<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: Programming the attestation key</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Programming-the-attestation-key/m-p/905030#M136565</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Jamesbone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am from hirain company in China, and our company is already made NDA with NXP,&amp;nbsp;&lt;/P&gt;&lt;P&gt;and for some questions, our FAE also cannot give me correct answers, and he&amp;nbsp;let me to try to ask questions in community.&lt;/P&gt;&lt;P&gt;And now i have document "Security Reference Manual for i.MX&amp;nbsp;8DualXPlus/8QuadXPlus Application Processors" and&lt;/P&gt;&lt;P&gt;document "i.MX Android™ Security User's Guide".&lt;/P&gt;&lt;P&gt;But i cannot find answers to my questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you give me the security manual document name? so that i can ask FAE to share the doc to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 May 2019 00:30:46 GMT</pubDate>
    <dc:creator>zhongyue_li</dc:creator>
    <dc:date>2019-05-09T00:30:46Z</dc:date>
    <item>
      <title>Programming the attestation key</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Programming-the-attestation-key/m-p/905028#M136563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear NXP engineer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to read document named "I.MX_Android_Security_User_Guide.pdf"&lt;/P&gt;&lt;P&gt;Following is the content mentioned in the doc.&lt;/P&gt;&lt;P&gt;3.3.6 Programming the attestation key&lt;BR /&gt;Attestation key is programmed in U-Boot. The keystore key attestation aims to provide a way to strongly determine if an&lt;BR /&gt;asymmetric key pair is hardware-backed, what the properties of the key are, and what constraints are applied to its usage.Google provides the attestation "keybox", which contains private keys (RSA and ECDSA) and the corresponding certificate chains to partners from the Android Partner Front End (APFE). After retrieving the "keybox" from Google, you need to parsethe "keybox", provision the keys and certificates to secure storage. Both keys and certificates should be encoded with Distinguished Encoding Rules (DER).&lt;BR /&gt;Fastboot commands are provided to provision the attestation keys and certificates. Make sure that the secure storage is&lt;BR /&gt;properly initialized for Trusty OS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Referring to above content,&lt;/P&gt;&lt;P&gt;I have two questions, could you help to check them?&lt;/P&gt;&lt;P&gt;1. Where is the secure storage mentioned in above content?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; the attestation key will be stored in this secure storage?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;How are the attestation keys used after provision?&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;Have a nice day.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2019 14:47:38 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Programming-the-attestation-key/m-p/905028#M136563</guid>
      <dc:creator>zhongyue_li</dc:creator>
      <dc:date>2019-05-08T14:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Programming the attestation key</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Programming-the-attestation-key/m-p/905029#M136564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to access the security reference Manual to get the answer, but this manual it is under NDA, and you need to contact your local FAE or sales,&amp;nbsp; and ask for the security manual, they will help to provide it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a nice day&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2019 16:47:04 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Programming-the-attestation-key/m-p/905029#M136564</guid>
      <dc:creator>jamesbone</dc:creator>
      <dc:date>2019-05-08T16:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Programming the attestation key</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Programming-the-attestation-key/m-p/905030#M136565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Jamesbone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am from hirain company in China, and our company is already made NDA with NXP,&amp;nbsp;&lt;/P&gt;&lt;P&gt;and for some questions, our FAE also cannot give me correct answers, and he&amp;nbsp;let me to try to ask questions in community.&lt;/P&gt;&lt;P&gt;And now i have document "Security Reference Manual for i.MX&amp;nbsp;8DualXPlus/8QuadXPlus Application Processors" and&lt;/P&gt;&lt;P&gt;document "i.MX Android™ Security User's Guide".&lt;/P&gt;&lt;P&gt;But i cannot find answers to my questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you give me the security manual document name? so that i can ask FAE to share the doc to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2019 00:30:46 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Programming-the-attestation-key/m-p/905030#M136565</guid>
      <dc:creator>zhongyue_li</dc:creator>
      <dc:date>2019-05-09T00:30:46Z</dc:date>
    </item>
  </channel>
</rss>

