mbedtls/esp_rsa_ds): Introduce ESP-RSA DS opaque key context 2026-03-03 18:36:18 +05:30
harshal.patil 8bd87b67e2 fix(nvs_flash): Use h/w accelerated AES-ECB for XTS-AES operations 2026-02-11 15:24:03 +05:30
Harshal Patil 9cf49269aa Merge branch 'fix/support_truncated_hmac' into 'master'
Allow truncated ESP-PSA HMAC driver operations

Closes IDF-15299

See merge request espressif/esp-idf!45754
2026-02-11 10:25:04 +05:30
harshal.patil 6964de6f45 test(esp_security): Update the Key Manager test to support ESP32-P4 2026-02-10 17:48:52 +05:30
harshal.patil b4542bf748 fix(mbedtls): Support truncated HMAC 2026-02-10 14:08:46 +05:30
harshal.patil 0cebfe7771 change(mbedtls): Disable MBEDTLS_SHA3_C by default 2026-02-03 14:55:44 +08:00
harshal.patil 2bc49effb4 test(mbedtls): Re-introduce the extensive AES, AES-GCM and the SHA tests
- Also extend the PSRAM encryption test to ESP32-S3
2026-02-02 16:58:01 +05:30
harshal.patil 1c0e4455bb fix(mbedtls/sha): Fix SHA-512 parallel engine driver to the use h/w engine 2026-02-02 16:57:25 +05:30
harshal.patil 0c8fbdcc83 feat(esp_tee/tee_sec_storage): Use PSA interface internally 2026-01-31 13:30:58 +05:30
harshal.patil 48c373aea2 fix(mbedtls/psa_driver_aes_gcm): Support shortened tag length for AES-GCM 2026-01-31 13:30:57 +05:30
harshal.patil b450664e2b fix(mbedtls/include): Fix include libs in the driver's public headers 2026-01-31 13:30:57 +05:30
harshal.patil 4ab9ac1ccd fix(mbedtls): Make the driver define macros public to allow application access
- Also, use the PSA HMAC opaque key interface for HMAC-PBKDF2
2026-01-31 13:30:55 +05:30
harshal.patil 7750c40c45 feat(mbedlts/hmac): Support HMAC(MD5) using the MD5 driver 2026-01-31 00:45:12 +05:30
harshal.patil be73538452 change(mbedtls): Remove legacy headers 2026-01-31 00:45:12 +05:30
harshal.patil ae459b5204 feat(mbedtls): Introduce ESP-HMAC PSA opaque driver 2026-01-31 00:45:11 +05:30
harshal.patil 53072bfa9d fix(mbedtls): Enable h/w accel for CMAC and HMAC operations
- Refactor ESP-MAC drivers
2026-01-31 00:45:11 +05:30
harshal.patil f18b893e7a fix(mbedtls/ecdsa): Improve build time efuse validation checks in the ecdsa driver 2026-01-29 23:07:34 +05:30
Harshal Patil 87fb2eb4e9 Merge branch 'fix/dead_code_and_uninitialised_scalar' into 'master'
fix(examples/tee): Remove dead code and fix unintialised scalar usage

Closes IDF-15182 and IDF-15183

See merge request espressif/esp-idf!45325
2026-01-21 12:32:44 +05:30
harshal.patil 16e01b7b75 fix(examples/tee): Remove dead code and fix unintialised scalar usage 2026-01-21 10:12:33 +05:30
harshal.patil acb71bc858 feat(esp_tee): Support deterministic ECDSA signatures for ESP-TEE based keys 2026-01-19 09:14:37 +05:30
harshal.patil e9ea55bea2 feat(mbedtls/ecdsa): Introduce PSA ECDSA driver 2026-01-19 09:14:37 +05:30
harshal.patil 488ee5dfbc fix(mbedtls/aes): Cache invalidate the output buffer before the AES-DMA operation
Instead of performing the cache-to-memory (C2M) operation on the output buffer,
even a cache invalidate (M2C) is sufficient to ensure that no write-back occurs
during the DMA write operation
2026-01-07 23:40:59 +05:30
Harshal Patil eec7e5bb64 Merge branch 'fix/partial-hardware-aes-gcm-and-software-non-aes-ciphers' into 'master'
Fix partial hardware AES-GCM, software-fallback for non-AES ciphers

Closes IDF-12474, IDF-15050, and IDF-15051

See merge request espressif/esp-idf!44616
2026-01-05 18:34:34 +05:30
harshal.patil e91d50ed1e fix(mbedtls): Support partial hardware AES-GCM and s/w fallback for non-AES ciphers
- Support software-fallback for unsupported hardware AES lengths
2026-01-03 12:17:50 +05:30
harshal.patil 35b305f916 fix(mbedlts/aes): Ensure cache coherency when DMA writes to cacheable PSRAM buffers 2025-12-26 12:26:36 +05:30
harshal.patil 60637470c2 test(ota): Add tests for verifying app build's SBv2 ECDSA signature verify APIs 2025-12-23 23:24:46 +05:30
harshal.patil bf16835aa1 test(mbedtls): Run mbedtls HW tests only if HW enabled 2025-12-16 10:05:25 +05:30
harshal.patil 2f3fdba22f fix(mbedtls/aes): Reallocate buffers only if in external RAM 2025-12-12 14:44:24 +05:30
harshal.patil 37251c2ce2 test(mbedtls): add more tests for alignment, buffer size related
- Also, enabled Flash Encryption enabled tests for ESP32-C5
- Removed ESP32-P4 specific configs, as those configs are set as default now
2025-12-12 14:44:22 +05:30
harshal.patil 4263319f27 fix(secure_boot): Application's Secure Boot verify API support ECDSA-P384 2025-12-12 12:33:49 +05:30
harshal.patil 19cddd6739 fix(key_mgr): Correct XTS-AES key length register configuration
The key_mgr_ll_set_xts_aes_key_len() function was incorrectly using
REG_SET_FIELD() with the key_len enum value directly. Since
KEYMNG_FLASH_KEY_LEN is a 1-bit register field (0=128-bit, 1=256-bit),
writing ESP_KEY_MGR_XTS_AES_LEN_128 (value 3) resulted in the LSB (1)
being stored, incorrectly configuring 256-bit mode.

Fixed by using a switch statement to properly map:
- ESP_KEY_MGR_XTS_AES_LEN_128 → REG_CLR_BIT (0)
- ESP_KEY_MGR_XTS_AES_LEN_256 → REG_SET_BIT (1)

Thus, matching the correct ESP32-C5 implementation.
2025-12-04 13:56:00 +05:30
harshal.patil 55fd8a5fb2 fix(mbedtls/port): Use internal buffers to perform chunkwise operations
when the external input and output buffers are unaligned.
This also fixes as a recursion loop that occurs when the size of the input
buffer is not aligned to dcache_line_size but is aligned to AES_BLOCK_BYTES
2025-12-01 14:43:10 +05:30
Harshal Patil b873a82d5b Merge branch 'feat/generic_key_mgr_key_types' into 'master'
Store key_len field in the key_config

See merge request espressif/esp-idf!42692
2025-11-18 15:12:03 +05:30
harshal.patil 1c1bcf44be feat(esp_security): Support ECDSA-P384 key deployment using Key Manager 2025-11-17 12:34:09 +05:30
harshal.patil dac0bbfcc2 change(mbedtls): Generalize key source union for the hardware ECDSA context 2025-11-17 12:34:09 +05:30
harshal.patil 1f2cbde525 change(esp_key_mgr): Store key_len field in the key_info
- Update the Key Manager key types to be generic
- Define a new enum to determine the length of the keys
- Refactor the Key Manager driver support generic key types and key lengths
- Also store key deployment mode in the key recovery info
2025-11-17 12:34:09 +05:30
harshal.patil 25fe0d6786 test(examples): Fix cert bundle stress test 2025-11-13 12:34:56 +05:30
Harshal Patil 0debe71b3d Merge branch 'feat/flash_enc_using_key_manager' into 'master'
Support Flash Encryption using Key Manager

Closes IDF-13462 and IDF-14278

See merge request espressif/esp-idf!41879
2025-11-13 07:55:15 +05:30
harshal.patil 0c3c284819 feat(bootloader_support): Support FE XTS-AES-256 using Key Manager for ESP32-C5 2025-11-11 12:23:27 +05:30
harshal.patil f73cfa5def fix(hal): Force HUK power up when configuring HUK for ESP32-C5 2025-11-11 12:23:27 +05:30
harshal.patil 38f8b57fe5 feat(flash_encryption): Remove mspi reset when switching the XTS-AES key source 2025-11-11 12:23:27 +05:30
harshal.patil c9417e418b change(bootloader_support): Rename the esp_flash_encryption_enable_key_mgr() API 2025-11-11 12:23:26 +05:30
harshal.patil 540c719c66 change(esp_key_mgr): Make Key Manager driver bootloader compatible
- Independent of heap
2025-11-11 12:23:26 +05:30
harshal.patil 8abea3c537 feat(bootloader_support): Support Flash Encryption using Key Manager 2025-11-11 12:23:25 +05:30
harshal.patil 304bd1c77b fix(esp_security/esp_key_mgr): Fix missed error codes and some cleanup 2025-11-11 12:22:08 +05:30
Harshal Patil ed57a94687 Merge branch 'feat/extend_pmp_protection_esp32p4_eco5' into 'master'
Extend PMP memprot for ESP32-P4 V3

Closes IDF-14075

See merge request espressif/esp-idf!42402
2025-11-11 10:07:21 +05:30
harshal.patil a6de2c79ed fix(mbedtls/port): Align AES and SHA DMA buffers to 16 when SPIRAM encryption is enabled
- Targets that support GDMA and MSPI encryption module need data and addresses aligned to 16
2025-11-06 12:28:19 +05:30
harshal.patil c66ef46f99 feat(cpu_region_protect): Extend PMP memprot for ESP32-P4 V3 2025-11-05 13:34:47 +05:30
harshal.patil 3090e91e60 fix(esp_security): Set WR_DIS_SECURE_BOOT_SHA384_EN by default when
Flash Encryption Release mode is enabled and Secure Boot P384 scheme not is enabled.
2025-11-05 08:39:55 +05:30
harshal.patil 7168b9f7d3 fix(esp_security): Fix undefined efuse build failure in case of ESP32-P4
- The `wr_dis` efuse bit corresponding to `SECURE_BOOT_SHA384_EN` is absent in P4
2025-11-05 08:39:55 +05:30
harshal.patil 86b52c4f64 change(efuse): Fix the incorrect efuse field name of SECURE_BOOT_EN_SHA384 2025-11-05 08:39:50 +05:30