1
0
mirror of https://github.com/trezor/trezor-firmware.git synced 2025-01-16 10:20:57 +00:00

feat(core): make random delays use chacha_drbg

This commit is contained in:
Ondřej Vejpustek 2021-03-25 19:33:21 +01:00
parent e1a5f42c81
commit 6fd4739c5c
13 changed files with 128 additions and 107 deletions

View File

@ -0,0 +1 @@
Random delays use ChaCha-based DRBG instead of HMAC-DRBG.

View File

@ -22,13 +22,14 @@ CPPDEFINES_MOD += [
] ]
SOURCE_MOD += [ SOURCE_MOD += [
'vendor/trezor-crypto/blake2s.c', 'vendor/trezor-crypto/blake2s.c',
'vendor/trezor-crypto/chacha_drbg.c',
'vendor/trezor-crypto/chacha20poly1305/chacha_merged.c',
'vendor/trezor-crypto/ed25519-donna/curve25519-donna-32bit.c', 'vendor/trezor-crypto/ed25519-donna/curve25519-donna-32bit.c',
'vendor/trezor-crypto/ed25519-donna/curve25519-donna-helpers.c', 'vendor/trezor-crypto/ed25519-donna/curve25519-donna-helpers.c',
'vendor/trezor-crypto/ed25519-donna/ed25519.c', 'vendor/trezor-crypto/ed25519-donna/ed25519.c',
'vendor/trezor-crypto/ed25519-donna/ed25519-donna-32bit-tables.c', 'vendor/trezor-crypto/ed25519-donna/ed25519-donna-32bit-tables.c',
'vendor/trezor-crypto/ed25519-donna/ed25519-donna-impl-base.c', 'vendor/trezor-crypto/ed25519-donna/ed25519-donna-impl-base.c',
'vendor/trezor-crypto/ed25519-donna/modm-donna-32bit.c', 'vendor/trezor-crypto/ed25519-donna/modm-donna-32bit.c',
'vendor/trezor-crypto/hmac_drbg.c',
'vendor/trezor-crypto/memzero.c', 'vendor/trezor-crypto/memzero.c',
'vendor/trezor-crypto/rand.c', 'vendor/trezor-crypto/rand.c',
'vendor/trezor-crypto/sha2.c', 'vendor/trezor-crypto/sha2.c',

View File

@ -22,13 +22,14 @@ CPPDEFINES_MOD += [
] ]
SOURCE_MOD += [ SOURCE_MOD += [
'vendor/trezor-crypto/blake2s.c', 'vendor/trezor-crypto/blake2s.c',
'vendor/trezor-crypto/chacha_drbg.c',
'vendor/trezor-crypto/chacha20poly1305/chacha_merged.c',
'vendor/trezor-crypto/ed25519-donna/curve25519-donna-32bit.c', 'vendor/trezor-crypto/ed25519-donna/curve25519-donna-32bit.c',
'vendor/trezor-crypto/ed25519-donna/curve25519-donna-helpers.c', 'vendor/trezor-crypto/ed25519-donna/curve25519-donna-helpers.c',
'vendor/trezor-crypto/ed25519-donna/ed25519.c', 'vendor/trezor-crypto/ed25519-donna/ed25519.c',
'vendor/trezor-crypto/ed25519-donna/ed25519-donna-32bit-tables.c', 'vendor/trezor-crypto/ed25519-donna/ed25519-donna-32bit-tables.c',
'vendor/trezor-crypto/ed25519-donna/ed25519-donna-impl-base.c', 'vendor/trezor-crypto/ed25519-donna/ed25519-donna-impl-base.c',
'vendor/trezor-crypto/ed25519-donna/modm-donna-32bit.c', 'vendor/trezor-crypto/ed25519-donna/modm-donna-32bit.c',
'vendor/trezor-crypto/hmac_drbg.c',
'vendor/trezor-crypto/memzero.c', 'vendor/trezor-crypto/memzero.c',
'vendor/trezor-crypto/rand.c', 'vendor/trezor-crypto/rand.c',
'vendor/trezor-crypto/sha2.c', 'vendor/trezor-crypto/sha2.c',

View File

@ -14,7 +14,8 @@ CPPPATH_MOD += [
'vendor/trezor-crypto', 'vendor/trezor-crypto',
] ]
SOURCE_MOD += [ SOURCE_MOD += [
'vendor/trezor-crypto/hmac_drbg.c', 'vendor/trezor-crypto/chacha_drbg.c',
'vendor/trezor-crypto/chacha20poly1305/chacha_merged.c',
'vendor/trezor-crypto/memzero.c', 'vendor/trezor-crypto/memzero.c',
'vendor/trezor-crypto/rand.c', 'vendor/trezor-crypto/rand.c',
'vendor/trezor-crypto/sha2.c', 'vendor/trezor-crypto/sha2.c',

View File

@ -26,7 +26,7 @@
#include "image.h" #include "image.h"
#include "mini_printf.h" #include "mini_printf.h"
#include "mpu.h" #include "mpu.h"
#include "rng.h" #include "random_delays.h"
#include "secbool.h" #include "secbool.h"
#include "touch.h" #include "touch.h"
#include "usb.h" #include "usb.h"
@ -236,7 +236,7 @@ static void check_bootloader_version(void) {
#endif #endif
int main(void) { int main(void) {
drbg_init(); random_delays_init();
// display_init_seq(); // display_init_seq();
touch_init(); touch_init();
touch_power_on(); touch_power_on();

View File

@ -26,6 +26,7 @@
#include "image.h" #include "image.h"
#include "mini_printf.h" #include "mini_printf.h"
#include "mpu.h" #include "mpu.h"
#include "random_delays.h"
#include "rng.h" #include "rng.h"
#include "secbool.h" #include "secbool.h"
#include "touch.h" #include "touch.h"
@ -214,7 +215,7 @@ static void check_bootloader_version(void) {
#endif #endif
int main(void) { int main(void) {
drbg_init(); random_delays_init();
touch_init(); touch_init();
touch_power_on(); touch_power_on();

View File

@ -52,8 +52,8 @@
#include "touch.h" #include "touch.h"
int main(void) { int main(void) {
// initialize pseudo-random number generator random_delays_init();
drbg_init();
#ifdef RDI #ifdef RDI
rdi_start(); rdi_start();
#endif #endif

View File

@ -27,6 +27,7 @@
#include "display.h" #include "display.h"
#include "flash.h" #include "flash.h"
#include "mini_printf.h" #include "mini_printf.h"
#include "random_delays.h"
#include "rng.h" #include "rng.h"
#include "sbu.h" #include "sbu.h"
#include "sdcard.h" #include "sdcard.h"
@ -371,7 +372,7 @@ static secbool startswith(const char *s, const char *prefix) {
int main(void) { int main(void) {
display_orientation(0); display_orientation(0);
drbg_init(); random_delays_init();
sdcard_init(); sdcard_init();
touch_init(); touch_init();
sbu_init(); sbu_init();

View File

@ -24,7 +24,6 @@
#include "common.h" #include "common.h"
#include "display.h" #include "display.h"
#include "flash.h" #include "flash.h"
#include "hmac_drbg.h"
#include "rand.h" #include "rand.h"
#include "stm32f4xx_ll_utils.h" #include "stm32f4xx_ll_utils.h"
@ -32,8 +31,6 @@
// from util.s // from util.s
extern void shutdown(void); extern void shutdown(void);
static HMAC_DRBG_CTX drbg_ctx;
#define COLOR_FATAL_ERROR RGB16(0x7F, 0x00, 0x00) #define COLOR_FATAL_ERROR RGB16(0x7F, 0x00, 0x00)
void __attribute__((noreturn)) void __attribute__((noreturn))
@ -170,23 +167,3 @@ void collect_hw_entropy(void) {
FLASH_OTP_BLOCK_SIZE), FLASH_OTP_BLOCK_SIZE),
NULL); NULL);
} }
void drbg_init(void) {
uint8_t entropy[48];
random_buffer(entropy, sizeof(entropy));
hmac_drbg_init(&drbg_ctx, entropy, sizeof(entropy), NULL, 0);
}
void drbg_reseed(const uint8_t *entropy, size_t len) {
hmac_drbg_reseed(&drbg_ctx, entropy, len, NULL, 0);
}
void drbg_generate(uint8_t *buf, size_t len) {
hmac_drbg_generate(&drbg_ctx, buf, len);
}
uint32_t drbg_random32(void) {
uint32_t value;
drbg_generate((uint8_t *)&value, sizeof(value));
return value;
}

View File

@ -74,11 +74,6 @@ void collect_hw_entropy(void);
#define HW_ENTROPY_LEN (12 + 32) #define HW_ENTROPY_LEN (12 + 32)
extern uint8_t HW_ENTROPY_DATA[HW_ENTROPY_LEN]; extern uint8_t HW_ENTROPY_DATA[HW_ENTROPY_LEN];
void drbg_init(void);
void drbg_reseed(const uint8_t *entropy, size_t len);
void drbg_generate(uint8_t *buf, size_t len);
uint32_t drbg_random32(void);
// the following functions are defined in util.s // the following functions are defined in util.s
void memset_reg(volatile void *start, volatile void *stop, uint32_t val); void memset_reg(volatile void *start, volatile void *stop, uint32_t val);

View File

@ -36,6 +36,7 @@ https://link.springer.com/content/pdf/10.1007%2F978-3-540-72354-7_3.pdf
#include "random_delays.h" #include "random_delays.h"
#include <stdatomic.h>
#include <stdbool.h> #include <stdbool.h>
#include "chacha_drbg.h" #include "chacha_drbg.h"
@ -46,51 +47,79 @@ https://link.springer.com/content/pdf/10.1007%2F978-3-540-72354-7_3.pdf
// from util.s // from util.s
extern void shutdown(void); extern void shutdown(void);
#define DRBG_RESEED_INTERVAL_CALLS 1000
#define DRBG_TRNG_ENTROPY_LENGTH 50
_Static_assert(CHACHA_DRBG_OPTIMAL_RESEED_LENGTH(1) == DRBG_TRNG_ENTROPY_LENGTH,
"");
#define BUFFER_LENGTH 64 #define BUFFER_LENGTH 64
#define RESEED_INTERVAL 65536
static CHACHA_DRBG_CTX drbg_ctx; static CHACHA_DRBG_CTX drbg_ctx;
static uint8_t buffer[BUFFER_LENGTH]; static secbool drbg_initialized = secfalse;
static size_t buffer_index;
static uint8_t session_delay; static uint8_t session_delay;
static bool refresh_session_delay; static bool refresh_session_delay;
static secbool rdi_disabled = sectrue; static secbool rdi_disabled = sectrue;
static void rdi_reseed(void) { static void drbg_init() {
uint8_t entropy[CHACHA_DRBG_SEED_LENGTH]; uint8_t entropy[DRBG_TRNG_ENTROPY_LENGTH] = {0};
random_buffer(entropy, CHACHA_DRBG_SEED_LENGTH); random_buffer(entropy, sizeof(entropy));
chacha_drbg_init(&drbg_ctx, entropy, sizeof(entropy), NULL, 0);
memzero(entropy, sizeof(entropy));
drbg_initialized = sectrue;
}
static void drbg_reseed() {
ensure(drbg_initialized, NULL);
uint8_t entropy[DRBG_TRNG_ENTROPY_LENGTH] = {0};
random_buffer(entropy, sizeof(entropy));
chacha_drbg_reseed(&drbg_ctx, entropy, sizeof(entropy), NULL, 0); chacha_drbg_reseed(&drbg_ctx, entropy, sizeof(entropy), NULL, 0);
memzero(entropy, sizeof(entropy));
} }
static void buffer_refill(void) { static void drbg_generate(uint8_t *buffer, size_t length) {
chacha_drbg_generate(&drbg_ctx, buffer, BUFFER_LENGTH); ensure(drbg_initialized, NULL);
if (drbg_ctx.reseed_counter > DRBG_RESEED_INTERVAL_CALLS) {
drbg_reseed();
}
chacha_drbg_generate(&drbg_ctx, buffer, length);
} }
static uint32_t random8(void) { // WARNING: Returns a constant if the function's critical section is locked
buffer_index += 1; static uint32_t drbg_random8(void) {
if (buffer_index >= BUFFER_LENGTH) { // Since the function is called both from an interrupt (rdi_handler,
buffer_refill(); // wait_random) and the main thread (wait_random), we use a lock to
if (RESEED_INTERVAL != 0 && drbg_ctx.reseed_counter > RESEED_INTERVAL) // synchronise access to global variables
rdi_reseed(); static volatile atomic_flag locked = ATOMIC_FLAG_INIT;
buffer_index = 0;
} if (atomic_flag_test_and_set(&locked))
return buffer[buffer_index]; // locked_old = locked; locked = true; locked_old
{
// If the critical section is locked we return a non-random value, which
// should be ok for our purposes
return 128;
} }
void rdi_refresh_session_delay(void) { static size_t buffer_index = 0;
if (rdi_disabled == secfalse) // if rdi enabled static uint8_t buffer[BUFFER_LENGTH] = {0};
refresh_session_delay = true;
if (buffer_index == 0) {
drbg_generate(buffer, sizeof(buffer));
} }
void rdi_handler(uint32_t uw_tick) { // To be extra sure there is no buffer overflow, we use a local copy of
if (rdi_disabled == secfalse) { // if rdi enabled // buffer_index
if (refresh_session_delay) { size_t buffer_index_local = buffer_index % sizeof(buffer);
session_delay = random8(); uint8_t value = buffer[buffer_index_local];
refresh_session_delay = false; memzero(&buffer[buffer_index_local], 1);
buffer_index = (buffer_index_local + 1) % sizeof(buffer);
atomic_flag_clear(&locked); // locked = false
return value;
} }
uint32_t delay = random8() + session_delay; static void wait(uint32_t delay) {
// wait (30 + delay) ticks // wait (30 + delay) ticks
asm volatile( asm volatile(
"ldr r0, %0;" // r0 = delay "ldr r0, %0;" // r0 = delay
@ -119,18 +148,14 @@ void rdi_handler(uint32_t uw_tick) {
: :
: "m"(delay) : "m"(delay)
: "r0", "r1"); : "r0", "r1");
} else { // if rdi disabled or rdi_disabled corrupted
ensure(rdi_disabled, "Fault detected");
}
} }
void random_delays_init() { drbg_init(); }
void rdi_start(void) { void rdi_start(void) {
ensure(drbg_initialized, NULL);
if (rdi_disabled == sectrue) { // if rdi disabled if (rdi_disabled == sectrue) { // if rdi disabled
uint8_t entropy[CHACHA_DRBG_SEED_LENGTH];
random_buffer(entropy, CHACHA_DRBG_SEED_LENGTH);
chacha_drbg_init(&drbg_ctx, entropy, sizeof(entropy), NULL, 0);
buffer_refill();
buffer_index = 0;
refresh_session_delay = true; refresh_session_delay = true;
rdi_disabled = secfalse; rdi_disabled = secfalse;
} }
@ -140,7 +165,25 @@ void rdi_stop(void) {
if (rdi_disabled == secfalse) { // if rdi enabled if (rdi_disabled == secfalse) { // if rdi enabled
rdi_disabled = sectrue; rdi_disabled = sectrue;
session_delay = 0; session_delay = 0;
memzero(&drbg_ctx, sizeof(drbg_ctx)); }
}
void rdi_refresh_session_delay(void) {
if (rdi_disabled == secfalse) // if rdi enabled
refresh_session_delay = true;
}
void rdi_handler(uint32_t uw_tick) {
if (rdi_disabled == secfalse) { // if rdi enabled
if (refresh_session_delay) {
session_delay = drbg_random8();
refresh_session_delay = false;
}
wait(drbg_random8() + session_delay);
} else { // if rdi disabled or rdi_disabled corrupted
ensure(rdi_disabled, "Fault detected");
} }
} }
@ -149,7 +192,7 @@ void rdi_stop(void) {
* against fault injection. * against fault injection.
*/ */
void wait_random(void) { void wait_random(void) {
int wait = drbg_random32() & 0xff; int wait = drbg_random8();
volatile int i = 0; volatile int i = 0;
volatile int j = wait; volatile int j = wait;
while (i < wait) { while (i < wait) {

View File

@ -22,6 +22,8 @@
#include <stdint.h> #include <stdint.h>
void random_delays_init(void);
void rdi_start(void); void rdi_start(void);
void rdi_stop(void); void rdi_stop(void);
void rdi_refresh_session_delay(void); void rdi_refresh_session_delay(void);

View File

@ -107,8 +107,6 @@ error_shutdown(const char *line1, const char *line2, const char *line3,
void hal_delay(uint32_t ms) { usleep(1000 * ms); } void hal_delay(uint32_t ms) { usleep(1000 * ms); }
void wait_random(void) {}
uint8_t HW_ENTROPY_DATA[HW_ENTROPY_LEN]; uint8_t HW_ENTROPY_DATA[HW_ENTROPY_LEN];
void collect_hw_entropy(void) { memzero(HW_ENTROPY_DATA, HW_ENTROPY_LEN); } void collect_hw_entropy(void) { memzero(HW_ENTROPY_DATA, HW_ENTROPY_LEN); }