Repository navigation
SiLabs: Let caller choose Secure Element key flags for wrapped keys and fix the attestation key binding - #11687
Conversation
There was a problem hiding this comment.
🔵 Needs a closer look
Reduced-configuration test failures remain, and vendor-specific key behavior needs human review across supported SDKs and devices.
1 open finding
What changed in this PR
Updates wolfCrypt’s SiLabs port to support caller-selected wrapped-key flags and correct attestation-key binding, addressing #11685 and #11686.
Changes:
- Adds flag parameters to wrapped AES and ECC key APIs.
- Uses SDK attestation flags and shares the legacy spelling alias.
- Adds regression tests and updates usage documentation.
| File | Description |
|---|---|
| wolfssl/wolfcrypt/port/silabs/silabs_shim.h | Models SDK attestation flags. |
| wolfssl/wolfcrypt/port/silabs/silabs_ecc.h | Exposes the legacy flag alias. |
| wolfssl/wolfcrypt/port/silabs/silabs_cryptocb.h | Updates API signatures and flag documentation. |
| wolfcrypt/test/test.c | Adds wrapped-key and attestation tests. |
| wolfcrypt/src/port/silabs/silabs_key.c | Applies caller flags and SDK attestation flags. |
| wolfcrypt/src/port/silabs/silabs_ecc.c | Removes the relocated compatibility alias. |
| wolfcrypt/src/port/silabs/README.md | Documents flag matching and key usage. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
1889441 to
c9a2692
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11687
Scan targets checked: wolfcrypt-port-bugs, wolfssl-src, wolfssl-bugs
Coverage: 6 of 6 in-scope changed file(s) opened by the reviewer
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite

The SiLabs wrapped-key APIs now take the SE key flags, which the Secure Element requires to match the flags the key was wrapped with, so wrapped keys can sign and application-wrapped keys can be bound. The attestation key binding now uses the SDK's flags. Validated on an EFR32FG25.
Fixes #11685
Fixes #11686