Skip to content

Add NXP EdgeLock Secure Enclave (ELE) crypto callback port with TRNG - #11709

Open
dgarske wants to merge 1 commit into
wolfSSL:masterfrom
dgarske:imx95_ele
Open

dgarske wants to merge 1 commit into
wolfSSL:masterfrom
dgarske:imx95_ele

Conversation

@dgarske

@dgarske dgarske commented Oct 9, 2026

Copy link
Copy Markdown
Member

Description

Adds a wolfCrypt crypto-callback port for the NXP EdgeLock Secure Enclave (ELE), which replaces CAAM on i.MX 8ULP / 93 / 95. TRNG only: every other algorithm returns CRYPTOCB_UNAVAILABLE, so wolfCrypt falls back to software and applications need no conditional code. The enclave TRNG arrives through the Linux hwrng framework, so the port pulls in no NXP userspace library and no vendor SDK headers, and builds anywhere.

  • wolfcrypt/src/port/nxp/ele_rng.c, ele_cryptocb.c - the TRNG and the callback device, devId 0x454C45
  • wolfssl/wolfcrypt/port/nxp/ele.h - public API; the settings macros sit inline in wolfssl/wolfcrypt/settings.h
  • --enable-ele, and an ELE section in wolfcrypt/src/port/nxp/README.md

Registration is left to the application rather than done from wolfCrypt_Init() the way some ports do it: the hwrng node is root-only by default, so registering unconditionally would turn every RNG call in an unprivileged process into a failure instead of letting it use software.

Testing

Validated on a Toradex SMARC i.MX95 under Torizon OS, where /sys/class/misc/hw_random/rng_current reads ele-trng. Registering the device and calling wc_InitRng_ex() with its devId yields entropy as root and fails unprivileged, because the node is root-only - that difference is what establishes the enclave is really being reached, since a test that tolerates the software fallback passes either way. wolfcrypt/test gained an ele_trng_test that checks the node is readable before requiring entropy, so it is a clean skip on a machine without the enclave. On a Linux host --enable-ele passes make check and testwolfcrypt, and a default build with the option off is unaffected.

@dgarske
dgarske requested a review from Frauschi October 9, 2026 21:15
@dgarske dgarske self-assigned this Oct 9, 2026
Copilot AI balanced review requested due to automatic review settings October 9, 2026 21:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

CMake integration is missing, and the new test breaks no-filesystem builds while allowing non-ELE hardware RNGs to pass.

4 open findings
What changed in this PR

Adds an NXP EdgeLock Secure Enclave crypto-callback port that sources TRNG entropy through Linux /dev/hwrng.

Changes:

  • Adds ELE TRNG and crypto-callback implementations.
  • Adds Autotools configuration, headers, settings, and documentation.
  • Adds an ELE hardware test.
File Description
.wolfssl_known_macro_extras Registers ELE configuration macros.
configure.ac Adds --enable-ele.
wolfcrypt/​src/​include.am Builds and distributes ELE sources.
wolfcrypt/​src/​port/​nxp/​README.md Documents configuration and usage.
wolfcrypt/​src/​port/​nxp/​ele_cryptocb.c Implements callback registration and routing.
wolfcrypt/​src/​port/​nxp/​ele_rng.c Reads entropy from the hwrng device.
wolfcrypt/​test/​test.c Adds the ELE TRNG test.
wolfssl/​wolfcrypt/​include.am Installs the ELE public header.
wolfssl/​wolfcrypt/​port/​nxp/​ele.h Declares the ELE API.
wolfssl/​wolfcrypt/​settings.h Defines ELE defaults and callback settings.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread configure.ac
Comment on lines +5155 to +5158
AC_ARG_ENABLE([ele],
[AS_HELP_STRING([--enable-ele],[Enable NXP EdgeLock Secure Enclave support (default: disabled)])],
[ENABLED_ELE=$enableval],
[ENABLED_ELE=no])
Comment thread wolfcrypt/test/test.c Outdated
Comment on lines +98190 to +98191
#if defined(WOLFSSL_NXP_ELE) && defined(WOLFSSL_NXP_ELE_TRNG) && \
!defined(WC_NO_RNG)
Comment thread wolfcrypt/test/test.c
Comment on lines +98206 to +98209
f = XFOPEN(WOLFSSL_NXP_ELE_TRNG_DEVICE, "rb");
if (f == XBADFILE)
return 0; /* no accessible enclave TRNG on this machine */
XFCLOSE(f);
Comment thread wolfssl/wolfcrypt/port/nxp/ele.h Outdated
extern "C" {
#endif

/* 0 on success, WC_HW_E or RNG_FAILURE_E on error. */
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants