| поискавой системы для электроныых деталей |
|
ATSHA204A датащи(PDF) 85 Page - Microchip Technology |
|
|
|||||||||||||||||||||||||||||
ATSHA204A датащи(HTML) 85 Page - Microchip Technology |
|
85 / 93 page ![]() 13.3.3 Created Keys In order to support unique ephemeral keys for every Client, the ATSHA204A also supports key creation. In this mechanism, a “parent” key (specified by SlotConfig.writeKey) is combined with a fixed or random nonce to create a unique key, which is then used for any cryptographic purpose. The ability to create unique keys is especially useful if the parent key has usage restrictions (see Section Limited-use Keys and Section Limited-use Key in the following sections). In this mode, the limited use parent key can be employed to create an unlimited use child key. Because the child key is useful only for this particular Host-Client pair, attacks on its value are less valuable. This capability is also implemented using the DeriveKey command. Prior to execution of the DeriveKey command, the Nonce command must be run to load the nonce value into TempKey. Each time the create operation is performed on slots 0 through 7; the UpdateCount field for that slot is incremented. 13.3.4 Limited-use Keys For the SlotID values corresponding to slots 0 through 7 in the data section of the EEPROM, repeated usage of the key stored in the slot can be strictly limited. This feature is enabled if the LimitedUse bit is set in the SlotConfig field. The LimitedUse bit is ignored for slots 8 through 14. The number of remaining uses is stored as a bit map in the UseFlag byte corresponding to the slot in question. Prior to execution of any cryptographic command that uses this slot as a key, the following takes place: • If SlotConfig<SlotID>.LimitedUse is set and UseFlag<SlotID> is 0x00, the device returns an error. • Starting at bit 7 of UseFlag<SlotID>, clear to zero the first bit that is currently a one. In practice, this procedure permits LimitedUse keys to be used eight times between “refreshes” using the DeriveKey command. If power is lost during the execution of any command referencing a key that has this feature enabled, one of the use bits in UseFlag may still be cleared even though the command did not complete. For this reason, Microchip recommends that the key be used a single time only, with the other bits providing a safety margin for errors. Under normal circumstances, all eight UseFlag bytes should be initialized to 0xFF. If it is the intention to permit fewer than eight uses of a particular key, these bytes should be initialized to 0x7F (seven uses), 0x3F (six uses), 0x1F (five uses), 0x0F (four uses), 0x07 (three uses), 0x03 (two uses), or 0x01 (one use). Initialization to any other value besides these values or 0xFF is prohibited. The Read, Write and DeriveKey commands operate slightly differently as noted below: • Read and Write These commands ignore the state of the LimitedUse bit and the UseFlag byte does not change as a result of their execution. LimitedUse slots in which the UseFlag is exhausted (value of 0x00) can still be read or written (subject to the appropriate SlotConfig limitations) although the value in the slot cannot ever be used as a key for cryptographic commands. If SlotConfig.WriteKey for slot X points back to X, but UseFlag<X> is exhausted, then encrypted writes to the slot never succeed because the prior GenDig command will have returned an error due to the usage limitation. A similar situation occurs with reads and ReadKey. Slots used as keys should never have IsSecret set to zero or WriteConfig set to always. • DeriveKey If the parent key is used for either authentication or as the source, then if LimitedUse (for the parent) is set and UseFlag (also for the parent) is 0x00, the DeriveKey command returns an error. The LimitedUse and UseFlag bits are ignored for the target key. When successfully executed, ATSHA204A Reference and Application Notes © 2018 Microchip Technology Inc. DS40002025A-page 85 |
|
ссылки URL |
| Вашему бизинису помогли Аллдатащит? [ DONATE ] |
Что такое Аллдатащит | реклама | контакт | Конфиденциальность | Ссылка на техническое описание | обмен ссыками | поиск по производителю All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |