<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Secure Authenticationのトピックchange read policy for shared secret</title>
    <link>https://community.nxp.com/t5/Secure-Authentication/change-read-policy-for-shared-secret/m-p/1286207#M505</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to implement the mbedtls_ecdh_compute_shared with the SE050.&amp;nbsp;&lt;BR /&gt;You can find the implementation in the attached file. I followed more or less the implementation in ecdh_alt_ax.c, except that I only covered the case for&amp;nbsp;&lt;SPAN&gt;MBEDTLS_ECP_DP_SECP256R1.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now on the last function call which is&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;sss_key_store_get_key i get&amp;nbsp;SM_ERR_ACCESS_DENIED_BASED_ON_POLICY using session-less access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;According to the APDU spec (SE050 APDU Specification -&amp;nbsp;3.7.1.4 Table 11) symmetric keys do not have the policy object&amp;nbsp;POLICY_OBJ_ALLOW_READ but the implementation in the plug and trust MW in ecdh_alt_ax.c does read the shared secret anyways. (have not tried to run it though)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How can I read the key and write it to the mbedtls context?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Tue, 08 Jun 2021 12:49:27 GMT</pubDate>
    <dc:creator>ziml</dc:creator>
    <dc:date>2021-06-08T12:49:27Z</dc:date>
    <item>
      <title>change read policy for shared secret</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/change-read-policy-for-shared-secret/m-p/1286207#M505</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to implement the mbedtls_ecdh_compute_shared with the SE050.&amp;nbsp;&lt;BR /&gt;You can find the implementation in the attached file. I followed more or less the implementation in ecdh_alt_ax.c, except that I only covered the case for&amp;nbsp;&lt;SPAN&gt;MBEDTLS_ECP_DP_SECP256R1.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now on the last function call which is&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;sss_key_store_get_key i get&amp;nbsp;SM_ERR_ACCESS_DENIED_BASED_ON_POLICY using session-less access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;According to the APDU spec (SE050 APDU Specification -&amp;nbsp;3.7.1.4 Table 11) symmetric keys do not have the policy object&amp;nbsp;POLICY_OBJ_ALLOW_READ but the implementation in the plug and trust MW in ecdh_alt_ax.c does read the shared secret anyways. (have not tried to run it though)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How can I read the key and write it to the mbedtls context?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 12:49:27 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/change-read-policy-for-shared-secret/m-p/1286207#M505</guid>
      <dc:creator>ziml</dc:creator>
      <dc:date>2021-06-08T12:49:27Z</dc:date>
    </item>
  </channel>
</rss>

