Using ZMK for blobs

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 
已解决

Using ZMK for blobs

跳至解决方案
1,311 次查看
eren_yilmaz
Contributor III

Thanks Yuri.

As a workaround for SEC_CONFIG being not set, can I use ZMK since that can be set in a non-secure mode, and have CAAM use that for blob encapsulation and decapsulation?

0 项奖励
回复
1 解答
1,200 次查看
Yuri
NXP Employee
NXP Employee

Correct,  ZMK cannot be used in non-secure mode with CAAM.

~Yuri.

在原帖中查看解决方案

5 回复数
1,200 次查看
Yuri
NXP Employee
NXP Employee

Hello,

  from i.MX6 Security RM:

When the chip is in the non-secure state, CAAM cannot decapsulate blobs that were
encapsulated while CAAM was in a trustworthy state (either secure state or trusted state).


Have a great day,
Yuri

-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!

- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.

0 项奖励
回复
1,200 次查看
eren_yilmaz
Contributor III

Hello  Yuri,

Yes I know that. But my question is for operations in non-secure state.

Can CAAM use ZMK to encapsulate and decapsulate blobs in a non-secure state?

0 项奖励
回复
1,200 次查看
Yuri
NXP Employee
NXP Employee

Hello,

  In non-secure mode a fixed default key with a known value  is used in place of the master key.

Regards,

Yuri.

0 项奖励
回复
1,200 次查看
eren_yilmaz
Contributor III

Hi Yuri,

So ZMK cannot be used in non-secure mode with CAAM? Instead of that default known key.

Thanks

0 项奖励
回复
1,201 次查看
Yuri
NXP Employee
NXP Employee

Correct,  ZMK cannot be used in non-secure mode with CAAM.

~Yuri.