<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックHow to decrypt and use a black key?</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/How-to-decrypt-and-use-a-black-key/m-p/675113#M104093</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;imx 6ul‌&amp;nbsp;caam&amp;nbsp;cryptography&amp;nbsp;secure memory&amp;nbsp;&lt;A href="https://community.nxp.com/t5/tag/black key/tg-p"&gt;#black key&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Suppose that, we have following scenario:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Generate some random 256 bit key, and treat as red key.&lt;/LI&gt;&lt;LI&gt;Create an encryption device mapper (e.g. root file system) with red key.&lt;/LI&gt;&lt;LI&gt;Encapsulate this red key into red blob and store in no-volatile memory.&lt;/LI&gt;&lt;LI&gt;Decapsulate red blob to obtain red key and store in&amp;nbsp;secure memory.&lt;/LI&gt;&lt;LI&gt;Cover the red key to a black key and store in secure memory.&lt;/LI&gt;&lt;LI&gt;Use the covered key to decrypt something - in particular pass this key as keyfile to the plain dm-crypt (volume with encrypted root file system.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using i.MX6 UL, Linux version 4.1.15-6UL ( with CONFIG_CRYPTO_DEV_FSL_CAAM_SM_TEST=y) , CAAM read to use. There is know how to accomplish the first 5 points.The point 6 in the scenario is the blocker. I&amp;nbsp;try to uncover the blackened key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a&amp;nbsp;starting point I modified the &lt;EM&gt;sm_test.c&lt;/EM&gt; and &lt;EM&gt;sm_store.c&lt;/EM&gt; from &lt;EM&gt;drivers/crypto/caam:&lt;/EM&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Just focused on 256 bit case.&lt;/LI&gt;&lt;LI&gt;Covered (blacken/encrypt key) loaded clear key and obtain black key.&lt;/LI&gt;&lt;LI&gt;Allocated secured memory for 256 bit key slot for uncovering process.&lt;/LI&gt;&lt;LI&gt;Uncover (whiten) black key and store it in the key slot. ( based on&amp;nbsp;blacken_key_jobdesc function )&lt;/LI&gt;&lt;LI&gt;Read, display and compare the clear key with the uncovered key.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[ 2.078030] platform caam_sm: blkkey_ex: 8 keystore units available&lt;BR /&gt;[ 2.084656] platform caam_sm: 256-bit clear key:&lt;BR /&gt;[ 2.089487] platform caam_sm: [0000] 00 01 02 03 04 0f 06 07&lt;BR /&gt;[ 2.095196] platform caam_sm: [0008] 08 09 0a 0b 0c 0d 0e 0f&lt;BR /&gt;[ 2.101254] platform caam_sm: [0016] 10 11 12 13 14 15 16 17&lt;BR /&gt;[ 2.107062] platform caam_sm: [0024] 18 19 1a 1b 1c 1d 1e 1f&lt;BR /&gt;[ 2.140432] platform caam_sm: &lt;STRONG&gt;256-bit black key:&lt;/STRONG&gt;&lt;BR /&gt;[ 2.145091] platform caam_sm: [0000] f7 7f ef d3 dd 15 45 34&lt;BR /&gt;[ 2.150823] platform caam_sm: [0008] 84 8d 39 3d 85 fe e7 69&lt;BR /&gt;[ 2.156556] platform caam_sm: [0016] 5c 54 c5 27 1c 36 86 49&lt;BR /&gt;[ 2.162255] platform caam_sm: [0024] d0 6d 34 c2 35 6f 6a a7&lt;BR /&gt;[ 2.195698] platform caam_sm: &lt;STRONG&gt;256-bit uncover black key:&lt;/STRONG&gt;&lt;BR /&gt;[ 2.201050] platform caam_sm: [0000] f7 7f ef d3 dd 15 45 34&lt;BR /&gt;[ 2.206781] platform caam_sm: [0008] 84 8d 39 3d 85 fe e7 69&lt;BR /&gt;[ 2.212479] platform caam_sm: [0016] 5c 54 c5 27 1c 36 86 49&lt;BR /&gt;[ 2.218210] platform caam_sm: [0024] d0 6d 34 c2 35 6f 6a a7&lt;BR /&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The uncovering procedure work bad...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;General questions are:&lt;/P&gt;&lt;P&gt;Is my thinking process it&amp;nbsp;correct?&lt;/P&gt;&lt;P&gt;It is possible to read and display uncovered key?&lt;/P&gt;&lt;P&gt;Does anybody has working caam job&amp;nbsp;descriptor for this uncovering process?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;Robert Lubaś&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Jun 2017 15:48:07 GMT</pubDate>
    <dc:creator>robertlubas</dc:creator>
    <dc:date>2017-06-27T15:48:07Z</dc:date>
    <item>
      <title>How to decrypt and use a black key?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/How-to-decrypt-and-use-a-black-key/m-p/675113#M104093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;imx 6ul‌&amp;nbsp;caam&amp;nbsp;cryptography&amp;nbsp;secure memory&amp;nbsp;&lt;A href="https://community.nxp.com/t5/tag/black key/tg-p"&gt;#black key&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Suppose that, we have following scenario:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Generate some random 256 bit key, and treat as red key.&lt;/LI&gt;&lt;LI&gt;Create an encryption device mapper (e.g. root file system) with red key.&lt;/LI&gt;&lt;LI&gt;Encapsulate this red key into red blob and store in no-volatile memory.&lt;/LI&gt;&lt;LI&gt;Decapsulate red blob to obtain red key and store in&amp;nbsp;secure memory.&lt;/LI&gt;&lt;LI&gt;Cover the red key to a black key and store in secure memory.&lt;/LI&gt;&lt;LI&gt;Use the covered key to decrypt something - in particular pass this key as keyfile to the plain dm-crypt (volume with encrypted root file system.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using i.MX6 UL, Linux version 4.1.15-6UL ( with CONFIG_CRYPTO_DEV_FSL_CAAM_SM_TEST=y) , CAAM read to use. There is know how to accomplish the first 5 points.The point 6 in the scenario is the blocker. I&amp;nbsp;try to uncover the blackened key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a&amp;nbsp;starting point I modified the &lt;EM&gt;sm_test.c&lt;/EM&gt; and &lt;EM&gt;sm_store.c&lt;/EM&gt; from &lt;EM&gt;drivers/crypto/caam:&lt;/EM&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Just focused on 256 bit case.&lt;/LI&gt;&lt;LI&gt;Covered (blacken/encrypt key) loaded clear key and obtain black key.&lt;/LI&gt;&lt;LI&gt;Allocated secured memory for 256 bit key slot for uncovering process.&lt;/LI&gt;&lt;LI&gt;Uncover (whiten) black key and store it in the key slot. ( based on&amp;nbsp;blacken_key_jobdesc function )&lt;/LI&gt;&lt;LI&gt;Read, display and compare the clear key with the uncovered key.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[ 2.078030] platform caam_sm: blkkey_ex: 8 keystore units available&lt;BR /&gt;[ 2.084656] platform caam_sm: 256-bit clear key:&lt;BR /&gt;[ 2.089487] platform caam_sm: [0000] 00 01 02 03 04 0f 06 07&lt;BR /&gt;[ 2.095196] platform caam_sm: [0008] 08 09 0a 0b 0c 0d 0e 0f&lt;BR /&gt;[ 2.101254] platform caam_sm: [0016] 10 11 12 13 14 15 16 17&lt;BR /&gt;[ 2.107062] platform caam_sm: [0024] 18 19 1a 1b 1c 1d 1e 1f&lt;BR /&gt;[ 2.140432] platform caam_sm: &lt;STRONG&gt;256-bit black key:&lt;/STRONG&gt;&lt;BR /&gt;[ 2.145091] platform caam_sm: [0000] f7 7f ef d3 dd 15 45 34&lt;BR /&gt;[ 2.150823] platform caam_sm: [0008] 84 8d 39 3d 85 fe e7 69&lt;BR /&gt;[ 2.156556] platform caam_sm: [0016] 5c 54 c5 27 1c 36 86 49&lt;BR /&gt;[ 2.162255] platform caam_sm: [0024] d0 6d 34 c2 35 6f 6a a7&lt;BR /&gt;[ 2.195698] platform caam_sm: &lt;STRONG&gt;256-bit uncover black key:&lt;/STRONG&gt;&lt;BR /&gt;[ 2.201050] platform caam_sm: [0000] f7 7f ef d3 dd 15 45 34&lt;BR /&gt;[ 2.206781] platform caam_sm: [0008] 84 8d 39 3d 85 fe e7 69&lt;BR /&gt;[ 2.212479] platform caam_sm: [0016] 5c 54 c5 27 1c 36 86 49&lt;BR /&gt;[ 2.218210] platform caam_sm: [0024] d0 6d 34 c2 35 6f 6a a7&lt;BR /&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The uncovering procedure work bad...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;General questions are:&lt;/P&gt;&lt;P&gt;Is my thinking process it&amp;nbsp;correct?&lt;/P&gt;&lt;P&gt;It is possible to read and display uncovered key?&lt;/P&gt;&lt;P&gt;Does anybody has working caam job&amp;nbsp;descriptor for this uncovering process?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;Robert Lubaś&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jun 2017 15:48:07 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/How-to-decrypt-and-use-a-black-key/m-p/675113#M104093</guid>
      <dc:creator>robertlubas</dc:creator>
      <dc:date>2017-06-27T15:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to decrypt and use a black key?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/How-to-decrypt-and-use-a-black-key/m-p/675114#M104094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Sorry, but the information you are requesting is treated as confidential info at this time and requires a signed NDA (Non-Disclosure Agreement). Naturally, we cannot discuss this with you in public anyway, this requires to be handled as a Service Request (SR). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://www.nxp.com/support/support:SUPPORTHOME?tid=sbmenu" title="http://www.nxp.com/support/support:SUPPORTHOME?tid=sbmenu"&gt;Support|NXP&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a great day,&lt;BR /&gt;Yuri&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note: If this post answers your question, please click the Correct Answer button. Thank you!&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.nxp.com/docs/DOC-334096"&gt;Example code to protect user keys and sensitive data with black key and blob on i.MX6UL platform&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jun 2017 09:49:57 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/How-to-decrypt-and-use-a-black-key/m-p/675114#M104094</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2017-06-29T09:49:57Z</dc:date>
    </item>
  </channel>
</rss>

