How to Store KEK and Use Wrapped DEK using SSS API on SE051

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to Store KEK and Use Wrapped DEK using SSS API on SE051

22 Views
Fjk
Contributor I

Hello,

I am currently evaluating the SE051 using the SSS API tool from the Plug & Trust Middleware, and I would appreciate your guidance on the correct implementation method for my use case.

Security Requirement & Goal:
To prevent key exposure on host memory, the Plain Data Encryption Key (DEK) must never be handled in plaintext on the Host (i.MX 8M) once it has been wrapped.
Therefore, my goal is to ensure that after initial wrapping, all key unwrapping and file encryption/decryption operations are executed entirely inside the SE051 without ever revealing the plain DEK to the host.

Target Workflow:
[ Phase 1: Key Provisioning & Wrapping ]
1. Store the Key Encryption Key (KEK) into SE051.
2. Import the Plain DEK to SE051, wrap it using KEK inside SE051, and export the Wrapped DEK to Host Storage.

1_Key_Provisioning_and_Wrapping.png1_Key_Provisioning_and_Wrapping.png

[ Phase 2: Runtime File Protection ]
3. Send the Plain File and Wrapped DEK to SE051 -> SE051 unwraps the DEK internally and encrypts the file -> Output Encrypted File to Host.
4. Send the Encrypted File and Wrapped DEK to SE051 -> SE051 unwraps the DEK internally and decrypts the file -> Output Plain File to Host.

2_Runtime_File_Protection.png2_Runtime_File_Protection.png

(Please refer to the attached sequence diagram for details).

Questions:

  1. Implementation Method & API Guidance:
    What is the recommended SSS API implementation method to execute this end-to-end workflow without revealing the plain DEK to the host?
  2. Key Unwrapping & Transient Objects:
    What specific SSS APIs and policies are required to import a Wrapped DEK, unwrap it within SE051, and hold it as a transient key object for immediate file encryption/decryption?
  3. Reference Code:
    Are there any code samples in Plug & Trust MW v04.00.00 that demonstrate key wrapping/unwrapping combined with symmetric encryption operations inside SE051?

Environment:

  • Board: MCIMX8M-WEVK and OM-SE051ARD
  • Linux version: 5.4.70-2.3.2+g8c73bc625c4d (SE-PLUG-TRUST-SD-CARD-IMAGE-IMX8M-NEW)
  • Plug & Trust MW version: v04.00.00

Any guidance or example code snippets would be greatly appreciated.

Labels (1)
0 Kudos
Reply
1 Reply

8 Views
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @Fjk ,

 

Thanks for the reaching out! Please have my comments as below:

Q1: Implementation Method & API Guidance:

What is the recommended SSS API implementation method to execute this end-to-end workflow without revealing the plain DEK to the host?

The correct approach uses a two-layer API strategy:

  • Key management (KEK store, DEK wrap/unwrap): Use Se05x_API_ExportObject() / Se05x_API_ImportObject() from se05x_APDU_apis.h. These operate entirely inside the SE051 and are the only way to wrap/unwrap a key using another key stored in SE051 without ever revealing plaintext to the host.
  • File encryption/decryption: Use sss_cipher_one_go() (or sss_cipher_init + sss_cipher_update + sss_cipher_finish for large files) against the transient DEK object created by the import step above.

The SSS high-level layer (sss_key_store_set_key) cannot be used for DEK import-from-wrapped, because it always requires the key in plaintext on the host side. The APDU-level Se05x_API_ImportObject is required for the unwrap step to remain fully inside SE051.

Q2 : Key Unwrapping & Transient Objects:

What specific SSS APIs and policies are required to import a Wrapped DEK, unwrap it within SE051, and hold it as a transient key object for immediate file encryption/decryption?

Phase 1: Key Provisioning & Wrapping

Step 1 — Store the KEK as a persistent object:

// Policy for KEK: allow ENC/DEC and IMPORT_EXPORT (for use as wrapping key)
sss_policy_u kekPolicyList[] = {
{ .type = KPolicy_Sym_Key,
.policy = { .symmkey = { .can_Encrypt = 1, .can_Decrypt = 1,
.can_Import_Export = 1 } } }
};
sss_policy_t kekPolicy = { .nPolicies = 1, .policies = kekPolicyList };

sss_object_t kekObject = {0};
sss_key_object_init(&kekObject, &pCtx->ks);
sss_key_object_allocate_handle(&kekObject, KEK_KEY_ID,
kSSS_KeyPart_Default, kSSS_CipherType_AES,
AES256_KEY_BYTES, kKeyObject_Mode_Persistent);
sss_key_store_set_key(&pCtx->ks, &kekObject,
kekData, kekLen, kekLen * 8, &kekPolicy, sizeof(kekPolicy));

Step 2 — Import the plain DEK into SE051 as a transient object:

// Policy for DEK: allow ENC/DEC and IMPORT_EXPORT (so it can be wrapped for export)
sss_policy_u dekPolicyList[] = {
{ .type = KPolicy_Sym_Key,
.policy = { .symmkey = { .can_Encrypt = 1, .can_Decrypt = 1,
.can_Import_Export = 1 } } }
};
sss_policy_t dekPolicy = { .nPolicies = 1, .policies = dekPolicyList };

sss_object_t dekObject = {0};
sss_key_object_init(&dekObject, &pCtx->ks);
sss_key_object_allocate_handle(&dekObject, DEK_TEMP_ID,
kSSS_KeyPart_Default, kSSS_CipherType_AES,
AES256_KEY_BYTES, kKeyObject_Mode_Transient);
sss_key_store_set_key(&pCtx->ks, &dekObject,
plainDEK, dekLen, dekLen * 8, &dekPolicy, sizeof(dekPolicy));
// plainDEK is the ONLY moment the DEK appears on the host — during initial provisioning only

Step 3 — Export the DEK wrapped by the KEK (entirely inside SE051):

// Se05x_API_ExportObject wraps DEK_TEMP_ID using KEK_KEY_ID — no plaintext leaves SE051
uint8_t wrappedDEK[AES256_KEY_BYTES + 8]; // RFC 3394 adds 8 bytes overhead
size_t wrappedDEKLen = sizeof(wrappedDEK);

pSe05xSession_t se05xSession =
&((sss_se05x_session_t *)&pCtx->session)->s_ctx;

Se05x_API_ExportObject(se05xSession,
DEK_TEMP_ID, // Object to wrap (the transient DEK)
kSE05x_TransientIndicator_TRANSIENT,
wrappedDEK,
&wrappedDEKLen);
// Store wrappedDEK to host persistent storage — safe, never reveals plaintext DEK

//Please note The transient DEK_TEMP_ID object is automatically deleted when the session closes. After exporting the wrapped DEK, the plain DEK is gone from SE051.

Phase 2: Runtime File Protection:

Step 4 — Import wrapped DEK: SE051 unwraps internally using KEK, stores as transient:

// Se05x_API_ImportObject unwraps the wrapped DEK using KEK_KEY_ID INSIDE SE051
// The DEK never appears in plaintext on the host — this is the key security guarantee
Se05x_API_ImportObject(se05xSession,
DEK_RUNTIME_ID, // Target object ID for the unwrapped DEK
kSE05x_RSAKeyComponent_NA, // N/A for symmetric keys
NULL, // Use default policy
0,
wrappedDEK, // Wrapped DEK from host storage
wrappedDEKLen,
kSE05x_TransientIndicator_TRANSIENT, // Store as transient — clears on session end
KEK_KEY_ID); // SE051 uses this key to unwrap internally

Step 5 — Encrypt/Decrypt the file using the transient DEK:

// Get handle to the now-unwrapped transient DEK
sss_object_t dekTransient = {0};
sss_key_object_init(&dekTransient, &pCtx->ks);
sss_key_object_get_handle(&dekTransient, DEK_RUNTIME_ID);

// Encrypt
sss_symmetric_t ctxEncrypt = {0};
sss_symmetric_context_init(&ctxEncrypt, &pCtx->session, &dekTransient,
kAlgorithm_SSS_AES_CBC, kMode_SSS_Encrypt);
sss_cipher_one_go(&ctxEncrypt, iv, ivLen,
plainFileData, encryptedFileData, dataLen);
sss_symmetric_context_free(&ctxEncrypt);

// Decrypt (same pattern, change mode to kMode_SSS_Decrypt)
sss_symmetric_t ctxDecrypt = {0};
sss_symmetric_context_init(&ctxDecrypt, &pCtx->session, &dekTransient,
kAlgorithm_SSS_AES_CBC, kMode_SSS_Decrypt);
sss_cipher_one_go(&ctxDecrypt, iv, ivLen,
encryptedFileData, decryptedFileData, dataLen);
sss_symmetric_context_free(&ctxDecrypt);

// Explicitly erase transient DEK after use (optional, also cleared on session close)
sss_key_store_erase_key(&pCtx->ks, &dekTransient);
sss_key_object_free(&dekTransient);

Q3: Reference Code:

Are there any code samples in Plug & Trust MW v04.00.00 that demonstrate key wrapping/unwrapping combined with symmetric encryption operations inside SE051?

There is no single example that combines key wrapping + symmetric encryption end-to-end, but the following examples should be helpful.

Purpose Path in simw-top/
AES symmetric encrypt/decrypt sss/ex/symmetric/ex_sss_symmetric.c
Using object policies demos/se05x/se05x_policy/
Key export/import at APDU level hostlib/hostLib/se05x/src/se05x_APDU_apis.c

 

Hope that helps,

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

 

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2409030%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EHow%20to%20Store%20KEK%20and%20Use%20Wrapped%20DEK%20using%20SSS%20API%20on%20SE051%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2409030%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EI%20am%20currently%20evaluating%20the%20SE051%20using%20the%20SSS%20API%20tool%20from%20the%20Plug%20%26amp%3B%20Trust%20Middleware%2C%20and%20I%20would%20appreciate%20your%20guidance%20on%20the%20correct%20implementation%20method%20for%20my%20use%20case.%3C%2FP%3E%3CP%3ESecurity%20Requirement%20%26amp%3B%20Goal%3A%3CBR%20%2F%3ETo%20prevent%20key%20exposure%20on%20host%20memory%2C%20the%20Plain%20Data%20Encryption%20Key%20(DEK)%20must%20never%20be%20handled%20in%20plaintext%20on%20the%20Host%20(i.MX%208M)%20once%20it%20has%20been%20wrapped.%3CBR%20%2F%3ETherefore%2C%20my%20goal%20is%20to%20ensure%20that%20after%20initial%20wrapping%2C%20all%20key%20unwrapping%20and%20file%20encryption%2Fdecryption%20operations%20are%20executed%20entirely%20inside%20the%20SE051%20without%20ever%20revealing%20the%20plain%20DEK%20to%20the%20host.%3C%2FP%3E%3CP%3ETarget%20Workflow%3A%3CBR%20%2F%3E%5B%20Phase%201%3A%20Key%20Provisioning%20%26amp%3B%20Wrapping%20%5D%3CBR%20%2F%3E1.%20Store%20the%20Key%20Encryption%20Key%20(KEK)%20into%20SE051.%3CBR%20%2F%3E2.%20Import%20the%20Plain%20DEK%20to%20SE051%2C%20wrap%20it%20using%20KEK%20inside%20SE051%2C%20and%20export%20the%20Wrapped%20DEK%20to%20Host%20Storage.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%221_Key_Provisioning_and_Wrapping.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%221_Key_Provisioning_and_Wrapping.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F395469i727A83B2C66D0D78%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%221_Key_Provisioning_and_Wrapping.png%22%20alt%3D%221_Key_Provisioning_and_Wrapping.png%22%20%2F%3E%3Cspan%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3E1_Key_Provisioning_and_Wrapping.png%3C%2Fspan%3E%3C%2Fspan%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3E1_Key_Provisioning_and_Wrapping.png%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%5B%20Phase%202%3A%20Runtime%20File%20Protection%20%5D%3CBR%20%2F%3E3.%20Send%20the%20Plain%20File%20and%20Wrapped%20DEK%20to%20SE051%20-%26gt%3B%20SE051%20unwraps%20the%20DEK%20internally%20and%20encrypts%20the%20file%20-%26gt%3B%20Output%20Encrypted%20File%20to%20Host.%3CBR%20%2F%3E4.%20Send%20the%20Encrypted%20File%20and%20Wrapped%20DEK%20to%20SE051%20-%26gt%3B%20SE051%20unwraps%20the%20DEK%20internally%20and%20decrypts%20the%20file%20-%26gt%3B%20Output%20Plain%20File%20to%20Host.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%222_Runtime_File_Protection.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%222_Runtime_File_Protection.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F395470iBE41B1A9B3F3B463%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%222_Runtime_File_Protection.png%22%20alt%3D%222_Runtime_File_Protection.png%22%20%2F%3E%3Cspan%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3E2_Runtime_File_Protection.png%3C%2Fspan%3E%3C%2Fspan%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3E2_Runtime_File_Protection.png%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E(Please%20refer%20to%20the%20attached%20sequence%20diagram%20for%20details).%3C%2FP%3E%3CP%3EQuestions%3A%3C%2FP%3E%3COL%3E%3CLI%3EImplementation%20Method%20%26amp%3B%20API%20Guidance%3A%3CBR%20%2F%3EWhat%20is%20the%20recommended%20SSS%20API%20implementation%20method%20to%20execute%20this%20end-to-end%20workflow%20without%20revealing%20the%20plain%20DEK%20to%20the%20host%3F%3C%2FLI%3E%3CLI%3EKey%20Unwrapping%20%26amp%3B%20Transient%20Objects%3A%3CBR%20%2F%3EWhat%20specific%20SSS%20APIs%20and%20policies%20are%20required%20to%20import%20a%20Wrapped%20DEK%2C%20unwrap%20it%20within%20SE051%2C%20and%20hold%20it%20as%20a%20transient%20key%20object%20for%20immediate%20file%20encryption%2Fdecryption%3F%3C%2FLI%3E%3CLI%3EReference%20Code%3A%3CBR%20%2F%3EAre%20there%20any%20code%20samples%20in%20Plug%20%26amp%3B%20Trust%20MW%20v04.00.00%20that%20demonstrate%20key%20wrapping%2Funwrapping%20combined%20with%20symmetric%20encryption%20operations%20inside%20SE051%3F%3C%2FLI%3E%3C%2FOL%3E%3CP%3EEnvironment%3A%3C%2FP%3E%3CUL%3E%3CLI%3EBoard%3A%20MCIMX8M-WEVK%20and%20OM-SE051ARD%3C%2FLI%3E%3CLI%3ELinux%20version%3A%205.4.70-2.3.2%2Bg8c73bc625c4d%20(SE-PLUG-TRUST-SD-CARD-IMAGE-IMX8M-NEW)%3C%2FLI%3E%3CLI%3EPlug%20%26amp%3B%20Trust%20MW%20version%3A%20v04.00.00%3C%2FLI%3E%3C%2FUL%3E%3CP%3EAny%20guidance%20or%20example%20code%20snippets%20would%20be%20greatly%20appreciated.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2409030%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CLINGO-LABEL%3ESE050%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2409114%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20Store%20KEK%20and%20Use%20Wrapped%20DEK%20using%20SSS%20API%20on%20SE051%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2409114%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F265995%22%20target%3D%22_blank%22%3E%40Fjk%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EThanks%20for%20the%20reaching%20out!%20Please%20have%20my%20comments%20as%20below%3A%3C%2FP%3E%0A%3CP%3EQ1%3A%20Implementation%20Method%20%26amp%3B%20API%20Guidance%3A%3C%2FP%3E%0A%3CP%3EWhat%20is%20the%20recommended%20SSS%20API%20implementation%20method%20to%20execute%20this%20end-to-end%20workflow%20without%20revealing%20the%20plain%20DEK%20to%20the%20host%3F%3C%2FP%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3EThe%20correct%20approach%20uses%20a%20two-layer%20API%20strategy%3A%3C%2FP%3E%0A%3CUL%20class%3D%22p8i6j07%20p8i6j02%22%3E%0A%3CLI%20class%3D%22p8i6j0a%22%3E%3CSTRONG%3EKey%20management%3C%2FSTRONG%3E%20(KEK%20store%2C%20DEK%20wrap%2Funwrap)%3A%20Use%20%3CCODE%20class%3D%22p8i6j0f%22%3ESe05x_API_ExportObject()%3C%2FCODE%3E%20%2F%20%3CCODE%20class%3D%22p8i6j0f%22%3ESe05x_API_ImportObject()%3C%2FCODE%3E%20from%20%3CCODE%20class%3D%22p8i6j0f%22%3Ese05x_APDU_apis.h%3C%2FCODE%3E.%20These%20operate%20entirely%20inside%20the%20SE051%20and%20are%20the%20only%20way%20to%20wrap%2Funwrap%20a%20key%20using%20another%20key%20stored%20in%20SE051%20without%20ever%20revealing%20plaintext%20to%20the%20host.%3C%2FLI%3E%0A%3CLI%20class%3D%22p8i6j0a%22%3E%3CSTRONG%3EFile%20encryption%2Fdecryption%3C%2FSTRONG%3E%3A%20Use%20%3CCODE%20class%3D%22p8i6j0f%22%3Esss_cipher_one_go()%3C%2FCODE%3E%20(or%20%3CCODE%20class%3D%22p8i6j0f%22%3Esss_cipher_init%3C%2FCODE%3E%20%2B%20%3CCODE%20class%3D%22p8i6j0f%22%3Esss_cipher_update%3C%2FCODE%3E%20%2B%20%3CCODE%20class%3D%22p8i6j0f%22%3Esss_cipher_finish%3C%2FCODE%3E%20for%20large%20files)%20against%20the%20transient%20DEK%20object%20created%20by%20the%20import%20step%20above.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3EThe%20SSS%20high-level%20layer%20(%3CCODE%20class%3D%22p8i6j0f%22%3Esss_key_store_set_key%3C%2FCODE%3E)%20%3CSTRONG%3Ecannot%3C%2FSTRONG%3E%20be%20used%20for%20DEK%20import-from-wrapped%2C%20because%20it%20always%20requires%20the%20key%20in%20plaintext%20on%20the%20host%20side.%20The%20APDU-level%20%3CCODE%20class%3D%22p8i6j0f%22%3ESe05x_API_ImportObject%3C%2FCODE%3E%20is%20required%20for%20the%20unwrap%20step%20to%20remain%20fully%20inside%20SE051.%3C%2FP%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3EQ2%20%3A%20Key%20Unwrapping%20%26amp%3B%20Transient%20Objects%3A%3C%2FP%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3EWhat%20specific%20SSS%20APIs%20and%20policies%20are%20required%20to%20import%20a%20Wrapped%20DEK%2C%20unwrap%20it%20within%20SE051%2C%20and%20hold%20it%20as%20a%20transient%20key%20object%20for%20immediate%20file%20encryption%2Fdecryption%3F%3C%2FP%3E%0A%3CH4%20class%3D%22_9k2iva0%20p8i6j0c%20_1ibi0s314%20heading4%20_9k2iva1%22%20id%3D%22toc-hId-258258443%22%20id%3D%22toc-hId-258260429%22%3EPhase%201%3A%20Key%20Provisioning%20%26amp%3B%20Wrapping%3C%2FH4%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3E%3CSTRONG%3EStep%201%20%E2%80%94%20Store%20the%20KEK%20as%20a%20persistent%20object%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%2F%2F%20Policy%20for%20KEK%3A%20allow%20ENC%2FDEC%20and%20IMPORT_EXPORT%20(for%20use%20as%20wrapping%20key)%3CBR%20%2F%3Esss_policy_u%20kekPolicyList%5B%5D%20%3D%20%7B%3CBR%20%2F%3E%7B%20.type%20%3D%20KPolicy_Sym_Key%2C%3CBR%20%2F%3E.policy%20%3D%20%7B%20.symmkey%20%3D%20%7B%20.can_Encrypt%20%3D%201%2C%20.can_Decrypt%20%3D%201%2C%3CBR%20%2F%3E.can_Import_Export%20%3D%201%20%7D%20%7D%20%7D%3CBR%20%2F%3E%7D%3B%3CBR%20%2F%3Esss_policy_t%20kekPolicy%20%3D%20%7B%20.nPolicies%20%3D%201%2C%20.policies%20%3D%20kekPolicyList%20%7D%3B%3C%2FP%3E%0A%3CP%3Esss_object_t%20kekObject%20%3D%20%7B0%7D%3B%3CBR%20%2F%3Esss_key_object_init(%26amp%3BkekObject%2C%20%26amp%3BpCtx-%26gt%3Bks)%3B%3CBR%20%2F%3Esss_key_object_allocate_handle(%26amp%3BkekObject%2C%20KEK_KEY_ID%2C%3CBR%20%2F%3EkSSS_KeyPart_Default%2C%20kSSS_CipherType_AES%2C%3CBR%20%2F%3EAES256_KEY_BYTES%2C%20kKeyObject_Mode_Persistent)%3B%3CBR%20%2F%3Esss_key_store_set_key(%26amp%3BpCtx-%26gt%3Bks%2C%20%26amp%3BkekObject%2C%3CBR%20%2F%3EkekData%2C%20kekLen%2C%20kekLen%20*%208%2C%20%26amp%3BkekPolicy%2C%20sizeof(kekPolicy))%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EStep%202%20%E2%80%94%20Import%20the%20plain%20DEK%20into%20SE051%20as%20a%20transient%20object%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%2F%2F%20Policy%20for%20DEK%3A%20allow%20ENC%2FDEC%20and%20IMPORT_EXPORT%20(so%20it%20can%20be%20wrapped%20for%20export)%3CBR%20%2F%3Esss_policy_u%20dekPolicyList%5B%5D%20%3D%20%7B%3CBR%20%2F%3E%7B%20.type%20%3D%20KPolicy_Sym_Key%2C%3CBR%20%2F%3E.policy%20%3D%20%7B%20.symmkey%20%3D%20%7B%20.can_Encrypt%20%3D%201%2C%20.can_Decrypt%20%3D%201%2C%3CBR%20%2F%3E.can_Import_Export%20%3D%201%20%7D%20%7D%20%7D%3CBR%20%2F%3E%7D%3B%3CBR%20%2F%3Esss_policy_t%20dekPolicy%20%3D%20%7B%20.nPolicies%20%3D%201%2C%20.policies%20%3D%20dekPolicyList%20%7D%3B%3C%2FP%3E%0A%3CP%3Esss_object_t%20dekObject%20%3D%20%7B0%7D%3B%3CBR%20%2F%3Esss_key_object_init(%26amp%3BdekObject%2C%20%26amp%3BpCtx-%26gt%3Bks)%3B%3CBR%20%2F%3Esss_key_object_allocate_handle(%26amp%3BdekObject%2C%20DEK_TEMP_ID%2C%3CBR%20%2F%3EkSSS_KeyPart_Default%2C%20kSSS_CipherType_AES%2C%3CBR%20%2F%3EAES256_KEY_BYTES%2C%20kKeyObject_Mode_Transient)%3B%3CBR%20%2F%3Esss_key_store_set_key(%26amp%3BpCtx-%26gt%3Bks%2C%20%26amp%3BdekObject%2C%3CBR%20%2F%3EplainDEK%2C%20dekLen%2C%20dekLen%20*%208%2C%20%26amp%3BdekPolicy%2C%20sizeof(dekPolicy))%3B%3CBR%20%2F%3E%2F%2F%20plainDEK%20is%20the%20ONLY%20moment%20the%20DEK%20appears%20on%20the%20host%20%E2%80%94%20during%20initial%20provisioning%20only%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EStep%203%20%E2%80%94%20Export%20the%20DEK%20wrapped%20by%20the%20KEK%20(entirely%20inside%20SE051)%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%2F%2F%20Se05x_API_ExportObject%20wraps%20DEK_TEMP_ID%20using%20KEK_KEY_ID%20%E2%80%94%20no%20plaintext%20leaves%20SE051%3CBR%20%2F%3Euint8_t%20wrappedDEK%5BAES256_KEY_BYTES%20%2B%208%5D%3B%20%2F%2F%20RFC%203394%20adds%208%20bytes%20overhead%3CBR%20%2F%3Esize_t%20wrappedDEKLen%20%3D%20sizeof(wrappedDEK)%3B%3C%2FP%3E%0A%3CP%3EpSe05xSession_t%20se05xSession%20%3D%3CBR%20%2F%3E%26amp%3B((sss_se05x_session_t%20*)%26amp%3BpCtx-%26gt%3Bsession)-%26gt%3Bs_ctx%3B%3C%2FP%3E%0A%3CP%3ESe05x_API_ExportObject(se05xSession%2C%3CBR%20%2F%3EDEK_TEMP_ID%2C%20%2F%2F%20Object%20to%20wrap%20(the%20transient%20DEK)%3CBR%20%2F%3EkSE05x_TransientIndicator_TRANSIENT%2C%3CBR%20%2F%3EwrappedDEK%2C%3CBR%20%2F%3E%26amp%3BwrappedDEKLen)%3B%3CBR%20%2F%3E%2F%2F%20Store%20wrappedDEK%20to%20host%20persistent%20storage%20%E2%80%94%20safe%2C%20never%20reveals%20plaintext%20DEK%3C%2FP%3E%0A%3CP%3E%2F%2FPlease%20note%26nbsp%3BThe%20transient%20%3CCODE%20class%3D%22p8i6j0f%22%3EDEK_TEMP_ID%3C%2FCODE%3E%20object%20is%20automatically%20deleted%20when%20the%20session%20closes.%20After%20exporting%20the%20wrapped%20DEK%2C%20the%20plain%20DEK%20is%20gone%20from%20SE051.%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EPhase%202%3A%20Runtime%20File%20Protection%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EStep%204%20%E2%80%94%20Import%20wrapped%20DEK%3A%20SE051%20unwraps%20internally%20using%20KEK%2C%20stores%20as%20transient%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%2F%2F%20Se05x_API_ImportObject%20unwraps%20the%20wrapped%20DEK%20using%20KEK_KEY_ID%20INSIDE%20SE051%3CBR%20%2F%3E%2F%2F%20The%20DEK%20never%20appears%20in%20plaintext%20on%20the%20host%20%E2%80%94%20this%20is%20the%20key%20security%20guarantee%3CBR%20%2F%3ESe05x_API_ImportObject(se05xSession%2C%3CBR%20%2F%3EDEK_RUNTIME_ID%2C%20%2F%2F%20Target%20object%20ID%20for%20the%20unwrapped%20DEK%3CBR%20%2F%3EkSE05x_RSAKeyComponent_NA%2C%20%2F%2F%20N%2FA%20for%20symmetric%20keys%3CBR%20%2F%3ENULL%2C%20%2F%2F%20Use%20default%20policy%3CBR%20%2F%3E0%2C%3CBR%20%2F%3EwrappedDEK%2C%20%2F%2F%20Wrapped%20DEK%20from%20host%20storage%3CBR%20%2F%3EwrappedDEKLen%2C%3CBR%20%2F%3EkSE05x_TransientIndicator_TRANSIENT%2C%20%2F%2F%20Store%20as%20transient%20%E2%80%94%20clears%20on%20session%20end%3CBR%20%2F%3EKEK_KEY_ID)%3B%20%2F%2F%20SE051%20uses%20this%20key%20to%20unwrap%20internally%3CSTRONG%3E%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EStep%205%20%E2%80%94%20Encrypt%2FDecrypt%20the%20file%20using%20the%20transient%20DEK%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%2F%2F%20Get%20handle%20to%20the%20now-unwrapped%20transient%20DEK%3CBR%20%2F%3Esss_object_t%20dekTransient%20%3D%20%7B0%7D%3B%3CBR%20%2F%3Esss_key_object_init(%26amp%3BdekTransient%2C%20%26amp%3BpCtx-%26gt%3Bks)%3B%3CBR%20%2F%3Esss_key_object_get_handle(%26amp%3BdekTransient%2C%20DEK_RUNTIME_ID)%3B%3C%2FP%3E%0A%3CP%3E%2F%2F%20Encrypt%3CBR%20%2F%3Esss_symmetric_t%20ctxEncrypt%20%3D%20%7B0%7D%3B%3CBR%20%2F%3Esss_symmetric_context_init(%26amp%3BctxEncrypt%2C%20%26amp%3BpCtx-%26gt%3Bsession%2C%20%26amp%3BdekTransient%2C%3CBR%20%2F%3EkAlgorithm_SSS_AES_CBC%2C%20kMode_SSS_Encrypt)%3B%3CBR%20%2F%3Esss_cipher_one_go(%26amp%3BctxEncrypt%2C%20iv%2C%20ivLen%2C%3CBR%20%2F%3EplainFileData%2C%20encryptedFileData%2C%20dataLen)%3B%3CBR%20%2F%3Esss_symmetric_context_free(%26amp%3BctxEncrypt)%3B%3C%2FP%3E%0A%3CP%3E%2F%2F%20Decrypt%20(same%20pattern%2C%20change%20mode%20to%20kMode_SSS_Decrypt)%3CBR%20%2F%3Esss_symmetric_t%20ctxDecrypt%20%3D%20%7B0%7D%3B%3CBR%20%2F%3Esss_symmetric_context_init(%26amp%3BctxDecrypt%2C%20%26amp%3BpCtx-%26gt%3Bsession%2C%20%26amp%3BdekTransient%2C%3CBR%20%2F%3EkAlgorithm_SSS_AES_CBC%2C%20kMode_SSS_Decrypt)%3B%3CBR%20%2F%3Esss_cipher_one_go(%26amp%3BctxDecrypt%2C%20iv%2C%20ivLen%2C%3CBR%20%2F%3EencryptedFileData%2C%20decryptedFileData%2C%20dataLen)%3B%3CBR%20%2F%3Esss_symmetric_context_free(%26amp%3BctxDecrypt)%3B%3C%2FP%3E%0A%3CP%3E%2F%2F%20Explicitly%20erase%20transient%20DEK%20after%20use%20(optional%2C%20also%20cleared%20on%20session%20close)%3CBR%20%2F%3Esss_key_store_erase_key(%26amp%3BpCtx-%26gt%3Bks%2C%20%26amp%3BdekTransient)%3B%3CBR%20%2F%3Esss_key_object_free(%26amp%3BdekTransient)%3B%3C%2FP%3E%0A%3CP%3EQ3%3A%20Reference%20Code%3A%3C%2FP%3E%0A%3CP%3EAre%20there%20any%20code%20samples%20in%20Plug%20%26amp%3B%20Trust%20MW%20v04.00.00%20that%20demonstrate%20key%20wrapping%2Funwrapping%20combined%20with%20symmetric%20encryption%20operations%20inside%20SE051%3F%3C%2FP%3E%0A%3CP%3EThere%20is%20no%20single%20example%20that%20combines%20key%20wrapping%20%2B%20symmetric%20encryption%20end-to-end%2C%20but%20the%20following%20examples%20should%20be%20helpful.%3C%2FP%3E%0A%3CTABLE%3E%0A%3CTHEAD%3E%0A%3CTR%3E%0A%3CTH%20scope%3D%22col%22%3EPurpose%3C%2FTH%3E%0A%3CTH%20scope%3D%22col%22%3EPath%20in%20simw-top%2F%3C%2FTH%3E%0A%3C%2FTR%3E%0A%3C%2FTHEAD%3E%0A%3CTBODY%3E%0A%3CTR%3E%0A%3CTD%3EAES%20symmetric%20encrypt%2Fdecrypt%3C%2FTD%3E%0A%3CTD%3Esss%2Fex%2Fsymmetric%2Fex_sss_symmetric.c%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%3EUsing%20object%20policies%3C%2FTD%3E%0A%3CTD%3Edemos%2Fse05x%2Fse05x_policy%2F%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%3EKey%20export%2Fimport%20at%20APDU%20level%3C%2FTD%3E%0A%3CTD%3Ehostlib%2FhostLib%2Fse05x%2Fsrc%2Fse05x_APDU_apis.c%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3C%2FTBODY%3E%0A%3C%2FTABLE%3E%0A%3CBR%20%2F%3E%0A%3CP%3EHope%20that%20helps%2C%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EHave%20a%20great%20day%2C%3CBR%20%2F%3EKan%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E-------------------------------------------------------------------------------%3CBR%20%2F%3ENote%3A%3CBR%20%2F%3E-%20If%20this%20post%20answers%20your%20question%2C%20please%20click%20the%20%22Mark%20Correct%22%20button.%20Thank%20you!%3CBR%20%2F%3E-%20We%20are%20following%20threads%20for%207%20weeks%20after%20the%20last%20post%2C%20later%20replies%20are%20ignored%3CBR%20%2F%3EPlease%20open%20a%20new%20thread%20and%20refer%20to%20the%20closed%20one%2C%20if%20you%20have%20a%20related%20question%20at%20a%20later%20point%20in%20time.%3CBR%20%2F%3E-------------------------------------------------------------------------------%3C%2FP%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E