CSEc command LOAD_KEY returns ERC_KEY_INVALID for some KeyIDs on S32k148

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 
已解决

CSEc command LOAD_KEY returns ERC_KEY_INVALID for some KeyIDs on S32k148

跳至解决方案
1,963 次查看
lwaszniowski
Contributor I

Hello,

I have encountered an interesting problem. I want to install CSEc keys to S32k148 device. The device is partitioned for 20 keys (uCSEcKeySize = 0x03u). I am using functions calculate_M1_to_M5 and LOAD_KEY from AN5401SW in my code.

It works correctly (the LOAD_KEY function returns value 1 = NO_ERROR) for all KeyIDs (0x04 – 0x0D, 0x14 – 0x18) when the master key is used for authorization.

It also works correctly for KeyIDs 0x04 – 0x0D and 0x15 and 0x17, when the old value of the key itself is used for authorization.

However, when I use the old value of the key itself for authorization, the LOAD_KEY function returns value 8 (KEY_INVALID) for KeyIDs 0x14, 0x16, 0x18.

I am sure that the key value used for authorization is correct (the blank key 0xff…ff). I have tested that LOAD_KEY function returns value 0x80 (KEY_UPDATE_ERROR) when wrong value of the authorization key is used.

I have tested it several times. I always unsecure device by the following sequence:

DBG_CHAL,

DBG_AUTH,

FLASH_DRV_EraseAllBlock,

FLASH_DRV_Program configuration fields on address 0x0400 by values {0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, 0xFF,0xFF,0xFF,0xFF,0xFE,0x7F,0xFF,0xFF};

FLASH_DRV_DEFlashPartition

 

Have anybody any idea what can be the root of the problem?

I can use it with master key authorization, but I want to be sure that I understand the process well.

Thanks

Libor Waszniowski

0 项奖励
回复
1 解答
1,952 次查看
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @lwaszniowski 

I reported a bug in function calculate_M1_to_M5() short time ago. It looks like the root cause is the same in your case. See please the report and suggestion how to fix it below:

***

In case of keys from second bank (when KBS = 1, keys KEY_11 - KEY_17), it is not possible to use the same key as authorization key when loading a key. Only MASTER_ECU_KEY can be used.

Reason:

AN5401 says that KBS field should not be considered when calculating M1 and M4 values:

lukaszadrapa_0-1717650875246.png

 

 

lukaszadrapa_1-1717650875053.png

 

However, the function calculate_M1_to_M5() masks KBS only in case of key_id:

lukaszadrapa_2-1717650875130.png

 

If such M1-M5 values are used to load a key to second bank when using the same key as authorization key, ERC_KEY_INVALID is returned.

The solution is to add also this code here:

auth_key_id = auth_key_id & 0x0F;

Then everything works as expected.

Regards,

Lukas

在原帖中查看解决方案

0 项奖励
回复
2 回复数
1,953 次查看
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @lwaszniowski 

I reported a bug in function calculate_M1_to_M5() short time ago. It looks like the root cause is the same in your case. See please the report and suggestion how to fix it below:

***

In case of keys from second bank (when KBS = 1, keys KEY_11 - KEY_17), it is not possible to use the same key as authorization key when loading a key. Only MASTER_ECU_KEY can be used.

Reason:

AN5401 says that KBS field should not be considered when calculating M1 and M4 values:

lukaszadrapa_0-1717650875246.png

 

 

lukaszadrapa_1-1717650875053.png

 

However, the function calculate_M1_to_M5() masks KBS only in case of key_id:

lukaszadrapa_2-1717650875130.png

 

If such M1-M5 values are used to load a key to second bank when using the same key as authorization key, ERC_KEY_INVALID is returned.

The solution is to add also this code here:

auth_key_id = auth_key_id & 0x0F;

Then everything works as expected.

Regards,

Lukas

0 项奖励
回复
1,948 次查看
lwaszniowski
Contributor I

Thank you very much for fast response, it really works.

 

Thanks

Libor Waszniowski

0 项奖励
回复
%3CLINGO-SUB%20id%3D%22lingo-sub-1881286%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ECSEc%20%E5%91%BD%E4%BB%A4%20LOAD_KEY%20%E5%AF%B9%20S32k148%20%E4%B8%8A%E7%9A%84%E6%9F%90%E4%BA%9B%20KeyID%20%E8%BF%94%E5%9B%9E%20ERC_KEY_INVALID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1881286%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%E6%88%91%E9%81%87%E5%88%B0%E4%BA%86%E4%B8%80%E4%B8%AA%E6%9C%89%E8%B6%A3%E7%9A%84%E9%97%AE%E9%A2%98%E3%80%82%E6%88%91%E6%83%B3%E5%B0%86%20CSEc%20%E5%AF%86%E9%92%A5%E5%AE%89%E8%A3%85%E5%88%B0%20S32k148%20%E8%AE%BE%E5%A4%87%E4%B8%8A%E3%80%82%E8%AF%A5%E8%AE%BE%E5%A4%87%E5%88%86%E5%8C%BA%E4%B8%BA%2020%20%E4%B8%AA%E5%AF%86%E9%92%A5%EF%BC%88uCSEcKeySize%20%3D%200x03u%EF%BC%89%E3%80%82%E6%88%91%E5%9C%A8%E6%88%91%E7%9A%84%E4%BB%A3%E7%A0%81%E4%B8%AD%E4%BD%BF%E7%94%A8%E4%BA%86%20AN5401SW%20%E7%9A%84%E5%87%BD%E6%95%B0%3CEM%3Ecalculate_M1_to_M5%3C%2FEM%3E%E5%92%8C%3CEM%3ELOAD_KEY%3C%2FEM%3E%20%E3%80%82%3C%2FP%3E%3CP%3E%E5%BD%93%E4%BD%BF%E7%94%A8%E4%B8%BB%E5%AF%86%E9%92%A5%E8%BF%9B%E8%A1%8C%E6%8E%88%E6%9D%83%E6%97%B6%EF%BC%8C%E5%AE%83%E5%AF%B9%E6%89%80%E6%9C%89%20KeyID%EF%BC%880x04%20%E2%80%93%200x0D%E3%80%810x14%20%E2%80%93%200x18%EF%BC%89%E9%83%BD%E8%83%BD%E6%AD%A3%E5%B8%B8%E5%B7%A5%E4%BD%9C%EF%BC%88%20%3CEM%3ELOAD_KEY%3C%2FEM%3E%E5%87%BD%E6%95%B0%E8%BF%94%E5%9B%9E%E5%80%BC%201%20%3D%20NO_ERROR%EF%BC%89%E3%80%82%3C%2FP%3E%3CP%3E%E5%BD%93%E4%BD%BF%E7%94%A8%E5%AF%86%E9%92%A5%E6%9C%AC%E8%BA%AB%E7%9A%84%E6%97%A7%E5%80%BC%E8%BF%9B%E8%A1%8C%E6%8E%88%E6%9D%83%E6%97%B6%EF%BC%8C%E5%AE%83%E4%B9%9F%E8%83%BD%E6%AD%A3%E7%A1%AE%E5%9C%B0%E9%80%82%E7%94%A8%E4%BA%8E%20KeyID%200x04%20%E2%80%93%200x0D%20%E5%92%8C%200x15%20%E5%92%8C%200x17%E3%80%82%3C%2FP%3E%3CP%3E%E4%BD%86%E6%98%AF%EF%BC%8C%E5%BD%93%E6%88%91%E4%BD%BF%E7%94%A8%E5%AF%86%E9%92%A5%E6%9C%AC%E8%BA%AB%E7%9A%84%E6%97%A7%E5%80%BC%E8%BF%9B%E8%A1%8C%E6%8E%88%E6%9D%83%E6%97%B6%EF%BC%8C%20%3CEM%3ELOAD_KEY%3C%2FEM%3E%E5%87%BD%E6%95%B0%E5%AF%B9%E4%BA%8E%20KeyID%200x14%E3%80%810x16%E3%80%810x18%20%E8%BF%94%E5%9B%9E%E5%80%BC%208%EF%BC%88KEY_INVALID%EF%BC%89%E3%80%82%3C%2FP%3E%3CP%3E%E6%88%91%E7%A1%AE%E5%AE%9A%E7%94%A8%E4%BA%8E%E6%8E%88%E6%9D%83%E7%9A%84%E5%AF%86%E9%92%A5%E5%80%BC%E6%98%AF%E6%AD%A3%E7%A1%AE%E7%9A%84%EF%BC%88%E7%A9%BA%E7%99%BD%E5%AF%86%E9%92%A50xff%E2%80%A6ff%EF%BC%89%E3%80%82%E6%88%91%E5%B7%B2%E7%BB%8F%E6%B5%8B%E8%AF%95%E8%BF%87%EF%BC%8C%E5%BD%93%E4%BD%BF%E7%94%A8%E9%94%99%E8%AF%AF%E7%9A%84%E6%8E%88%E6%9D%83%E5%AF%86%E9%92%A5%E5%80%BC%E6%97%B6%EF%BC%8C%20%3CEM%3ELOAD_KEY%3C%2FEM%3E%E5%87%BD%E6%95%B0%E5%B0%86%E8%BF%94%E5%9B%9E%E5%80%BC%200x80%EF%BC%88KEY_UPDATE_ERROR%EF%BC%89%E3%80%82%3C%2FP%3E%3CP%3E%E6%88%91%E5%B7%B2%E7%BB%8F%E6%B5%8B%E8%AF%95%E8%BF%87%E5%87%A0%E6%AC%A1%E4%BA%86%E3%80%82%E6%88%91%E6%80%BB%E6%98%AF%E6%8C%89%E7%85%A7%E4%BB%A5%E4%B8%8B%E9%A1%BA%E5%BA%8F%E5%8F%96%E6%B6%88%E8%AE%BE%E5%A4%87%E5%AE%89%E5%85%A8%EF%BC%9A%3C%2FP%3E%3CP%3EDBG_CHAL%EF%BC%8C%3C%2FP%3E%3CP%3EDBG_AUTH%EF%BC%8C%3C%2FP%3E%3CP%3EFLASH_DRV_EraseAllBlock%EF%BC%8C%3C%2FP%3E%3CP%3EFLASH_DRV_Program%20%E9%85%8D%E7%BD%AE%E5%AD%97%E6%AE%B5%E4%BD%8D%E4%BA%8E%E5%9C%B0%E5%9D%80%200x0400%EF%BC%8C%E5%80%BC%E4%B8%BA%20%7B0xFF%2C0xFF%2C0xFF%2C0xFF%2C0xFF%2C0xFF%2C0xFF%2C0xFF%2C%200xFF%2C0xFF%2C0xFF%2C0xFE%2C0x7F%2C0xFF%2C0xFF%7D%3B%3C%2FP%3E%3CP%3EFLASH_DRV_DEFlash%E5%88%86%E5%8C%BA%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%E6%9C%89%E8%B0%81%E7%9F%A5%E9%81%93%E9%97%AE%E9%A2%98%E7%9A%84%E6%A0%B9%E6%BA%90%E6%98%AF%E4%BB%80%E4%B9%88%E5%90%97%EF%BC%9F%3C%2FP%3E%3CP%3E%E6%88%91%E5%8F%AF%E4%BB%A5%E4%BD%BF%E7%94%A8%E4%B8%BB%E5%AF%86%E9%92%A5%E6%8E%88%E6%9D%83%E6%9D%A5%E4%BD%BF%E7%94%A8%E5%AE%83%EF%BC%8C%E4%BD%86%E6%88%91%E6%83%B3%E7%A1%AE%E4%BF%9D%E6%88%91%E5%BE%88%E5%A5%BD%E5%9C%B0%E7%90%86%E8%A7%A3%E4%BA%86%E8%BF%99%E4%B8%AA%E8%BF%87%E7%A8%8B%E3%80%82%3C%2FP%3E%3CP%3E%E8%B0%A2%E8%B0%A2%EF%BC%81%3C%2FP%3E%3CP%3ELibor%20Waszniowski%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1882431%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E5%9B%9E%E5%A4%8D%EF%BC%9ACSEc%20%E5%91%BD%E4%BB%A4%20LOAD_KEY%20%E5%AF%B9%20S32k148%20%E4%B8%8A%E7%9A%84%E6%9F%90%E4%BA%9B%20KeyID%20%E8%BF%94%E5%9B%9E%20ERC_KEY_INVALID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1882431%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E9%9D%9E%E5%B8%B8%E6%84%9F%E8%B0%A2%E6%82%A8%E7%9A%84%E5%BF%AB%E9%80%9F%E5%9B%9E%E5%A4%8D%EF%BC%8C%E5%AE%83%E7%A1%AE%E5%AE%9E%E6%9C%89%E6%95%88%E3%80%82%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%E8%B0%A2%E8%B0%A2%EF%BC%81%3C%2FP%3E%3CP%3ELibor%20Waszniowski%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1882363%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E5%9B%9E%E5%A4%8D%EF%BC%9ACSEc%20%E5%91%BD%E4%BB%A4%20LOAD_KEY%20%E5%AF%B9%20S32k148%20%E4%B8%8A%E7%9A%84%E6%9F%90%E4%BA%9B%20KeyID%20%E8%BF%94%E5%9B%9E%20ERC_KEY_INVALID%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1882363%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F145729%22%20target%3D%22_blank%22%3E%40lwaszniowski%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%E4%B8%8D%E4%B9%85%E5%89%8D%E6%88%91%E6%8A%A5%E5%91%8A%E4%BA%86%E5%87%BD%E6%95%B0calculate_M1_to_M5()%E4%B8%AD%E7%9A%84%E4%B8%80%E4%B8%AA%E9%94%99%E8%AF%AF%E3%80%82%E7%9C%8B%E8%B5%B7%E6%9D%A5%E6%82%A8%E7%9A%84%E6%83%85%E5%86%B5%E7%9A%84%E6%A0%B9%E6%9C%AC%E5%8E%9F%E5%9B%A0%E6%98%AF%E4%B8%80%E6%A0%B7%E7%9A%84%E3%80%82%E8%AF%B7%E5%8F%82%E9%98%85%E4%B8%8B%E9%9D%A2%E7%9A%84%E6%8A%A5%E5%91%8A%E5%92%8C%E4%BF%AE%E5%A4%8D%E5%BB%BA%E8%AE%AE%EF%BC%9A%3C%2FP%3E%0A%3CP%3E***%3C%2FP%3E%0A%3CP%3E%E5%AF%B9%E4%BA%8E%E6%9D%A5%E8%87%AA%E7%AC%AC%E4%BA%8C%E5%BA%93%E7%9A%84%E5%AF%86%E9%92%A5%EF%BC%88%E5%BD%93%20KBS%20%3D%201%20%E6%97%B6%EF%BC%8C%E5%AF%86%E9%92%A5%20KEY_11%20-%20KEY_17%EF%BC%89%EF%BC%8C%E5%8A%A0%E8%BD%BD%E5%AF%86%E9%92%A5%E6%97%B6%E4%B8%8D%E5%8F%AF%E8%83%BD%E4%BD%BF%E7%94%A8%E4%B8%8E%E6%8E%88%E6%9D%83%E5%AF%86%E9%92%A5%E7%9B%B8%E5%90%8C%E7%9A%84%E5%AF%86%E9%92%A5%E3%80%82%E4%BB%85%E5%8F%AF%E4%BD%BF%E7%94%A8MASTER_ECU_KEY%E3%80%82%3C%2FP%3E%0A%3CP%3E%E5%8E%9F%E5%9B%A0%EF%BC%9A%3C%2FP%3E%0A%3CP%3EAN5401%20%E6%8C%87%E5%87%BA%EF%BC%8C%E8%AE%A1%E7%AE%97%20M1%20%E5%92%8C%20M4%20%E5%80%BC%E6%97%B6%E4%B8%8D%E5%BA%94%E8%80%83%E8%99%91%20KBS%20%E5%AD%97%E6%AE%B5%EF%BC%9A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22lukaszadrapa_0-1717650875246.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22lukaszadrapa_0-1717650875246.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F282766i13BF8C88AF947261%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22lukaszadrapa_0-1717650875246.png%22%20alt%3D%22lukaszadrapa_0-1717650875246.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CBR%20%2F%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22lukaszadrapa_1-1717650875053.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22lukaszadrapa_1-1717650875053.png%22%20style%3D%22width%3A%20399px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F282767i7214BB0782E051DF%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22lukaszadrapa_1-1717650875053.png%22%20alt%3D%22lukaszadrapa_1-1717650875053.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3E%E4%BD%86%E6%98%AF%EF%BC%8C%E5%87%BD%E6%95%B0calculate_M1_to_M5()%E4%BB%85%E5%9C%A8key_id%E7%9A%84%E6%83%85%E5%86%B5%E4%B8%8B%E5%B1%8F%E8%94%BDKBS%EF%BC%9A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22lukaszadrapa_2-1717650875130.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22lukaszadrapa_2-1717650875130.png%22%20style%3D%22width%3A%20397px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F282765iD9392FCA9AA6A8E5%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22lukaszadrapa_2-1717650875130.png%22%20alt%3D%22lukaszadrapa_2-1717650875130.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3E%E5%A6%82%E6%9E%9C%E4%BD%BF%E7%94%A8%E4%B8%8E%E6%8E%88%E6%9D%83%E5%AF%86%E9%92%A5%E7%9B%B8%E5%90%8C%E7%9A%84%E5%AF%86%E9%92%A5%E5%B0%86%E6%AD%A4%E7%B1%BB%20M1-M5%20%E5%80%BC%E5%8A%A0%E8%BD%BD%E5%88%B0%E7%AC%AC%E4%BA%8C%E5%AE%B6%E9%93%B6%E8%A1%8C%EF%BC%8C%E5%88%99%E4%BC%9A%E8%BF%94%E5%9B%9E%20ERC_KEY_INVALID%E3%80%82%3C%2FP%3E%0A%3CP%3E%E8%A7%A3%E5%86%B3%E6%96%B9%E6%A1%88%E6%98%AF%E5%9C%A8%E6%AD%A4%E5%A4%84%E6%B7%BB%E5%8A%A0%E4%BB%A5%E4%B8%8B%E4%BB%A3%E7%A0%81%EF%BC%9A%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3Eauth_key_id%20%3D%20auth_key_id%20%26amp%3B%200x0F%3B%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%E7%84%B6%E5%90%8E%E4%B8%80%E5%88%87%E9%83%BD%E6%8C%89%E9%A2%84%E6%9C%9F%E8%BF%9B%E8%A1%8C%E3%80%82%3C%2FP%3E%0A%3CP%3E%E6%AD%A4%E8%87%B4%EF%BC%8C%3C%2FP%3E%0A%3CP%3ELukas%3C%2FP%3E%3C%2FLINGO-BODY%3E