| поискавой системы для электроныых деталей |
|
STSAFE-A120 датащи(PDF) 12 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
STSAFE-A120 датащи(HTML) 12 Page - STMicroelectronics |
|
12 / 38 page ![]() 3 Pairing with local host To protect and authenticate the data exchange between the STSAFE-A120 and the local host, a secure channel protocol using symmetric cryptography is set in place, namely the host secure-channel. Figure 10. Host secure channel IoT device Local host STSAFE-A120 Host secure channel The host secure-channel protocol constitutes the pairing. It is based on a set of four mechanisms using two symmetric keys, the so-called host keys. The host MAC key is used to compute and verify message authentication codes (MAC) for the commands (C-MAC) and respective responses (R-MAC). The host cypher key is used to encrypt the commands and decrypt their respective response to avoid eavesdropping. The host MAC key and the host cipher key must be shared between the host and the STSAFE-A120. The STSAFE-A120 supports AES-128 or AES-256 keys, and uses an incremental 32-bit C-MAC sequence counter (the V2 slot type) for host key storage. The C-MAC sequence counter determines the limitation of the usage of the host keys. The number of C-MAC operations is limited to 232 - 1 operations. After that, the commands requiring a C-MAC will fail. There is no mechanism to reset the counter. When the STSAFE-A120 receives an invalid host C-MAC, it increments a ratification counter called the host C- MAC ratification counter. When the counter reaches 50, the STSAFE-A120 refuses to use its host MAC key. Thus, commands requiring a host C-MAC are refused. When the STSAFE-A120 receives a valid host C-MAC and before the host MAC keys are blocked, it resets the host C-MAC ratification counter to 0. The host keys can be provisioned with either: • Plaintext: The keys are sent by the host in plaintext within the command • Wrapped: The keys are sent wrapped with a working KEK (key encryption key) that is a one-time use key derived from a volatile base KEK established by an ECDHE process. Command flow for plaintext host keys provisioning This use case assumes that the slots are empty. 1. The local host requests the STSAFE-A120 to generate a 128-bit random to be used as the host C-MAC key. 2. The local host requests the STSAFE-A120 to generate a 128-bit random to be used as the host cipher key. 3. The local host sends the PUT ATTRIBUTE command for the “Host key slot” attribute, together with the two generated keys (forming a 256-bit payload). 4. The STSAFE-A120 stores the keys into their respective slots and returns a successful response. 5. The local host stores the host C-MAC and cipher keys to a secure area. STSAFE-A120 Pairing with local host DS14609 - Rev 1 page 12/38 |
|
ссылки URL |
| Вашему бизинису помогли Аллдатащит? [ DONATE ] |
Что такое Аллдатащит | реклама | контакт | Конфиденциальность | Ссылка на техническое описание | обмен ссыками | поиск по производителю All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |