<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using HSE APIs from OP-TEE Trusted Application on S32G3 (BSP 43) in S32G</title>
    <link>https://community.nxp.com/t5/S32G/Using-HSE-APIs-from-OP-TEE-Trusted-Application-on-S32G3-BSP-43/m-p/2098767#M13484</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/234498"&gt;@yashasdu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your post.&lt;/P&gt;
&lt;P&gt;The whole features/examples that are supported in BSP43 for OPTEE is detailed described in chapter 26 of BSP43 UM for S32G3.&lt;/P&gt;
&lt;P&gt;Currently, the user space application would take use of the OPTEE driver in Linux to communicate with TEE, and the APIs in TEE support communicating with HSE directly&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chenyin_h_0-1747381089464.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/338180iC69F1FE129312804/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chenyin_h_0-1747381089464.png" alt="chenyin_h_0-1747381089464.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;chenyin_h_0-1747381089464.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;BR&lt;/P&gt;
&lt;P&gt;Chenyin&lt;/P&gt;</description>
    <pubDate>Fri, 16 May 2025 07:42:09 GMT</pubDate>
    <dc:creator>chenyin_h</dc:creator>
    <dc:date>2025-05-16T07:42:09Z</dc:date>
    <item>
      <title>Using HSE APIs from OP-TEE Trusted Application on S32G3 (BSP 43)</title>
      <link>https://community.nxp.com/t5/S32G/Using-HSE-APIs-from-OP-TEE-Trusted-Application-on-S32G3-BSP-43/m-p/2097753#M13468</link>
      <description>&lt;P class=""&gt;Hi,&lt;/P&gt;&lt;P class=""&gt;I'm working on a custom S32G3 board running BSP 43 with OP-TEE initialized and HSE support available. I would like to offload cryptographic operations (e.g., AES, RSA, SHA) to the HSE, but execute them securely through an OP-TEE Trusted Application (TA).&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;My intended flow:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;A Linux user-space application invokes a crypto operation via the OP-TEE Client API.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;The call is handled by a Trusted Application in OP-TEE.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;The TA performs the cryptographic operation using HSE and returns the result to the normal world.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;STRONG&gt;My questions:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P class=""&gt;Are there any reference examples or existing OP-TEE TAs that use HSE APIs from within the secure world?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;What is the recommended way to invoke HSE API calls inside an OP-TEE TA?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Does OP-TEE need special integration to access HSE drivers, or is this already handled by BSP 43?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Is the pkcs11-hse repo a good starting point, or is there a simpler example for direct HSE usage in a TA?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;Any advice or references on how to structure this setup would be greatly appreciated.&lt;/P&gt;&lt;P class=""&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 05:08:54 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/Using-HSE-APIs-from-OP-TEE-Trusted-Application-on-S32G3-BSP-43/m-p/2097753#M13468</guid>
      <dc:creator>yashasdu</dc:creator>
      <dc:date>2025-05-15T05:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using HSE APIs from OP-TEE Trusted Application on S32G3 (BSP 43)</title>
      <link>https://community.nxp.com/t5/S32G/Using-HSE-APIs-from-OP-TEE-Trusted-Application-on-S32G3-BSP-43/m-p/2098767#M13484</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/234498"&gt;@yashasdu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your post.&lt;/P&gt;
&lt;P&gt;The whole features/examples that are supported in BSP43 for OPTEE is detailed described in chapter 26 of BSP43 UM for S32G3.&lt;/P&gt;
&lt;P&gt;Currently, the user space application would take use of the OPTEE driver in Linux to communicate with TEE, and the APIs in TEE support communicating with HSE directly&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chenyin_h_0-1747381089464.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/338180iC69F1FE129312804/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chenyin_h_0-1747381089464.png" alt="chenyin_h_0-1747381089464.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;chenyin_h_0-1747381089464.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;BR&lt;/P&gt;
&lt;P&gt;Chenyin&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2025 07:42:09 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/Using-HSE-APIs-from-OP-TEE-Trusted-Application-on-S32G3-BSP-43/m-p/2098767#M13484</guid>
      <dc:creator>chenyin_h</dc:creator>
      <dc:date>2025-05-16T07:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Using HSE APIs from OP-TEE Trusted Application on S32G3 (BSP 43)</title>
      <link>https://community.nxp.com/t5/S32G/Using-HSE-APIs-from-OP-TEE-Trusted-Application-on-S32G3-BSP-43/m-p/2119906#M13803</link>
      <description>&lt;P&gt;Thank you for the response.&lt;/P&gt;&lt;P&gt;I’ve reviewed Chapter 26 of the BSP43 UM, and I understand that OP-TEE TAs can communicate with HSE directly using supported APIs.&lt;/P&gt;&lt;P&gt;To clarify my current use case:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;I need to generate and store keys inside the HSE key catalog.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;From within an OP-TEE Trusted Application, I need to reference those keys using &lt;STRONG&gt;HSE key handles&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Then, I need to perform encryption/decryption operations using those key handles via the HSE Crypto Engine.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Given that, I’d like to clarify the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Do the standard OP-TEE crypto APIs (e.g., TEE_AEEncryptFinal, TEE_AllocateTransientObject, etc.) automatically route cryptographic operations to the HSE engine?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If not, is it required to &lt;STRONG&gt;manually construct HSE service descriptors&lt;/STRONG&gt; (e.g., HSE_SRV_ID_IMPORT_KEY, HSE_SRV_ID_SYM_CIPHER) and invoke the corresponding APIs from inside the TA?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Is there a reference or documented method in BSP43 that shows how a TA can build and submit HSE service descriptors?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Specifically, how can a TA access and use key handles for encryption/decryption via HSE? Are there APIs or interface layers exposed for this purpose?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there particular headers or secure-side libraries I should include in the TA to enable direct use of HSE service APIs?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any guidance or examples related to this HSE + OP-TEE integration, especially involving key handle usage inside the TEE, would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;Yashas&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 06:00:08 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32G/Using-HSE-APIs-from-OP-TEE-Trusted-Application-on-S32G3-BSP-43/m-p/2119906#M13803</guid>
      <dc:creator>yashasdu</dc:creator>
      <dc:date>2025-06-20T06:00:08Z</dc:date>
    </item>
  </channel>
</rss>

