How to revert Platform SCP03 keys back to default using se05x_TP_PlatformSCP03keys.c?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to revert Platform SCP03 keys back to default using se05x_TP_PlatformSCP03keys.c?

39 Views
Uc_S
Contributor II

Hello NXP Community,

I am working with the SE051 secure element and would like to ask how to properly revert the Platform SCP03 keys back to their default values using the Plug and Trust Middleware.

What I have done so far:

  1. I modified demos/se05x/se05x_RotatePlatformSCP03Keys/se05x_TP_PlatformSCP03keys.c by commenting out the key reversion section (between doc:start:revert-scp03-keys and doc:end:revert-scp03-keys).
  2. I built and executed the application on my setup.
  3. The execution was successful, showing the message: "Congratulations !!! Key Rotation Successful!!!!"
  4. To verify the key change, I updated /tmp/SE05X/plain_scp.txt with the new key value (0x4041... for ENC, MAC, and DEK) and successfully connected via ssscli connect.
  5. Subsequent operations (ssscli generate rsa, ssscli set aes, and ssscli se05x readidlist) were all completed successfully, confirming that keys were written and IDs were retrieved without issues.
  6. Now, I would like to restore the Platform SCP03 keys back to the default keys (defined in sss/ex/inc/ex_sss_tp_scp03_keys.h).

Could anyone guide me on how to modify se05x_TP_PlatformSCP03keys.c or what the correct process is to perform this key reversion?

Environment:

  • Board: MCIMX8M-WEVK with OM-SE051ARD
  • Plug and Trust MW Version: v04.07.01
  • OP-TEE OS Version: 3.19.0
  • Linux Kernel: 6.1.151
  • OEF ID: A8FA

Any advice or code pointers would be greatly appreciated.

Labels (1)
0 Kudos
Reply
3 Replies

19 Views
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @Uc_S ,

 

Rotating the Platform SCP03 keys back to the default values is only possible when the current keys are known, as a successfully authenticated SCP03 session is required before any key update (PutKey) command can be issued to the SE051.

If the current keys have been lost or forgotten, it is not possible to authenticate to the SE051 and perform the key rotation. There is no backdoor or override mechanism — this is by design to preserve the security model of the device.

Additionally, a factory reset does not help, as Platform SCP03 keys are explicitly unaffected by the factory reset procedure.

In this situation, the only option is to replace the SE051 with a new device that still carries the default NXP-provisioned keys.

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

0 Kudos
Reply

14 Views
Uc_S
Contributor II

@Kan_Li 

Thank you for the clarification.

In my case, the current keys are known (0x4041... for ENC, MAC, and DEK), and I can successfully establish an SCP03 session using these keys via ssscli.

Since I have the current keys available to authenticate, could you please provide details on how to modify se05x_TP_PlatformSCP03keys.c to perform the key rotation back to the default values?

Specifically, I would like to know:

  • Which variables or macros should be updated with the current keys (0x4041...) for authentication during session setup.
  • Which variables or structures should hold the target default key values (ex_sss_tp_scp03_keys.h) for the PutKey operation.

Any code snippets or specific line references in se05x_TP_PlatformSCP03keys.c (or related boot/auth headers) would be greatly appreciated.

Tags (2)
0 Kudos
Reply

8 Views
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @Uc_S ,

If you just need to rotate the keys back to the default, the nano-package example is the recommended simpler path — only the three scp03_* arrays (current keys for auth) and the three NEW_scp03_* arrays (default keys as target) need to be updated, and the revert call within ex_se05x_rotate_scp03_keys() needs to be commented out. Please refer to the following for details.

Change 1 — Set the current keys (used to open the SCP03 session)

Lines 38–43 are the auth keys passed to ex_set_scp03_keys(). Replace the placeholder 0xABCD... values with your current keys (0x4041...

uint8_t scp03_enc_key[AES_KEY_LEN_nBYTE] = {
    0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47,
    0x48, 0x49, 0x4A, 0x4B, 0x4C, 0x4D, 0x4E, 0x4F };

uint8_t scp03_mac_key[AES_KEY_LEN_nBYTE] = {
    0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47,
    0x48, 0x49, 0x4A, 0x4B, 0x4C, 0x4D, 0x4E, 0x4F };

uint8_t scp03_dek_key[AES_KEY_LEN_nBYTE] = {
    0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47,
    0x48, 0x49, 0x4A, 0x4B, 0x4C, 0x4D, 0x4E, 0x4F };
c
 

Change 2 — Set the NEW target keys (the default SE051C A8FA keys)

Lines 45–50 are the keys that will be written into the SE051 via PutKey. Replace the 0x4041... placeholder with the SE051C OEF A8FA default values:

uint8_t NEW_scp03_enc_key[AES_KEY_LEN_nBYTE] = {
    0xbf, 0xc2, 0xdb, 0xe1, 0x82, 0x8e, 0x03, 0x5d,
    0x3e, 0x7f, 0xa3, 0x6b, 0x90, 0x2a, 0x05, 0xc6 };

uint8_t NEW_scp03_mac_key[AES_KEY_LEN_nBYTE] = {
    0xbe, 0xf8, 0x5b, 0xd7, 0xba, 0x04, 0x97, 0xd6,
    0x28, 0x78, 0x1c, 0xe4, 0x7b, 0x18, 0x8c, 0x96 };

uint8_t NEW_scp03_dek_key[AES_KEY_LEN_nBYTE] = {
    0xd8, 0x73, 0xf3, 0x16, 0xbe, 0x29, 0x7f, 0x2f,
    0xc9, 0xc0, 0xe4, 0x5f, 0x54, 0x71, 0x06, 0x99 };
c
 

Change 3 — Comment out the revert block

In ex_se05x_rotate_scp03_keys(), comment out lines 85–90 so the code does a single rotation only (current → default) and does not try to rotate back again:

/* -- Comment out the revert block below -- */
// SMLOG_I("Reverting SCP03 keys(version - %02x) to OLD KEYS \n", KEY_VERSION);
// ret = ex_se05x_change_keys(&se05x_session, &scp03_enc_key[0], &scp03_mac_key[0], &scp03_dek_key[0]);
// if (ret != 0) {
//     SMLOG_E("Error in ex_se05x_change_keys \n");
//     return 1;
// }
c
 

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2411142%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EHow%20to%20revert%20Platform%20SCP03%20keys%20back%20to%20default%20using%20se05x_TP_PlatformSCP03keys.c%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2411142%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%20NXP%20Community%2C%3C%2FP%3E%3CP%3EI%20am%20working%20with%20the%20SE051%20secure%20element%20and%20would%20like%20to%20ask%20how%20to%20properly%20revert%20the%20Platform%20SCP03%20keys%20back%20to%20their%20default%20values%20using%20the%20Plug%20and%20Trust%20Middleware.%3C%2FP%3E%3CH4%20id%3D%22toc-hId-258943727%22%20id%3D%22toc-hId-258947482%22%3EWhat%20I%20have%20done%20so%20far%3A%3C%2FH4%3E%3COL%3E%3CLI%3EI%20modified%20demos%2Fse05x%2Fse05x_RotatePlatformSCP03Keys%2Fse05x_TP_PlatformSCP03keys.c%20by%20commenting%20out%20the%20key%20reversion%20section%20(between%20doc%3Astart%3Arevert-scp03-keys%20and%20doc%3Aend%3Arevert-scp03-keys).%3C%2FLI%3E%3CLI%3EI%20built%20and%20executed%20the%20application%20on%20my%20setup.%3C%2FLI%3E%3CLI%3EThe%20execution%20was%20successful%2C%20showing%20the%20message%3A%20%22Congratulations%20!!!%20Key%20Rotation%20Successful!!!!%22%3C%2FLI%3E%3CLI%3ETo%20verify%20the%20key%20change%2C%20I%20updated%20%2Ftmp%2FSE05X%2Fplain_scp.txt%20with%20the%20new%20key%20value%20(0x4041...%20for%20ENC%2C%20MAC%2C%20and%20DEK)%20and%20successfully%20connected%20via%20ssscli%20connect.%3C%2FLI%3E%3CLI%3ESubsequent%20operations%20(ssscli%20generate%20rsa%2C%20ssscli%20set%20aes%2C%20and%20ssscli%20se05x%20readidlist)%20were%20all%20completed%20successfully%2C%20confirming%20that%20keys%20were%20written%20and%20IDs%20were%20retrieved%20without%20issues.%3C%2FLI%3E%3CLI%3ENow%2C%20I%20would%20like%20to%20restore%20the%20Platform%20SCP03%20keys%20back%20to%20the%20default%20keys%20(defined%20in%20sss%2Fex%2Finc%2Fex_sss_tp_scp03_keys.h).%3C%2FLI%3E%3C%2FOL%3E%3CP%3ECould%20anyone%20guide%20me%20on%20how%20to%20modify%20se05x_TP_PlatformSCP03keys.c%20or%20what%20the%20correct%20process%20is%20to%20perform%20this%20key%20reversion%3F%3C%2FP%3E%3CH4%20id%3D%22toc-hId--1548510736%22%20id%3D%22toc-hId--1548506981%22%3EEnvironment%3A%3C%2FH4%3E%3CUL%3E%3CLI%3EBoard%3A%20MCIMX8M-WEVK%20with%20OM-SE051ARD%3C%2FLI%3E%3CLI%3EPlug%20and%20Trust%20MW%20Version%3A%20v04.07.01%3C%2FLI%3E%3CLI%3EOP-TEE%20OS%20Version%3A%203.19.0%3C%2FLI%3E%3CLI%3ELinux%20Kernel%3A%206.1.151%3C%2FLI%3E%3CLI%3EOEF%20ID%3A%20A8FA%3C%2FLI%3E%3C%2FUL%3E%3CP%3EAny%20advice%20or%20code%20pointers%20would%20be%20greatly%20appreciated.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2411142%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CLINGO-LABEL%3ESE050%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2411228%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20revert%20Platform%20SCP03%20keys%20back%20to%20default%20using%20se05x_TP_PlatformSCP03keys.c%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2411228%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F259681%22%20target%3D%22_blank%22%3E%40Uc_S%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%0A%3CP%3EIf%20you%20just%20need%20to%20rotate%20the%20keys%20back%20to%20the%20default%2C%26nbsp%3Bthe%20nano-package%20example%20is%20the%20%3CSTRONG%3Erecommended%20simpler%20path%3C%2FSTRONG%3E%20%E2%80%94%20only%20the%20three%20%3CCODE%20class%3D%22p8i6j0f%22%3Escp03_*%3C%2FCODE%3E%20arrays%20(current%20keys%20for%20auth)%20and%20the%20three%20%3CCODE%20class%3D%22p8i6j0f%22%3ENEW_scp03_*%3C%2FCODE%3E%20arrays%20(default%20keys%20as%20target)%20need%20to%20be%20updated%2C%20and%20the%20revert%20call%20within%26nbsp%3Bex_se05x_rotate_scp03_keys()%20needs%20to%20be%20commented%20out.%20Please%20refer%20to%20the%20following%20for%20details.%3C%2FP%3E%0A%3CH3%20class%3D%22_9k2iva0%20p8i6j0c%20_1ibi0s314%20heading3%20_9k2iva1%22%20id%3D%22toc-hId-2055895991%22%20id%3D%22toc-hId--1559010085%22%3EChange%201%20%E2%80%94%20Set%20the%20current%20keys%20(used%20to%20open%20the%20SCP03%20session)%3C%2FH3%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3ELines%2038%E2%80%9343%20are%20the%20auth%20keys%20passed%20to%20%3CCODE%20class%3D%22p8i6j0f%22%3Eex_set_scp03_keys()%3C%2FCODE%3E.%20Replace%20the%20placeholder%20%3CCODE%20class%3D%22p8i6j0f%22%3E0xABCD...%3C%2FCODE%3E%20values%20with%20your%20%3CSTRONG%3Ecurrent%20keys%3C%2FSTRONG%3E%20(%3CCODE%20class%3D%22p8i6j0f%22%3E0x4041...%3C%2FCODE%3E%3CLI-EMOJI%20id%3D%22lia_disappointed-face%22%20title%3D%22%3Adisappointed_face%3A%22%3E%3C%2FLI-EMOJI%3E%20%3CA%20id%3D%22base-ui-%3Ar4q5%3A%22%20class%3D%22wdbi343%20wdbi341%20_1ibi0s3ec%20_1ibi0s376%22%20tabindex%3D%220%22%20role%3D%22button%22%20href%3D%22https%3A%2F%2Fraw.githubusercontent.com%2FNXPPlugNTrust%2Fnano-package%2Fmaster%2Fexamples%2Fse05x_rotate_scp03_keys%2Fsrc%2Fex_se05x_rotate_scp03_keys.c%22%20rel%3D%22noreferrer%20nofollow%20noopener%22%20aria-expanded%3D%22false%22%20aria-haspopup%3D%22dialog%22%20data-base-ui-click-trigger%3D%22%22%20data-label%3D%222%22%20aria-label%3D%22Citation%202%22%20target%3D%22_blank%22%3E%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%20class%3D%22l8rrz21%20_1ibi0s3en%22%20data-ui-element%3D%22code-block-container%22%3E%0A%3CPRE%3E%3CCODE%20class%3D%22markdown-code-c%20p8i6j0e%20hljs%20language-c%20_12n1b832%22%3E%3CSPAN%20class%3D%22hljs-type%22%3Euint8_t%3C%2FSPAN%3E%20scp03_enc_key%5BAES_KEY_LEN_nBYTE%5D%20%3D%20%7B%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0x40%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x41%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x42%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x43%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x44%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x45%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x46%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x47%3C%2FSPAN%3E%2C%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0x48%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x49%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4A%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4B%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4C%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4D%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4E%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4F%3C%2FSPAN%3E%20%7D%3B%0A%0A%3CSPAN%20class%3D%22hljs-type%22%3Euint8_t%3C%2FSPAN%3E%20scp03_mac_key%5BAES_KEY_LEN_nBYTE%5D%20%3D%20%7B%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0x40%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x41%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x42%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x43%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x44%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x45%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x46%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x47%3C%2FSPAN%3E%2C%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0x48%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x49%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4A%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4B%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4C%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4D%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4E%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4F%3C%2FSPAN%3E%20%7D%3B%0A%0A%3CSPAN%20class%3D%22hljs-type%22%3Euint8_t%3C%2FSPAN%3E%20scp03_dek_key%5BAES_KEY_LEN_nBYTE%5D%20%3D%20%7B%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0x40%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x41%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x42%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x43%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x44%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x45%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x46%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x47%3C%2FSPAN%3E%2C%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0x48%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x49%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4A%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4B%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4C%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4D%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4E%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x4F%3C%2FSPAN%3E%20%7D%3B%0A%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CDIV%20class%3D%22l8rrz23%20_1ibi0s3dp%20_1ibi0s332%20_1ibi0s3eo%20_1ibi0s3bm%20_1ibi0s3ce%22%3E%0A%3CDIV%20class%3D%22l8rrz25%20_1ibi0s3eb%22%3Ec%3C%2FDIV%3E%0A%3CDIV%20class%3D%22lqznwq0%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3CH3%20class%3D%22_9k2iva0%20p8i6j0c%20_1ibi0s314%20heading3%20_9k2iva1%22%20id%3D%22toc-hId-248441528%22%20id%3D%22toc-hId-928502748%22%3EChange%202%20%E2%80%94%20Set%20the%20NEW%20target%20keys%20(the%20default%20SE051C%20A8FA%20keys)%3C%2FH3%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3ELines%2045%E2%80%9350%20are%20the%20keys%20that%20will%20be%20%3CSTRONG%3Ewritten%20into%20the%20SE051%3C%2FSTRONG%3E%20via%20%3CCODE%20class%3D%22p8i6j0f%22%3EPutKey%3C%2FCODE%3E.%20Replace%20the%20%3CCODE%20class%3D%22p8i6j0f%22%3E0x4041...%3C%2FCODE%3E%20placeholder%20with%20the%20SE051C%20OEF%20A8FA%20default%20values%3A%20%3CA%20id%3D%22base-ui-%3Ar4qa%3A%22%20class%3D%22wdbi343%20wdbi341%20_1ibi0s3ec%20_1ibi0s376%22%20tabindex%3D%220%22%20role%3D%22button%22%20href%3D%22https%3A%2F%2Fraw.githubusercontent.com%2FNXPPlugNTrust%2Fnano-package%2Fmaster%2Fexamples%2Fse05x_rotate_scp03_keys%2Fsrc%2Fex_se05x_rotate_scp03_keys.c%22%20rel%3D%22noreferrer%20nofollow%20noopener%22%20aria-expanded%3D%22false%22%20aria-haspopup%3D%22dialog%22%20data-base-ui-click-trigger%3D%22%22%20data-label%3D%222%22%20aria-label%3D%22Citation%202%22%20target%3D%22_blank%22%3E%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%20class%3D%22l8rrz21%20_1ibi0s3en%22%20data-ui-element%3D%22code-block-container%22%3E%0A%3CPRE%3E%3CCODE%20class%3D%22markdown-code-c%20p8i6j0e%20hljs%20language-c%20_12n1b832%22%3E%3CSPAN%20class%3D%22hljs-type%22%3Euint8_t%3C%2FSPAN%3E%20NEW_scp03_enc_key%5BAES_KEY_LEN_nBYTE%5D%20%3D%20%7B%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0xbf%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xc2%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xdb%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xe1%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x82%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x8e%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x03%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x5d%3C%2FSPAN%3E%2C%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0x3e%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x7f%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xa3%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x6b%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x90%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x2a%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x05%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xc6%3C%2FSPAN%3E%20%7D%3B%0A%0A%3CSPAN%20class%3D%22hljs-type%22%3Euint8_t%3C%2FSPAN%3E%20NEW_scp03_mac_key%5BAES_KEY_LEN_nBYTE%5D%20%3D%20%7B%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0xbe%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xf8%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x5b%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xd7%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xba%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x04%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x97%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xd6%3C%2FSPAN%3E%2C%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0x28%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x78%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x1c%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xe4%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x7b%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x18%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x8c%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x96%3C%2FSPAN%3E%20%7D%3B%0A%0A%3CSPAN%20class%3D%22hljs-type%22%3Euint8_t%3C%2FSPAN%3E%20NEW_scp03_dek_key%5BAES_KEY_LEN_nBYTE%5D%20%3D%20%7B%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0xd8%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x73%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xf3%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x16%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xbe%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x29%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x7f%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x2f%3C%2FSPAN%3E%2C%0A%20%20%20%20%3CSPAN%20class%3D%22hljs-number%22%3E0xc9%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xc0%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0xe4%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x5f%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x54%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x71%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x06%3C%2FSPAN%3E%2C%20%3CSPAN%20class%3D%22hljs-number%22%3E0x99%3C%2FSPAN%3E%20%7D%3B%0A%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CDIV%20class%3D%22l8rrz23%20_1ibi0s3dp%20_1ibi0s332%20_1ibi0s3eo%20_1ibi0s3bm%20_1ibi0s3ce%22%3E%0A%3CDIV%20class%3D%22l8rrz25%20_1ibi0s3eb%22%3Ec%3C%2FDIV%3E%0A%3CDIV%20class%3D%22lqznwq0%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3CH3%20class%3D%22_9k2iva0%20p8i6j0c%20_1ibi0s314%20heading3%20_9k2iva1%22%20id%3D%22toc-hId--1559012935%22%20id%3D%22toc-hId--878951715%22%3EChange%203%20%E2%80%94%20Comment%20out%20the%20revert%20block%3C%2FH3%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3EIn%20%3CCODE%20class%3D%22p8i6j0f%22%3Eex_se05x_rotate_scp03_keys()%3C%2FCODE%3E%2C%20comment%20out%20lines%2085%E2%80%9390%20so%20the%20code%20does%20a%20%3CSTRONG%3Esingle%20rotation%20only%3C%2FSTRONG%3E%20(current%20%E2%86%92%20default)%20and%20does%20not%20try%20to%20rotate%20back%20again%3A%20%3CA%20id%3D%22base-ui-%3Ar4qf%3A%22%20class%3D%22wdbi343%20wdbi341%20_1ibi0s3ec%20_1ibi0s376%22%20tabindex%3D%220%22%20role%3D%22button%22%20href%3D%22https%3A%2F%2Fraw.githubusercontent.com%2FNXPPlugNTrust%2Fnano-package%2Fmaster%2Fexamples%2Fse05x_rotate_scp03_keys%2Fsrc%2Fex_se05x_rotate_scp03_keys.c%22%20rel%3D%22noreferrer%20nofollow%20noopener%22%20aria-expanded%3D%22false%22%20aria-haspopup%3D%22dialog%22%20data-base-ui-click-trigger%3D%22%22%20data-label%3D%222%22%20aria-label%3D%22Citation%202%22%20target%3D%22_blank%22%3E%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%20class%3D%22l8rrz21%20_1ibi0s3en%22%20data-ui-element%3D%22code-block-container%22%3E%0A%3CPRE%3E%3CCODE%20class%3D%22markdown-code-c%20p8i6j0e%20hljs%20language-c%20_12n1b832%22%3E%3CSPAN%20class%3D%22hljs-comment%22%3E%2F*%20--%20Comment%20out%20the%20revert%20block%20below%20--%20*%2F%3C%2FSPAN%3E%0A%3CSPAN%20class%3D%22hljs-comment%22%3E%2F%2F%20SMLOG_I(%22Reverting%20SCP03%20keys(version%20-%20%2502x)%20to%20OLD%20KEYS%20%5Cn%22%2C%20KEY_VERSION)%3B%3C%2FSPAN%3E%0A%3CSPAN%20class%3D%22hljs-comment%22%3E%2F%2F%20ret%20%3D%20ex_se05x_change_keys(%26amp%3Bse05x_session%2C%20%26amp%3Bscp03_enc_key%5B0%5D%2C%20%26amp%3Bscp03_mac_key%5B0%5D%2C%20%26amp%3Bscp03_dek_key%5B0%5D)%3B%3C%2FSPAN%3E%0A%3CSPAN%20class%3D%22hljs-comment%22%3E%2F%2F%20if%20(ret%20!%3D%200)%20%7B%3C%2FSPAN%3E%0A%3CSPAN%20class%3D%22hljs-comment%22%3E%2F%2F%20%20%20%20%20SMLOG_E(%22Error%20in%20ex_se05x_change_keys%20%5Cn%22)%3B%3C%2FSPAN%3E%0A%3CSPAN%20class%3D%22hljs-comment%22%3E%2F%2F%20%20%20%20%20return%201%3B%3C%2FSPAN%3E%0A%3CSPAN%20class%3D%22hljs-comment%22%3E%2F%2F%20%7D%3C%2FSPAN%3E%0A%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CDIV%20class%3D%22l8rrz23%20_1ibi0s3dp%20_1ibi0s332%20_1ibi0s3eo%20_1ibi0s3bm%20_1ibi0s3ce%22%3E%0A%3CDIV%20class%3D%22l8rrz25%20_1ibi0s3eb%22%3Ec%3C%2FDIV%3E%0A%3CDIV%20class%3D%22lqznwq0%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3CH2%20class%3D%22_9k2iva0%20p8i6j0c%20_1ibi0s314%20heading2%20_9k2iva1%22%20id%3D%22toc-hId--1569516039%22%20id%3D%22toc-hId--889454819%22%3E%26nbsp%3B%3C%2FH2%3E%0A%3CP%3EHave%20a%20great%20day%2C%3CBR%20%2F%3EKan%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E-------------------------------------------------------------------------------%3CBR%20%2F%3ENote%3A%3CBR%20%2F%3E-%20If%20this%20post%20answers%20your%20question%2C%20please%20click%20the%20%22Mark%20Correct%22%20button.%20Thank%20you!%3CBR%20%2F%3E-%20We%20are%20following%20threads%20for%207%20weeks%20after%20the%20last%20post%2C%20later%20replies%20are%20ignored%3CBR%20%2F%3EPlease%20open%20a%20new%20thread%20and%20refer%20to%20the%20closed%20one%2C%20if%20you%20have%20a%20related%20question%20at%20a%20later%20point%20in%20time.%3CBR%20%2F%3E-------------------------------------------------------------------------------%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2411213%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20revert%20Platform%20SCP03%20keys%20back%20to%20default%20using%20se05x_TP_PlatformSCP03keys.c%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2411213%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F59276%22%20target%3D%22_blank%22%3E%40Kan_Li%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20the%20clarification.%3C%2FP%3E%3CP%3EIn%20my%20case%2C%20the%20current%20keys%20are%20known%20(0x4041...%20for%20ENC%2C%20MAC%2C%20and%20DEK)%2C%20and%20I%20can%20successfully%20establish%20an%20SCP03%20session%20using%20these%20keys%20via%20ssscli.%3C%2FP%3E%3CP%3ESince%20I%20have%20the%20current%20keys%20available%20to%20authenticate%2C%20could%20you%20please%20provide%20details%20on%20how%20to%20modify%20se05x_TP_PlatformSCP03keys.c%20to%20perform%20the%20key%20rotation%20back%20to%20the%20default%20values%3F%3C%2FP%3E%3CP%3ESpecifically%2C%20I%20would%20like%20to%20know%3A%3C%2FP%3E%3CUL%3E%3CLI%3EWhich%20variables%20or%20macros%20should%20be%20updated%20with%20the%20current%20keys%20(0x4041...)%20for%20authentication%20during%20session%20setup.%3C%2FLI%3E%3CLI%3EWhich%20variables%20or%20structures%20should%20hold%20the%20target%20default%20key%20values%20(ex_sss_tp_scp03_keys.h)%20for%20the%20PutKey%20operation.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EAny%20code%20snippets%20or%20specific%20line%20references%20in%20se05x_TP_PlatformSCP03keys.c%20(or%20related%20boot%2Fauth%20headers)%20would%20be%20greatly%20appreciated.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2411210%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20revert%20Platform%20SCP03%20keys%20back%20to%20default%20using%20se05x_TP_PlatformSCP03keys.c%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2411210%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F259681%22%20target%3D%22_blank%22%3E%40Uc_S%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3ERotating%20the%20Platform%20SCP03%20keys%20back%20to%20the%20default%20values%20is%20only%20possible%20when%20the%20%3CSTRONG%3Ecurrent%20keys%20are%20known%3C%2FSTRONG%3E%2C%20as%20a%20successfully%20authenticated%20SCP03%20session%20is%20required%20before%20any%20key%20update%20(%3CCODE%20class%3D%22p8i6j0f%22%3EPutKey%3C%2FCODE%3E)%20command%20can%20be%20issued%20to%20the%20SE051.%3C%2FP%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3EIf%20the%20current%20keys%20have%20been%20lost%20or%20forgotten%2C%20it%20is%20%3CSTRONG%3Enot%20possible%3C%2FSTRONG%3E%20to%20authenticate%20to%20the%20SE051%20and%20perform%20the%20key%20rotation.%20There%20is%20no%20backdoor%20or%20override%20mechanism%20%E2%80%94%20this%20is%20by%20design%20to%20preserve%20the%20security%20model%20of%20the%20device.%3C%2FP%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3EAdditionally%2C%20a%20factory%20reset%20does%20%3CSTRONG%3Enot%3C%2FSTRONG%3E%20help%2C%20as%20Platform%20SCP03%20keys%20are%20explicitly%20unaffected%20by%20the%20factory%20reset%20procedure.%20%3CA%20id%3D%22base-ui-%3Ar4ho%3A%22%20class%3D%22wdbi343%20wdbi341%20_1ibi0s3ec%20_1ibi0s376%22%20tabindex%3D%220%22%20role%3D%22button%22%20href%3D%22https%3A%2F%2Fnxp1-my.sharepoint.com%2Fpersonal%2Fkan_li_nxp_com%2FDocuments%2Fdata%2520sheet%2FSE051%2Fdoc%2FSE051%2520-%2520User%2520Guidelines(AN12730.pdf%3Fweb%3D1%22%20rel%3D%22noreferrer%20nofollow%20noopener%22%20aria-expanded%3D%22false%22%20aria-haspopup%3D%22dialog%22%20data-base-ui-click-trigger%3D%22%22%20data-label%3D%221%22%20aria-label%3D%22Citation%201%22%20target%3D%22_blank%22%3E%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3EIn%20this%20situation%2C%20the%20only%20option%20is%20to%20%3CSTRONG%3Ereplace%20the%20SE051%20with%20a%20new%20device%3C%2FSTRONG%3E%20that%20still%20carries%20the%20default%20NXP-provisioned%20keys.%3C%2FP%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHave%20a%20great%20day%2C%3CBR%20%2F%3EKan%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E-------------------------------------------------------------------------------%3CBR%20%2F%3ENote%3A%3CBR%20%2F%3E-%20If%20this%20post%20answers%20your%20question%2C%20please%20click%20the%20%22Mark%20Correct%22%20button.%20Thank%20you!%3CBR%20%2F%3E-%20We%20are%20following%20threads%20for%207%20weeks%20after%20the%20last%20post%2C%20later%20replies%20are%20ignored%3CBR%20%2F%3EPlease%20open%20a%20new%20thread%20and%20refer%20to%20the%20closed%20one%2C%20if%20you%20have%20a%20related%20question%20at%20a%20later%20point%20in%20time.%3CBR%20%2F%3E-------------------------------------------------------------------------------%3C%2FP%3E%3C%2FLINGO-BODY%3E