<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restriction of access Manager in Secure Authentication</title>
    <link>https://community.nxp.com/t5/Secure-Authentication/Restriction-of-access-Manager/m-p/1573832#M1029</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;a "broken connection" would happen when e.g. the access manager creates a secure session (PlatformSCP authentication) and then another process circumvents the access manager and sends a command to the SE. This would break the established secure channel (all commands are cryptographically chained) and the following communication would not succeed until a new authentication happens. Restarting the access manager re-authenticates the IC.&lt;/P&gt;
&lt;P&gt;If there is a chance seen for accesses outside the access manager which may break the secure channel, then a client service which periodically tries to communicate over the access manager with the SE can detect any secure channel breakdown.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;BR /&gt;Michael&lt;/P&gt;</description>
    <pubDate>Thu, 22 Dec 2022 16:40:13 GMT</pubDate>
    <dc:creator>michaelsalfer</dc:creator>
    <dc:date>2022-12-22T16:40:13Z</dc:date>
    <item>
      <title>Restriction of access Manager</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/Restriction-of-access-Manager/m-p/1572893#M1027</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;While going through&amp;nbsp;Restrictions of Access manager, we need help to understand more on below restriction of access manager.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;"The Access Manager does not attempt to re-establish a broken connection to the SE05x. To recognize and recover from a broken connection, a system integrator must monitor failure to communicate to the Secure Element by the client processes. As and if required the Access Manager must be restarted and the affected client processes must reconnect to the Access Manager."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;1.&lt;EM&gt;&amp;nbsp;"Broken connection":&lt;/EM&gt; what are&amp;nbsp;scenarios this could happen?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2. "system integrator " does&amp;nbsp;&lt;/EM&gt;&lt;I&gt;it mean&lt;/I&gt;&amp;nbsp;we need have separate daemon just to monitor&amp;nbsp;communication&amp;nbsp;failures of&amp;nbsp;clients?&lt;I&gt;&lt;BR /&gt;&lt;BR /&gt;3."&lt;EM&gt;Access Manager must be restarted"&amp;nbsp;&lt;/EM&gt;&lt;/I&gt;what is guarantee that restarting access Manager will fix the broken connection?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 05:32:46 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/Restriction-of-access-Manager/m-p/1572893#M1027</guid>
      <dc:creator>vishwanchandapu</dc:creator>
      <dc:date>2022-12-21T05:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Restriction of access Manager</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/Restriction-of-access-Manager/m-p/1573832#M1029</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;a "broken connection" would happen when e.g. the access manager creates a secure session (PlatformSCP authentication) and then another process circumvents the access manager and sends a command to the SE. This would break the established secure channel (all commands are cryptographically chained) and the following communication would not succeed until a new authentication happens. Restarting the access manager re-authenticates the IC.&lt;/P&gt;
&lt;P&gt;If there is a chance seen for accesses outside the access manager which may break the secure channel, then a client service which periodically tries to communicate over the access manager with the SE can detect any secure channel breakdown.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;BR /&gt;Michael&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 16:40:13 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/Restriction-of-access-Manager/m-p/1573832#M1029</guid>
      <dc:creator>michaelsalfer</dc:creator>
      <dc:date>2022-12-22T16:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Restriction of access Manager</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/Restriction-of-access-Manager/m-p/1575978#M1079</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/165803"&gt;@michaelsalfer&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the reply,&lt;BR /&gt;&lt;BR /&gt;Thats means as long as if we&amp;nbsp;restrict access of secure element only through " Access Manager" chances for communication breakdown is less.?&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Vishwa&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 07:20:08 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/Restriction-of-access-Manager/m-p/1575978#M1079</guid>
      <dc:creator>vishwanchandapu</dc:creator>
      <dc:date>2023-01-02T07:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Restriction of access Manager</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/Restriction-of-access-Manager/m-p/1579138#M1103</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/155293"&gt;@vishwanchandapu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, your understanding is correct!&amp;nbsp;&lt;SPAN&gt;When using the AM then, yes, the chance for breakdown for sure is much lower - as the AM was designed to prevent that.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day,&lt;BR /&gt;Kan&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;BR /&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 08:51:00 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/Restriction-of-access-Manager/m-p/1579138#M1103</guid>
      <dc:creator>Kan_Li</dc:creator>
      <dc:date>2023-01-09T08:51:00Z</dc:date>
    </item>
  </channel>
</rss>

