<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>S32 SDKのトピックRe: CSEc for storing keys</title>
    <link>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692596#M88</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Veronica,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;This is the information I was looking for. Its very clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need couple of clarifications if you don't mind:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Assume we are going to release 100 products with S32K144 MCU. Should we be programming same security keys(to &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;CSEc module) in all 100 products ?&lt;/P&gt;&lt;P&gt;2. Assume product has Application processor(Qualcomm snapdragon) and S32K144 MCU communicating over UART. &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;How I can use CSEc module of S32K144 to validate messages received from application processor and vice versa.&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. When messages are exchanged between two S32K144 EVB over CAN. How CAN message is protected from &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;intruders. How CSEc module works in this case ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Aug 2017 12:00:42 GMT</pubDate>
    <dc:creator>mrajanna</dc:creator>
    <dc:date>2017-08-03T12:00:42Z</dc:date>
    <item>
      <title>CSEc for storing keys</title>
      <link>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692594#M86</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can someone please explain in detail summary what below functions will do in csec_keyconfig example project.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/* Initialize Flash for CSEc operation */&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;initFlashForCsecOperation();&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/* Load the MASTER_ECU key with a known value, which will be used as Authorization key (a secret key known by the application in order to configure other user keys) */&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;setAuthKey();&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/* Load the selected key First load =&amp;gt; counter == 1 */&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;keyLoaded = loadKey(CSEC_KEY_1, key, 1);&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;CSEC_DRV_EncryptECB();&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sorry for asking this questions blindly. Though in debug mode by single stepping the source code, I could understand it theoretically.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But&amp;nbsp;I want to program my own security keys to CSEc module in our products before releasing it to market.&lt;/P&gt;&lt;P&gt;So it would be of great help if someone explains it with S32K144 context and how it works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2017 07:20:23 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692594#M86</guid>
      <dc:creator>mrajanna</dc:creator>
      <dc:date>2017-08-03T07:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: CSEc for storing keys</title>
      <link>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692595#M87</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mohan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find below an explanation for each of the functions mentioned by you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;initFlashForCsecOperation(void)&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;checks if the Flash was partitioned for CSEc operation;&lt;/LI&gt;&lt;LI&gt;if not, partition the Flash and select the number of user keys - &lt;EM&gt;FLASH_DRV_DEFlashPartition(&amp;amp;flashSSDConfig, 0x2, 0x4, 0x3, false, true)&lt;/EM&gt;;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- the 0x3 parameter specifies that there will be 24 available user keys; for more details, please see the documentation of the &lt;EM&gt;FLASH_DRV_DEFlashPartition&lt;/EM&gt; function.&lt;BR /&gt; &lt;BR /&gt;&lt;STRONG&gt;setAuthKey(void)&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;this function sets the &lt;EM&gt;MASTER_ECU&lt;/EM&gt; key with the value of &lt;EM&gt;g_authIdKey&lt;/EM&gt; (in the &lt;EM&gt;csec_utils.c&lt;/EM&gt; source file);&lt;/LI&gt;&lt;LI&gt;in order to be able to configure a non-volatile key, a secret (the value of the key) must be known; in this case, we will use the &lt;EM&gt;MASTER_ECU&lt;/EM&gt; key (which can be used for updating any of the keys) as our secret when setting up the user keys;&lt;/LI&gt;&lt;LI&gt;this function will compute the M1-M3 values according to the SHE specification and then load the key by passing the computed values to the &lt;EM&gt;CSEC_DRV_LoadKey&lt;/EM&gt; function;&lt;/LI&gt;&lt;LI&gt;in order to compute the values, the &lt;EM&gt;computeM1M2M3&lt;/EM&gt; function is used, receiving as first parameter &lt;EM&gt;g_emptyKey&lt;/EM&gt;, as the first time we load the MASTER_ECU key, coming from a clean state, the slot will be empty.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;loadKey(CSEC_KEY_1, key, 1)&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;this function will load the first user key with the value specified by the &lt;EM&gt;key&lt;/EM&gt; parameter;&lt;/LI&gt;&lt;LI&gt;the last parameter, the counter, needs to be incremented each time you update the key; the CSEc module will not update the key if the counter is &amp;lt;= the previous counter used when storing the key;&lt;/LI&gt;&lt;LI&gt;this function will also compute the M1-M3 values according to the SHE specification and then load the key by passing the computed values to the &lt;EM&gt;CSEC_DRV_LoadKey&lt;/EM&gt; function;&lt;/LI&gt;&lt;LI&gt;the first parameter of &lt;EM&gt;computeM1M2M3&lt;/EM&gt; will be &lt;EM&gt;g_authIdKey&lt;/EM&gt;, as we are using the value of&amp;nbsp;&lt;EM&gt;MASTER_ECU&lt;/EM&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;as the secret needed when updating the key.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CSEC_DRV_EncryptECB(CSEC_KEY_1, plainText, 16, cipherText)&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;this function will encrypt the &lt;EM&gt;plainText&lt;/EM&gt; using the user key loaded previously and output the result into the &lt;EM&gt;cipherText&lt;/EM&gt; parameter;&lt;/LI&gt;&lt;LI&gt;the plain text will be encrypted using AES-128 with the ECB mode of chaining.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note that if you plan to use another &lt;EM&gt;MASTER_ECU&lt;/EM&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;key&lt;/SPAN&gt;&lt;/SPAN&gt;, you should first erase the keys by updating the value of the&amp;nbsp;&lt;EM&gt;ERASE_ALL_KEYS&lt;/EM&gt;&amp;nbsp;macro to 1.&lt;BR /&gt;I hope this answers your question. If not, let me know and I will go into more detail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;Veronica&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2017 10:52:42 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692595#M87</guid>
      <dc:creator>veronicavelciu</dc:creator>
      <dc:date>2017-08-03T10:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: CSEc for storing keys</title>
      <link>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692596#M88</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Veronica,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;This is the information I was looking for. Its very clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need couple of clarifications if you don't mind:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Assume we are going to release 100 products with S32K144 MCU. Should we be programming same security keys(to &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;CSEc module) in all 100 products ?&lt;/P&gt;&lt;P&gt;2. Assume product has Application processor(Qualcomm snapdragon) and S32K144 MCU communicating over UART. &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;How I can use CSEc module of S32K144 to validate messages received from application processor and vice versa.&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. When messages are exchanged between two S32K144 EVB over CAN. How CAN message is protected from &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;intruders. How CSEc module works in this case ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2017 12:00:42 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692596#M88</guid>
      <dc:creator>mrajanna</dc:creator>
      <dc:date>2017-08-03T12:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: CSEc for storing keys</title>
      <link>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692597#M89</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mohan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately I cannot answer the three questions, as it depends on the application and how exactly it uses the keys. These questions should probably be answered by a security architect, having a complete overview of the system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In terms of CSEc features which could be used for providing confidentiality and authentication, the module provides:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;AES-128 encryption using ECB and CBC chaining modes&lt;/LI&gt;&lt;LI&gt;AES-128 CMAC calculation and authentication&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Veronica&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2017 13:18:40 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692597#M89</guid>
      <dc:creator>veronicavelciu</dc:creator>
      <dc:date>2017-08-03T13:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: CSEc for storing keys</title>
      <link>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692598#M90</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Veronica,&lt;/P&gt;&lt;P&gt;Thanks for the reply. I shall investigate more from my side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From Data spec of S32K144, I only understand there is 512 KB of flash and 64 KB of system RAM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But from one of reference manual of S32K144, I got below screenshot which I am not able to interpret. Can you please provide more information if you can please ?&lt;/P&gt;&lt;P&gt;Referring to below screenshot, I know PRAM is of 128 Bytes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_1.png"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/14236i5D96BB866F11E38D/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_1.png" alt="pastedImage_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mohan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 08:43:45 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/692598#M90</guid>
      <dc:creator>mrajanna</dc:creator>
      <dc:date>2017-08-07T08:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: CSEc for storing keys</title>
      <link>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/1645903#M3067</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; ERC_KEY_UPDATE_ERROR occurs when I use setAuthKey to read the error bit. The manual explains ERC_KEY_UPDATE_ERROR. Example: key update authentication failed; for&lt;BR /&gt;LOAD_KEY : M3 =! M3* or UID is empty and AuthID isn't the same key slot, how can I determine the specific cause, I guess AuthID isn't the same key slot, how can I solve this problem.&lt;/P&gt;</description>
      <pubDate>Sat, 06 May 2023 07:55:50 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32-SDK/CSEc-for-storing-keys/m-p/1645903#M3067</guid>
      <dc:creator>ZEROOO</dc:creator>
      <dc:date>2023-05-06T07:55:50Z</dc:date>
    </item>
  </channel>
</rss>

