Request: Implement C_UnwrapKey in SIMW Top PKCS#11 (SE05X) for CMS ECDH

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 

Request: Implement C_UnwrapKey in SIMW Top PKCS#11 (SE05X) for CMS ECDH

682 次查看
vishwaec08
Contributor I

Hello NXP Team,

We need C_UnwrapKey (AES-CBC/AES-CBC-PAD) implemented in SE05X SDK PKCS#11 to enable CMS ECDH handle-only decrypt on SE05X.

Currently C_UnwrapKey returns CKR_FUNCTION_NOT_SUPPORTED in sss_pkcs11_pal_core.c. The flow requires unwrapping the CMS CEK on-token using the derived AES handle plus the 16-byte IV from CMS.

 

Regards
Vishwa

0 项奖励
回复
2 回复数

646 次查看
vishwaec08
Contributor I

Hi,

The overall idea is that we want to encrypt and decrypt the data using OpenSSL CMS with an EC key.

For reference, the OpenSSL commands are listed below.

pkcs11-tool --module /usr/lib/libsss_pkcs11.so --slot 1 --keypairgen --key-type EC:prime256v1 --label "sss:20202022"

OPENSSL_CONF=engine.conf openssl req -engine pkcs11 -new -key "pkcs11:object=sss:20202022;type=private" -keyform engine -out ec_req.pem -x509 -subj "/CN=Test EC" -days 365

OPENSSL_CONF=engine.conf openssl x509 -engine pkcs11 -signkey "pkcs11:object=sss:20202022;type=private" -keyform engine -in ec_req.pem -out ec_cert.pem

openssl cms -encrypt -binary -outform DER -aes128 -in smcont.txt -recip ec_cert.pem -out test_ec.cms

OPENSSL_CONF=engine.conf openssl cms -decrypt -binary -inform DER -engine pkcs11 -keyform engine -inkey "pkcs11:object=sss:20202022;type=private" -recip ec_cert.pem -in test_ec.cms -out smtst.txt

 

0 项奖励
回复

660 次查看
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @vishwaec08 ,

 

I have forwarded your feature request to the expert team, and will let you know when I have any feedback from there.

 

Thanks for your patience!

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

0 项奖励
回复
%3CLINGO-SUB%20id%3D%22lingo-sub-2295622%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E8%AF%B7%E6%B1%82%EF%BC%9A%E4%B8%BA%20CMS%20ECDH%20%E5%9C%A8%20SIMW%20Top%20PKCS%2311%20(SE05X)%20%E4%B8%AD%E5%AE%9E%E6%96%BD%20C_UnwrapKey%20%E5%8A%9F%E8%83%BD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2295622%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E6%82%A8%E5%A5%BD%EF%BC%8CNXP%E5%9B%A2%E9%98%9F%EF%BC%8C%3C%2FP%3E%3CP%3E%E6%88%91%E4%BB%AC%E9%9C%80%E8%A6%81%E5%9C%A8%20SE05X%20SDK%20PKCS%2311%20%E4%B8%AD%E5%AE%9E%E7%8E%B0%E7%9A%84%20C_UnwrapKey%20(AES-%E5%AF%86%E7%A0%81%E5%9D%97%E9%93%BE%E6%8E%A5(CBC)%2FAES-%E5%AF%86%E7%A0%81%E5%9D%97%E9%93%BE%E6%8E%A5(CBC)-PAD)%20%E6%89%8D%E8%83%BD%E5%9C%A8%20SE05X%20%E4%B8%8A%E5%90%AF%E7%94%A8%20CMS%20ECDH%20%E4%BB%85%E9%99%90%E5%8F%A5%E6%9F%84%E7%9A%84%E8%A7%A3%E5%AF%86%E3%80%82%3CBR%20%2F%3E%3CBR%20%2F%3E%E7%9B%AE%E5%89%8D%EF%BC%8C%E5%9C%A8%20sss_pkcs11_pal_core.c%20%E4%B8%AD%EF%BC%8CC_UnwrapKey%20%E8%BF%94%E5%9B%9E%20CKR_FUNCTION_NOT_SUPPORTED%E3%80%82%E8%AF%A5%E6%B5%81%E7%A8%8B%E9%9C%80%E8%A6%81%E4%BD%BF%E7%94%A8%E6%B4%BE%E7%94%9F%E7%9A%84%20AES%20%E5%8F%A5%E6%9F%84%E5%8A%A0%E4%B8%8A%E6%9D%A5%E8%87%AA%20CMS%20%E7%9A%84%2016%20%E5%AD%97%E8%8A%82%20IV%20%E5%9C%A8%E4%BB%A3%E5%B8%81%E4%B8%8A%E8%A7%A3%E5%8C%85%20CMS%20CEK%E3%80%82%3C%2FP%3E%3CBR%20%2F%3E%3CP%3ERegards%3CBR%20%2F%3E%3CSPAN%3E%20Vishwa%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2295797%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Request%3A%20Implement%20C_UnwrapKey%20in%20SIMW%20Top%20PKCS%2311%20(SE05X)%20for%20CMS%20ECDH%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2295797%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E4%BD%A0%E5%A5%BD%EF%BC%8C%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3E%E6%80%BB%E4%BD%93%E6%80%9D%E8%B7%AF%E6%98%AF%E6%88%91%E4%BB%AC%E8%A6%81%E4%BD%BF%E7%94%A8%E5%B8%A6%E6%9C%89%20EC%20%E5%AF%86%E9%92%A5%E7%9A%84%20OpenSSL%20CMS%20%E6%9D%A5%E5%8A%A0%E5%AF%86%E5%92%8C%E8%A7%A3%E5%AF%86%E6%95%B0%E6%8D%AE%E3%80%82%3CBR%20%2F%3E%3CBR%20%2F%3E%E4%B8%BA%E4%BA%86%E4%BE%BF%E4%BA%8E%E5%8F%82%E8%80%83%EF%BC%8C%E4%B8%8B%E9%9D%A2%E5%88%97%E5%87%BA%E4%BA%86%20OpenSSL%20%E5%91%BD%E4%BB%A4%3C%2FSPAN%3E%E3%80%82%3C%2FP%3E%3CP%3Epkcs11-tool%20--module%20%2Fusr%2Flib%2Flibsss_pkcs11.so%20--slot%201%20--keypairgen%20--key-type%20EC%3Aprime256v1%20--label%22sss%3A20202022%22%3C%2FP%3E%3CP%3EOPENSSL_CONF%3Dengine.conf%20openssl%20req%20-engine%20pkcs11%20-new%20-key%22pkcs11%3Aobject%3Dsss%3A20202022%3Btype%3Dprivate%22%20-keyform%20engine%20-out%20ec_req.pem%20-x509%20-subj%22%2FCN%3DTest%20EC%22%20-days%20365%3C%2FP%3E%3CP%3EOPENSSL_CONF%3Dengine.conf%20openssl%20x509%20-engine%20pkcs11%20-signkey%22pkcs11%3Aobject%3Dsss%3A20202022%3Btype%3Dprivate%22%20-keyform%20engine%20-in%20ec_req.pem%20-out%20ec_cert.pem%3C%2FP%3E%3CP%3Eopenssl%20cms-encrypt-%E4%BA%8C%E8%BF%9B%E5%88%B6-outform%20DER-aes128-in%20smcont.txt-recip%20ec_cert.pem%20out-out%20test_ec.cms%20%3CBR%20%2F%3E%20%3CBR%20%2F%3EopenSSL_conf%3Dengine.conf%20openssl%20cms-%E8%A7%A3%E5%AF%86-%E4%BA%8C%E8%BF%9B%E5%88%B6-inform%20DER-engine%20pkcs11-keyform%20%E5%BC%95%E6%93%8E-inkey%20%22%20pkcs11%3Aobject%3Dss%3A20202022%EF%BC%9Btype%3Dprivate%20%22-recip%20ec_cert.pem-in%20test_ec.cms%20%E8%BE%93%E5%87%BA%20smtst.txt%3C%2FP%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2295665%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Request%3A%20Implement%20C_UnwrapKey%20in%20SIMW%20Top%20PKCS%2311%20(SE05X)%20for%20CMS%20ECDH%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2295665%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E4%BD%A0%E5%A5%BD%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F213664%22%20target%3D%22_blank%22%3E%40vishwaec08%3C%2FA%3E%EF%BC%8C%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3E%E6%88%91%E5%B7%B2%E5%B0%86%E6%82%A8%E7%9A%84%E5%8A%9F%E8%83%BD%E8%AF%B7%E6%B1%82%E8%BD%AC%E7%BB%99%E4%B8%93%E5%AE%B6%E5%9B%A2%E9%98%9F%EF%BC%8C%E4%B8%80%E6%97%A6%E6%9C%89%E4%BB%BB%E4%BD%95%E5%8F%8D%E9%A6%88%EF%BC%8C%E6%88%91%E5%B0%86%E9%80%9A%E7%9F%A5%E6%82%A8%E3%80%82%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3E%E6%84%9F%E8%B0%A2%E6%82%A8%E7%9A%84%E8%80%90%E5%BF%83%E7%AD%89%E5%BE%85%EF%BC%81%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3E%E7%A5%9D%E6%82%A8%E6%84%89%E5%BF%AB%EF%BC%8C%3CBR%20%2F%3EKan%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E-------------------------------------------------------------------------------%3CBR%20%2F%3E%E6%B3%A8%EF%BC%9A%3CBR%20%2F%3E-%20%E5%A6%82%E6%9E%9C%E6%9C%AC%E5%B8%96%E5%9B%9E%E7%AD%94%E4%BA%86%E6%82%A8%E7%9A%84%E9%97%AE%E9%A2%98%EF%BC%8C%E8%AF%B7%E7%82%B9%E5%87%BB%22%E6%A0%87%E8%AE%B0%E6%AD%A3%E7%A1%AE%22%20%E6%8C%89%E9%92%AE%E3%80%82%E8%B0%A2%E8%B0%A2%EF%BC%81%3CBR%20%2F%3E-%20%E6%88%91%E4%BB%AC%E4%BC%9A%E5%9C%A8%E6%9C%80%E5%90%8E%E4%B8%80%E6%AC%A1%E5%8F%91%E5%B8%96%E5%90%8E%E7%9A%84%207%20%E5%91%A8%E5%86%85%E8%B7%9F%E8%B8%AA%E4%B8%BB%E9%A2%98%EF%BC%8C%E4%B9%8B%E5%90%8E%E7%9A%84%E5%9B%9E%E5%A4%8D%E5%B0%86%E8%A2%AB%E5%BF%BD%E7%95%A5%3CBR%20%2F%3E%E5%A6%82%E6%9E%9C%E6%82%A8%E4%BB%A5%E5%90%8E%E6%9C%89%E7%9B%B8%E5%85%B3%E9%97%AE%E9%A2%98%EF%BC%8C%E8%AF%B7%E6%89%93%E5%BC%80%E4%B8%80%E4%B8%AA%E6%96%B0%E4%B8%BB%E9%A2%98%E5%B9%B6%E5%8F%82%E8%80%83%E5%B7%B2%E5%85%B3%E9%97%AD%E7%9A%84%E4%B8%BB%E9%A2%98%E3%80%82%3CBR%20%2F%3E-------------------------------------------------------------------------------%3C%2FP%3E%3C%2FLINGO-BODY%3E