| Zakładka z wyszukiwarką danych komponentów |
|
ATECC508A Arkusz danych(PDF) 31 Page - Microchip Technology |
|
|
|||||||||||||||||||||||||||||
ATECC508A Arkusz danych(HTML) 31 Page - Microchip Technology |
|
31 / 109 page ![]() There is no reset mechanism for this limitation. After 128 uses (or the number of one bits set in LastKeyUse on personalization), Key 15 is permanently disabled. This capability is not susceptible to power interruptions. Even if the power is interrupted during execution of the command, only a single bit in LastKeyUse will be unknown, all other bits in LastKeyUse will be unchanged, and the key will remain unchanged. If fewer than 128 uses are desired for Key 15, then some of the bytes within this array should not be initialized to 0xFF. The only legal values for bytes within this field (besides 0xFF) are 0x7F, 0x3F, 0x1F, 0x0F, 0x07, 0x03, 0x01, or 0x00. The total number of bits set to one indicates the number of uses. Example: How to set 16 uses is shown as follows: 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 The limited use capability applies to the same commands, and in the same situations, in which they are checked for the LimitedUse feature (see the previous section for more information). In addition, the Verify command will check for single use restrictions on both the public key (when that key is stored internally), and the key to be validated when the command is run in validation mode and either is stored in slot 15. 3.2.7 Password Checking Many applications require a user to enter a password to enable features, decrypt stored data, or perform some other task. Typically, the expected password has to be stored somewhere in the memory, and therefore is subject to discovery. The ATECC508A can securely store the expected password and perform a number of useful operations upon it. The password is never passed in the clear to the device, and it cannot be read from the device. It is hashed with a random number in the system software before being passed to the device. The copy capability of the CheckMac command enables the following types of password checking options: 1. CheckMac does an internal comparison with the expected password and returns a boolean result to the system to indicate whether the password was correctly entered or not. 2. If the device determines that the correct password has been entered, then the value of the password can optionally be combined with a stored ephemeral value to create a key that can be used by the system for data protection purposes. 3. If the device determines that the correct password has been entered, then the device can use this fact to optionally release a secondary high entropy secret, which can be used for data protection without the risk of an exhaustive dictionary attack. 4. If the password has been lost, then an entity with knowledge of a parent key value can optionally write a new password into the slot. Optionally, the current value can be encrypted with a parent key and read from the device. To prepare for this CheckMac/Copy capability, passwords should be stored in even numbered slots. If the password is to be mapped to a secondary value (using the third option above), then the target slot containing this value is located in the next higher slot number (i.e. the password’s slot number plus one); otherwise, the target slot is the same as the password slot. ReadKey for the target slot must be set to zero to enable this capability. In order to prevent fraudulent or unintended usage of this capability, do not set ReadKey for any slot to zero unless this CheckMac/Copy capability is specifically required. In ATECC508A Security Information © 2017 Microchip Technology Inc. Datasheet Complete DS20005927A-page 31 |
|
Link URL |
| Czy Alldatasheet okazała się pomocna? [ DONATE ] |
O Alldatasheet | Reklama | Kontakt | Polityka prywatności | Link do karty katalogowej | Linki | Lista producentów All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |