S32K3 SHE key update

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 
已解决

S32K3 SHE key update

跳至解决方案
3,885 次查看
JiayuZhou
Contributor II

1. In K3 HSE_B Firmware RM document, FID is defined by 6 bit, so K3 not support to FID-5bit, right?[In K146 chip, FID not only support to 6 bit, but also 5 bit.]

So, in S32K3, if use FID-5bit to generate M1-M3, SHE key cannot be updated, right?

JiayuZhou_0-1728703913045.png

 

2. In S32K3 MCAL's crypto driver, SHE key's M4 stored in key element 2(CRYPTO_KE_MAC_PROOF), and M5 stored in key element 6(CRYPTO_KE_CIPHER_PROOF). but, As far as I know, M4M5 should store in key element 2, not element 6. Does NXP's crypto code not comply with autosar standard?

JiayuZhou_1-1728704593426.png

 

0 项奖励
回复
1 解答
3,805 次查看
lukaszadrapa
NXP TechSupport
NXP TechSupport

1. There's no difference. According to SHE specification, FID is used only for M2 calculation and it looks like this:

lukaszadrapa_0-1729068195045.png

So, M2 is the CBC-encrypted concatenation of the new counter value CID, the according flags FID, a pattern to fill the first block with ‘0’ bits and the new key KID.
VERIFY_ONLY extension flag is added to the end of FID - it replaces the first zero in that 95bits padding.
If you keep VERIFY_ONLY zero, it meets SHE specification. No other changes are necessary, no specific HSE firmware is needed. The behavior will correspond to SHE spec without this extension.

2. As I wrote, this was reported short time ago, it's not resolved yet.
I expect that only the CRYPTO_KE_CIPHER_PROOF definition will be changed from 6 to 2 as required by the standard.
And because it's not resolved yet, I can't provide expected release date.

Regards,
Lukas

在原帖中查看解决方案

0 项奖励
回复
3 回复数
3,849 次查看
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @JiayuZhou 

1. This extension of SHE spec is available on both CSEc on K1 and HSE on K3. It’s up to you if you will use it or not. Both options are possible:

From AN5401 for S32K1:

lukaszadrapa_0-1728994930679.png

 From HSE FW RM for S32K3:

lukaszadrapa_1-1728995010732.png

2. Yes, you are right. I can see that this was already reported short time ago. This will be fixed in next RTD versions in the near future.

Regards,

Lukas

 

0 项奖励
回复
3,844 次查看
JiayuZhou
Contributor II
Hi,lukaszadrapa,
1.In your figure, S32K3 don't have SFE flag like S32K1, so it only support to FID 6 bit, can not meet to FID 5bit, because it must configure VERIFY_ONLY bit. Wether NXP provide HSE firmware to support to use FID 5bit?
2.when is the next RTD provide? Can you provide a way to modify the relevant code in the current RTD? We‘re using this RTD to develop SW currently and already need to use this function.
0 项奖励
回复
3,806 次查看
lukaszadrapa
NXP TechSupport
NXP TechSupport

1. There's no difference. According to SHE specification, FID is used only for M2 calculation and it looks like this:

lukaszadrapa_0-1729068195045.png

So, M2 is the CBC-encrypted concatenation of the new counter value CID, the according flags FID, a pattern to fill the first block with ‘0’ bits and the new key KID.
VERIFY_ONLY extension flag is added to the end of FID - it replaces the first zero in that 95bits padding.
If you keep VERIFY_ONLY zero, it meets SHE specification. No other changes are necessary, no specific HSE firmware is needed. The behavior will correspond to SHE spec without this extension.

2. As I wrote, this was reported short time ago, it's not resolved yet.
I expect that only the CRYPTO_KE_CIPHER_PROOF definition will be changed from 6 to 2 as required by the standard.
And because it's not resolved yet, I can't provide expected release date.

Regards,
Lukas

0 项奖励
回复
%3CLINGO-SUB%20id%3D%22lingo-sub-1972546%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ES32K3%20SHE%E5%AF%86%E9%92%A5%E6%9B%B4%E6%96%B0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1972546%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E1.%E5%9C%A8K3%20HSE_B%20Firmware%20RM%E6%96%87%E6%A1%A3%E4%B8%AD%EF%BC%8CFID%E5%AE%9A%E4%B9%89%E4%B8%BA6%E4%BD%8D%EF%BC%8C%E6%89%80%E4%BB%A5K3%E4%B8%8D%E6%94%AF%E6%8C%81FID-5bit%EF%BC%8C%E5%AF%B9%E5%90%97%EF%BC%9F%5B%E5%9C%A8K146%E8%8A%AF%E7%89%87%EF%BC%8CFID%E4%B8%8D%E4%BB%85%E6%94%AF%E6%8C%81%E5%88%B06%E4%BD%8D%EF%BC%8C%E8%BF%98%E6%94%AF%E6%8C%81%E5%88%B05%E4%BD%8D%E3%80%82%5D%3C%2FP%3E%3CP%3E%E6%89%80%E4%BB%A5%EF%BC%8C%E5%9C%A8S32K3%E4%B8%AD%EF%BC%8C%E5%A6%82%E6%9E%9C%E4%BD%BF%E7%94%A8FID-5bit%E7%94%9F%E6%88%90M1-M3%EF%BC%8CSHE%E5%AF%86%E9%92%A5%E6%97%A0%E6%B3%95%E6%9B%B4%E6%96%B0%EF%BC%8C%E5%AF%B9%E5%90%97%EF%BC%9F%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22JiayuZhou_0-1728703913045.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22JiayuZhou_0-1728703913045.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F304320i905B0E8005123C84%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22JiayuZhou_0-1728703913045.png%22%20alt%3D%22JiayuZhou_0-1728703913045.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E2.%E5%9C%A8S32K3%20MCAL%E7%9A%84%E5%8A%A0%E5%AF%86%E9%A9%B1%E5%8A%A8%E7%A8%8B%E5%BA%8F%E4%B8%AD%EF%BC%8CSHE%E5%AF%86%E9%92%A5%E7%9A%84M4%E5%AD%98%E5%82%A8%E5%9C%A8%E5%AF%86%E9%92%A5%E5%85%83%E7%B4%A02%EF%BC%88CRYPTO_KE_MAC_PROOF%EF%BC%89%E4%B8%AD%EF%BC%8CM5%E5%AD%98%E5%82%A8%E5%9C%A8%E5%AF%86%E9%92%A5%E5%85%83%E7%B4%A06%EF%BC%88CRYPTO_KE_CIPHER_PROOF%EF%BC%89%E4%B8%AD%E3%80%82%E4%BD%86%E6%98%AF%EF%BC%8C%E6%8D%AE%E6%88%91%E6%89%80%E7%9F%A5%EF%BC%8CM4M5%E5%BA%94%E8%AF%A5%E5%AD%98%E5%82%A8%E5%9C%A8%E5%AF%86%E9%92%A5%E5%85%83%E7%B4%A02%E4%B8%AD%EF%BC%8C%E8%80%8C%E4%B8%8D%E6%98%AF%E5%85%83%E7%B4%A06%E4%B8%AD%E3%80%82NXP%E7%9A%84%E5%8A%A0%E5%AF%86%E4%BB%A3%E7%A0%81%E4%B8%8D%E7%AC%A6%E5%90%88autosar%E6%A0%87%E5%87%86%E5%90%97%EF%BC%9F%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22JiayuZhou_1-1728704593426.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22JiayuZhou_1-1728704593426.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F304323i033F8D61CB0F27FF%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22JiayuZhou_1-1728704593426.png%22%20alt%3D%22JiayuZhou_1-1728704593426.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1974288%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E5%9B%9E%E5%A4%8D%EF%BC%9AS32K3%20SHE%20%E5%AF%86%E9%92%A5%E6%9B%B4%E6%96%B0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1974288%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E4%BD%A0%E5%A5%BD%EF%BC%8Clukaszadrapa%EF%BC%8C%3CBR%20%2F%3E%201.%E5%9C%A8%E4%BD%A0%E7%9A%84%E5%9B%BE%E4%B8%AD%EF%BC%8CS32K3%E6%B2%A1%E6%9C%89%E5%83%8FS32K1%E9%82%A3%E6%A0%B7%E7%9A%84SFE%E6%A0%87%E5%BF%97%EF%BC%8C%E6%89%80%E4%BB%A5%E5%AE%83%E5%8F%AA%E6%94%AF%E6%8C%81FID%206%E4%BD%8D%EF%BC%8C%E4%B8%8D%E8%83%BD%E6%BB%A1%E8%B6%B3FID%205%E4%BD%8D%EF%BC%8C%E5%9B%A0%E4%B8%BA%E5%AE%83%E5%BF%85%E9%A1%BB%E9%85%8D%E7%BD%AEVERIFY_ONLY%E4%BD%8D%E3%80%82NXP%E6%98%AF%E5%90%A6%E6%8F%90%E4%BE%9BHSE%E5%9B%BA%E4%BB%B6%E6%94%AF%E6%8C%81%E4%BD%BF%E7%94%A8FID%205bit%EF%BC%9F%3CBR%20%2F%3E%202.%20%E4%B8%8B%E4%B8%80%E6%AC%A1%20RTD%20%E4%BB%80%E4%B9%88%E6%97%B6%E5%80%99%E6%8F%90%E4%BE%9B%EF%BC%9F%E6%82%A8%E8%83%BD%E6%8F%90%E4%BE%9B%E4%BF%AE%E6%94%B9%E5%BD%93%E5%89%8D%20RTD%20%E4%B8%AD%E7%9B%B8%E5%85%B3%E4%BB%A3%E7%A0%81%E7%9A%84%E6%96%B9%E6%B3%95%E5%90%97%EF%BC%9F%E6%88%91%E4%BB%AC%E7%9B%AE%E5%89%8D%E6%AD%A3%E5%9C%A8%E4%BD%BF%E7%94%A8%E8%BF%99%E4%B8%AA%20RTD%20%E5%BC%80%E5%8F%91%E8%BD%AF%E4%BB%B6%EF%BC%8C%E5%B7%B2%E7%BB%8F%E9%9C%80%E8%A6%81%E4%BD%BF%E7%94%A8%E8%BF%99%E4%B8%AA%E5%8A%9F%E8%83%BD%E4%BA%86%E3%80%82%3C%2FLINGO-BODY%3E