File tree Expand file tree Collapse file tree 5 files changed +52
-0
lines changed Expand file tree Collapse file tree 5 files changed +52
-0
lines changed Original file line number Diff line number Diff line change @@ -152,6 +152,12 @@ function(zephyr_mcuboot_tasks)
152
152
set (imgtool_args --align ${write_block_size} ${imgtool_args} )
153
153
endif ()
154
154
155
+ if (NOT "${keyfile_enc} " STREQUAL "" )
156
+ if (CONFIG_MCUBOOT_ENCRYPTION_ALG_AES_256 )
157
+ set (imgtool_args ${imgtool_args} --encrypt-keylen 256 )
158
+ endif ()
159
+ endif ()
160
+
155
161
# Extensionless prefix of any output file.
156
162
set (output ${ZEPHYR_BINARY_DIR} /${KERNEL_NAME} )
157
163
Original file line number Diff line number Diff line change @@ -89,6 +89,22 @@ config MCUBOOT_ENCRYPTION_KEY_FILE
89
89
90
90
If left empty, you must encrypt the Zephyr binaries manually.
91
91
92
+ if MCUBOOT_ENCRYPTION_KEY_FILE != ""
93
+
94
+ choice MCUBOOT_ENCRYPTION_ALG
95
+ prompt "Algorithm used for image encryption"
96
+ default MCUBOOT_ENCRYPTION_ALG_AES_128
97
+
98
+ config MCUBOOT_ENCRYPTION_ALG_AES_128
99
+ bool "Use AES-128 for image encryption"
100
+
101
+ config MCUBOOT_ENCRYPTION_ALG_AES_256
102
+ bool "Use AES-256 for image encryption"
103
+
104
+ endchoice # BOOT_ENCRYPT_ALG
105
+
106
+ endif # MCUBOOT_ENCRYPTION_KEY_FILE != ""
107
+
92
108
config MCUBOOT_IMGTOOL_SIGN_VERSION
93
109
string "Version to pass to imgtool when signing"
94
110
default "$(APP_VERSION_TWEAK_STRING)" if "$(VERSION_MAJOR)" != ""
Original file line number Diff line number Diff line change @@ -51,4 +51,13 @@ if(SB_CONFIG_BOOTLOADER_MCUBOOT)
51
51
set_config_bool (${ZCMAKE_APPLICATION} CONFIG_RETENTION_BOOT_MODE y )
52
52
endif ()
53
53
endif ()
54
+
55
+ if (SB_CONFIG_BOOT_ENCRYPTION )
56
+ if (SB_CONFIG_BOOT_ENCRYPTION_ALG_AES_128 )
57
+ set_config_bool (${ZCMAKE_APPLICATION} CONFIG_MCUBOOT_ENCRYPTION_ALG_AES_128 y )
58
+ elseif (SB_CONFIG_BOOT_ENCRYPTION_ALG_AES_256 )
59
+ set_config_bool (${ZCMAKE_APPLICATION} CONFIG_MCUBOOT_ENCRYPTION_ALG_AES_256 y )
60
+ endif ()
61
+ endif ()
62
+
54
63
endif ()
Original file line number Diff line number Diff line change @@ -18,5 +18,10 @@ if(SB_CONFIG_BOOTLOADER_MCUBOOT)
18
18
set_config_bool (${image} CONFIG_BOOT_ENCRYPT_IMAGE "${SB_CONFIG_BOOT_ENCRYPTION} " )
19
19
if (SB_CONFIG_BOOT_ENCRYPTION )
20
20
set_config_string (${image} CONFIG_BOOT_ENCRYPTION_KEY_FILE "${SB_CONFIG_BOOT_ENCRYPTION_KEY_FILE} " )
21
+ if (SB_CONFIG_BOOT_ENCRYPTION_ALG_AES_128 )
22
+ set_config_bool (${image} CONFIG_BOOT_ENCRYPT_ALG_AES_128 y )
23
+ elseif (SB_CONFIG_BOOT_ENCRYPTION_ALG_AES_256 )
24
+ set_config_bool (${image} CONFIG_BOOT_ENCRYPT_ALG_AES_256 y )
25
+ endif ()
21
26
endif ()
22
27
endif ()
Original file line number Diff line number Diff line change @@ -204,4 +204,20 @@ config BOOT_ENCRYPTION_KEY_FILE
204
204
help
205
205
Absolute path to encryption key file to use with MCUBoot.
206
206
207
+ if BOOT_ENCRYPTION
208
+
209
+ choice BOOT_ENCRYPTION_ALG
210
+ prompt "Algorithm used for image encryption"
211
+ default BOOT_ENCRYPTION_ALG_AES_128
212
+
213
+ config BOOT_ENCRYPTION_ALG_AES_128
214
+ bool "Use AES-128 for image encryption"
215
+
216
+ config BOOT_ENCRYPTION_ALG_AES_256
217
+ bool "Use AES-256 for image encryption"
218
+
219
+ endchoice # BOOT_ENCRYPT_ALG
220
+
221
+ endif # BOOT_ENCRYPTION
222
+
207
223
endif
You can’t perform that action at this time.
0 commit comments