2408622_en-US

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

2408622_en-US

2408622_en-US

iMX93 firmware-ele-imx

Does the i.MX93 A1 ele firmware (v2.0.4) support the Generic Crypto APIs? 

Imx-secure-enclave git repo suggests in the sab_msg.def generic crypto is supported by firmware. RM00284 also suggests it in section 3.44. However, every attempt to use the feature has resulted in a response indicator of 0x0000f429. This either means the message is invalid or, if following the SAB error code path, that the feature is disabled.

The hsm_test.c includes the following which suggests the feature is only for the IMX95 and IMX8ULP.

	if ((se_get_soc_id() == SOC_IMX95 && se_get_soc_rev() < SOC_REV_B0) ||
	    se_get_soc_id() == SOC_IMX8ULP)
		gc_cipher_test(hsm_session_hdl);

This contradicts RM00284:

3.45 i.MX 95
Generic Crypto APIs are not supported.
SM3 and SM4 are not supported.

So far, keystore calls work normally, the ele_hsm_test works. Life cycle is open and secure boot is not enabled at the moment.

Since the Generic crypto calls do not use the key store, do they require a session handle? If not, what about the message units relation to the SAB ID? I ask because my firmware user guide doesn't show a field for a session handle under the HSM generic commands. 

Summary of setup:

SOC: i.MX93 A1
Build system: Yocto walnascar
Kernel: 6.12.49

Thanks,
Clay

Yocto ProjectRe: iMX93 firmware-ele-imx

could you send the code path or link about the code you mentioned as below, let me double confirm this

if ((se_get_soc_id() == SOC_IMX95 && se_get_soc_rev() < SOC_REV_B0) ||
	    se_get_soc_id() == SOC_IMX8ULP)
		gc_cipher_test(hsm_session_hdl);

 for your first request, I checked, By CR RSA decryption support on i.MX93, ELE firmware team remove generic crypto APIs

Re: iMX93 firmware-ele-imx

Line 840 is where the gc_cipher_test() is kicked off within hsm_test.c. The test itself is under test/common/test_gc_cipher.c.


Where in documentation is it stated that the generic crypto APIs where removed? 
Does that mean a third party crypto library is required if one doesn't want to use a key store? 

What is the intended path if, for example, I wanted to simply derive a soc specific key (maybe generated from the HUK) and encrypt/decrypt a few bytes stored on the filesystem?

Thanks,
Clay

Re: iMX93 firmware-ele-imx

this is not mentioned in the public document, you can refer to the 2.0.4 ele user guide, did you have this? if no, you can request it from nxp.com

i.MX 93 Applications Processors Family | NXP Semiconductors

click “secure” in the "Documentation", you can find the new cmd ID, you can refer to the 4.3.2 Cipher vs key attributes

Tags (1)
No ratings
Version history
Last update:
‎09-03-2026 02:28 AM
Updated by: