[Security] Problems using SDK CSEC Driver

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

[Security] Problems using SDK CSEC Driver

Jump to solution
3,069 Views
Gideon
Contributor III

Dear NXPs:

SDK CSEC Driver
csec_driver.h
csec_driver.c
csec_hw_access.c
csec_hw_access.h
I transplanted the SDK CSEC Driver to the normal project (without free RTOS) for use. The chip objects are S32K142 and S32K146. I found that the SDK CSEC Driver only used the OS timer for timeout processing, so my solution was to delete the OS part of the CSEC Driver C file, which met my needs.
The interface I plan to use is:
void CSEC_DRV_Init(csec_state_t *state);
void CSEC_DRV_Deinit(void);
status_t CSEC_DRV_EncryptCBC(csec_key_id_t keyId,
const uint8_t *plainText, uint32_t length,
const uint8_t *iv, uint8_t *cipherText, uint32_t timeout);
status_t CSEC_DRV_DecryptCBC(csec_key_id_t keyId, const uint8_t *cipherText,
uint32_t length, const uint8_t* iv, uint8_t *plainText, uint32_t timeout);
status_t CSEC_DRV_GenerateMAC(csec_key_id_t keyId, const uint8_t *msg,
uint32_t msgLen, uint8_t *cmac, uint32_t timeout);
status_t CSEC_DRV_GenerateMACAddrMode(csec_key_id_t keyId,
const uint8_t *msg, uint32_t msgLen, uint8_t *cmac);
status_t CSEC_DRV_VerifyMAC(csec_key_id_t keyId, const uint8_t *msg,
uint32_t msgLen, const uint8_t *mac, uint16_t macLen, bool *verifStatus,
uint32_t timeout);
status_t CSEC_DRV_VerifyMACAddrMode(csec_key_id_t keyId, const uint8_t *msg,
uint32_t msgLen, const uint8_t *mac, uint16_t macLen, bool *verifStatus);
status_t CSEC_DRV_LoadKey(csec_key_id_t keyId, const uint8_t *m1,
const uint8_t *m2, const uint8_t *m3, uint8_t *m4, uint8_t *m5);
status_t CSEC_DRV_BootFailure(void);
status_t CSEC_DRV_BootOK(void);
status_t CSEC_DRV_BootDefine(uint32_t bootSize, csec_boot_flavor_t bootFlavor);
static inline csec_status_t CSEC_DRV_GetStatus(void);
status_t CSEC_DRV_MPCompress(const uint8_t *msg, uint16_t msgLen,
uint8_t *mpCompress, uint32_t timeout);
Q:What I want to inquire about is transplanting the SDK CSEC Driver to the Normal project (142/146, no OS). Are there any potential risks? ?

0 Kudos
Reply
1 Solution
2,960 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

You can find the manual here:
c:\NXP\S32DS.3.4\S32DS\software\S32SDK_S32K1XX_RTM_4.0.3\doc\S32SDK_S32K144_UserManual.pdf

No configuration is needed. If you have a project without FreeRTOS then baremetal version is selected automatically.

View solution in original post

0 Kudos
Reply
3 Replies
3,038 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @Gideon 

there's implementation of OSIF for both FreeRTOS and baremetal configuration. So, there's no problem even if you don't use FreeRTOS. Take a look at section "OS Interface (OSIF)" in SDK user manual.

lukaszadrapa_0-1713559726522.png

I can't see a reason to do such changes. 

And if SDK is not used ever, it's better to use code from AN5401.

Regards,

Lukas

 

0 Kudos
Reply
3,000 Views
Gideon
Contributor III

Dear NXPs:

Q1:Where can I view the document you sent a screenshot of?

Q2:Could you provide me with a baremetal configuration S32K14x CSEC driver?

0 Kudos
Reply
2,961 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

You can find the manual here:
c:\NXP\S32DS.3.4\S32DS\software\S32SDK_S32K1XX_RTM_4.0.3\doc\S32SDK_S32K144_UserManual.pdf

No configuration is needed. If you have a project without FreeRTOS then baremetal version is selected automatically.

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-1849608%22%20slang%3D%22zh-CN%22%20mode%3D%22CREATE%22%3E%5BSecurity%5D%20Problems%20using%20SDK%20CSEC%20Driver%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1849608%22%20slang%3D%22zh-CN%22%20mode%3D%22CREATE%22%3E%3CP%3EDear%20NXPs%EF%BC%9A%3C%2FP%3E%3CP%3ESDK%20CSEC%20Driver%3CBR%20%2F%3Ecsec_driver.h%3CBR%20%2F%3Ecsec_driver.c%3CBR%20%2F%3Ecsec_hw_access.c%3CBR%20%2F%3Ecsec_hw_access.h%3CBR%20%2F%3EI%20transplanted%20the%20SDK%20CSEC%20Driver%20to%20the%20normal%20project%20(without%20free%20RTOS)%20for%20use.%20The%20chip%20objects%20are%20S32K142%20and%20S32K146.%20I%20found%20that%20the%20SDK%20CSEC%20Driver%20only%20used%20the%20OS%20timer%20for%20timeout%20processing%2C%20so%20my%20solution%20was%20to%20delete%20the%20OS%20part%20of%20the%20CSEC%20Driver%20C%20file%2C%20which%20met%20my%20needs.%3CBR%20%2F%3EThe%20interface%20I%20plan%20to%20use%20is%3A%3CBR%20%2F%3Evoid%20CSEC_DRV_Init(csec_state_t%20*state)%3B%3CBR%20%2F%3Evoid%20CSEC_DRV_Deinit(void)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_EncryptCBC(csec_key_id_t%20keyId%2C%3CBR%20%2F%3Econst%20uint8_t%20*plainText%2C%20uint32_t%20length%2C%3CBR%20%2F%3Econst%20uint8_t%20*iv%2C%20uint8_t%20*cipherText%2C%20uint32_t%20timeout)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_DecryptCBC(csec_key_id_t%20keyId%2C%20const%20uint8_t%20*cipherText%2C%3CBR%20%2F%3Euint32_t%20length%2C%20const%20uint8_t*%20iv%2C%20uint8_t%20*plainText%2C%20uint32_t%20timeout)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_GenerateMAC(csec_key_id_t%20keyId%2C%20const%20uint8_t%20*msg%2C%3CBR%20%2F%3Euint32_t%20msgLen%2C%20uint8_t%20*cmac%2C%20uint32_t%20timeout)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_GenerateMACAddrMode(csec_key_id_t%20keyId%2C%3CBR%20%2F%3Econst%20uint8_t%20*msg%2C%20uint32_t%20msgLen%2C%20uint8_t%20*cmac)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_VerifyMAC(csec_key_id_t%20keyId%2C%20const%20uint8_t%20*msg%2C%3CBR%20%2F%3Euint32_t%20msgLen%2C%20const%20uint8_t%20*mac%2C%20uint16_t%20macLen%2C%20bool%20*verifStatus%2C%3CBR%20%2F%3Euint32_t%20timeout)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_VerifyMACAddrMode(csec_key_id_t%20keyId%2C%20const%20uint8_t%20*msg%2C%3CBR%20%2F%3Euint32_t%20msgLen%2C%20const%20uint8_t%20*mac%2C%20uint16_t%20macLen%2C%20bool%20*verifStatus)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_LoadKey(csec_key_id_t%20keyId%2C%20const%20uint8_t%20*m1%2C%3CBR%20%2F%3Econst%20uint8_t%20*m2%2C%20const%20uint8_t%20*m3%2C%20uint8_t%20*m4%2C%20uint8_t%20*m5)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_BootFailure(void)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_BootOK(void)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_BootDefine(uint32_t%20bootSize%2C%20csec_boot_flavor_t%20bootFlavor)%3B%3CBR%20%2F%3Estatic%20inline%20csec_status_t%20CSEC_DRV_GetStatus(void)%3B%3CBR%20%2F%3Estatus_t%20CSEC_DRV_MPCompress(const%20uint8_t%20*msg%2C%20uint16_t%20msgLen%2C%3CBR%20%2F%3Euint8_t%20*mpCompress%2C%20uint32_t%20timeout)%3B%3CBR%20%2F%3EQ%EF%BC%9AWhat%20I%20want%20to%20inquire%20about%20is%20transplanting%20the%20SDK%20CSEC%20Driver%20to%20the%20Normal%20project%20(142%2F146%2C%20no%20OS).%20Are%20there%20any%20potential%20risks%3F%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1852097%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E5%9B%9E%E5%A4%8D%EF%BC%9A%5B%E5%AE%89%E5%85%A8%5D%20%E4%BD%BF%E7%94%A8%20SDK%20CSEC%20%E9%A9%B1%E5%8A%A8%E7%A8%8B%E5%BA%8F%E7%9A%84%E9%97%AE%E9%A2%98%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1852097%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E6%82%A8%E5%8F%AF%E4%BB%A5%E5%9C%A8%E8%BF%99%E9%87%8C%E6%89%BE%E5%88%B0%E8%AF%A5%E6%89%8B%E5%86%8C%EF%BC%9A%3CBR%20%2F%3E%20c%3A%5CNXP%5CS32DS.3.4%5CS32DS%5C%E8%BD%AF%E4%BB%B6%5CS32SDK_S32K1XX_RTM_4.0.3%5Cdoc%5CS32SDK_S32K144_UserManual.pdf%3C%2FP%3E%0A%3CP%3E%E6%97%A0%E9%9C%80%E9%85%8D%E7%BD%AE%E3%80%82%E5%A6%82%E6%9E%9C%E6%82%A8%E7%9A%84%E9%A1%B9%E7%9B%AE%E6%B2%A1%E6%9C%89%20FreeRTOS%EF%BC%8C%E5%88%99%E4%BC%9A%E8%87%AA%E5%8A%A8%E9%80%89%E6%8B%A9%E8%A3%B8%E6%9C%BA%E7%89%88%E6%9C%AC%E3%80%82%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1851122%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E5%9B%9E%E5%A4%8D%EF%BC%9A%5B%E5%AE%89%E5%85%A8%5D%20%E4%BD%BF%E7%94%A8%20SDK%20CSEC%20%E9%A9%B1%E5%8A%A8%E7%A8%8B%E5%BA%8F%E7%9A%84%E9%97%AE%E9%A2%98%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1851122%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E5%B0%8A%E6%95%AC%E7%9A%84%E6%81%A9%E6%99%BA%E6%B5%A6%E7%94%A8%E6%88%B7%EF%BC%9A%3C%2FP%3E%3CP%3E%3CSPAN%3EQ1%EF%BC%9A%E6%88%91%E5%9C%A8%E5%93%AA%E9%87%8C%E5%8F%AF%E4%BB%A5%E6%9F%A5%E7%9C%8B%E6%82%A8%E5%8F%91%E9%80%81%E7%9A%84%E6%88%AA%E5%9B%BE%E6%96%87%E6%A1%A3%EF%BC%9F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EQ2%EF%BC%9A%E6%82%A8%E8%83%BD%E7%BB%99%E6%88%91%E6%8F%90%E4%BE%9B%E8%A3%B8%E6%9C%BA%E9%85%8D%E7%BD%AE%20S32K14x%20CSEC%20%E9%A9%B1%E5%8A%A8%E7%A8%8B%E5%BA%8F%E5%90%97%EF%BC%9F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1850943%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E5%9B%9E%E5%A4%8D%EF%BC%9A%5B%E5%AE%89%E5%85%A8%5D%20%E4%BD%BF%E7%94%A8%20SDK%20CSEC%20%E9%A9%B1%E5%8A%A8%E7%A8%8B%E5%BA%8F%E7%9A%84%E9%97%AE%E9%A2%98%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1850943%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F218898%22%20target%3D%22_blank%22%3E%40Gideon%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFreeRTOS%20%E5%92%8C%E8%A3%B8%E6%9C%BA%E9%85%8D%E7%BD%AE%E9%83%BD%E6%9C%89%20OSIF%20%E7%9A%84%E5%AE%9E%E7%8E%B0%E3%80%82%E6%89%80%E4%BB%A5%EF%BC%8C%E5%8D%B3%E4%BD%BF%E4%B8%8D%E4%BD%BF%E7%94%A8FreeRTOS%E4%B9%9F%E6%B2%A1%E6%9C%89%E9%97%AE%E9%A2%98%E3%80%82%E6%9F%A5%E7%9C%8B%20SDK%20%E7%94%A8%E6%88%B7%E6%89%8B%E5%86%8C%E4%B8%AD%E7%9A%84%E2%80%9COS%20%E6%8E%A5%E5%8F%A3%20(OSIF)%E2%80%9D%E9%83%A8%E5%88%86%E3%80%82%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22lukaszadrapa_0-1713559726522.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22lukaszadrapa_0-1713559726522.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F274794i593B225734045E9F%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22lukaszadrapa_0-1713559726522.png%22%20alt%3D%22lukaszadrapa_0-1713559726522.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%E6%88%91%E7%9C%8B%E4%B8%8D%E5%87%BA%E8%BF%9B%E8%A1%8C%E6%AD%A4%E7%B1%BB%E6%94%B9%E5%8F%98%E7%9A%84%E7%90%86%E7%94%B1%E3%80%82%3C%2FP%3E%0A%3CP%3E%E5%A6%82%E6%9E%9C%E4%BB%8E%E6%9C%AA%E4%BD%BF%E7%94%A8%E8%BF%87%20SDK%EF%BC%8C%E6%9C%80%E5%A5%BD%E4%BD%BF%E7%94%A8%20AN5401%20%E4%B8%AD%E7%9A%84%E4%BB%A3%E7%A0%81%E3%80%82%3C%2FP%3E%0A%3CP%3E%E6%AD%A4%E8%87%B4%EF%BC%8C%3C%2FP%3E%0A%3CP%3ELukas%3C%2FP%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E