Merge pull request #9651 from waleed-elmelegy-arm/add-iop-key-gen-complete

Add PSA interruptible key generation complete API
This commit is contained in:
Janos Follath
2024-11-26 18:34:40 +00:00
committed by GitHub
5 changed files with 160 additions and 40 deletions
+37 -3
View File
@@ -8314,7 +8314,9 @@ static psa_status_t psa_generate_key_iop_abort_internal(
return PSA_SUCCESS;
}
status = mbedtls_psa_generate_key_iop_abort(&operation->ctx);
status = mbedtls_psa_ecp_generate_key_iop_abort(&operation->ctx);
psa_reset_key_attributes(&operation->attributes);
operation->id = 0;
@@ -8366,7 +8368,7 @@ psa_status_t psa_generate_key_iop_setup(
/* We only support the builtin/Mbed TLS driver for now. */
operation->id = PSA_CRYPTO_MBED_TLS_DRIVER_ID;
status = mbedtls_psa_generate_key_iop_setup(&operation->ctx, attributes);
status = mbedtls_psa_ecp_generate_key_iop_setup(&operation->ctx, attributes);
exit:
if (status != PSA_SUCCESS) {
@@ -8386,10 +8388,42 @@ psa_status_t psa_generate_key_iop_complete(
psa_generate_key_iop_t *operation,
mbedtls_svc_key_id_t *key)
{
#if defined(MBEDTLS_ECP_RESTARTABLE)
psa_status_t status;
uint8_t key_data[PSA_KEY_EXPORT_ECC_KEY_PAIR_MAX_SIZE(PSA_VENDOR_ECC_MAX_CURVE_BITS)+1] = { 0 };
size_t key_len = 0;
if (operation->id == 0 || operation->error_occurred) {
return PSA_ERROR_BAD_STATE;
}
status = mbedtls_psa_ecp_generate_key_iop_complete(&operation->ctx, key_data,
sizeof(key_data), &key_len);
if (status != PSA_SUCCESS) {
goto exit;
}
status = psa_import_key(&operation->attributes,
key_data + (sizeof(key_data) - key_len),
key_len,
key);
exit:
if (status != PSA_OPERATION_INCOMPLETE) {
if (status != PSA_SUCCESS) {
operation->error_occurred = 1;
}
psa_generate_key_iop_abort_internal(operation);
}
mbedtls_platform_zeroize(key_data, sizeof(key_data));
return status;
#else
(void) operation;
(void) key;
return PSA_ERROR_NOT_SUPPORTED;
return PSA_ERROR_BAD_STATE;
#endif
}
psa_status_t psa_generate_key_iop_abort(
-34
View File
@@ -435,40 +435,6 @@ psa_status_t psa_generate_key_internal(const psa_key_attributes_t *attributes,
size_t key_buffer_size,
size_t *key_buffer_length);
/**
* \brief Setup a new interruptible key generation operation.
*
* \param[in] operation The \c mbedtls_psa_generate_key_iop_t to use.
* This must be initialized first.
* \param[in] attributes The desired attributes of the generated key.
*
* \retval #PSA_SUCCESS
* The operation started successfully - call \c mbedtls_psa_generate_key_complete()
* with the same operation to complete the operation.
* * \retval #PSA_ERROR_NOT_SUPPORTED
* Either no internal interruptible operations are
* currently supported, or the key attributes are not unsupported.
* * \retval #PSA_ERROR_INSUFFICIENT_MEMORY
* There was insufficient memory to load the key representation.
*
*/
psa_status_t mbedtls_psa_generate_key_iop_setup(
mbedtls_psa_generate_key_iop_t *operation,
const psa_key_attributes_t *attributes);
/**
* \brief Abort a key generation operation.
*
* \param[in] operation The \c mbedtls_psa_generate_key_iop_t to abort.
*
* \retval #PSA_SUCCESS
* The operation was aborted successfully.
*
*/
psa_status_t mbedtls_psa_generate_key_iop_abort(
mbedtls_psa_generate_key_iop_t *operation);
/** Sign a message with a private key. For hash-and-sign algorithms,
* this includes the hashing step.
*