<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: KEK to wrap asymmetric keys in Secure Authentication</title>
    <link>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645011#M1236</link>
    <description>&lt;P&gt;I'd take a look at AN12413, Figure 5 and section 3.2.9.&amp;nbsp; I'm not sure which middleware calls implement that diagram, but it looks like it is certainly possible to upload a key securely.&lt;/P&gt;</description>
    <pubDate>Thu, 04 May 2023 21:07:49 GMT</pubDate>
    <dc:creator>msjcard</dc:creator>
    <dc:date>2023-05-04T21:07:49Z</dc:date>
    <item>
      <title>KEK to wrap asymmetric keys</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1644768#M1235</link>
      <description>&lt;P&gt;There's some indication that a customer can use a KEK to wrap keys&lt;/P&gt;
&lt;P&gt;I "inject" into the SE05x keystore. Unfortunately, injecting keys into the part is non-compliant for this customer. Instead, can they use a KEK to wrap asymmetric keys that they generate on the SE05x using the sss_key_store_generate_key() API?&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 14:44:24 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1644768#M1235</guid>
      <dc:creator>todd_nuzum</dc:creator>
      <dc:date>2023-05-04T14:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: KEK to wrap asymmetric keys</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645011#M1236</link>
      <description>&lt;P&gt;I'd take a look at AN12413, Figure 5 and section 3.2.9.&amp;nbsp; I'm not sure which middleware calls implement that diagram, but it looks like it is certainly possible to upload a key securely.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 21:07:49 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645011#M1236</guid>
      <dc:creator>msjcard</dc:creator>
      <dc:date>2023-05-04T21:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: KEK to wrap asymmetric keys</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645126#M1237</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/85136"&gt;@todd_nuzum&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KEK is just available when you write&amp;nbsp;SymmKey , but to cover all the secure objects injection, you may use the external import method, as mentioned by&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/165840"&gt;@msjcard&lt;/a&gt;&amp;nbsp;.&amp;nbsp; We have a demo to demonstrate how to &lt;SPAN&gt;prepare a complete raw APDU for that purpose, please kindly refer to&amp;nbsp;simw-top/doc/demos/se05x/se05x_ImportExternalObjectPrepare/Readme.html for details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day,&lt;BR /&gt;Kan&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;BR /&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 02:14:49 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645126#M1237</guid>
      <dc:creator>Kan_Li</dc:creator>
      <dc:date>2023-05-05T02:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: KEK to wrap asymmetric keys</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645393#M1238</link>
      <description>Is it possible to use an AES128 KEK to wrap RSA keys generated within the SE? I'm not allowed to generate the RSA keys outside of the SE and then import them into the SE.</description>
      <pubDate>Fri, 05 May 2023 09:51:51 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645393#M1238</guid>
      <dc:creator>TonyMo</dc:creator>
      <dc:date>2023-05-05T09:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: KEK to wrap asymmetric keys</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645857#M1239</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/213597"&gt;@TonyMo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KEK is not a valid option for&amp;nbsp;WriteRSAKey APDU command, for such use case, you have to use the external import&amp;nbsp;mechanism, please kindly refer to "3.2.9 Secure Object external import" in&amp;nbsp;&lt;A href="https://www.nxp.com/webapp/Download?colCode=AN12543" target="_blank"&gt;https://www.nxp.com/webapp/Download?colCode=AN12543&lt;/A&gt;&amp;nbsp;for details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day,&lt;BR /&gt;Kan&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;BR /&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 May 2023 04:08:46 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645857#M1239</guid>
      <dc:creator>Kan_Li</dc:creator>
      <dc:date>2023-05-06T04:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: KEK to wrap asymmetric keys</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645931#M1240</link>
      <description>Unfortunately "3.2.9 Secure Object External Import" does not satisfy design requirements for me. The secure object must be generated inside of the security entity. Thank you for answering my question.</description>
      <pubDate>Sat, 06 May 2023 10:56:11 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1645931#M1240</guid>
      <dc:creator>TonyMo</dc:creator>
      <dc:date>2023-05-06T10:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: KEK to wrap asymmetric keys</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1646029#M1241</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/213597"&gt;@TonyMo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SE050 has an APDU command to generate RSA key pair inside, but there is no KEK option, which is for symmetric keys indeed, while you may set up the policy for the RSA key pair, so that only the specific user may access this secure object and of course the private kay can not be fetched by any means. You may refer to&amp;nbsp; "4.7.1.2 WriteRSAKey" and "3.7 Policies" in AN12543 for more details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day,&lt;BR /&gt;Kan&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;BR /&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 01:53:32 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1646029#M1241</guid>
      <dc:creator>Kan_Li</dc:creator>
      <dc:date>2023-05-08T01:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: KEK to wrap asymmetric keys</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1646322#M1242</link>
      <description>This is excellent information. This should satisfy my design requirement. Thank you for your help Kan.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Tony</description>
      <pubDate>Mon, 08 May 2023 10:05:50 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/KEK-to-wrap-asymmetric-keys/m-p/1646322#M1242</guid>
      <dc:creator>TonyMo</dc:creator>
      <dc:date>2023-05-08T10:05:50Z</dc:date>
    </item>
  </channel>
</rss>

