Table of Contents
1. Document Objective and Overall Flow
This document describes how to complete the OEM Key Import flow using the EdgeLock Enclave (ELE) on the i.MX RT1180. The flow is mainly used to securely import OEM-generated or OEM-owned key material into the device key store through the secure import mechanism supported by ELE, and then verify the imported key by performing AES encryption and decryption.
The overall flow can be summarized as follows:
Install the tool environment
↓
Program and verify SRKH
↓
Import the AN14861SW demo project
↓
Export the NXP Manufacturing Public Key from ELE
↓
Generate a local ECC key pair for ECDH key agreement
↓
Generate the KEY_EXCHANGE_REQ Signed Message
↓
Generate the OEM Import Key TLV Blob
↓
Replace the generated C arrays in the demo project
↓
Run the demo and perform Key Agreement and OEM Key Import
Note: The commands in this document primarily use Windows/PowerShell and the SPSDK CLI. When running them on Linux, adjust path separators and shell syntax as required.
2. Software and Hardware Environment Preparation
2.1 Hardware Platform
The following hardware is recommended:
2.2 Install SPT 26.06
It is recommended to install the latest SPT release. The version used in this document is:
SPT 26.06
SPT stands for Secure Provisioning Tool. It is used to generate SRK/SRKH data, configure signed images, program fuses, and configure secure boot.
After installation, confirm the following:
2.3 Install the Latest SPSDK
It is recommended to install SPSDK in a Python virtual environment to avoid conflicts with Python packages already installed on the system.
python -m venv .venv
.\.venv\Scripts\activate
pip install -U pip
pip install -U spsdk
Verify the installation:
spsdk --version
nxpcrypto --help
nxpimage --help
If a command is not recognized, check the following:
3. Program SRKH on the RT1180 Board
This step establishes the OEM Root of Trust. Before programming, make sure that the SRK table and SRKH are the final versions intended for use, because fuse programming or locking is normally irreversible.
3.1 Generate and Program SRKH Using SPT
The relevant configuration screenshots are shown below:
Figure 1 - SPT SRKH configuration
Figure 2 - SRKH programming confirmation
Figure 3 - SRKH fuse operation
Recommended checkpoints:
Risk notice: SRKH is a core element of the secure boot chain of trust. Programming or locking must be confirmed by the project security owner in advance.
4. Import the AN14861SW Project
Use MCUXpresso IDE to import the AN14861SW project.
Recommended steps:
It is recommended to keep the original project unchanged at first and complete one baseline build and run. This confirms that the demo environment itself is functional.
5. Obtain the NXP Manufacturing Public Key from ELE
5.1 Enable the NXP Production Key Export Path in the Demo
AN14861 requires reading the NXP Manufacturing Public Key from ELE. This key is subsequently used as the peer public key for ECDH key agreement and is required to generate the Signed Message and TLV Blob materials.
The relevant flow screenshots are shown below:
Figure 4 - Enable key export in the project
Figure 5 - Exported NXP Manufacturing Public Key
After running the demo, a HEX string similar to the following is obtained:
744a536d9078795b037db78f8738dbab5ae7dbab76660eb7067a06f386791687
f6988017e90c73a889f5b6dd9abb3b5c1bb9c1cffdca34c6ba64600244e8a314
The string must be converted to a binary file and then converted to a PEM-format public key.
5.2 Convert the HEX String to a Binary File Using PowerShell
Create the following script:
create_key.ps1
Script content:
$hex = "744a536d9078795b037db78f8738dbab5ae7dbab76660eb7067a06f386791687f6988017e90c73a889f5b6dd9abb3b5c1bb9c1cffdca34c6ba64600244e8a314"
[byte[]]$bytes = for ($i = 0; $i -lt $hex.Length; $i += 2) {
[Convert]::ToByte($hex.Substring($i, 2), 16)
}
[System.IO.File]::WriteAllBytes("key.bin", $bytes)
Write-Host "Created key.bin successfully."
Write-Host "File size:" (Get-Item ".\key.bin").Length "bytes"
Run the script:
.\create_key.ps1
Expected output:
Created key.bin successfully.
File size: 80 bytes
The test result is shown below:
Figure 6 - PowerShell generated key.bin
If script execution is restricted by the PowerShell execution policy, temporarily allow execution in the current session:
Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass
5.3 Convert key.bin to a PEM-Format Public Key
Run:
nxpcrypto key convert -e PEM -i key.bin -o nxp_prod.pub
Generated file:
nxp_prod.pub
Use the following command to inspect the PEM content:
openssl pkey -pubin -in nxp_prod.pub -text -noout
6. Generate Signed Content and the TLV Blob
This chapter corresponds to Section 7.4 of AN14861 and covers the following tasks:
6.1 Generate a Local ECC Key Pair
This key pair is used to perform ECDH key agreement with the NXP Manufacturing Public Key inside ELE.
nxpcrypto key generate -k secp256r1 --force -o app_ecc256.pem
Expected generated files:
app_ecc256.pem
app_ecc256.pub
Notes:
6.2 Convert the ECC Public Key to RAW Binary
nxpcrypto key convert -e RAW -i app_ecc256.pub -o ecc256_pub_key.bin
Then convert it to a C array:
nxpimage utils convert bin2carr -i ecc256_pub_key.bin -e little -c 8 -n ecc256_pub_key -o app_ecc256_pub.c
Parameter description:
6.3 Calculate the SHA-256 Digest of the ECC Public Key
nxpcrypto digest -h sha256 -i ecc256_pub_key.bin
Example output:
SHA256(ecc256_pub_key.bin)= b3a20b5679c5ddd77d6bd1a3eb0ff6ea7ab32ac6883d597db30dfcb64d5f8164
This digest must later be entered in the Signed Message configuration file to identify the local ECC public key participating in the key exchange.
6.4 Obtain the KEY_EXCHANGE_REQ Signed Message Template
nxpimage signed-msg get-template -f rt118x -m KEY_EXCHANGE_REQ -o signed_msg_config.yaml --force
6.5 Edit signed_msg_config.yaml
Edit the template file:
signed_msg_config.yaml
Verify the following items carefully:
6.6 Generate the Signed Message Binary
After entering the SPT workspace, run:
nxpimage signed-msg export -c signed_msg_config.yaml -w ecdh_derived_key
The result is shown below:
Figure 7 - Export signed message
Expected generated file:
signed_message.bin
ECDH-derived-key intermediate files are also generated in the working directory.
6.7 Convert signed_message.bin to a C Array
nxpimage utils convert bin2carr -i signed_message.bin -e little -c 8 -n signed_msg_bin -o signed_message.c
The test result is shown below:
Figure 8 - Convert signed message to a C array
Generated file:
signed_message.c
It contains:
const uint8_t signed_msg_bin[] = {
...
};
6.8 Obtain the Key Import TLV Blob Template
nxpimage signed-msg tlv get-template -f rt118x -o oem_import_key.yaml --force
The result is shown below:
Figure 9 - Get TLV template
6.9 Edit oem_import_key.yaml
Configure the following items according to the target key to be imported:
Keep the configuration consistent with the parsing logic in the demo project. Otherwise, TLV generation may succeed while the ELE Import step fails. A reference sample is provided in the attachment.
6.10 Generate the TLV Blob
nxpimage signed-msg tlv export -c oem_import_key.yaml
The result is shown below:
Figure 10 - Export TLV blob
Expected generated file:
tlv.bin
6.11 Convert tlv.bin to a C Array
nxpimage utils convert bin2carr -i tlv.bin -e little -c 8 -n oem_tlv_blob -o oem_tlv_blob.c
The result is shown below:
Figure 11 - Convert TLV blob to a C array
Generated file:
oem_tlv_blob.c
It contains:
const uint8_t oem_tlv_blob[] = {
...
};
7. Replace the C Arrays in the Demo Project
Replace the generated C arrays in the ele_crypto_hsm.c file of the demo project.
The arrays to replace are:
ecc256_pub_key[]
signed_msg_bin[]
oem_tlv_blob[]
The relevant screenshots are shown below:
Figure 12 - Replace the ecc256_pub_key array
Figure 13 - Replace the signed_msg_bin array
Figure 14 - Replace the oem_tlv_blob array
Recommended procedure:
8. Build, Run, and Analyze the Success Log
8.1 Disable the NXP Product Key Export Code Path
After replacing the arrays, disable the code path used to export the product key, and then rebuild the demo.
The relevant screenshot is shown below:
Figure 15 - Disable the product key export path
8.2 Rebuild the Project
In MCUXpresso IDE, run:
Clean Project
Build Project
Debug / Run
8.3 Key Success Log Messages
The successful demo log is lengthy. Focus on the following key messages:
EdgeLock FW loaded and authenticated successfully.
EdgeLock RNG Start success.
EdgeLock services initialized successfully.
Open session successfully.
Open service and create Key Store successfully.
ele perform key agreement successfully. Derived key ID: 0x3fffffff
Import key successfully. User key ID: 0x3ffffffe
OEM_IMPORT_MK_SK deleted successfully.
AES-ECB decrypted data match the original plain text - success.
End of Example with SUCCESS!!
These messages indicate the following:
8.4 Detailed Runtime Log
Original successful log summary:
EdgeLock Enclave Sub-System oem provsioning example:
****************** Load EdgeLock FW ***********************
EdgeLock FW loaded and authenticated successfully.
****************** Start RNG ******************************
EdgeLock RNG Start success.
EdgeLock RNG ready to use.
****************** Initialize EdgeLock services ***********
EdgeLock services initialized successfully.
****************** Load EdgeLock NVM Mgr ******************
EdgeLock NVM manager registered.
****************** Open EdgeLock session ******************
Open session successfully. Session ID: 0xbe962305
****************** Create Key Store ***********************
Open service and create Key Store successfully. Key Store ID: 0xbe962e85
****************** Open NVM Storage service ***************
Open NVM Storage service successfully. Handle ID: 0xbe96294d
****************** Key Management Open ********************
Open Key management service successfully. Key Handle ID: 0xbe96293d
ele perform key agreement successfully. Derived key ID: 0x3fffffff
Write sd, blob_id_msb = 4, 45, 12345678
Write sd, blob_id_msb = 3, 0, 12345678
Write sd, blob_id_msb = 0, 0, 0
Import key successfully. User key ID: 0x3ffffffe
OEM_IMPORT_MK_SK deleted successfully. Key Pair ID: 0x3fffffff
****************** Close Key Management Service ***********
Close Key Management Service successfully.
****************** Close Key Store ************************
Close Key Store successfully.
Close NVM storage session successfully.
****************** Close EdgeLock session *****************
Close session successfully.
...
****************** Cipher AES ECB *************************
Output returned by AES-ECB encryption.
****************** Decrypt Cipher AES-ECB *****************
Read sd, blob_id msb = 0x4, lsb: 0x45, ext: 0x12345678
AES-ECB decrypted data match the original plain text - success.
...
End of Example with SUCCESS!!