Reduce key duplication by enabling hardware RNG (#8803)
* Reduce key duplication by enabling hardware RNG * Apply suggestion from @Copilot Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Apply suggestion from @Copilot Use micros() for worst case random seed for nrf52 Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Minor cleanup, remove dead code and clarify comment * trunk * Add useRadioEntropy bool, default false. --------- Co-authored-by: Ben Meadors <benmmeadors@gmail.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: Jonathan Bennett <jbennett@incomsystems.biz>
This commit is contained in:
committed by
Ben Meadors
co-authored by
Ben Meadors
Copilot
Jonathan Bennett
parent
e1f5043489
commit
23321c4588
@@ -4,6 +4,7 @@
|
||||
#include <memory>
|
||||
|
||||
#if !(MESHTASTIC_EXCLUDE_PKI)
|
||||
#include "HardwareRNG.h"
|
||||
#include "NodeDB.h"
|
||||
#include "aes-ccm.h"
|
||||
#include "meshUtils.h"
|
||||
@@ -26,6 +27,15 @@ void CryptoEngine::generateKeyPair(uint8_t *pubKey, uint8_t *privKey)
|
||||
{
|
||||
// Mix in any randomness we can, to make key generation stronger.
|
||||
CryptRNG.begin(optstr(APP_VERSION));
|
||||
|
||||
uint8_t hardwareEntropy[64] = {0};
|
||||
if (HardwareRNG::fill(hardwareEntropy, sizeof(hardwareEntropy), true)) {
|
||||
CryptRNG.stir(hardwareEntropy, sizeof(hardwareEntropy));
|
||||
} else {
|
||||
LOG_WARN("Hardware entropy unavailable, falling back to software RNG");
|
||||
}
|
||||
memset(hardwareEntropy, 0, sizeof(hardwareEntropy));
|
||||
|
||||
if (myNodeInfo.device_id.size == 16) {
|
||||
CryptRNG.stir(myNodeInfo.device_id.bytes, myNodeInfo.device_id.size);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user