Using ZMK for blobs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Using ZMK for blobs

Jump to solution
1,012 Views
eren_yilmaz
Contributor III

Thanks Yuri.

As a workaround for SEC_CONFIG being not set, can I use ZMK since that can be set in a non-secure mode, and have CAAM use that for blob encapsulation and decapsulation?

0 Kudos
1 Solution
901 Views
Yuri
NXP Employee
NXP Employee

Correct,  ZMK cannot be used in non-secure mode with CAAM.

~Yuri.

View solution in original post

5 Replies
901 Views
Yuri
NXP Employee
NXP Employee

Hello,

  from i.MX6 Security RM:

When the chip is in the non-secure state, CAAM cannot decapsulate blobs that were
encapsulated while CAAM was in a trustworthy state (either secure state or trusted state).


Have a great day,
Yuri

-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!

- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.

0 Kudos
901 Views
eren_yilmaz
Contributor III

Hello  Yuri,

Yes I know that. But my question is for operations in non-secure state.

Can CAAM use ZMK to encapsulate and decapsulate blobs in a non-secure state?

0 Kudos
901 Views
Yuri
NXP Employee
NXP Employee

Hello,

  In non-secure mode a fixed default key with a known value  is used in place of the master key.

Regards,

Yuri.

0 Kudos
901 Views
eren_yilmaz
Contributor III

Hi Yuri,

So ZMK cannot be used in non-secure mode with CAAM? Instead of that default known key.

Thanks

0 Kudos
902 Views
Yuri
NXP Employee
NXP Employee

Correct,  ZMK cannot be used in non-secure mode with CAAM.

~Yuri.