Commit Graph
4 Commits
Author SHA1 Message Date
Nick Dunklee 874f0c9ff8 Minor ifdef rename as it now covers more than just Ed25519
for hardware encryption. Now `USE_CC310_HW_CRYPTO`
2026-07-16 21:44:35 -06:00
Nick Dunklee a9d2574039 feat: add more crypto
After soaking for a bit on the adverts without issue on multiple nodes,
I added more hardware crypto.

Supported nodes is unchanged in this PR addition, but if others can verify,
they can easily be added.

Some info on the CC310: https://docs.nordicsemi.com/r/bundle/ps_nrf9151/page/cryptocell.html

**Added:**

- AES-128 packet encryption/decryption now use hardware crypto
- HMAC-SHA-256 authentication now uses hardware crypto
- ACK hash computation and channel ID derivation now use hardware crypto
- RNG (random number generator) now uses hardware crypto rather than
  radio noise + weak software RNG (which can have issues if there's
  no surrounding radio noise.) NIST SP 800-90B certified.
  - Runs hardware self-tests on startup
  - Runs continuous health tests during operation
  - Uses thermal noise/shot noise for randomness

**Unchanged:**

- calcSharedSecret remains software - it would be a split hw/sw solution
  and added complexity for likely not a lot of gains. This only happens
  when establishing a new contact, so not too frequent to be worth it.
- ed25519_create_keypair remains software. This is only called when a
  node is first initialized. It does use the hardware RNG change, however,
  so better randomization.

Tested on (so far):

- Heltec t096

Build test on:
- Heltec t096 companion ble
- t1000e companion ble
- RAK 4631 repeater
- RAK 3401 companion BLE
- Heltec v3 companion wifi
2026-07-14 08:35:27 -06:00
Scott Powell 466caebd9a * Terminal Chat: "set ..." commands, save to "node_prefs" file, consistent with the other firmwares 2025-02-03 13:56:57 +11:00
Scott Powell 6c7efdd0f6 Initial commit 2025-01-13 14:07:48 +11:00