How To Import ELE Key To RT1180 Based On AN14861SW Table of Contents
Document Objective and Overall Flow
Software and Hardware Environment Preparation
Program SRKH on the RT1180 Board
Import the AN14861SW Project
Obtain the NXP Manufacturing Public Key from ELE
Generate Signed Content and the TLV Blob
Replace the C Arrays in the Demo Project
Build, Run, and Analyze the Success Log
1. Document Objective and Overall Flow
This document describes how to complete the OEM Key Import flow using the EdgeLock Enclave (ELE) on the i.MX RT1180. The flow is mainly used to securely import OEM-generated or OEM-owned key material into the device key store through the secure import mechanism supported by ELE, and then verify the imported key by performing AES encryption and decryption.
The overall flow can be summarized as follows:
Install the tool environment ↓ Program and verify SRKH ↓ Import the AN14861SW demo project ↓ Export the NXP Manufacturing Public Key from ELE ↓ Generate a local ECC key pair for ECDH key agreement ↓ Generate the KEY_EXCHANGE_REQ Signed Message ↓ Generate the OEM Import Key TLV Blob ↓ Replace the generated C arrays in the demo project ↓ Run the demo and perform Key Agreement and OEM Key Import
Note: The commands in this document primarily use Windows/PowerShell and the SPSDK CLI. When running them on Linux, adjust path separators and shell syntax as required.
2. Software and Hardware Environment Preparation
2.1 Hardware Platform
The following hardware is recommended:
i.MX RT1180 EVK or a custom RT1180 board
USB debug cable or an onboard debug interface
Serial terminal software, such as Tera Term, PuTTY, MobaXterm, or VS Code Serial Monitor
A boot configuration environment that has passed basic startup verification
2.2 Install SPT 26.06
It is recommended to install the latest SPT release. The version used in this document is:
SPT 26.06
SPT stands for Secure Provisioning Tool. It is used to generate SRK/SRKH data, configure signed images, program fuses, and configure secure boot.
After installation, confirm the following:
SPT starts normally.
The target RT1180 board can be detected.
Fuse read operations work correctly on the target board.
The selected connection interface matches the board boot mode.
2.3 Install the Latest SPSDK
It is recommended to install SPSDK in a Python virtual environment to avoid conflicts with Python packages already installed on the system.
python -m venv .venv .\.venv\Scripts\activate pip install -U pip pip install -U spsdk
Verify the installation:
spsdk --version nxpcrypto --help nxpimage --help
If a command is not recognized, check the following:
The virtual environment is active in the current PowerShell session.
The Python Scripts directory is included in PATH.
SPSDK is installed in the Python environment currently in use.
3. Program SRKH on the RT1180 Board
This step establishes the OEM Root of Trust. Before programming, make sure that the SRK table and SRKH are the final versions intended for use, because fuse programming or locking is normally irreversible.
3.1 Generate and Program SRKH Using SPT
The relevant configuration screenshots are shown below:
Figure 1 - SPT SRKH configuration
Figure 2 - SRKH programming confirmation
Figure 3 - SRKH fuse operation
Recommended checkpoints:
Confirm that the SRK table was generated from the correct OEM signing key.
Confirm that SRKH matches the SRK table used by the current project.
Save the configuration record before programming the fuses.
Perform readback verification after programming the fuses.
If Secure Boot will be enabled later, confirm that the SRKH locking policy meets the project manufacturing requirements.
Risk notice: SRKH is a core element of the secure boot chain of trust. Programming or locking must be confirmed by the project security owner in advance.
4. Import the AN14861SW Project
Use MCUXpresso IDE to import the AN14861SW project.
Recommended steps:
Open MCUXpresso IDE.
Select File → Import.
Select Existing Projects into Workspace.
Browse to the AN14861SW project directory.
Confirm that the project builds successfully.
Verify the Debug Probe, serial port, and boot configuration for the target board.
It is recommended to keep the original project unchanged at first and complete one baseline build and run. This confirms that the demo environment itself is functional.
5. Obtain the NXP Manufacturing Public Key from ELE
5.1 Enable the NXP Production Key Export Path in the Demo
AN14861 requires reading the NXP Manufacturing Public Key from ELE. This key is subsequently used as the peer public key for ECDH key agreement and is required to generate the Signed Message and TLV Blob materials.
The relevant flow screenshots are shown below:
Figure 4 - Enable key export in the project
Figure 5 - Exported NXP Manufacturing Public Key
After running the demo, a HEX string similar to the following is obtained:
744a536d9078795b037db78f8738dbab5ae7dbab76660eb7067a06f386791687 f6988017e90c73a889f5b6dd9abb3b5c1bb9c1cffdca34c6ba64600244e8a314
The string must be converted to a binary file and then converted to a PEM-format public key.
5.2 Convert the HEX String to a Binary File Using PowerShell
Create the following script:
create_key.ps1
Script content:
$hex = "744a536d9078795b037db78f8738dbab5ae7dbab76660eb7067a06f386791687f6988017e90c73a889f5b6dd9abb3b5c1bb9c1cffdca34c6ba64600244e8a314" [byte[]]$bytes = for ($i = 0; $i -lt $hex.Length; $i += 2) { [Convert]::ToByte($hex.Substring($i, 2), 16) } [System.IO.File]::WriteAllBytes("key.bin", $bytes) Write-Host "Created key.bin successfully." Write-Host "File size:" (Get-Item ".\key.bin").Length "bytes"
Run the script:
.\create_key.ps1
Expected output:
Created key.bin successfully. File size: 80 bytes
The test result is shown below:
Figure 6 - PowerShell generated key.bin
If script execution is restricted by the PowerShell execution policy, temporarily allow execution in the current session:
Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass
5.3 Convert key.bin to a PEM-Format Public Key
Run:
nxpcrypto key convert -e PEM -i key.bin -o nxp_prod.pub
Generated file:
nxp_prod.pub
Use the following command to inspect the PEM content:
openssl pkey -pubin -in nxp_prod.pub -text -noout
6. Generate Signed Content and the TLV Blob
This chapter corresponds to Section 7.4 of AN14861 and covers the following tasks:
Generate a local ECC key pair.
Export the ECC public key as raw binary.
Calculate the SHA-256 digest of the ECC public key.
Obtain and edit the Signed Message configuration template.
Generate signed_message.bin.
Generate the OEM Import Key TLV Blob.
Convert the binary files into C arrays for use in the demo.
6.1 Generate a Local ECC Key Pair
This key pair is used to perform ECDH key agreement with the NXP Manufacturing Public Key inside ELE.
nxpcrypto key generate -k secp256r1 --force -o app_ecc256.pem
Expected generated files:
app_ecc256.pem app_ecc256.pub
Notes:
secp256r1 selects the NIST P-256 curve.
The private key, app_ecc256.pem, must be stored securely.
The public key, app_ecc256.pub, will be converted to RAW format and embedded in the demo project.
6.2 Convert the ECC Public Key to RAW Binary
nxpcrypto key convert -e RAW -i app_ecc256.pub -o ecc256_pub_key.bin
Then convert it to a C array:
nxpimage utils convert bin2carr -i ecc256_pub_key.bin -e little -c 8 -n ecc256_pub_key -o app_ecc256_pub.c
Parameter description:
-i ecc256_pub_key.bin: input RAW binary public key.
-e little: output in little-endian format.
-c 8: output eight bytes per line.
-n ecc256_pub_key: generated C array name.
-o app_ecc256_pub.c: output C source file.
6.3 Calculate the SHA-256 Digest of the ECC Public Key
nxpcrypto digest -h sha256 -i ecc256_pub_key.bin
Example output:
SHA256(ecc256_pub_key.bin)= b3a20b5679c5ddd77d6bd1a3eb0ff6ea7ab32ac6883d597db30dfcb64d5f8164
This digest must later be entered in the Signed Message configuration file to identify the local ECC public key participating in the key exchange.
6.4 Obtain the KEY_EXCHANGE_REQ Signed Message Template
nxpimage signed-msg get-template -f rt118x -m KEY_EXCHANGE_REQ -o signed_msg_config.yaml --force
6.5 Edit signed_msg_config.yaml
Edit the template file:
signed_msg_config.yaml
Verify the following items carefully:
The family is rt118x.
The message type is KEY_EXCHANGE_REQ.
The correct NXP Manufacturing Public Key is used.
The ECC public key digest is correct.
The output file path is consistent with subsequent commands.
The working directory is located where SPT/SPSDK expects it.
A reference sample is provided in the attachment.
6.6 Generate the Signed Message Binary
After entering the SPT workspace, run:
nxpimage signed-msg export -c signed_msg_config.yaml -w ecdh_derived_key
The result is shown below:
Figure 7 - Export signed message
Expected generated file:
signed_message.bin
ECDH-derived-key intermediate files are also generated in the working directory.
6.7 Convert signed_message.bin to a C Array
nxpimage utils convert bin2carr -i signed_message.bin -e little -c 8 -n signed_msg_bin -o signed_message.c
The test result is shown below:
Figure 8 - Convert signed message to a C array
Generated file:
signed_message.c
It contains:
const uint8_t signed_msg_bin[] = { ... };
6.8 Obtain the Key Import TLV Blob Template
nxpimage signed-msg tlv get-template -f rt118x -o oem_import_key.yaml --force
The result is shown below:
Figure 9 - Get TLV template
6.9 Edit oem_import_key.yaml
Configure the following items according to the target key to be imported:
Key type
Key length
Key usage
Key policy
Blob ID
Storage location
Key group
TLV output file name
Keep the configuration consistent with the parsing logic in the demo project. Otherwise, TLV generation may succeed while the ELE Import step fails. A reference sample is provided in the attachment.
6.10 Generate the TLV Blob
nxpimage signed-msg tlv export -c oem_import_key.yaml
The result is shown below:
Figure 10 - Export TLV blob
Expected generated file:
tlv.bin
6.11 Convert tlv.bin to a C Array
nxpimage utils convert bin2carr -i tlv.bin -e little -c 8 -n oem_tlv_blob -o oem_tlv_blob.c
The result is shown below:
Figure 11 - Convert TLV blob to a C array
Generated file:
oem_tlv_blob.c
It contains:
const uint8_t oem_tlv_blob[] = { ... };
7. Replace the C Arrays in the Demo Project
Replace the generated C arrays in the ele_crypto_hsm.c file of the demo project.
The arrays to replace are:
ecc256_pub_key[] signed_msg_bin[] oem_tlv_blob[]
The relevant screenshots are shown below:
Figure 12 - Replace the ecc256_pub_key array
Figure 13 - Replace the signed_msg_bin array
Figure 14 - Replace the oem_tlv_blob array
Recommended procedure:
Back up the original ele_crypto_hsm.c file.
Use the contents of the generated .c files to replace the corresponding arrays. Do not change the array names.
8. Build, Run, and Analyze the Success Log
8.1 Disable the NXP Product Key Export Code Path
After replacing the arrays, disable the code path used to export the product key, and then rebuild the demo.
The relevant screenshot is shown below:
Figure 15 - Disable the product key export path
8.2 Rebuild the Project
In MCUXpresso IDE, run:
Clean Project Build Project Debug / Run
8.3 Key Success Log Messages
The successful demo log is lengthy. Focus on the following key messages:
EdgeLock FW loaded and authenticated successfully. EdgeLock RNG Start success. EdgeLock services initialized successfully. Open session successfully. Open service and create Key Store successfully. ele perform key agreement successfully. Derived key ID: 0x3fffffff Import key successfully. User key ID: 0x3ffffffe OEM_IMPORT_MK_SK deleted successfully. AES-ECB decrypted data match the original plain text - success. End of Example with SUCCESS!!
These messages indicate the following:
ELE firmware was loaded and authenticated successfully.
The RNG service started successfully.
ELE services were initialized successfully.
The session, Key Store, NVM, and Key Management services opened successfully.
ECDH key agreement succeeded.
OEM key import succeeded.
The temporary key pair was deleted successfully.
AES-ECB encryption and decryption verified that the imported key is usable.
8.4 Detailed Runtime Log
Original successful log summary:
EdgeLock Enclave Sub-System oem provsioning example: ****************** Load EdgeLock FW *********************** EdgeLock FW loaded and authenticated successfully. ****************** Start RNG ****************************** EdgeLock RNG Start success. EdgeLock RNG ready to use. ****************** Initialize EdgeLock services *********** EdgeLock services initialized successfully. ****************** Load EdgeLock NVM Mgr ****************** EdgeLock NVM manager registered. ****************** Open EdgeLock session ****************** Open session successfully. Session ID: 0xbe962305 ****************** Create Key Store *********************** Open service and create Key Store successfully. Key Store ID: 0xbe962e85 ****************** Open NVM Storage service *************** Open NVM Storage service successfully. Handle ID: 0xbe96294d ****************** Key Management Open ******************** Open Key management service successfully. Key Handle ID: 0xbe96293d ele perform key agreement successfully. Derived key ID: 0x3fffffff Write sd, blob_id_msb = 4, 45, 12345678 Write sd, blob_id_msb = 3, 0, 12345678 Write sd, blob_id_msb = 0, 0, 0 Import key successfully. User key ID: 0x3ffffffe OEM_IMPORT_MK_SK deleted successfully. Key Pair ID: 0x3fffffff ****************** Close Key Management Service *********** Close Key Management Service successfully. ****************** Close Key Store ************************ Close Key Store successfully. Close NVM storage session successfully. ****************** Close EdgeLock session ***************** Close session successfully. ... ****************** Cipher AES ECB ************************* Output returned by AES-ECB encryption. ****************** Decrypt Cipher AES-ECB ***************** Read sd, blob_id msb = 0x4, lsb: 0x45, ext: 0x12345678 AES-ECB decrypted data match the original plain text - success. ... End of Example with SUCCESS!! OEM Key Import, Signed Message, and TLV Blob Generation Flow Based on the i.MX RT1180 EdgeLock Enclave
View full article