From a0780c9d25161c3d611591466dc41a991f9a30ce Mon Sep 17 00:00:00 2001 From: Valerio Setti Date: Tue, 11 Aug 2026 13:02:40 +0200 Subject: [PATCH 1/7] scripts: crypto: add support for Blake2s and Blake2p Signed-off-by: Valerio Setti --- scripts/mbedtls_framework/crypto_data_tests.py | 2 ++ scripts/mbedtls_framework/crypto_knowledge.py | 3 +++ 2 files changed, 5 insertions(+) diff --git a/scripts/mbedtls_framework/crypto_data_tests.py b/scripts/mbedtls_framework/crypto_data_tests.py index ce83d700b..81972d06e 100644 --- a/scripts/mbedtls_framework/crypto_data_tests.py +++ b/scripts/mbedtls_framework/crypto_data_tests.py @@ -57,6 +57,8 @@ class HashPSALowLevel: 'PSA_ALG_SHAKE256_256': None, #lambda data: hashlib.shake_256(data).hexdigest(32), 'PSA_ALG_SHAKE256_512': None, #lambda data: hashlib.shake_256(data).hexdigest(64), 'PSA_ALG_ASCON_HASH256': None, #lambda data: ascon.ascon_hash(data), + 'PSA_ALG_BLAKE2S_HASH256': lambda data: hashlib.blake2s(data).hexdigest(), + 'PSA_ALG_BLAKE2B_HASH512': lambda data: hashlib.blake2b(data).hexdigest(), } #type: Dict[str, Optional[Callable[[bytes], str]]] @staticmethod diff --git a/scripts/mbedtls_framework/crypto_knowledge.py b/scripts/mbedtls_framework/crypto_knowledge.py index d406c8a9a..64cc70cae 100644 --- a/scripts/mbedtls_framework/crypto_knowledge.py +++ b/scripts/mbedtls_framework/crypto_knowledge.py @@ -353,6 +353,8 @@ class Algorithm: CATEGORY_FROM_HEAD = { 'AES_MMO_ZIGBEE': AlgorithmCategory.HASH, 'ASCON_HASH': AlgorithmCategory.HASH, + 'BLAKE2B': AlgorithmCategory.HASH, + 'BLAKE2S': AlgorithmCategory.HASH, 'SHA': AlgorithmCategory.HASH, 'SHAKE256_512': AlgorithmCategory.HASH, 'MD': AlgorithmCategory.HASH, @@ -360,6 +362,7 @@ class Algorithm: 'SM3': AlgorithmCategory.HASH, 'ANY_HASH': AlgorithmCategory.HASH, 'HMAC': AlgorithmCategory.MAC, + 'BLAKE2_MAC': AlgorithmCategory.MAC, 'STREAM_CIPHER': AlgorithmCategory.CIPHER, 'ASCON_AEAD': AlgorithmCategory.AEAD, 'CHACHA20_POLY1305': AlgorithmCategory.AEAD, From 8e8a8a171636e949a6b1eefe65bb4739b93ce3d0 Mon Sep 17 00:00:00 2001 From: Valerio Setti Date: Tue, 8 Sep 2026 10:25:07 +0200 Subject: [PATCH 2/7] crypto_knowledge: do not test RSA PKCS1 v1.5 with hash algorithms without OID Some hash algorithms don't have a standardized OID and therefore they cannot be tested with RSA PKCS1 v1.5. Signed-off-by: Valerio Setti --- scripts/mbedtls_framework/crypto_knowledge.py | 25 ++++++++++++++++++- 1 file changed, 24 insertions(+), 1 deletion(-) diff --git a/scripts/mbedtls_framework/crypto_knowledge.py b/scripts/mbedtls_framework/crypto_knowledge.py index 64cc70cae..a6301ba00 100644 --- a/scripts/mbedtls_framework/crypto_knowledge.py +++ b/scripts/mbedtls_framework/crypto_knowledge.py @@ -241,7 +241,7 @@ class KeyType: alg.head == 'STREAM_CIPHER': return True if self.head == 'RSA' and alg.head.startswith('RSA_'): - return True + return alg.is_valid_rsa_alg_with_hash() if alg.category == AlgorithmCategory.KEY_AGREEMENT and \ self.is_public(): # The PSA API does not use public key objects in key agreement @@ -485,6 +485,29 @@ class Algorithm: return False return kdf_alg in self.KEY_DERIVATIONS_INCOMPATIBLE_WITH_AGREEMENT + HASH_ALGS_WITHOUT_OID = [ + 'PSA_ALG_BLAKE2S_HASH256', + 'PSA_ALG_BLAKE2B_HASH512', + 'PSA_ALG_AES_MMO_ZIGBEE', + 'PSA_ALG_ASCON_HASH256', + 'PSA_ALG_SHAKE256_512', + ] + def is_valid_rsa_alg_with_hash(self) -> bool: + """Whether the specified combinaton of RSA_PKCS1V15_SIGN() and hash is supported. + Rationale: there are hash algorithms for which OID is not standardized (or not yet), + so RSA PKCS#1 v1.5 signature is not supported. For the full list of unsupported + hash algorithms please refer to the official PSA API documentation: + https://arm-software.github.io/psa-api/crypto/1.5/api/ops/signature.html#c.PSA_ALG_RSA_PKCS1V15_SIGN + """ + m = re.match(r'PSA_ALG_RSA_PKCS1V15_SIGN\(\s*(.*)\)\Z', self.expression) + if not m: + # Nothing to do for RSA_OAEP, RSA_PSS, or RSA_PKCS1V15_CRYPT. + return True + hash_alg = m.group(1) + if hash_alg in self.HASH_ALGS_WITHOUT_OID: + return False + return True + def short_expression(self, level: int = 0) -> str: """Abbreviate the expression, keeping it human-readable. From ba6f9a62d7042303741014208e348296e7d26a60 Mon Sep 17 00:00:00 2001 From: Valerio Setti Date: Tue, 8 Sep 2026 12:22:45 +0200 Subject: [PATCH 3/7] crypto_data_tests: add entry for SM3 Currently the lambda function is set to None meaning that no test data will be automatically generated. This is an hashlib Python library limitation though and it can be addressed in the future whenever the Python library is upgraded or a different solution is found to compute hashes. Signed-off-by: Valerio Setti --- scripts/mbedtls_framework/crypto_data_tests.py | 1 + 1 file changed, 1 insertion(+) diff --git a/scripts/mbedtls_framework/crypto_data_tests.py b/scripts/mbedtls_framework/crypto_data_tests.py index 81972d06e..c84e7292a 100644 --- a/scripts/mbedtls_framework/crypto_data_tests.py +++ b/scripts/mbedtls_framework/crypto_data_tests.py @@ -59,6 +59,7 @@ class HashPSALowLevel: 'PSA_ALG_ASCON_HASH256': None, #lambda data: ascon.ascon_hash(data), 'PSA_ALG_BLAKE2S_HASH256': lambda data: hashlib.blake2s(data).hexdigest(), 'PSA_ALG_BLAKE2B_HASH512': lambda data: hashlib.blake2b(data).hexdigest(), + 'PSA_ALG_SM3': None, #lambda data: hashlib.new('sm3').hexdigest(), } #type: Dict[str, Optional[Callable[[bytes], str]]] @staticmethod From c235c62ff052d6422a5d33ed22f0834190bd2ec3 Mon Sep 17 00:00:00 2001 From: Valerio Setti Date: Tue, 8 Sep 2026 18:06:58 +0200 Subject: [PATCH 4/7] crypto_knowledge: make HASH_ALGS_WITHOUT_OID a frozenset() Signed-off-by: Valerio Setti --- scripts/mbedtls_framework/crypto_knowledge.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/mbedtls_framework/crypto_knowledge.py b/scripts/mbedtls_framework/crypto_knowledge.py index a6301ba00..c3a07ffa4 100644 --- a/scripts/mbedtls_framework/crypto_knowledge.py +++ b/scripts/mbedtls_framework/crypto_knowledge.py @@ -485,13 +485,13 @@ class Algorithm: return False return kdf_alg in self.KEY_DERIVATIONS_INCOMPATIBLE_WITH_AGREEMENT - HASH_ALGS_WITHOUT_OID = [ + HASH_ALGS_WITHOUT_OID = frozenset([ 'PSA_ALG_BLAKE2S_HASH256', 'PSA_ALG_BLAKE2B_HASH512', 'PSA_ALG_AES_MMO_ZIGBEE', 'PSA_ALG_ASCON_HASH256', 'PSA_ALG_SHAKE256_512', - ] + ]) def is_valid_rsa_alg_with_hash(self) -> bool: """Whether the specified combinaton of RSA_PKCS1V15_SIGN() and hash is supported. Rationale: there are hash algorithms for which OID is not standardized (or not yet), From 075b92628d4af1134e829fed5a4e5e7afb57d2af Mon Sep 17 00:00:00 2001 From: Valerio Setti Date: Tue, 8 Sep 2026 23:42:05 +0200 Subject: [PATCH 5/7] crypto_data_tests: fix comment for PSA_ALG_SM3 Signed-off-by: Valerio Setti --- scripts/mbedtls_framework/crypto_data_tests.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/mbedtls_framework/crypto_data_tests.py b/scripts/mbedtls_framework/crypto_data_tests.py index c84e7292a..327ee87b0 100644 --- a/scripts/mbedtls_framework/crypto_data_tests.py +++ b/scripts/mbedtls_framework/crypto_data_tests.py @@ -59,7 +59,7 @@ class HashPSALowLevel: 'PSA_ALG_ASCON_HASH256': None, #lambda data: ascon.ascon_hash(data), 'PSA_ALG_BLAKE2S_HASH256': lambda data: hashlib.blake2s(data).hexdigest(), 'PSA_ALG_BLAKE2B_HASH512': lambda data: hashlib.blake2b(data).hexdigest(), - 'PSA_ALG_SM3': None, #lambda data: hashlib.new('sm3').hexdigest(), + 'PSA_ALG_SM3': None, #lambda data: hashlib.new('sm3', data).hexdigest(), } #type: Dict[str, Optional[Callable[[bytes], str]]] @staticmethod From 36054361c4febf00a7bdbddf043a1c8417ef9f2e Mon Sep 17 00:00:00 2001 From: Valerio Setti Date: Tue, 8 Sep 2026 23:42:41 +0200 Subject: [PATCH 6/7] crypto_knowledge: improve mechanism to skip testing RSA PKCS1v15 with hash algs w/o OID Signed-off-by: Valerio Setti --- scripts/mbedtls_framework/crypto_knowledge.py | 32 +++++++++++-------- 1 file changed, 18 insertions(+), 14 deletions(-) diff --git a/scripts/mbedtls_framework/crypto_knowledge.py b/scripts/mbedtls_framework/crypto_knowledge.py index c3a07ffa4..3f01b349e 100644 --- a/scripts/mbedtls_framework/crypto_knowledge.py +++ b/scripts/mbedtls_framework/crypto_knowledge.py @@ -241,7 +241,13 @@ class KeyType: alg.head == 'STREAM_CIPHER': return True if self.head == 'RSA' and alg.head.startswith('RSA_'): - return alg.is_valid_rsa_alg_with_hash() + # There are hash algorithms for which OID is not standardized (or not yet), + # so RSA PKCS#1 v1.5 signature is not supported. For the full list of unsupported + # hash algorithms please refer to the official PSA API documentation: + # https://arm-software.github.io/psa-api/crypto/1.5/api/ops/signature.html#c.PSA_ALG_RSA_PKCS1V15_SIGN + if alg.head == 'RSA_PKCS1V15_SIGN': + return alg.get_inner_algorithm().has_hash_standardized_oid() + return True if alg.category == AlgorithmCategory.KEY_AGREEMENT and \ self.is_public(): # The PSA API does not use public key objects in key agreement @@ -492,22 +498,20 @@ class Algorithm: 'PSA_ALG_ASCON_HASH256', 'PSA_ALG_SHAKE256_512', ]) - def is_valid_rsa_alg_with_hash(self) -> bool: - """Whether the specified combinaton of RSA_PKCS1V15_SIGN() and hash is supported. - Rationale: there are hash algorithms for which OID is not standardized (or not yet), - so RSA PKCS#1 v1.5 signature is not supported. For the full list of unsupported - hash algorithms please refer to the official PSA API documentation: - https://arm-software.github.io/psa-api/crypto/1.5/api/ops/signature.html#c.PSA_ALG_RSA_PKCS1V15_SIGN - """ - m = re.match(r'PSA_ALG_RSA_PKCS1V15_SIGN\(\s*(.*)\)\Z', self.expression) - if not m: - # Nothing to do for RSA_OAEP, RSA_PSS, or RSA_PKCS1V15_CRYPT. - return True - hash_alg = m.group(1) - if hash_alg in self.HASH_ALGS_WITHOUT_OID: + def has_hash_standardized_oid(self) -> bool: + """Whether the hash algorithm has a standardized OID.""" + if self.expression in self.HASH_ALGS_WITHOUT_OID: return False return True + def get_inner_algorithm(self) -> "Algorithm": + """Given an algorithm composed as outer_alg(inner_alg) return inner_alg.""" + m = re.match(r'\w+\(\s*(.*)\)\Z', self.expression) + if not m: + return None + inner_alg = m.group(1) + return Algorithm(inner_alg) + def short_expression(self, level: int = 0) -> str: """Abbreviate the expression, keeping it human-readable. From edeb57f200ef92c01dcdf77fa90616ed038ebcf5 Mon Sep 17 00:00:00 2001 From: Valerio Setti Date: Wed, 9 Sep 2026 10:10:04 +0200 Subject: [PATCH 7/7] crypto_knowledge: improve return values for get_inner_algorithm() Return a ValueError exception instead of None if the given algorithm is not a composed one. Signed-off-by: Valerio Setti --- scripts/mbedtls_framework/crypto_knowledge.py | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/scripts/mbedtls_framework/crypto_knowledge.py b/scripts/mbedtls_framework/crypto_knowledge.py index 3f01b349e..ee4a98125 100644 --- a/scripts/mbedtls_framework/crypto_knowledge.py +++ b/scripts/mbedtls_framework/crypto_knowledge.py @@ -505,10 +505,13 @@ class Algorithm: return True def get_inner_algorithm(self) -> "Algorithm": - """Given an algorithm composed as outer_alg(inner_alg) return inner_alg.""" + """Given an algorithm composed as outer_alg(inner_alg) return inner_alg. + + Raise ValueError if the algorithm is not a composed one. + """ m = re.match(r'\w+\(\s*(.*)\)\Z', self.expression) if not m: - return None + raise ValueError('Not a composed algorithm: ' + self.expression) inner_alg = m.group(1) return Algorithm(inner_alg)