| Zakładka z wyszukiwarką danych komponentów |
|
ATECC508A Arkusz danych(PDF) 19 Page - Microchip Technology |
|
|
|||||||||||||||||||||||||||||
ATECC508A Arkusz danych(HTML) 19 Page - Microchip Technology |
|
19 / 109 page ![]() Note: The source key for the computation performed by the DeriveKey command can either be the key directly specified in Param2 (Target) or the key at SlotConfig<Param2>.WriteKey (Parent). See Section Key Uses and Restrictions. The IsSecret bit controls internal circuitry necessary for proper security for slots in which reads and/or writes must be encrypted or are prohibited altogether. It must also be set for all slots that are to be used as keys, including those created or modified with the DeriveKey command. Specifically, to enable proper device operation, this bit must be set unless WriteConfig is Always. Four byte accesses are generally prohibited to and from slots in which this bit is set. Slots used to store key values should always have IsSecret set to one and EncryptRead set to zero (reads prohibited) for maximum security. For fixed key values, WriteConfig should be set to Never. When configured in this way, after the data zone is locked, there is no way to read or write the key; and it may only be used for crypto operations. Some security policies require that secrets be updated from time to time. The ATECC508A supports this capability in the following way: WriteConfig for the particular slot should be set to Encrypt and SlotConfig.WriteKey should point back to the same slot by setting WriteKey to the slot ID. A standard Write command can then be used to write a new value to this slot, provided that the authentication MAC is computed using the old (i.e. current) key value. 2.2.4 Writing ECC Private Keys ECC private keys are designated via the appropriate contents of KeyConfig.KeyType and KeyConfig.Private. They can never be written with the Write and/or DeriveKey commands. Instead, GenKey and PrivWrite can be used to modify these slots. It is always an error to attempt to execute GenKey or PrivWrite on a slot that is not configured to contain an ECC private key. SlotConfig.WriteConfig has the following interpretations for these commands: Table 2-10. Write Configuration Bits: GenKey Command Bit 15 Bit 14 Bit 13 Bit 12 Description X X 0 X GenKey may not be used to write random keys into this slot. X X 1 X GenKey may be used to write random keys into this slot. Table 2-11. Write Configuration Bits: PrivWrite Command Bit 15 Bit 14 Bit 13 Bit 12 Mode Name Description X 0 X X Forbidden PrivWrite will return an error if the target key slot has this value. X 1 X X Encrypt Writes to this slot require a properly computed MAC and the input data must be encrypted by the system with SlotConfig.WriteKey using the encryption algorithm documented in the PrivWrite command description (Section PrivWrite Command). 2.2.5 KeyConfig (Bytes 96 through 127) The 16 KeyConfig elements are used in addition to SlotConfig to restrict the actions that can be performed using information stored in a particular slot. The KeyConfig element is interpreted according to the table below when the data zone is locked. When the data zone is unlocked, these restrictions do not apply, with the exception that slots configured to contain private keys can be written only with the PrivWrite command. ATECC508A Device Organization © 2017 Microchip Technology Inc. Datasheet Complete DS20005927A-page 19 |
|
Link URL |
| Czy Alldatasheet okazała się pomocna? [ DONATE ] |
O Alldatasheet | Reklama | Kontakt | Polityka prywatności | Link do karty katalogowej | Linki | Lista producentów All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |