| Electronic Components Datasheet Search |
|
STSAFE-A120 Datasheet(PDF) 9 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
STSAFE-A120 Datasheet(HTML) 9 Page - STMicroelectronics |
|
9 / 38 page ![]() Depending on the personalization profile, the establish key command needs to be MACed and its answer is encrypted to avoid eavesdropping on the shared secret. The scenario assumes that the local host has set up a host C-MAC and cipher keys as described in Section 3: Pairing with local host. It is also assumed that the local host knows the host C-MAC sequence counter; if not, it can send a query command to the STSAFE-A120. Command flow 1. The remote host server sends its certificate to the local host. The local host extracts the public key and can optionally verify the validity of the certificate. In its response, the local host sends the STSAFE-A120 certificate. 2. The remote server verifies the STSAFE-A120 X.509 public key certificate with the CA public key (the host is responsible for getting this key). When the verification succeeds, the remote server has an authentic copy of the STSAFE-A120 public key. 3. The remote server then computes a shared secret (Z) by doing a scalar multiplication of the host’s private key with the STSAFE-A120 public key. 4. The remote server requests the local host to establish a secure connection. 5. The local host computes the host’s C-MAC for the establish key command 6. The local host sends the STSAFE-A120 an establish key command providing the remote host’s public key appended with the previously computed host’s C-MAC. The STSAFE-A120 does the same operation as the remote host server, and performs the scalar multiplication of its private key with the remote server’s public key to compute the shared secret (Z). It then encrypts the response using the host’s cipher key. 7. The local host reads the STSAFE-A120 answer and deciphers the shared secret (Z) with the locally stored host’s cipher key. 8. The remote host server and the local host have a shared secret Z. Figure 7. Key establishment command flow IoT device Remote server Local host (if needed) STSAFE-A120 Host Extracts public key from certificate Computes Z = scalar multiplication of host private key with STSAFE-A120 public key I2C RF or hardwired connection 1. Read STSAFE-A120 certificate Certificate Sends STSAFE-A120 certificate Sends host public key Establishes secure channel Computes host C-MAC for Establish Key command 2. Establish Key (Host public key) Ciphered Z Deciphers Z Done 2.5 Entity authentication An STSAFE-A120 device can authenticate an off-chip entity by verifying a digital signature generated by this entity with a private key. This is done over a challenge that was previously generated by the STSAFE-A120. STSAFE-A120 Product use cases DS14609 - Rev 1 page 9/38 |
|
Link URL |
| Does ALLDATASHEET help your business so far? [ DONATE ] |
About Alldatasheet | Advertisement | Contact us | Privacy Policy | Link to Datasheet | Link Exchange | Manufacturer List All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |