| поискавой системы для электроныых деталей |
|
ATSHA204A датащи(PDF) 84 Page - Microchip Technology |
|
|
|||||||||||||||||||||||||||||
ATSHA204A датащи(HTML) 84 Page - Microchip Technology |
|
84 / 93 page ![]() 13.3 Key Values All keys within the SHA204A are 256 bits long. The ATSHA204A uses these keys as part of the messages that are hashed with the MAC, CheckMac, HMAC and GenDig commands. Any slot in the Data zone of the EEPROM can be used to store a key, however, the value is secret only if the read and write permissions are properly set within SlotConfig (including the IsSecret bit). Except for the GenDig command, all but the least-significant four bits of the SlotID parameter are ignored in determining the source of key data. Only the least-significant four bits are used to select one of the slots of the Data zone. See Section Transport Keys, for information on how GenDig uses other SlotID values. In all cases for which a SHA-256 calculation is performed using Param2, the entire 16-bit SlotID as input is included in the message. 13.3.1 Diversified Keys If the host or validating entity has a place to securely store secrets, the key values stored in the EEPROM slot(s) can be diversified with the serial number embedded in the device (SN<0:8>). In this manner, every Client device can have a unique key, which can provide extra protection against known plaintext attacks and permit compromised serial numbers to be identified and blacklisted. To implement this, a root secret is externally combined with the device’s serial number during personalization using some cryptographic algorithm and the result written to the ATSHA204A key slot. The ATSHA204A CheckMac command provides a mechanism of securely generating and comparing diversified keys, eliminating this requirement from the Host system. Consult the following application note for more details: http://ww1.microchip.com/downloads/en/appnotes/doc8666.pdf 13.3.2 Rolled Keys In order to prevent repeated use of the same key value, the ATSHA204A supports key rolling. Normally, after a certain number of uses (perhaps as few as one), the current key value is replaced with the SHA-256 digest of its current value combined with some offset, which may either be a constant, something related to the current system (for example, a serial number or model number), or a random number. This capability is implemented using the DeriveKey command. Prior to execution of the DeriveKey command, the Nonce command must be run to load the offset into TempKey. Each time the roll operation is performed on slots 0 through 7, the UpdateCount field for that slot is incremented. One use of this capability is to permanently remove the original key from the device and replace it with a key that is only useful in a particular environment. After the key is rolled, there is no possible way to retrieve the old value, which improves the security of the system. Any power interruption during the execution of the DeriveKey command in Roll mode may cause either the key or the UpdateCount to have an unknown value. If writing to a slot is enabled using bit number 14 of SlotConfig, such keys can be written in encrypted and authenticated form using the Write command. Alternatively, multiple copies of the key can be stored in multiple slots so that failure of a single slot does not incapacitate the system. ATSHA204A Reference and Application Notes © 2018 Microchip Technology Inc. DS40002025A-page 84 |
|
ссылки URL |
| Вашему бизинису помогли Аллдатащит? [ DONATE ] |
Что такое Аллдатащит | реклама | контакт | Конфиденциальность | Ссылка на техническое описание | обмен ссыками | поиск по производителю All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |