How To Import ELE Key To RT1180 Based On AN14861SW

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

How To Import ELE Key To RT1180 Based On AN14861SW

How To Import ELE Key To RT1180 Based On AN14861SW

Table of Contents 

  1. Document Objective and Overall Flow 
  2. Software and Hardware Environment Preparation 
  3. Program SRKH on the RT1180 Board 
  4. Import the AN14861SW Project 
  5. Obtain the NXP Manufacturing Public Key from ELE 
  6. Generate Signed Content and the TLV Blob 
  7. Replace the C Arrays in the Demo Project 
  8. Build, Run, and Analyze the Success Log 

1. Document Objective and Overall Flow 

This document describes how to complete the OEM Key Import flow using the EdgeLock Enclave (ELE) on the i.MX RT1180. The flow is mainly used to securely import OEM-generated or OEM-owned key material into the device key store through the secure import mechanism supported by ELE, and then verify the imported key by performing AES encryption and decryption. 

The overall flow can be summarized as follows: 

Install the tool environment 
      ↓ 
Program and verify SRKH 
      ↓ 
Import the AN14861SW demo project 
      ↓ 
Export the NXP Manufacturing Public Key from ELE 
      ↓ 
Generate a local ECC key pair for ECDH key agreement 
      ↓ 
Generate the KEY_EXCHANGE_REQ Signed Message 
      ↓ 
Generate the OEM Import Key TLV Blob 
      ↓ 
Replace the generated C arrays in the demo project 
      ↓ 
Run the demo and perform Key Agreement and OEM Key Import 

Note: The commands in this document primarily use Windows/PowerShell and the SPSDK CLI. When running them on Linux, adjust path separators and shell syntax as required. 

2. Software and Hardware Environment Preparation 

2.1 Hardware Platform 

 

The following hardware is recommended: 

  • i.MX RT1180 EVK or a custom RT1180 board 
  • USB debug cable or an onboard debug interface 
  • Serial terminal software, such as Tera Term, PuTTY, MobaXterm, or VS Code Serial Monitor 
  • A boot configuration environment that has passed basic startup verification 

 

2.2 Install SPT 26.06 

It is recommended to install the latest SPT release. The version used in this document is: 

SPT 26.06 

SPT stands for Secure Provisioning Tool. It is used to generate SRK/SRKH data, configure signed images, program fuses, and configure secure boot. 

After installation, confirm the following: 

  • SPT starts normally. 
  • The target RT1180 board can be detected. 
  • Fuse read operations work correctly on the target board. 
  • The selected connection interface matches the board boot mode. 

2.3 Install the Latest SPSDK 

 

It is recommended to install SPSDK in a Python virtual environment to avoid conflicts with Python packages already installed on the system. 

python -m venv .venv 
.\.venv\Scripts\activate 
pip install -U pip 
pip install -U spsdk 

Verify the installation: 

spsdk --version 
nxpcrypto --help 
nxpimage --help 

If a command is not recognized, check the following: 

  • The virtual environment is active in the current PowerShell session. 
  • The Python Scripts directory is included in PATH. 
  • SPSDK is installed in the Python environment currently in use. 

 

3. Program SRKH on the RT1180 Board 

 

This step establishes the OEM Root of Trust. Before programming, make sure that the SRK table and SRKH are the final versions intended for use, because fuse programming or locking is normally irreversible. 

 

3.1 Generate and Program SRKH Using SPT 

 

The relevant configuration screenshots are shown below: 

Kan_Li_0-1790063387749.png

Figure 1 - SPT SRKH configuration 

Kan_Li_1-1790063417287.jpeg

Figure 2 - SRKH programming confirmation 

Kan_Li_2-1790063453161.png

Figure 3 - SRKH fuse operation 

Recommended checkpoints: 

  1. Confirm that the SRK table was generated from the correct OEM signing key. 
  1. Confirm that SRKH matches the SRK table used by the current project. 
  1. Save the configuration record before programming the fuses. 
  1. Perform readback verification after programming the fuses. 
  1. If Secure Boot will be enabled later, confirm that the SRKH locking policy meets the project manufacturing requirements. 

Risk notice: SRKH is a core element of the secure boot chain of trust. Programming or locking must be confirmed by the project security owner in advance. 

 

 

4. Import the AN14861SW Project 

 

Use MCUXpresso IDE to import the AN14861SW project. 

Recommended steps: 

  1. Open MCUXpresso IDE. 
  1. Select File → Import. 
  1. Select Existing Projects into Workspace. 
  1. Browse to the AN14861SW project directory. 
  1. Confirm that the project builds successfully. 
  1. Verify the Debug Probe, serial port, and boot configuration for the target board. 

It is recommended to keep the original project unchanged at first and complete one baseline build and run. This confirms that the demo environment itself is functional. 

 

5. Obtain the NXP Manufacturing Public Key from ELE 

5.1 Enable the NXP Production Key Export Path in the Demo 

 

AN14861 requires reading the NXP Manufacturing Public Key from ELE. This key is subsequently used as the peer public key for ECDH key agreement and is required to generate the Signed Message and TLV Blob materials. 

The relevant flow screenshots are shown below: 

Kan_Li_3-1790063545040.png

Figure 4 - Enable key export in the project 

Kan_Li_4-1790063577255.png

Figure 5 - Exported NXP Manufacturing Public Key 

After running the demo, a HEX string similar to the following is obtained: 

744a536d9078795b037db78f8738dbab5ae7dbab76660eb7067a06f386791687 
f6988017e90c73a889f5b6dd9abb3b5c1bb9c1cffdca34c6ba64600244e8a314 

The string must be converted to a binary file and then converted to a PEM-format public key. 

 

5.2 Convert the HEX String to a Binary File Using PowerShell 

 

Create the following script: 

create_key.ps1 

Script content: 

$hex = "744a536d9078795b037db78f8738dbab5ae7dbab76660eb7067a06f386791687f6988017e90c73a889f5b6dd9abb3b5c1bb9c1cffdca34c6ba64600244e8a314" 
 
[byte[]]$bytes = for ($i = 0; $i -lt $hex.Length; $i += 2) { 
    [Convert]::ToByte($hex.Substring($i, 2), 16) 
} 
 
[System.IO.File]::WriteAllBytes("key.bin", $bytes) 
Write-Host "Created key.bin successfully." 
Write-Host "File size:" (Get-Item ".\key.bin").Length "bytes" 

Run the script: 

.\create_key.ps1 

Expected output: 

Created key.bin successfully. 
File size: 80 bytes 

The test result is shown below: 

Kan_Li_5-1790063631735.png

Figure 6 - PowerShell generated key.bin 

If script execution is restricted by the PowerShell execution policy, temporarily allow execution in the current session: 

Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass 

 

5.3 Convert key.bin to a PEM-Format Public Key 

 

Run: 

nxpcrypto key convert -e PEM -i key.bin -o nxp_prod.pub 

Generated file: 

nxp_prod.pub 

Use the following command to inspect the PEM content: 

openssl pkey -pubin -in nxp_prod.pub -text -noout 

 

6. Generate Signed Content and the TLV Blob 

 

This chapter corresponds to Section 7.4 of AN14861 and covers the following tasks: 

  1. Generate a local ECC key pair. 
  1. Export the ECC public key as raw binary. 
  1. Calculate the SHA-256 digest of the ECC public key. 
  1. Obtain and edit the Signed Message configuration template. 
  1. Generate signed_message.bin. 
  1. Generate the OEM Import Key TLV Blob. 
  1. Convert the binary files into C arrays for use in the demo. 

 

6.1 Generate a Local ECC Key Pair 

 

This key pair is used to perform ECDH key agreement with the NXP Manufacturing Public Key inside ELE. 

nxpcrypto key generate -k secp256r1 --force -o app_ecc256.pem 

Expected generated files: 

app_ecc256.pem 
app_ecc256.pub 

Notes: 

  • secp256r1 selects the NIST P-256 curve. 
  • The private key, app_ecc256.pem, must be stored securely. 
  • The public key, app_ecc256.pub, will be converted to RAW format and embedded in the demo project. 

 

6.2 Convert the ECC Public Key to RAW Binary 

 

nxpcrypto key convert -e RAW -i app_ecc256.pub -o ecc256_pub_key.bin 

Then convert it to a C array: 

nxpimage utils convert bin2carr -i ecc256_pub_key.bin -e little -c 8 -n ecc256_pub_key -o app_ecc256_pub.c 

Parameter description: 

  • -i ecc256_pub_key.bin: input RAW binary public key. 
  • -e little: output in little-endian format. 
  • -c 8: output eight bytes per line. 
  • -n ecc256_pub_key: generated C array name. 
  • -o app_ecc256_pub.c: output C source file. 

 

6.3 Calculate the SHA-256 Digest of the ECC Public Key 

 

nxpcrypto digest -h sha256 -i ecc256_pub_key.bin 

Example output: 

SHA256(ecc256_pub_key.bin)= b3a20b5679c5ddd77d6bd1a3eb0ff6ea7ab32ac6883d597db30dfcb64d5f8164 

This digest must later be entered in the Signed Message configuration file to identify the local ECC public key participating in the key exchange. 

 

6.4 Obtain the KEY_EXCHANGE_REQ Signed Message Template 

 

nxpimage signed-msg get-template -f rt118x -m KEY_EXCHANGE_REQ -o signed_msg_config.yaml --force 

 

6.5 Edit signed_msg_config.yaml 

 

Edit the template file: 

signed_msg_config.yaml 

Verify the following items carefully: 

  • The family is rt118x. 
  • The message type is KEY_EXCHANGE_REQ. 
  • The correct NXP Manufacturing Public Key is used. 
  • The ECC public key digest is correct. 
  • The output file path is consistent with subsequent commands. 
  • The working directory is located where SPT/SPSDK expects it. 
  • A reference sample is provided in the attachment. 

 

6.6 Generate the Signed Message Binary 

 

After entering the SPT workspace, run: 

nxpimage signed-msg export -c signed_msg_config.yaml -w ecdh_derived_key 

The result is shown below: 

Kan_Li_6-1790063857502.png

Figure 7 - Export signed message 

Expected generated file: 

signed_message.bin 

ECDH-derived-key intermediate files are also generated in the working directory. 

 

6.7 Convert signed_message.bin to a C Array 

 

nxpimage utils convert bin2carr -i signed_message.bin -e little -c 8 -n signed_msg_bin -o signed_message.c 

The test result is shown below: 

Kan_Li_7-1790063888069.png

Figure 8 - Convert signed message to a C array 

Generated file: 

signed_message.c 

It contains: 

const uint8_t signed_msg_bin[] = { 
    ... 
}; 

 

6.8 Obtain the Key Import TLV Blob Template 

 

nxpimage signed-msg tlv get-template -f rt118x -o oem_import_key.yaml --force 

The result is shown below: 

Kan_Li_8-1790063930749.png

Figure 9 - Get TLV template 

 

6.9 Edit oem_import_key.yaml 

 

Configure the following items according to the target key to be imported: 

  • Key type 
  • Key length 
  • Key usage 
  • Key policy 
  • Blob ID 
  • Storage location 
  • Key group 
  • TLV output file name 

Keep the configuration consistent with the parsing logic in the demo project. Otherwise, TLV generation may succeed while the ELE Import step fails. A reference sample is provided in the attachment. 

 

6.10 Generate the TLV Blob 

 

nxpimage signed-msg tlv export -c oem_import_key.yaml 

The result is shown below: 

Kan_Li_9-1790063984570.png

Figure 10 - Export TLV blob 

Expected generated file: 

tlv.bin 

 

6.11 Convert tlv.bin to a C Array 

 

nxpimage utils convert bin2carr -i tlv.bin -e little -c 8 -n oem_tlv_blob -o oem_tlv_blob.c 

The result is shown below: 

Kan_Li_10-1790064013751.png

Figure 11 - Convert TLV blob to a C array 

Generated file: 

oem_tlv_blob.c 

It contains: 

const uint8_t oem_tlv_blob[] = { 
    ... 
}; 

 

7. Replace the C Arrays in the Demo Project 

 

Replace the generated C arrays in the ele_crypto_hsm.c file of the demo project. 

The arrays to replace are: 

ecc256_pub_key[] 
signed_msg_bin[] 
oem_tlv_blob[] 

The relevant screenshots are shown below: 

Kan_Li_11-1790064048372.png

Figure 12 - Replace the ecc256_pub_key array 

Kan_Li_12-1790064084253.png

Figure 13 - Replace the signed_msg_bin array 

Kan_Li_13-1790064114967.png

Figure 14 - Replace the oem_tlv_blob array 

Recommended procedure: 

  1. Back up the original ele_crypto_hsm.c file. 
  1. Use the contents of the generated .c files to replace the corresponding arrays. Do not change the array names. 

 

8. Build, Run, and Analyze the Success Log 

8.1 Disable the NXP Product Key Export Code Path 

 

After replacing the arrays, disable the code path used to export the product key, and then rebuild the demo. 

The relevant screenshot is shown below: 

Kan_Li_14-1790064153124.png

Figure 15 - Disable the product key export path 

 

8.2 Rebuild the Project 

 

In MCUXpresso IDE, run: 

Clean Project 
Build Project 
Debug / Run 

 

8.3 Key Success Log Messages 

 

The successful demo log is lengthy. Focus on the following key messages: 

EdgeLock FW loaded and authenticated successfully. 
EdgeLock RNG Start success. 
EdgeLock services initialized successfully. 
Open session successfully. 
Open service and create Key Store successfully. 
ele perform key agreement successfully. Derived key ID: 0x3fffffff 
Import key successfully. User key ID: 0x3ffffffe 
OEM_IMPORT_MK_SK deleted successfully. 
AES-ECB decrypted data match the original plain text - success. 
End of Example with SUCCESS!! 

These messages indicate the following: 

  • ELE firmware was loaded and authenticated successfully. 
  • The RNG service started successfully. 
  • ELE services were initialized successfully. 
  • The session, Key Store, NVM, and Key Management services opened successfully. 
  • ECDH key agreement succeeded. 
  • OEM key import succeeded. 
  • The temporary key pair was deleted successfully. 
  • AES-ECB encryption and decryption verified that the imported key is usable. 

 

8.4 Detailed Runtime Log 

Original successful log summary: 

EdgeLock Enclave Sub-System oem provsioning example: 
****************** Load EdgeLock FW *********************** 
EdgeLock FW loaded and authenticated successfully. 
****************** Start RNG ****************************** 
EdgeLock RNG Start success. 
EdgeLock RNG ready to use. 
****************** Initialize EdgeLock services *********** 
EdgeLock services initialized successfully. 
****************** Load EdgeLock NVM Mgr ****************** 
EdgeLock NVM manager registered. 
****************** Open EdgeLock session ****************** 
Open session successfully. Session ID: 0xbe962305 
****************** Create Key Store *********************** 
Open service and create Key Store successfully. Key Store ID: 0xbe962e85 
****************** Open NVM Storage service *************** 
Open NVM Storage service successfully. Handle ID: 0xbe96294d 
****************** Key Management Open ******************** 
Open Key management service successfully. Key Handle ID: 0xbe96293d 
ele perform key agreement successfully. Derived key ID: 0x3fffffff 
Write sd, blob_id_msb = 4, 45, 12345678 
Write sd, blob_id_msb = 3, 0, 12345678 
Write sd, blob_id_msb = 0, 0, 0 
Import key successfully. User key ID: 0x3ffffffe 
OEM_IMPORT_MK_SK deleted successfully. Key Pair ID: 0x3fffffff 
****************** Close Key Management Service *********** 
Close Key Management Service successfully. 
****************** Close Key Store ************************ 
Close Key Store successfully. 
Close NVM storage session successfully. 
****************** Close EdgeLock session ***************** 
Close session successfully. 
... 
****************** Cipher AES ECB ************************* 
Output returned by AES-ECB encryption. 
****************** Decrypt Cipher AES-ECB ***************** 
Read sd, blob_id msb = 0x4, lsb: 0x45, ext: 0x12345678 
AES-ECB decrypted data match the original plain text - success. 
... 
End of Example with SUCCESS!! 

評価なし
バージョン履歴
最終更新日:
1週間前
更新者: