Hardware acceleration for the mbedCrypto implementation of the Arm PSA Crypto API.
Overview
Note The PSA Crypto module does not provide any interfaces to the user. This release uses the mbedTLS version 3.6.6 which conforms to the PSA Crypto API 1.0 specification. Consult the Arm documentation at https://armmbed.github.io/mbed-crypto/psa/#application-programming-interface for further information. FSP 3.0 onward adopts a change by Arm where mbedCrypto has been integrated back to MbedTLS and the term mbedCrypto has been deprecated. The mbedCrypto term in FSP now refers to the crypto portion of the MbedTLS module.
HW Overview
Crypto Peripheral version Devices
RSIP-E50D RX74M, RX74N
Features
AES Engine AES Engine 2 SCE5 SCE5_B SCE7 SCE9 RSIP-E11A RSIP-E31A RSIP-E51A RSIP-E50D
TRNG Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
Hash SHA224, SHA256 – – – – Yes Yes Yes Yes Yes Yes
SHA384, SHA512 – – – – – – – Yes Yes Yes
SHA3-(224/256/384/512) – – – – – – – – – Yes
MAC HMAC-SHA224, HMAC-SHA256 – – – – Yes Yes Yes Yes Yes Yes
HMAC-SHA384, HMAC-SHA512 – – – – – – – Yes Yes Yes
AES128-CMAC – Yes Yes Yes Yes Yes Yes Yes Yes Yes
AES192-CMAC – – – – – – – – Yes Yes
AES256-CMAC – Yes Yes Yes Yes Yes Yes Yes Yes Yes
AES-CMAC-PRF-128 – Yes Yes Yes Yes Yes Yes Yes Yes Yes
AES AES128-ECB, CBC, CTR Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
AES128-XTS – – – – Yes Yes – – Yes Yes
AES128-GCM, GMAC, CCM – Yes Yes Yes Yes Yes Yes Yes Yes Yes
AES192-ECB, CBC, CTR – – – – Yes Yes – – Yes Yes
AES192-GCM, GMAC, CCM – – – – Yes Yes – – Yes Yes
AES256-ECB, CBC, CTR Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
AES256-XTS – – – – Yes Yes – – Yes Yes
AES256-GCM, GMAC, CCM – Yes Yes Yes Yes Yes Yes Yes Yes Yes
Key generation - plaintext Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
Key generation - wrapped – – Yes Yes Yes Yes Yes Yes Yes Yes
ChaCha ChaCha20 – – – – – – – – – Yes
ChaCha20-Poly1305 – – – – – – – – – Yes
ECC secp256r1 – – – – Yes Yes Yes Yes Yes Yes
secp384r1 – – – – Yes Yes – Yes Yes Yes
secp521r1 – – – – – – – – Yes Yes
Brainpool256r1 – – – – Yes Yes – Yes Yes Yes
Brainpool384r1 – – – – Yes Yes – Yes Yes Yes
Key generation - plaintext – – – – Yes Yes – – Yes Yes
Key generation - wrapped – – – – – Yes Yes Yes Yes Yes
RSA RSA-1024 – – – – – Yes – – Yes Yes
RSA-2048 – – – – Yes Yes – – Yes Yes
RSA-3072 – – – – – (1) – – Yes Yes
RSA-4096 – – – – – (1) – – Yes Yes
Key generation - plaintext – – – – Yes (2) – – (3) (3)
Key generation - wrapped – – – – Yes (2) – – (3) (3)
ML-KEM Key generation - plaintext – – – – – – – – – (4)
ML-KEM-512 – – – – – – – – – (4)
ML-KEM-768 – – – – – – – – – (4)
ML-KEM-1024 – – – – – – – – – (4)
Note
Signature verification only
RSA-1024 and RSA-2048 only
RSA-2048, RSA-3072, RSA-4096 only
SHA3 only
Configuration
Build Time Configurations for mbedCrypto
The following build time configurations are defined in arm/mbedtls/config.h:
Configuration Options Default Description
Hardware Acceleration > Key Format > AES MCU Specific Options Select AES key formats used
Hardware Acceleration > Key Format > ECC MCU Specific Options Select ECC key formats used
Hardware Acceleration > Key Format > RSA MCU Specific Options Select RSA key formats used
Hardware Acceleration > Hash > SHA256/224 MCU Specific Options Defines MBEDTLS_SHA256_ALT and MBEDTLS_SHA256_PROCESS_ALT.
Hardware Acceleration > Hash > SHA512/384 MCU Specific Options Defines MBEDTLS_SHA512_ALT and MBEDTLS_SHA512_PROCESS_ALT.
Hardware Acceleration > Hash > SHA3_224/256/384/512 MCU Specific Options Defines MBEDTLS_SHA3_ALT and MBEDTLS_SHA3_PROCESS_ALT.
Hardware Acceleration > Cipher > AES MCU Specific Options Defines MBEDTLS_AES_ALT, MBEDTLS_AES_SETKEY_ENC_ALT, MBEDTLS_AES_SETKEY_DEC_ALT, MBEDTLS_AES_ENCRYPT_ALT and MBEDTLS_AES_DECRYPT_ALT
Hardware Acceleration > Public Key Cryptography (PKC) > RSA 3072 > Key Generation MCU Specific Options Enables RSA 3072 Key Generation.
Hardware Acceleration > Public Key Cryptography (PKC) > RSA 3072 > Signing MCU Specific Options Enables RSA 3072 Key Signing.
Hardware Acceleration > Public Key Cryptography (PKC) > RSA 3072 > Verification MCU Specific Options Enables RSA 3072 Verify.
Hardware Acceleration > Public Key Cryptography (PKC) > RSA 4096 > Key Generation MCU Specific Options Enables RSA 4096 Key Generation.
Hardware Acceleration > Public Key Cryptography (PKC) > RSA 4096 > Signing MCU Specific Options Enables RSA 4096 Key Signing.
Hardware Acceleration > Public Key Cryptography (PKC) > RSA 4096 > Verification MCU Specific Options Enables RSA 4096 Verify.
Hardware Acceleration > Public Key Cryptography (PKC) > ECC MCU Specific Options Defines MBEDTLS_ECP_ALT
Hardware Acceleration > Public Key Cryptography (PKC) > ECDSA MCU Specific Options Defines MBEDTLS_ECDSA_SIGN_ALT and MBEDTLS_ECDSA_VERIFY_ALT
Hardware Acceleration > Public Key Cryptography (PKC) > ECDH MCU Specific Options Defines MBEDTLS_ECDH_ALT
Hardware Acceleration > Public Key Cryptography (PKC) > RSA 1024 MCU Specific Options Defines MBEDTLS_RSA_1024_ALT. RSA 1024 Key Generation, Signing and Verification are also enabled.
Hardware Acceleration > Public Key Cryptography (PKC) > RSA 2048 MCU Specific Options Defines MBEDTLS_RSA_ALT. RSA 2048 Key Generation, Signing and Verification are also enabled.
Hardware Acceleration > TRNG Enabled Enabled Defines MBEDTLS_ENTROPY_HARDWARE_ALT.
Hardware Acceleration > Crypto Engine Initialization Enabled Enabled MBEDTLS_PLATFORM_SETUP_TEARDOWN_ALT
Platform > Alternate > MBEDTLS_PLATFORM_SETBUF_ALT
Undefine MBEDTLS_PLATFORM_SETBUF_ALT
Platform > Alternate > MBEDTLS_PLATFORM_EXIT_ALT
Undefine MBEDTLS_PLATFORM_EXIT_ALT
Platform > Alternate > MBEDTLS_PLATFORM_TIME_ALT
Undefine MBEDTLS_PLATFORM_TIME_ALT
Platform > Alternate > MBEDTLS_PLATFORM_FPRINTF_ALT
Undefine MBEDTLS_PLATFORM_FPRINTF_ALT
Platform > Alternate > MBEDTLS_PLATFORM_PRINTF_ALT
Undefine MBEDTLS_PLATFORM_PRINTF_ALT
Platform > Alternate > MBEDTLS_PLATFORM_SNPRINTF_ALT
Undefine MBEDTLS_PLATFORM_SNPRINTF_ALT
Platform > Alternate > MBEDTLS_PLATFORM_VSNPRINTF_ALT
Undefine MBEDTLS_PLATFORM_VSNPRINTF_ALT
Platform > Alternate > MBEDTLS_PLATFORM_NV_SEED_ALT
Undefine MBEDTLS_PLATFORM_NV_SEED_ALT
Platform > Alternate > MBEDTLS_PLATFORM_MS_TIME_ALT
Undefine MBEDTLS_PLATFORM_MS_TIME_ALT
Platform > Alternate > MBEDTLS_PLATFORM_ZEROIZE_ALT
Undefine MBEDTLS_PLATFORM_ZEROIZE_ALT
Platform > Alternate > MBEDTLS_PLATFORM_GMTIME_R_ALT
Undefine MBEDTLS_PLATFORM_GMTIME_R_ALT
Platform > MBEDTLS_HAVE_ASM
Undefine MBEDTLS_HAVE_ASM
Platform > MBEDTLS_NO_UDBL_DIVISION
Undefine MBEDTLS_NO_UDBL_DIVISION
Platform > MBEDTLS_NO_64BIT_MULTIPLICATION
Undefine MBEDTLS_NO_64BIT_MULTIPLICATION
Platform > MBEDTLS_HAVE_SSE2
Undefine MBEDTLS_HAVE_SSE2
Platform > MBEDTLS_HAVE_TIME
Undefine MBEDTLS_HAVE_TIME
Platform > MBEDTLS_HAVE_TIME_DATE
Undefine MBEDTLS_HAVE_TIME_DATE
Platform > MBEDTLS_PLATFORM_MEMORY
Define MBEDTLS_PLATFORM_MEMORY
Platform > MBEDTLS_PLATFORM_NO_STD_FUNCTIONS
Undefine MBEDTLS_PLATFORM_NO_STD_FUNCTIONS
Platform > MBEDTLS_TIMING_ALT
Undefine MBEDTLS_TIMING_ALT
Platform > MBEDTLS_NO_PLATFORM_ENTROPY
Define MBEDTLS_NO_PLATFORM_ENTROPY
Platform > MBEDTLS_ENTROPY_C
Define MBEDTLS_ENTROPY_C
Platform > MBEDTLS_PLATFORM_C
Define MBEDTLS_PLATFORM_C
Platform > MBEDTLS_PLATFORM_STD_CALLOC
Undefine MBEDTLS_PLATFORM_STD_CALLOC
Platform > MBEDTLS_PLATFORM_STD_CALLOC value Manual Entry calloc MBEDTLS_PLATFORM_STD_CALLOC value
Platform > MBEDTLS_PLATFORM_STD_FREE
Undefine MBEDTLS_PLATFORM_STD_FREE
Platform > MBEDTLS_PLATFORM_STD_FREE value Manual Entry free MBEDTLS_PLATFORM_STD_FREE value
Platform > MBEDTLS_PLATFORM_STD_SETBUF
Undefine MBEDTLS_PLATFORM_STD_SETBUF
Platform > MBEDTLS_PLATFORM_STD_SETBUF value Manual Entry setbuf MBEDTLS_PLATFORM_STD_SETBUF value
Platform > MBEDTLS_PLATFORM_STD_EXIT
Undefine MBEDTLS_PLATFORM_STD_EXIT
Platform > MBEDTLS_PLATFORM_STD_EXIT value Manual Entry exit MBEDTLS_PLATFORM_STD_EXIT value
Platform > MBEDTLS_PLATFORM_STD_TIME
Undefine MBEDTLS_PLATFORM_STD_TIME
Platform > MBEDTLS_PLATFORM_STD_TIME value Manual Entry time MBEDTLS_PLATFORM_STD_TIME value
Platform > MBEDTLS_PLATFORM_STD_FPRINTF
Undefine MBEDTLS_PLATFORM_STD_FPRINTF
Platform > MBEDTLS_PLATFORM_STD_FPRINTF value Manual Entry fprintf MBEDTLS_PLATFORM_STD_FPRINTF value
Platform > MBEDTLS_PLATFORM_STD_PRINTF
Undefine MBEDTLS_PLATFORM_STD_PRINTF
Platform > MBEDTLS_PLATFORM_STD_PRINTF value Manual Entry printf MBEDTLS_PLATFORM_STD_PRINTF value
Platform > MBEDTLS_PLATFORM_STD_SNPRINTF
Undefine MBEDTLS_PLATFORM_STD_SNPRINTF
Platform > MBEDTLS_PLATFORM_STD_SNPRINTF value Manual Entry snprintf MBEDTLS_PLATFORM_STD_SNPRINTF value
Platform > MBEDTLS_PLATFORM_STD_EXIT_SUCCESS
Undefine MBEDTLS_PLATFORM_STD_EXIT_SUCCESS
Platform > MBEDTLS_PLATFORM_STD_EXIT_SUCCESS value Manual Entry 0 MBEDTLS_PLATFORM_STD_EXIT_SUCCESS value
Platform > MBEDTLS_PLATFORM_STD_EXIT_FAILURE
Undefine MBEDTLS_PLATFORM_STD_EXIT_FAILURE
Platform > MBEDTLS_PLATFORM_STD_EXIT_FAILURE value Manual Entry 1 MBEDTLS_PLATFORM_STD_EXIT_FAILURE value
Platform > MBEDTLS_PLATFORM_STD_NV_SEED_READ
Undefine MBEDTLS_PLATFORM_STD_NV_SEED_READ
Platform > MBEDTLS_PLATFORM_STD_NV_SEED_READ value Manual Entry mbedtls_platform_std_nv_seed_read MBEDTLS_PLATFORM_STD_NV_SEED_READ value
Platform > MBEDTLS_PLATFORM_STD_NV_SEED_WRITE
Undefine MBEDTLS_PLATFORM_STD_NV_SEED_WRITE
Platform > MBEDTLS_PLATFORM_STD_NV_SEED_WRITE value Manual Entry mbedtls_platform_std_nv_seed_write MBEDTLS_PLATFORM_STD_NV_SEED_WRITE value
Platform > MBEDTLS_PLATFORM_STD_NV_SEED_FILE
Undefine MBEDTLS_PLATFORM_STD_NV_SEED_FILE
Platform > MBEDTLS_PLATFORM_STD_NV_SEED_FILE value Manual Entry MBEDTLS_PLATFORM_STD_NV_SEED_FILE value
Platform > MBEDTLS_PLATFORM_CALLOC_MACRO
Undefine MBEDTLS_PLATFORM_CALLOC_MACRO
Platform > MBEDTLS_PLATFORM_CALLOC_MACRO value Manual Entry calloc MBEDTLS_PLATFORM_CALLOC_MACRO value
Platform > MBEDTLS_PLATFORM_FREE_MACRO
Undefine MBEDTLS_PLATFORM_FREE_MACRO
Platform > MBEDTLS_PLATFORM_FREE_MACRO value Manual Entry free MBEDTLS_PLATFORM_FREE_MACRO value
Platform > MBEDTLS_PLATFORM_EXIT_MACRO
Undefine MBEDTLS_PLATFORM_EXIT_MACRO
Platform > MBEDTLS_PLATFORM_EXIT_MACRO value Manual Entry exit MBEDTLS_PLATFORM_EXIT_MACRO value
Platform > MBEDTLS_PLATFORM_SETBUF_MACRO
Define MBEDTLS_PLATFORM_SETBUF_MACRO
Platform > MBEDTLS_PLATFORM_SETBUF_MACRO value Manual Entry dummy_setbuf MBEDTLS_PLATFORM_SETBUF_MACRO value
Platform > MBEDTLS_PLATFORM_TIME_MACRO
Undefine MBEDTLS_PLATFORM_TIME_MACRO
Platform > MBEDTLS_PLATFORM_TIME_MACRO value Manual Entry time MBEDTLS_PLATFORM_TIME_MACRO value
Platform > MBEDTLS_PLATFORM_TIME_TYPE_MACRO
Undefine MBEDTLS_PLATFORM_TIME_TYPE_MACRO
Platform > MBEDTLS_PLATFORM_TIME_TYPE_MACRO value Manual Entry time_t MBEDTLS_PLATFORM_TIME_TYPE_MACRO value
Platform > MBEDTLS_PLATFORM_MS_TIME_TYPE_MACRO
Undefine MBEDTLS_PLATFORM_MS_TIME_TYPE_MACRO
Platform > MBEDTLS_PLATFORM_MS_TIME_TYPE_MACRO value Manual Entry int64_t MBEDTLS_PLATFORM_MS_TIME_TYPE_MACRO value
Platform > MBEDTLS_PRINTF_MS_TIME
Undefine MBEDTLS_PRINTF_MS_TIME
Platform > MBEDTLS_PLATFORM_DEV_RANDOM
Undefine MBEDTLS_PLATFORM_DEV_RANDOM
Platform > MBEDTLS_PRINTF_MS_TIME value Manual Entry PRId64 MBEDTLS_PRINTF_MS_TIME value
Platform > MBEDTLS_PLATFORM_FPRINTF_MACRO
Undefine MBEDTLS_PLATFORM_FPRINTF_MACRO
Platform > MBEDTLS_PLATFORM_FPRINTF_MACRO value Manual Entry fprintf MBEDTLS_PLATFORM_FPRINTF_MACRO value
Platform > MBEDTLS_PLATFORM_PRINTF_MACRO
Undefine MBEDTLS_PLATFORM_PRINTF_MACRO
Platform > MBEDTLS_PLATFORM_PRINTF_MACRO value Manual Entry printf MBEDTLS_PLATFORM_PRINTF_MACRO value
Platform > MBEDTLS_PLATFORM_SNPRINTF_MACRO
Undefine MBEDTLS_PLATFORM_SNPRINTF_MACRO
Platform > MBEDTLS_PLATFORM_SNPRINTF_MACRO value Manual Entry snprintf MBEDTLS_PLATFORM_SNPRINTF_MACRO value
Platform > MBEDTLS_PLATFORM_VSNPRINTF_MACRO
Undefine MBEDTLS_PLATFORM_VSNPRINTF_MACRO
Platform > MBEDTLS_PLATFORM_VSNPRINTF_MACRO value Manual Entry vsnprintf MBEDTLS_PLATFORM_VSNPRINTF_MACRO value
Platform > MBEDTLS_PLATFORM_NV_SEED_READ_MACRO
Undefine MBEDTLS_PLATFORM_NV_SEED_READ_MACRO
Platform > MBEDTLS_PLATFORM_NV_SEED_READ_MACRO value Manual Entry mbedtls_platform_std_nv_seed_read MBEDTLS_PLATFORM_NV_SEED_READ_MACRO value
Platform > MBEDTLS_PLATFORM_NV_SEED_WRITE_MACRO
Undefine MBEDTLS_PLATFORM_NV_SEED_WRITE_MACRO
Platform > MBEDTLS_PLATFORM_NV_SEED_WRITE_MACRO value Manual Entry mbedtls_platform_std_nv_seed_write MBEDTLS_PLATFORM_NV_SEED_WRITE_MACRO value
General > MBEDTLS_PSA_CRYPTO_DRIVERS
Undefine MBEDTLS_PSA_CRYPTO_DRIVERS
General > MBEDTLS_DEPRECATED_WARNING
Undefine MBEDTLS_DEPRECATED_WARNING
General > MBEDTLS_DEPRECATED_REMOVED
Define MBEDTLS_DEPRECATED_REMOVED
General > MBEDTLS_CHECK_RETURN_WARNING
Undefine MBEDTLS_CHECK_RETURN_WARNING
General > MBEDTLS_ERROR_STRERROR_DUMMY
Define MBEDTLS_ERROR_STRERROR_DUMMY
General > MBEDTLS_MEMORY_DEBUG
Undefine MBEDTLS_MEMORY_DEBUG
General > MBEDTLS_MEMORY_BACKTRACE
Undefine MBEDTLS_MEMORY_BACKTRACE
General > MBEDTLS_PSA_CRYPTO_CLIENT
Undefine MBEDTLS_PSA_CRYPTO_CLIENT
General > MBEDTLS_PSA_CRYPTO_SPM
Undefine MBEDTLS_PSA_CRYPTO_SPM
General > MBEDTLS_PSA_KEY_STORE_DYNAMIC
Undefine MBEDTLS_PSA_KEY_STORE_DYNAMIC
General > MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS
Undefine MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS
General > MBEDTLS_SELF_TEST
Undefine MBEDTLS_SELF_TEST
General > MBEDTLS_THREADING_ALT
Define MBEDTLS_THREADING_ALT
General > MBEDTLS_THREADING_PTHREAD
Undefine MBEDTLS_THREADING_PTHREAD
General > MBEDTLS_USE_PSA_CRYPTO Undefine Undefine MBEDTLS_USE_PSA_CRYPTO
General > MBEDTLS_VERSION_FEATURES
Define MBEDTLS_VERSION_FEATURES
General > MBEDTLS_ERROR_C
Define MBEDTLS_ERROR_C
General > MBEDTLS_MEMORY_BUFFER_ALLOC_C
Undefine MBEDTLS_MEMORY_BUFFER_ALLOC_C
General > MBEDTLS_PSA_CRYPTO_C
Define MBEDTLS_PSA_CRYPTO_C
General > MBEDTLS_PSA_CRYPTO_SE_C
Undefine MBEDTLS_PSA_CRYPTO_SE_C
General > MBEDTLS_THREADING_C
Define MBEDTLS_THREADING_C
General > MBEDTLS_TIMING_C
Undefine MBEDTLS_TIMING_C
General > MBEDTLS_VERSION_C
Define MBEDTLS_VERSION_C
General > MBEDTLS_MEMORY_ALIGN_MULTIPLE
Undefine MBEDTLS_MEMORY_ALIGN_MULTIPLE
General > MBEDTLS_MEMORY_ALIGN_MULTIPLE value Manual Entry 4 MBEDTLS_MEMORY_ALIGN_MULTIPLE value
General > MBEDTLS_CHECK_RETURN
Define MBEDTLS_CHECK_RETURN
General > MBEDTLS_IGNORE_RETURN
Undefine MBEDTLS_IGNORE_RETURN
General > MBEDTLS_PSA_CRYPTO_CONFIG
Undefine MBEDTLS_PSA_CRYPTO_CONFIG
Cipher > Alternate > MBEDTLS_ARIA_ALT
Undefine MBEDTLS_ARIA_ALT
Cipher > Alternate > MBEDTLS_CAMELLIA_ALT
Undefine MBEDTLS_CAMELLIA_ALT
Cipher > Alternate > MBEDTLS_CCM_ALT MCU Specific Options MBEDTLS_CCM_ALT
Cipher > Alternate > MBEDTLS_CHACHA20_ALT MCU Specific Options MBEDTLS_CHACHA20_ALT
Cipher > Alternate > MBEDTLS_CHACHAPOLY_ALT MCU Specific Options MBEDTLS_CHACHAPOLY_ALT
Cipher > Alternate > MBEDTLS_CMAC_ALT MCU Specific Options MBEDTLS_CMAC_ALT
Cipher > Alternate > MBEDTLS_DES_ALT
Undefine MBEDTLS_DES_ALT
Cipher > Alternate > MBEDTLS_GCM_ALT MCU Specific Options MBEDTLS_GCM_ALT
Cipher > Alternate > MBEDTLS_NIST_KW_ALT
Undefine MBEDTLS_NIST_KW_ALT
Cipher > Alternate > MBEDTLS_DES_SETKEY_ALT
Undefine MBEDTLS_DES_SETKEY_ALT
Cipher > Alternate > MBEDTLS_DES_CRYPT_ECB_ALT
Undefine MBEDTLS_DES_CRYPT_ECB_ALT
Cipher > Alternate > MBEDTLS_DES3_CRYPT_ECB_ALT
Undefine MBEDTLS_DES3_CRYPT_ECB_ALT
Cipher > AES > MBEDTLS_AES_ROM_TABLES
Undefine MBEDTLS_AES_ROM_TABLES
Cipher > AES > MBEDTLS_AES_FEWER_TABLES
Undefine MBEDTLS_AES_FEWER_TABLES
Cipher > AES > MBEDTLS_AES_ONLY_128_BIT_KEY_LENGTH
Undefine MBEDTLS_AES_ONLY_128_BIT_KEY_LENGTH
Cipher > MBEDTLS_CAMELLIA_SMALL_MEMORY
Undefine MBEDTLS_CAMELLIA_SMALL_MEMORY
Cipher > MBEDTLS_CIPHER_MODE_CBC
Define MBEDTLS_CIPHER_MODE_CBC
Cipher > MBEDTLS_CIPHER_MODE_CFB
Define MBEDTLS_CIPHER_MODE_CFB
Cipher > MBEDTLS_CIPHER_MODE_CTR
Define MBEDTLS_CIPHER_MODE_CTR
Cipher > MBEDTLS_CIPHER_MODE_OFB
Undefine MBEDTLS_CIPHER_MODE_OFB
Cipher > MBEDTLS_CIPHER_MODE_XTS
Undefine MBEDTLS_CIPHER_MODE_XTS
Cipher > MBEDTLS_CIPHER_NULL_CIPHER
Undefine MBEDTLS_CIPHER_NULL_CIPHER
Cipher > MBEDTLS_CIPHER_PADDING_PKCS7
Define MBEDTLS_CIPHER_PADDING_PKCS7
Cipher > MBEDTLS_CIPHER_PADDING_ONE_AND_ZEROS
Define MBEDTLS_CIPHER_PADDING_ONE_AND_ZEROS
Cipher > MBEDTLS_CIPHER_PADDING_ZEROS_AND_LEN
Define MBEDTLS_CIPHER_PADDING_ZEROS_AND_LEN
Cipher > MBEDTLS_CIPHER_PADDING_ZEROS
Define MBEDTLS_CIPHER_PADDING_ZEROS
Cipher > MBEDTLS_AES_C Define Define MBEDTLS_AES_C
Cipher > MBEDTLS_BLOCK_CIPHER_NO_DECRYPT
Undefine MBEDTLS_BLOCK_CIPHER_NO_DECRYPT
Cipher > MBEDTLS_CAMELLIA_C
Undefine MBEDTLS_CAMELLIA_C
Cipher > MBEDTLS_ARIA_C
Undefine MBEDTLS_ARIA_C
Cipher > MBEDTLS_CCM_C
Define MBEDTLS_CCM_C
Cipher > MBEDTLS_CHACHA20_C
Undefine MBEDTLS_CHACHA20_C
Cipher > MBEDTLS_CHACHAPOLY_C
Undefine MBEDTLS_CHACHAPOLY_C
Cipher > MBEDTLS_CIPHER_C
Define MBEDTLS_CIPHER_C
Cipher > MBEDTLS_DES_C
Undefine MBEDTLS_DES_C
Cipher > MBEDTLS_GCM_C
Define MBEDTLS_GCM_C
Cipher > MBEDTLS_GCM_LARGE_TABLE
Undefine MBEDTLS_GCM_LARGE_TABLE
Cipher > MBEDTLS_NIST_KW_C
Undefine MBEDTLS_NIST_KW_C
Public Key Cryptography (PKC) > DHM > Alternate > MBEDTLS_DHM_ALT
Undefine MBEDTLS_DHM_ALT
Public Key Cryptography (PKC) > DHM > MBEDTLS_DHM_C
Undefine MBEDTLS_DHM_C
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECJPAKE_ALT
Undefine MBEDTLS_ECJPAKE_ALT
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECDSA_GENKEY_ALT
Undefine MBEDTLS_ECDSA_GENKEY_ALT
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECP_INTERNAL_ALT
Undefine MBEDTLS_ECP_INTERNAL_ALT
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECP_RANDOMIZE_JAC_ALT
Undefine MBEDTLS_ECP_RANDOMIZE_JAC_ALT
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECP_ADD_MIXED_ALT
Undefine MBEDTLS_ECP_ADD_MIXED_ALT
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECP_DOUBLE_JAC_ALT
Undefine MBEDTLS_ECP_DOUBLE_JAC_ALT
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECP_NORMALIZE_JAC_MANY_ALT
Undefine MBEDTLS_ECP_NORMALIZE_JAC_MANY_ALT
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECP_NORMALIZE_JAC_ALT
Undefine MBEDTLS_ECP_NORMALIZE_JAC_ALT
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECP_DOUBLE_ADD_MXZ_ALT
Undefine MBEDTLS_ECP_DOUBLE_ADD_MXZ_ALT
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECP_RANDOMIZE_MXZ_ALT
Undefine MBEDTLS_ECP_RANDOMIZE_MXZ_ALT
Public Key Cryptography (PKC) > ECC > Alternate > MBEDTLS_ECP_NORMALIZE_MXZ_ALT
Undefine MBEDTLS_ECP_NORMALIZE_MXZ_ALT
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_SECP192R1_ENABLED
Undefine MBEDTLS_ECP_DP_SECP192R1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_SECP224R1_ENABLED
Undefine MBEDTLS_ECP_DP_SECP224R1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_SECP256R1_ENABLED
Define MBEDTLS_ECP_DP_SECP256R1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_SECP384R1_ENABLED
Undefine MBEDTLS_ECP_DP_SECP384R1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_SECP521R1_ENABLED
Undefine MBEDTLS_ECP_DP_SECP521R1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_SECP192K1_ENABLED
Undefine MBEDTLS_ECP_DP_SECP192K1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_SECP224K1_ENABLED
Undefine MBEDTLS_ECP_DP_SECP224K1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_SECP256K1_ENABLED
Undefine MBEDTLS_ECP_DP_SECP256K1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_BP256R1_ENABLED
Undefine MBEDTLS_ECP_DP_BP256R1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_BP384R1_ENABLED
Undefine MBEDTLS_ECP_DP_BP384R1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_BP512R1_ENABLED
Undefine MBEDTLS_ECP_DP_BP512R1_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_CURVE25519_ENABLED
Undefine MBEDTLS_ECP_DP_CURVE25519_ENABLED
Public Key Cryptography (PKC) > ECC > Curves > MBEDTLS_ECP_DP_CURVE448_ENABLED
Undefine MBEDTLS_ECP_DP_CURVE448_ENABLED
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECDH_GEN_PUBLIC_ALT
Undefine MBEDTLS_ECDH_GEN_PUBLIC_ALT
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECDH_COMPUTE_SHARED_ALT
Undefine MBEDTLS_ECDH_COMPUTE_SHARED_ALT
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECP_NO_FALLBACK
Undefine MBEDTLS_ECP_NO_FALLBACK
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECP_NIST_OPTIM
Undefine MBEDTLS_ECP_NIST_OPTIM
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECP_RESTARTABLE
Undefine MBEDTLS_ECP_RESTARTABLE
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECDSA_DETERMINISTIC
Undefine MBEDTLS_ECDSA_DETERMINISTIC
Public Key Cryptography (PKC) > ECC > MBEDTLS_PK_PARSE_EC_COMPRESSED
Undefine MBEDTLS_PK_PARSE_EC_COMPRESSED
Public Key Cryptography (PKC) > ECC > MBEDTLS_PK_PARSE_EC_EXTENDED
Undefine MBEDTLS_PK_PARSE_EC_EXTENDED
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECDH_C
Undefine MBEDTLS_ECDH_C
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECDSA_C
Define MBEDTLS_ECDSA_C
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECP_C
Define MBEDTLS_ECP_C
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECJPAKE_C
Undefine MBEDTLS_ECJPAKE_C
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECP_WINDOW_SIZE
Undefine MBEDTLS_ECP_WINDOW_SIZE
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECP_WINDOW_SIZE value Manual Entry 6 MBEDTLS_ECP_WINDOW_SIZE value
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECP_FIXED_POINT_OPTIM
Undefine MBEDTLS_ECP_FIXED_POINT_OPTIM
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECP_FIXED_POINT_OPTIM value Manual Entry 1 MBEDTLS_ECP_FIXED_POINT_OPTIM value
Public Key Cryptography (PKC) > ECC > MBEDTLS_ECDH_VARIANT_EVEREST_ENABLED
Undefine MBEDTLS_ECDH_VARIANT_EVEREST_ENABLED
Public Key Cryptography (PKC) > RSA > MBEDTLS_PK_RSA_ALT_SUPPORT
Undefine MBEDTLS_PK_RSA_ALT_SUPPORT
Public Key Cryptography (PKC) > RSA > MBEDTLS_RSA_NO_CRT
Define MBEDTLS_RSA_NO_CRT
Public Key Cryptography (PKC) > RSA > MBEDTLS_RSA_C
Define MBEDTLS_RSA_C
Public Key Cryptography (PKC) > RSA > MBEDTLS_RSA_GEN_KEY_MIN_BITS
Undefine MBEDTLS_RSA_GEN_KEY_MIN_BITS
Public Key Cryptography (PKC) > RSA > MBEDTLS_RSA_GEN_KEY_MIN_BITS value Manual Entry 1024 MBEDTLS_RSA_GEN_KEY_MIN_BITS value
Public Key Cryptography (PKC) > MBEDTLS_GENPRIME
Define MBEDTLS_GENPRIME
Public Key Cryptography (PKC) > MBEDTLS_PKCS1_V15
Define MBEDTLS_PKCS1_V15
Public Key Cryptography (PKC) > MBEDTLS_PKCS1_V21
Define MBEDTLS_PKCS1_V21
Public Key Cryptography (PKC) > MBEDTLS_ASN1_PARSE_C
Define MBEDTLS_ASN1_PARSE_C
Public Key Cryptography (PKC) > MBEDTLS_ASN1_WRITE_C
Define MBEDTLS_ASN1_WRITE_C
Public Key Cryptography (PKC) > MBEDTLS_BASE64_C
Define MBEDTLS_BASE64_C
Public Key Cryptography (PKC) > MBEDTLS_BIGNUM_C
Define MBEDTLS_BIGNUM_C
Public Key Cryptography (PKC) > MBEDTLS_LMS_C
Define MBEDTLS_LMS_C
Public Key Cryptography (PKC) > MBEDTLS_LMS_PRIVATE
Undefine MBEDTLS_LMS_PRIVATE
Public Key Cryptography (PKC) > MBEDTLS_OID_C
Define MBEDTLS_OID_C
Public Key Cryptography (PKC) > MBEDTLS_PEM_PARSE_C
Define MBEDTLS_PEM_PARSE_C
Public Key Cryptography (PKC) > MBEDTLS_PEM_WRITE_C
Define MBEDTLS_PEM_WRITE_C
Public Key Cryptography (PKC) > MBEDTLS_PK_C
Define MBEDTLS_PK_C
Public Key Cryptography (PKC) > MBEDTLS_PK_PARSE_C
Define MBEDTLS_PK_PARSE_C
Public Key Cryptography (PKC) > MBEDTLS_PK_WRITE_C
Define MBEDTLS_PK_WRITE_C
Public Key Cryptography (PKC) > MBEDTLS_PKCS5_C
Define MBEDTLS_PKCS5_C
Public Key Cryptography (PKC) > MBEDTLS_PKCS7_C
Undefine MBEDTLS_PKCS7_C
Public Key Cryptography (PKC) > MBEDTLS_PKCS12_C
Define MBEDTLS_PKCS12_C
Public Key Cryptography (PKC) > MBEDTLS_MPI_WINDOW_SIZE
Undefine MBEDTLS_MPI_WINDOW_SIZE
Public Key Cryptography (PKC) > MBEDTLS_MPI_WINDOW_SIZE value Manual Entry 6 MBEDTLS_MPI_WINDOW_SIZE value
Public Key Cryptography (PKC) > MBEDTLS_MPI_MAX_SIZE
Undefine MBEDTLS_MPI_MAX_SIZE
Public Key Cryptography (PKC) > MBEDTLS_MPI_MAX_SIZE value Manual Entry 1024 MBEDTLS_MPI_MAX_SIZE value
Hash > Alternate > MBEDTLS_MD5_ALT
Undefine MBEDTLS_MD5_ALT
Hash > Alternate > MBEDTLS_RIPEMD160_ALT
Undefine MBEDTLS_RIPEMD160_ALT
Hash > Alternate > MBEDTLS_SHA1_ALT
Undefine MBEDTLS_SHA1_ALT
Hash > Alternate > MBEDTLS_MD5_PROCESS_ALT
Undefine MBEDTLS_MD5_PROCESS_ALT
Hash > Alternate > MBEDTLS_RIPEMD160_PROCESS_ALT
Undefine MBEDTLS_RIPEMD160_PROCESS_ALT
Hash > Alternate > MBEDTLS_SHA1_PROCESS_ALT
Undefine MBEDTLS_SHA1_PROCESS_ALT
Hash > MBEDTLS_SHA256_SMALLER
Undefine MBEDTLS_SHA256_SMALLER
Hash > MBEDTLS_SHA512_SMALLER
Undefine MBEDTLS_SHA512_SMALLER
Hash > MBEDTLS_MD_C
Define MBEDTLS_MD_C
Hash > MBEDTLS_MD5_C
Define MBEDTLS_MD5_C
Hash > MBEDTLS_RIPEMD160_C
Undefine MBEDTLS_RIPEMD160_C
Hash > MBEDTLS_SHA1_C
Define MBEDTLS_SHA1_C
Hash > MBEDTLS_SHA3_C
Undefine MBEDTLS_SHA3_C
Hash > MBEDTLS_SHA224_C
Define MBEDTLS_SHA224_C
Hash > MBEDTLS_SHA256_C
Define MBEDTLS_SHA256_C
Hash > MBEDTLS_SHA384_C
Undefine MBEDTLS_SHA384_C
Hash > MBEDTLS_SHA512_C
Undefine MBEDTLS_SHA512_C
Message Authentication Code (MAC) > Alternate > MBEDTLS_POLY1305_ALT
Undefine MBEDTLS_POLY1305_ALT
Message Authentication Code (MAC) > MBEDTLS_CMAC_C
Undefine MBEDTLS_CMAC_C
Message Authentication Code (MAC) > MBEDTLS_HKDF_C
Define MBEDTLS_HKDF_C
Message Authentication Code (MAC) > MBEDTLS_HMAC_DRBG_C
Undefine MBEDTLS_HMAC_DRBG_C
Message Authentication Code (MAC) > MBEDTLS_POLY1305_C
Undefine MBEDTLS_POLY1305_C
Storage > MBEDTLS_FS_IO
Undefine MBEDTLS_FS_IO
Storage > MBEDTLS_PSA_CRYPTO_STORAGE_C
Undefine MBEDTLS_PSA_CRYPTO_STORAGE_C
Storage > MBEDTLS_PSA_ITS_FILE_C
Undefine MBEDTLS_PSA_ITS_FILE_C
Storage > MBEDTLS_PSA_STATIC_KEY_SLOTS
Undefine MBEDTLS_PSA_STATIC_KEY_SLOTS
RNG > MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES
Undefine MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES
RNG > MBEDTLS_ENTROPY_FORCE_SHA256
Undefine MBEDTLS_ENTROPY_FORCE_SHA256
RNG > MBEDTLS_ENTROPY_NV_SEED
Undefine MBEDTLS_ENTROPY_NV_SEED
RNG > MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG
Undefine MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG
RNG > MBEDTLS_PSA_INJECT_ENTROPY
Undefine MBEDTLS_PSA_INJECT_ENTROPY
RNG > MBEDTLS_CTR_DRBG_C
Define MBEDTLS_CTR_DRBG_C
RNG > MBEDTLS_CTR_DRBG_C_ALT Define Define MBEDTLS_CTR_DRBG_C_ALT
RNG > MBEDTLS_CTR_DRBG_ENTROPY_LEN
Undefine RNG|MBEDTLS_CTR_DRBG_ENTROPY_LEN
RNG > MBEDTLS_CTR_DRBG_ENTROPY_LEN value Manual Entry 48 RNG value|MBEDTLS_CTR_DRBG_ENTROPY_LEN
RNG > MBEDTLS_CTR_DRBG_RESEED_INTERVAL
Undefine RNG|MBEDTLS_CTR_DRBG_RESEED_INTERVAL
RNG > MBEDTLS_CTR_DRBG_RESEED_INTERVAL value Manual Entry 10000 RNG value|MBEDTLS_CTR_DRBG_RESEED_INTERVAL
RNG > MBEDTLS_CTR_DRBG_MAX_INPUT
Undefine MBEDTLS_CTR_DRBG_MAX_INPUT
RNG > MBEDTLS_CTR_DRBG_MAX_INPUT value Manual Entry 256 MBEDTLS_CTR_DRBG_MAX_INPUT value
RNG > MBEDTLS_CTR_DRBG_MAX_REQUEST
Undefine MBEDTLS_CTR_DRBG_MAX_REQUEST
RNG > MBEDTLS_CTR_DRBG_MAX_REQUEST value Manual Entry 1024 MBEDTLS_CTR_DRBG_MAX_REQUEST value
RNG > MBEDTLS_CTR_DRBG_MAX_SEED_INPUT
Undefine MBEDTLS_CTR_DRBG_MAX_SEED_INPUT
RNG > MBEDTLS_CTR_DRBG_MAX_SEED_INPUT value Manual Entry 384 MBEDTLS_CTR_DRBG_MAX_SEED_INPUT value
RNG > MBEDTLS_CTR_DRBG_USE_128_BIT_KEY
Undefine MBEDTLS_CTR_DRBG_USE_128_BIT_KEY
RNG > MBEDTLS_HMAC_DRBG_RESEED_INTERVAL
Undefine MBEDTLS_HMAC_DRBG_RESEED_INTERVAL
RNG > MBEDTLS_HMAC_DRBG_RESEED_INTERVAL value Manual Entry 10000 MBEDTLS_HMAC_DRBG_RESEED_INTERVAL value
RNG > MBEDTLS_HMAC_DRBG_MAX_INPUT
Undefine MBEDTLS_HMAC_DRBG_MAX_INPUT
RNG > MBEDTLS_HMAC_DRBG_MAX_INPUT value Manual Entry 256 MBEDTLS_HMAC_DRBG_MAX_INPUT value
RNG > MBEDTLS_HMAC_DRBG_MAX_REQUEST
Undefine MBEDTLS_HMAC_DRBG_MAX_REQUEST
RNG > MBEDTLS_HMAC_DRBG_MAX_REQUEST value Manual Entry 1024 MBEDTLS_HMAC_DRBG_MAX_REQUEST value
RNG > MBEDTLS_HMAC_DRBG_MAX_SEED_INPUT
Undefine MBEDTLS_HMAC_DRBG_MAX_SEED_INPUT
RNG > MBEDTLS_HMAC_DRBG_MAX_SEED_INPUT value Manual Entry 384 MBEDTLS_HMAC_DRBG_MAX_SEED_INPUT value
RNG > MBEDTLS_ENTROPY_MAX_SOURCES
Undefine MBEDTLS_ENTROPY_MAX_SOURCES
RNG > MBEDTLS_ENTROPY_MAX_SOURCES value Manual Entry 20 MBEDTLS_ENTROPY_MAX_SOURCES value
RNG > MBEDTLS_ENTROPY_MAX_GATHER
Undefine MBEDTLS_ENTROPY_MAX_GATHER
RNG > MBEDTLS_ENTROPY_MAX_GATHER value Manual Entry 128 MBEDTLS_ENTROPY_MAX_GATHER value
RNG > MBEDTLS_ENTROPY_MIN_HARDWARE
Undefine MBEDTLS_ENTROPY_MIN_HARDWARE
RNG > MBEDTLS_ENTROPY_MIN_HARDWARE value Manual Entry 32 MBEDTLS_ENTROPY_MIN_HARDWARE value
Key Configuration > MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER
Undefine MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER
Key Configuration > MBEDTLS_PSA_CRYPTO_BUILTIN_KEYS
Undefine MBEDTLS_PSA_CRYPTO_BUILTIN_KEYS
Key Configuration > PSA_CRYPTO_DRIVER_TFM_BUILTIN_KEY_LOADER
Undefine PSA_CRYPTO_DRIVER_TFM_BUILTIN_KEY_LOADER
Key Configuration > MBEDTLS_PSA_KEY_SLOT_COUNT
Undefine MBEDTLS_PSA_KEY_SLOT_COUNT
Key Configuration > MBEDTLS_PSA_KEY_SLOT_COUNT value Manual Entry 32 MBEDTLS_PSA_KEY_SLOT_COUNT value
Key Configuration > MBEDTLS_PSA_STATIC_KEY_SLOT_BUFFER_SIZE value Manual Entry 256 MBEDTLS_PSA_STATIC_KEY_SLOT_BUFFER_SIZE value
Post Quantum Cryptography (PQC) > MBEDTLS_MLKEM_C
Undefine MBEDTLS_MLKEM_C
Post Quantum Cryptography (PQC) > MBEDTLS_ML_DSA_C
Undefine MBEDTLS_ML_DSA_C
HMAC > MBEDTLS_PSA_HMAC_DRBG_MD_TYPE
Define MBEDTLS_PSA_HMAC_DRBG_MD_TYPE
SHA256 Configuration
To enable hardware acceleration for the SHA256/224 calculation, the macro MBEDTLS_SHA256_ALT and MBEDTLS_SHA256_PROCESS_ALT must be defined in the configuration file. By default SHA256 is enabled. SHA256 can be disabled, but SHA512 then needs to be enabled (software version) because the PSA implementation uses it for the entropy accumulator. This can be done using the FSP Configuration editor.
AES Configuration
To enable hardware acceleration for the AES128/256 operation, the macro MBEDTLS_AES_SETKEY_ENC_ALT, MBEDTLS_AES_SETKEY_DEC_ALT, MBEDTLS_AES_ENCRYPT_ALT and MBEDTLS_AES_DECRYPT_ALT must be defined in the configuration file. By default AES is enabled. AES cannot be disabled because the PSA implementation requires it for the CTR_DRBG random number generator. This can be done using the FSP Configuration editor.
Note Only AES XTS 128 is currently supported. RA2 devices support acceleration for ECB part alone, while other devices support full AES XTS hardware acceleration.
ECC Configuration
To enable hardware acceleration for the ECC Key Generation operation, the macro MBEDTLS_ECP_ALT must be defined in the configuration file. For ECDSA, the macros MBEDTLS_ECDSA_SIGN_ALT and MBEDTLS_ECDSA_VERIFY_ALT must be defined. By default ECC, ECDSA and ECDHE are enabled. To disable ECC, undefine MBEDTLS_ECP_C, MBEDTLS_ECDSA_C and MBEDTLS_ECDH_C. This can be done using the FSP Configuration editor.
RSA Configuration
To enable hardware acceleration for the RSA2048 operation, the macro MBEDTLS_RSA_ALT must be defined in the configuration file. By default RSA is enabled. To disable RSA, undefine MBEDTLS_RSA_C, MBEDTLS_PK_C, MBEDTLS_PK_PARSE_C, MBEDTLS_PK_WRITE_C. This can be done using the FSP Configuration editor.
Post Quantum Cryptography (PQC) Configuration
ML-KEM Configuration
To enable software only PQC ML-KEM key generation, encapsulation, and decapsulation operations, the macro MBEDTLS_MLKEM_C must be defined in the configuration file. By default, PQC ML-KEM is disabled as the PQC stack is optional. This can be done using the FSP Configuration editor.
ML-DSA Configuration
To enable software only PQC ML-DSA key generation, signing, and verification operations, the macro MBEDTLS_ML_DSA_C must be defined in the configuration file. By default, PQC ML-DSA is disabled as the PQC stack is optional. This can be done using the FSP Configuration editor.
Wrapped Key Usage
To use the Secure Crypto Engine to generate and use wrapped keys, use PSA_KEY_TYPE_AES_WRAPPED or PSA_KEY_TYPE_ECC_KEY_PAIR_WRAPPED(curve) or PSA_KEY_TYPE_RSA_KEY_PAIR when setting the key type attribute. Setting the key's type attribute using this value will cause the SCE to use wrapped key mode for all operations related to that key. The user can use the export functionality to save the wrapped keys to user ROM and import it later for usage. This mode requires that Wrapped Key functionality for the algorithm is enabled in the project configuration.
Note On the SCE9 devices, only the RSA public key can be exported. A file system must be used to store the internally generated private key.
Persistent Key Storage
Persistent key storage can be enabled by defining MBEDTLS_FS_IO, MBEDTLS_PSA_CRYPTO_STORAGE_C, and MBEDTLS_PSA_ITS_FILE_C. The key lifetime must also be specified as PSA_KEY_LIFETIME_PERSISTENT. A lower level storage module must be added in the FSP Configuration editor and initialized in the code before generating persistent keys. Persistent storage supports the use of plaintext and vendor keys. Refer to the lower level storage module documentation for information on how it should be initialized. To generate a persistent key the key must be assigned a unique id prior to calling generate using the psa_set_key_id api.
if (PSA_KEY_LIFETIME_IS_PERSISTENT(lifetime))
{
psa_set_key_id(&attributes, (psa_key_id_t) 5);
}
Platform Configuration
To run the mbedCrypto implementation of the PSA Crypto API on the MCU, the macro MBEDTLS_PLATFORM_SETUP_TEARDOWN_ALT must be defined in the configuration file. This enables code that will initialize the SCE. Parameter checking (General|MBEDTLS_CHECK_PARAMS) is enabled by default. To reduce code size, disable parameter checking.
Random Number Configuration
To run the mbedCrypto implementation of the PSA Crypto API on the MCU, the macro MBEDTLS_ENTROPY_HARDWARE_ALT must be defined in the configuration file. This enables using the TRNG as an entropy source. None of the other cryptographic operations (even in software only mode) will work without this feature.
Usage Notes
Hardware Initialization
mbedtls_platform_setup() must be invoked before using the PSA Crypto API to ensure that the SCE peripheral is initialized.
Memory Usage
In general, depending on the mbedCrypto features being used a heap size of 0x1000 to 0x5000 bytes is required. The total allocated heap should be the sum of the heap requirements of the individual algorithms.
A minimum stack of 0x1000 is required where the module is used. This is either the main stack in a bare metal application or the task stack of the task used for crypto operations. The total allocated stack should be the sum of the stack requirements of the individual algorithms.
Algorithm Required Heap (bytes) Required Stack (bytes)
SHA256/224 None –
AES 0x200 –
Hardware ECC 0x400 –
Software ECC 0x1800 –
RSA 0x1500 –
ML-DSA 0x1800 0x1500
ML-KEM 0x1000 0x3000
Limitations
Only little endian mode is supported.
Stdio Buffering
The MBEDTLS_PLATFORM_SETBUF_MACRO was introduced in mbedTLS 3.2.1 to prevent stdio read/write functions from buffering stream data to reduce the likelihood of key leakage by setting the buffer argument in setbuf() to NULL. FSP uses a dummy_setbuf() function in rm_psa_crypto.c to prevent build errors; since FSP uses LittleFS by default (where the usage of a buffer is mandatory) this function does not perform any action. Setting the cache size in LittleFS to the minimum supported by the Data Flash (4) can minimize but not remove the likelihood of key data leakage. The dummy function can be replaced with a user-defined function by defining a different value for MBEDTLS_PLATFORM_SETBUF_MACRO_value in the FSP configurator.
Post Quantum Cryptography (PQC)
The PSA API Specificiation v1.3 supports ML-KEM and ML-DSA however MbedTLS currently does not provide an implementation. The implementation in the FSP release is thus likely to change and may cause backward compatibility issues when MbedTLS officially supports it.
ASN.1 encoding not implemented. Keys are currently implemented in raw bytes.
The underlying PQC-Lib library is a release candidate of V2.00.
ML-DSA
The FIPS204 Standard allows the user to provide an optional context string for ML-DSA signature generation and verification. The current implementation does not allow the user to provide such a string. Internally this field is set to a value of 0 with a length of 0.
The data format for import and export of the key pair is a byte array of the 32 byte seed value.
ML-DSA-44, ML-DSA-65, and ML-DSA-87 supported.
The current implementation of ML-DSA is too big for devices with less than 64KB of RAM.
ML-KEM
ML-KEM-512, ML-KEM-768, and ML-KEM-1024 supported.
Key derivation not supported.
The data format for import and export of the key pair is the concatenation of the two 32 byte seed values: d || z
SCE9 Usage
The SCE9 is used in Compatibility Mode for mbedCrypto acceleration. The crypto capabilities in this mode on the SCE9 are different which results in the below usage limitations with mbedCrypto:
The module includes both wrapped and plaintext keys code irrespective of whether the application requires it.
Plaintext key generation is not supported for RSA and ECC; only wrapped keys can be generated.
If ECDH is used, only wrapped key will be generated on SCE9 and will not return an error even if the user context is somehow set for plain key. This may be relevant only if the psa_key_agreement() function with plaintext key on SCE9 is attempted.
Note For a detailed description of the different SCE9 operating modes, refer to Application Note R11AN0498.
Using PSA Crypto with TrustZone
Unlike FSP drivers, PSA Crypto cannot be configured as Non-secure callable in the FSP Configurator for a secure project. The reason for this is that in order to achieve the security objective of controlling access to protected keys, both the PSA Crypto code as well as the keys must be placed in the secure region. Since the PSA Crypto API requires access to the keys directly during initialization and later via a key handle, allowing non-secure code to use the API by making it Non-secure callable will require the keys to be stored in non-secure memory.
This section will provide a short explanation of how to add PSA Crypto to a secure project and have it usable by the non-secure project without exposing the keys. In this example the secure project will contain an RSA private key and the non-secure project is expected to be able to perform sign and verify operations using that key.
mbedcrypto-nsc.svg
PSA Crypto Non-secure callable example
Examples
Hash Example
This is an example on calculating the SHA256 hash using the PSA Crypto API.
const uint8_t NIST_SHA256ShortMsgLen200[] =
{
0x2e, 0x7e, 0xa8, 0x4d, 0xa4, 0xbc, 0x4d, 0x7c, 0xfb, 0x46, 0x3e, 0x3f, 0x2c, 0x86, 0x47, 0x05,
0x7a, 0xff, 0xf3, 0xfb, 0xec, 0xec, 0xa1, 0xd2, 00
};
const uint8_t NIST_SHA256ShortMsgLen200_expected[] =
{
0x76, 0xe3, 0xac, 0xbc, 0x71, 0x88, 0x36, 0xf2, 0xdf, 0x8a, 0xd2, 0xd0, 0xd2, 0xd7, 0x6f, 0x0c,
0xfa, 0x5f, 0xea, 0x09, 0x86, 0xbe, 0x91, 0x8f, 0x10, 0xbc, 0xee, 0x73, 0x0d, 0xf4, 0x41, 0xb9
};
void psa_crypto_sha256_example (void )
{
psa_algorithm_t alg = PSA_ALG_SHA_256;
psa_hash_operation_t operation = {0};
size_t expected_hash_len = PSA_HASH_LENGTH(alg);
uint8_t actual_hash[PSA_HASH_MAX_SIZE];
size_t actual_hash_len;
{
debugger_break();
}
else if (PSA_SUCCESS != psa_hash_setup(&operation, alg))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_hash_update(&operation, NIST_SHA256ShortMsgLen200, sizeof (NIST_SHA256ShortMsgLen200)))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_hash_finish(&operation, &actual_hash[0], sizeof (actual_hash), &actual_hash_len))
{
debugger_break();
}
else if (0 != memcmp(&actual_hash[0], &NIST_SHA256ShortMsgLen200_expected[0], actual_hash_len))
{
debugger_break();
}
else if (0 != memcmp(&expected_hash_len, &actual_hash_len, sizeof (expected_hash_len)))
{
debugger_break();
}
else
{
debugger_break();
}
}
AES Example
This is an example on using the PSA Crypto API to generate an AES256 key, encrypting and decrypting multi-block data and using PKCS7 padding.
static psa_status_t cipher_operation (psa_cipher_operation_t * operation,
const uint8_t * input,
size_t input_size,
size_t part_size,
uint8_t * output,
size_t output_size,
size_t * output_len)
{
psa_status_t status;
size_t bytes_to_write = 0;
size_t bytes_written = 0;
size_t len = 0;
*output_len = 0;
while (bytes_written != input_size)
{
bytes_to_write = (input_size - bytes_written > part_size ?
part_size :
input_size - bytes_written);
status = psa_cipher_update(operation,
input + bytes_written,
bytes_to_write,
output + *output_len,
output_size - *output_len,
&len);
if (PSA_SUCCESS != status)
{
return status;
}
bytes_written += bytes_to_write;
*output_len += len;
}
status = psa_cipher_finish(operation, output + *output_len, output_size - *output_len, &len);
if (PSA_SUCCESS != status)
{
return status;
}
*output_len += len;
return status;
}
void psa_crypto_aes256cbcmultipart_example (void )
{
enum
{
block_size = PSA_BLOCK_CIPHER_BLOCK_LENGTH(PSA_KEY_TYPE_AES),
key_bits = 256,
input_size = 100,
part_size = 10,
};
const psa_algorithm_t alg = PSA_ALG_CBC_PKCS7;
psa_cipher_operation_t operation_1 = PSA_CIPHER_OPERATION_INIT;
psa_cipher_operation_t operation_2 = PSA_CIPHER_OPERATION_INIT;
size_t iv_len = 0;
psa_key_handle_t key_handle = 0;
size_t encrypted_length = 0;
size_t decrypted_length = 0;
uint8_t iv[block_size] = {0};
uint8_t input[input_size] = {0};
uint8_t encrypted_data[input_size + block_size] = {0};
uint8_t decrypted_data[input_size + block_size] = {0};
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_lifetime_t lifetime;
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT);
psa_set_key_algorithm(&attributes, alg);
psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
psa_set_key_bits(&attributes, key_bits);
lifetime = PSA_KEY_LIFETIME_VOLATILE;
psa_set_key_lifetime(&attributes, lifetime);
if (PSA_KEY_LIFETIME_IS_PERSISTENT(lifetime))
{
psa_set_key_id(&attributes, (psa_key_id_t) 5);
}
if (PSA_SUCCESS != psa_generate_random(input, sizeof (input)))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_generate_key(&attributes, &key_handle))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_encrypt_setup(&operation_1, key_handle, alg))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_generate_iv(&operation_1, iv, sizeof (iv), &iv_len))
{
debugger_break();
}
else if (PSA_SUCCESS !=
cipher_operation(&operation_1, input, input_size, part_size, encrypted_data, sizeof (encrypted_data),
&encrypted_length))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_abort(&operation_1))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_decrypt_setup(&operation_2, key_handle, alg))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_set_iv(&operation_2, iv, sizeof (iv)))
{
debugger_break();
}
else if (PSA_SUCCESS !=
cipher_operation(&operation_2, encrypted_data, encrypted_length, part_size, decrypted_data,
sizeof (decrypted_data), &decrypted_length))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_abort(&operation_2))
{
debugger_break();
}
else if (0 != memcmp(input, decrypted_data, sizeof (input)))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_destroy_key(key_handle))
{
debugger_break();
}
else
{
}
}
void psa_crypto_aes128xtsmultipart_example (void )
{
enum
{
block_size = PSA_BLOCK_CIPHER_BLOCK_LENGTH(PSA_KEY_TYPE_AES),
key_bits = 256,
input_size = 32,
part_size = 16,
};
const psa_algorithm_t alg = PSA_ALG_XTS;
psa_cipher_operation_t operation_1 = PSA_CIPHER_OPERATION_INIT;
psa_cipher_operation_t operation_2 = PSA_CIPHER_OPERATION_INIT;
size_t iv_len = 0;
psa_key_handle_t key_handle = 0;
size_t encrypted_length = 0;
size_t decrypted_length = 0;
uint8_t iv[block_size] = {0};
uint8_t input[input_size] = {0};
uint8_t encrypted_data[input_size] = {0};
uint8_t decrypted_data[input_size] = {0};
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_lifetime_t lifetime;
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT);
psa_set_key_algorithm(&attributes, alg);
psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
psa_set_key_bits(&attributes, key_bits);
lifetime = PSA_KEY_LIFETIME_VOLATILE;
psa_set_key_lifetime(&attributes, lifetime);
if (PSA_KEY_LIFETIME_IS_PERSISTENT(lifetime))
{
psa_set_key_id(&attributes, (psa_key_id_t) 5);
}
if (PSA_SUCCESS != psa_generate_random(input, sizeof (input)))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_generate_key(&attributes, &key_handle))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_encrypt_setup(&operation_1, key_handle, alg))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_generate_iv(&operation_1, iv, sizeof (iv), &iv_len))
{
debugger_break();
}
else if (PSA_SUCCESS !=
cipher_operation(&operation_1, input, sizeof (input), part_size, encrypted_data, sizeof (encrypted_data),
&encrypted_length))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_abort(&operation_1))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_decrypt_setup(&operation_2, key_handle, alg))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_set_iv(&operation_2, iv, sizeof (iv)))
{
debugger_break();
}
else if (PSA_SUCCESS !=
cipher_operation(&operation_2, encrypted_data, encrypted_length, part_size, decrypted_data,
sizeof (decrypted_data), &decrypted_length))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_abort(&operation_2))
{
debugger_break();
}
else if (0 != memcmp(input, decrypted_data, sizeof (input)))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_destroy_key(key_handle))
{
debugger_break();
}
else
{
}
}
AES-CCM Example
This is an example on using the PSA Crypto API to generate an AES256 key, encrypting and decrypting multi-block data and using PKCS7 padding using AES-CCM.
if (PSA_SUCCESS != psa_generate_random(input, sizeof (input)))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_generate_key(&attributes, &key_handle))
{
debugger_break();
}
else if (PSA_SUCCESS !=
psa_aead_encrypt(key_handle, PSA_ALG_CCM, nonce, sizeof (nonce), additional_data, sizeof (additional_data),
input, sizeof (input), encrypt, sizeof (encrypt), &output_len))
{
debugger_break();
}
else if (PSA_SUCCESS !=
psa_aead_decrypt(key_handle, PSA_ALG_CCM, nonce, sizeof (nonce), additional_data, sizeof (additional_data),
encrypt, output_len, decrypt, sizeof (decrypt), &output_len))
{
debugger_break();
}
else if (0U != memcmp(input, decrypt, sizeof (input)))
{
debugger_break();
}
else
{
}
AES-XTS Example
This is an example on using the PSA Crypto API to generate an AES128 XTS key, encrypting and decrypting multi-block data.
if (PSA_SUCCESS != psa_generate_random(input, sizeof (input)))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_generate_key(&attributes, &key_handle))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_encrypt_setup(&operation_1, key_handle, alg))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_generate_iv(&operation_1, iv, sizeof (iv), &iv_len))
{
debugger_break();
}
else if (PSA_SUCCESS !=
cipher_operation(&operation_1, input, sizeof (input), part_size, encrypted_data, sizeof (encrypted_data),
&encrypted_length))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_abort(&operation_1))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_decrypt_setup(&operation_2, key_handle, alg))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_set_iv(&operation_2, iv, sizeof (iv)))
{
debugger_break();
}
else if (PSA_SUCCESS !=
cipher_operation(&operation_2, encrypted_data, encrypted_length, part_size, decrypted_data,
sizeof (decrypted_data), &decrypted_length))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_cipher_abort(&operation_2))
{
debugger_break();
}
else if (0 != memcmp(input, decrypted_data, sizeof (input)))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_destroy_key(key_handle))
{
debugger_break();
}
else
{
}
CMAC Example
This is an example on using the PSA Crypto API to generate an AES256 key, followed by generation and verification of MAC for random data of known length.
if (PSA_SUCCESS != psa_generate_random(input, sizeof (input)))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_generate_key(&attributes, &key_handle))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_mac_sign_setup(&operation, key_handle, alg))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_mac_update(&operation, input, input_size))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_mac_sign_finish(&operation, AES_CMAC_mac, sizeof (AES_CMAC_mac), &mac_ret))
{
debugger_break();
}
else
{
}
if (PSA_SUCCESS != psa_mac_verify_setup(&verify_operation, key_handle, alg))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_mac_update(&verify_operation, input, input_size))
{
debugger_break();
}
else if (PSA_SUCCESS != psa_mac_verify_finish(&verify_operation, AES_CMAC_mac, mac_ret))
{
debugger_break();
}
else
{
}
ECC Example
This is an example on using the PSA Crypto API to generate an ECC-P256R1 key, signing and verifying data after hashing it first using SHA256.
Note Unlike RSA, ECDSA does not have any padding schemes. Thus the hash argument for the ECC sign operation MUST have a size larger than or equal to the curve size; i.e. for PSA_ECC_CURVE_SECP256R1 the payload size must be at least 256/8 bytes. nist.fips.186-4: " A hash function that provides a lower security strength than the security strength associated with the bit length of 'n' ordinarily should not be used, since this would reduce the security strength of the digital signature process to a level no greater than that provided by the hash function."
#define ECC_256_BIT_LENGTH 256
#define ECC_256_EXPORTED_SIZE 500
uint8_t exportedECC_SECP256R1Key[ECC_256_EXPORTED_SIZE];
size_t exportedECC_SECP256R1Keylength = 0;
void psa_ecc256R1_example (void )
{
unsigned char payload[] = "ASYMMETRIC_INPUT_FOR_SIGN......" ;
unsigned char signature1[PSA_SIGNATURE_MAX_SIZE] = {0};
unsigned char signature2[PSA_SIGNATURE_MAX_SIZE] = {0};
size_t signature_length1 = 0;
size_t signature_length2 = 0;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_attributes_t read_attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_handle_t ecc_key_handle = {0};
psa_hash_operation_t hash_operation = {0};
uint8_t payload_hash[PSA_HASH_MAX_SIZE];
size_t payload_hash_len;
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH | PSA_KEY_USAGE_VERIFY_HASH | PSA_KEY_USAGE_EXPORT);
psa_set_key_algorithm(&attributes, PSA_ALG_ECDSA(PSA_ALG_SHA_256));
psa_set_key_type(&attributes, PSA_KEY_TYPE_ECC_KEY_PAIR(PSA_ECC_FAMILY_SECP_R1));
psa_set_key_bits(&attributes, ECC_256_BIT_LENGTH);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
if (PSA_SUCCESS != psa_generate_key(&attributes, &ecc_key_handle))
{
debugger_break();
}
if (PSA_SUCCESS != psa_get_key_attributes(ecc_key_handle, &read_attributes))
{
debugger_break();
}
if (PSA_SUCCESS != psa_hash_setup(&hash_operation, PSA_ALG_SHA_256))
{
debugger_break();
}
if (PSA_SUCCESS != psa_hash_update(&hash_operation, payload, sizeof (payload)))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_hash_finish(&hash_operation, &payload_hash[0], sizeof (payload_hash), &payload_hash_len))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_sign_hash(ecc_key_handle, PSA_ALG_ECDSA(PSA_ALG_SHA_256), payload_hash, payload_hash_len, signature1,
sizeof (signature1), &signature_length1))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_verify_hash(ecc_key_handle, PSA_ALG_ECDSA(PSA_ALG_SHA_256), payload_hash, payload_hash_len, signature1,
signature_length1))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_export_key(ecc_key_handle, exportedECC_SECP256R1Key, sizeof (exportedECC_SECP256R1Key),
&exportedECC_SECP256R1Keylength))
{
debugger_break();
}
if (PSA_SUCCESS != psa_destroy_key(ecc_key_handle))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_import_key(&attributes, exportedECC_SECP256R1Key, exportedECC_SECP256R1Keylength, &ecc_key_handle))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_sign_hash(ecc_key_handle, PSA_ALG_ECDSA(PSA_ALG_SHA_256), payload_hash, payload_hash_len, signature2,
sizeof (signature2), &signature_length2))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_verify_hash(ecc_key_handle, PSA_ALG_ECDSA(PSA_ALG_SHA_256), payload_hash, payload_hash_len, signature2,
signature_length2))
{
debugger_break();
}
}
RSA Example
This is an example on using the PSA Crypto API to generate an RSA2048 key, encrypting and decrypting multi-block data and using PKCS7 padding.
#define RSA_2048_BIT_LENGTH 2048
#define RSA_2048_EXPORTED_SIZE 1210
uint8_t exportedRSA2048Key[RSA_2048_EXPORTED_SIZE];
size_t exportedRSA2048Keylength = 0;
void psa_rsa2048_example (void )
{
psa_key_handle_t key_handle = {0};
unsigned char payload[] = "ASYMMETRIC_INPUT_FOR_SIGN" ;
unsigned char signature1[PSA_SIGNATURE_MAX_SIZE] = {0};
unsigned char signature2[PSA_SIGNATURE_MAX_SIZE] = {0};
size_t signature_length1 = 0;
size_t signature_length2 = 0;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_attributes_t read_attributes = PSA_KEY_ATTRIBUTES_INIT;
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH | PSA_KEY_USAGE_VERIFY_HASH | PSA_KEY_USAGE_EXPORT);
psa_set_key_algorithm(&attributes, PSA_ALG_RSA_PKCS1V15_SIGN_RAW);
psa_set_key_type(&attributes, PSA_KEY_TYPE_RSA_KEY_PAIR);
psa_set_key_bits(&attributes, RSA_2048_BIT_LENGTH);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
if (PSA_SUCCESS != psa_generate_key(&attributes, &key_handle))
{
debugger_break();
}
if (PSA_SUCCESS != psa_get_key_attributes(key_handle, &read_attributes))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_sign_hash(key_handle, PSA_ALG_RSA_PKCS1V15_SIGN_RAW, payload, sizeof (payload), signature1,
sizeof (signature1), &signature_length1))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_verify_hash(key_handle, PSA_ALG_RSA_PKCS1V15_SIGN_RAW, payload, sizeof (payload), signature1,
signature_length1))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_export_key(key_handle, exportedRSA2048Key, sizeof (exportedRSA2048Key), &exportedRSA2048Keylength))
{
debugger_break();
}
if (PSA_SUCCESS != psa_destroy_key(key_handle))
{
debugger_break();
}
if (PSA_SUCCESS != psa_import_key(&attributes, exportedRSA2048Key, exportedRSA2048Keylength, &key_handle))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_sign_hash(key_handle, PSA_ALG_RSA_PKCS1V15_SIGN_RAW, payload, sizeof (payload), signature2,
sizeof (signature2), &signature_length2))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_verify_hash(key_handle, PSA_ALG_RSA_PKCS1V15_SIGN_RAW, payload, sizeof (payload), signature2,
signature_length2))
{
debugger_break();
}
if (0 != memcmp(signature2, signature1, signature_length2))
{
debugger_break();
}
mbedtls_psa_crypto_free();
}
const uint8_t RSAKeydata[] = "-----BEGIN RSA PRIVATE KEY-----\n"
"MIIEowIBAAKCAQEAplaPU68h4hW/eAlH2hbQl1WjoDT1znCk0O9cnE9lAnB26IUi"
"78wUAxuTZSlrlKez9FGGIVbUMTy7dTw0ZBanogrKCaAMaRFz5LRv4I8RQzsDxxqe"
"nud9Y6mVRWb9hyutL/yBwDd6jzAwcviAhcatTv0E5wpEJ6ezMDyaiSCbn84hfb0T"
"ZPXQVGhmjii3f0FfFWW9ce70qkuwdkvO6HBrOGVi2++b11As+Uh/7pxyOb7wpE7K"
"X64nohaCtXgNnV8Hr+LOPQRHEbGTCPOfx1davKEIYFvm8hVxqv20csMD5uc8AJCd"
"0cdom13KcOpVXCnrFPNJt0lITOcH/fBzp4xoaQIDAQABAoIBAGc56qKVWeKzempk"
"4AlRBUwVYoEGvNDLiQz8rq12fAoCf1iXXvIP5Q90qokqJlBPrtbdTO8dsnuH5BHC"
"NgUzJf7i0TUd9PWzVgfFjnR+dMkTM6n5NB0LLf6OfEtguc+L5GOWQXNnOpDn5/lB"
"jIj4ng8Z6FP1RAyT/xjdU03sRYfq5OPlDZ8+ck7WwQ8VxSBKsJcZVv+K4r64Vmr1"
"MO1zfBYuwafi4oO9Z9x89Iil9GBcYuCvhLvDoWhnTUxlOTfz+Jt+qwlmVimEz6xs"
"6ew1Ox7e6SInly3IAXe9E84yP9MDmiGkCrVr8s8GUybZ5t/yeZ3g5lPYSQ/FiuHY"
"kvJCH4ECgYEA2IthRDkElOQGqJ9T/LjgcIVLQs0F6i7zZWg6UKv18EmG7uHd6tsZ"
"byFfFiBat80rq6q4AUx2OOE7+LI5MxIvgRgLk14WV8H2OKK/lfxOFb6a4feGM7bH"
"VdERQSMNeGq0bP9IOPxU1EvFp0Vfv7cfGsQhcAPgA8up61jWREhI+fECgYEAxKVT"
"9pKinIwgjsHgmxalaNbnRf+bcqtdS98SB2MuICg8ubcBSrjm4wtGe3oCX/PbM1GV"
"FvEDKl4TyeWFIH4MStsyDHYxwoV2C01bBHEtHTYBnjeIShMruIomsG9GeTrNmyzg"
"dVdSg5/lxYOxuZSXvfcbyIMsW29ddgeICu9RHfkCgYBaljQibhfUkW+Xqs9fsZdy"
"etB5KXuH9AwuJ+P9S3KfCqM/240SaoXBT5yPjQlmSpYyQkCnim0Kbm7AIw56pujo"
"gD6Xb4y5OZLfLnYnMF0aC5qPXRTvHU9WPxeQwDEqZrkDv+der3BtPyV4TDU55klE"
"0TeLvJNCAzkaExfPiM2+gQKBgQC5ceBYq7hGQa+CcTvLhfO/hsrbrE2AOjLllhx+"
"cv3QvaFm0jqZqP20J7H0R/9tVZ7mKo2a8Pa3QbkPsS92kOguv7/XGK+cbhgAWJb4"
"/XI6FfA4sM4KbUHR6hbKVGX1dYroR831WsAp+OTK+4LjLEpdj2fYFDwEjmVpJXka"
"Ns4coQKBgGESrtpJF7OQG4xcXwR2ZiJESPvMKVmtvxRzDrc9gmoiIIIKx1fimwCv"
"RtOz1bQcXMRw21+ZAZpen3ahWh63KC0KxMSNBJTXdczlf2uprVkSPtmAjV4qBgwv"
"tqjmP0lnGc9wkJsVvGmMAAfQOWgxs9h/VH/b+6biEkzaaZLOyABV"
"-----END RSA PRIVATE KEY-----\n" ;
const uint8_t RSAExpectedSignature[256] =
{
0x25, 0xC0, 0x15, 0x64, 0xD3, 0xF7, 0xC1, 0xB7, 0xA8, 0x9B, 0x56, 0x1C, 0xB5, 0xA4, 0xA5, 0x0D, 0x61, 0x52, 0x32,
0x0C, 0x4E, 0xE8, 0xCA, 0x4B, 0x9E, 0xA2, 0x4D, 0x35, 0x0E, 0xB1, 0xA1, 0x5B,
0x5B, 0xD8, 0xC1, 0x93, 0x28, 0x60, 0x90, 0x18, 0x37, 0x88, 0x66, 0xD4, 0xED, 0x37, 0x6B, 0xEC, 0x48, 0xFF, 0x3D,
0xFB, 0x99, 0xB7, 0xEF, 0x3C, 0x8D, 0x25, 0xE9, 0xF3, 0xCF, 0x02, 0x7C, 0x7D,
0xB9, 0x4D, 0x2F, 0x2F, 0x1E, 0x30, 0x48, 0x54, 0x18, 0xE4, 0x51, 0xD5, 0xC1, 0xB7, 0x3B, 0x0D, 0xE4, 0xB4, 0x19,
0x7B, 0x9B, 0xF4, 0x35, 0x82, 0xCC, 0x91, 0x4C, 0x10, 0xE9, 0xB6, 0xF1, 0x0A,
0x23, 0xEB, 0x7D, 0x51, 0x47, 0x36, 0xFE, 0x13, 0xAF, 0x3C, 0x23, 0x9F, 0x7E, 0xFC, 0xCF, 0x7A, 0x7C, 0x2D, 0xDB,
0xD9, 0xDA, 0xEB, 0xF7, 0xB5, 0x6B, 0x8D, 0xE0, 0x18, 0x9A, 0x5B, 0xB7, 0x0A,
0xA3, 0x4E, 0xE1, 0xB7, 0xF7, 0xD1, 0x94, 0xD5, 0x7A, 0xD3, 0x27, 0xE2, 0x1F, 0x3A, 0xEB, 0xF0, 0x83, 0x10, 0x52,
0x51, 0x5F, 0x58, 0xF8, 0x81, 0x42, 0x48, 0x83, 0x2D, 0xF0, 0xA9, 0x7D, 0x79,
0x2B, 0xF1, 0x68, 0xC2, 0x22, 0xC0, 0x0C, 0x72, 0x63, 0x37, 0xBF, 0xEC, 0x72, 0x97, 0xD4, 0xA5, 0x91, 0x2E, 0x1F,
0xA3, 0x78, 0x9A, 0xCE, 0xFE, 0x27, 0x7F, 0x2B, 0x85, 0x7D, 0x22, 0x2C, 0x0D,
0x1E, 0x10, 0xB7, 0xFF, 0x9A, 0xA7, 0x99, 0xD2, 0xB9, 0x40, 0x53, 0xB3, 0xA9, 0x52, 0x5D, 0xBD, 0xC8, 0x12, 0x8D,
0x39, 0xD7, 0x97, 0x03, 0xD2, 0x80, 0x21, 0xC3, 0xA7, 0x8B, 0xE3, 0x3D, 0xF0,
0x4D, 0x4C, 0x4D, 0xC4, 0xC7, 0xE5, 0xE4, 0x35, 0x75, 0xAA, 0x45, 0x3B, 0x9C, 0x64, 0xC1, 0x94, 0x6E, 0x15, 0x0A,
0xE8, 0x84, 0xCD, 0xFC, 0x7A, 0xBC, 0x5C, 0x8C, 0xA8, 0x95, 0x07, 0x79, 0x4E,
};
void psa_rsa2048_pem_format_import_example (void )
{
psa_key_handle_t key_handle = {0};
unsigned char payload[] = "ASYMMETRIC_INPUT_FOR_SIGN" ;
unsigned char signature[PSA_SIGNATURE_MAX_SIZE] = {0};
size_t signature_length = 0U;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_attributes_t read_attributes = PSA_KEY_ATTRIBUTES_INIT;
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH | PSA_KEY_USAGE_VERIFY_HASH);
psa_set_key_algorithm(&attributes, PSA_ALG_RSA_PKCS1V15_SIGN_RAW);
psa_set_key_type(&attributes, PSA_KEY_TYPE_RSA_KEY_PAIR);
psa_set_key_bits(&attributes, RSA_2048_BIT_LENGTH);
mbedtls_pk_context ctx_rsa;
mbedtls_pk_init(&ctx_rsa);
if (PSA_SUCCESS !=
mbedtls_pk_parse_key(&ctx_rsa, RSAKeydata, sizeof (RSAKeydata), NULL, 0, mbedtls_psa_get_random,
MBEDTLS_PSA_RANDOM_STATE))
{
debugger_break();
}
if (PSA_SUCCESS != mbedtls_pk_import_into_psa(&ctx_rsa, &attributes, &key_handle))
{
debugger_break();
}
mbedtls_pk_free(&ctx_rsa);
if (PSA_SUCCESS != psa_get_key_attributes(key_handle, &read_attributes))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_sign_hash(key_handle, PSA_ALG_RSA_PKCS1V15_SIGN_RAW, payload, sizeof (payload), signature, sizeof (signature),
&signature_length))
{
debugger_break();
}
if (0 != memcmp(signature, &RSAExpectedSignature, sizeof (RSAExpectedSignature)))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_verify_hash(key_handle, PSA_ALG_RSA_PKCS1V15_SIGN_RAW, payload, sizeof (payload), RSAExpectedSignature,
sizeof (RSAExpectedSignature)))
{
debugger_break();
}
if (PSA_SUCCESS != psa_destroy_key(key_handle))
{
debugger_break();
}
mbedtls_psa_crypto_free();
}
CHACHA20 Example
This is an example on using the PSA Crypto API to import an ChaCha20 key, encrypting and decrypting single block data.
const uint8_t chacha_key[] =
{
0x80, 0x81, 0x82, 0x83, 0x84, 0x85, 0x86, 0x87,
0x88, 0x89, 0x8a, 0x8b, 0x8c, 0x8d, 0x8e, 0x8f,
0x90, 0x91, 0x92, 0x93, 0x94, 0x95, 0x96, 0x97,
0x98, 0x99, 0x9a, 0x9b, 0x9c, 0x9d, 0x9e, 0x9f
};
const uint8_t chacha_iv[] =
{
0x07, 0x00, 0x00, 0x00,
0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47
};
const uint8_t chacha_plaintext[] =
{
0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D, 0x0E, 0x0F,
0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18, 0x19, 0x1A, 0x1B, 0x1C, 0x1D, 0x1E, 0x1F,
0x20, 0x21, 0x22, 0x23
};
const uint8_t chacha_ciphertext[] =
{
0x9F, 0x7A, 0xEB, 0x5E, 0x05, 0xF8, 0x46, 0xBD, 0x1D, 0xEB, 0x85, 0xF0, 0x3A, 0x8C, 0x04, 0xA1,
0xD1, 0xD1, 0x9A, 0x2C, 0x1D, 0x14, 0x78, 0xC9, 0xC5, 0x93, 0xCA, 0x9C, 0x49, 0x9F, 0x1D, 0xBA,
0x6E, 0xBF, 0xE9, 0x1B
};
const uint8_t chacha_mac[] =
{
0xC8, 0xB3, 0xFA, 0xDC, 0xF9, 0x1F, 0x78, 0x97,
0xCD, 0xD7, 0x54, 0xE2, 0xFC, 0x0B, 0xE1, 0xE5
};
typedef struct import_key_items_symmetric_s
{
const uint8_t * key;
size_t key_size;
const uint8_t * nonce_iv;
size_t nonce_iv_size;
const uint8_t * aad;
size_t aad_size;
const uint8_t * mac;
size_t mac_size;
const uint8_t * plaintext;
size_t plaintext_size;
const uint8_t * ciphertext;
size_t ciphertext_size;
} import_key_items_symmetric_t;
const import_key_items_symmetric_t chacha_testdata =
{
chacha_key,
sizeof (chacha_key),
chacha_iv,
sizeof (chacha_iv),
NULL,
0,
chacha_mac,
16,
chacha_plaintext,
sizeof (chacha_plaintext),
chacha_ciphertext,
sizeof (chacha_ciphertext),
};
void psa_crypto_chacha20_example (void )
{
psa_key_handle_t key_handle = 0;
size_t encr_len = 0;
size_t decr_len = 0;
uint8_t encrypt[200];
uint8_t decrypt[200];
import_key_items_symmetric_t * p_import_key_items = (import_key_items_symmetric_t *) &chacha_testdata;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
const psa_algorithm_t alg = PSA_ALG_STREAM_CIPHER;
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT);
psa_set_key_algorithm(&attributes, alg);
psa_set_key_type(&attributes, PSA_KEY_TYPE_CHACHA20);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
psa_set_key_bits(&attributes, 256);
if (PSA_KEY_LIFETIME_IS_PERSISTENT(PSA_KEY_LIFETIME_VOLATILE))
{
psa_set_key_id(&attributes, (psa_key_id_t) 2);
}
if (PSA_SUCCESS != psa_import_key(&attributes, p_import_key_items->key, p_import_key_items->key_size, &key_handle))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_cipher_encrypt(key_handle, alg, p_import_key_items->plaintext, p_import_key_items->plaintext_size, encrypt,
sizeof (encrypt), &encr_len))
{
debugger_break();
}
if (PSA_SUCCESS != psa_cipher_decrypt(key_handle, alg, encrypt, encr_len, decrypt, sizeof (decrypt), &decr_len))
{
debugger_break();
}
if (p_import_key_items->plaintext_size == decr_len)
{
debugger_break();
}
if (0 != memcmp(p_import_key_items->plaintext, decrypt, p_import_key_items->plaintext_size))
{
debugger_break();
}
if (PSA_SUCCESS != psa_destroy_key(key_handle))
{
debugger_break();
}
}
CHACHA20-POLY1305 Example
This is an example on using the PSA Crypto API to import an ChaCha20 key, encrypting/decrypting single block data and generates the MAC (authentication tag)
const uint8_t chachapoly_key[] =
{
0x80, 0x81, 0x82, 0x83, 0x84, 0x85, 0x86, 0x87,
0x88, 0x89, 0x8a, 0x8b, 0x8c, 0x8d, 0x8e, 0x8f,
0x90, 0x91, 0x92, 0x93, 0x94, 0x95, 0x96, 0x97,
0x98, 0x99, 0x9a, 0x9b, 0x9c, 0x9d, 0x9e, 0x9f
};
const uint8_t chachapoly_iv[] =
{
0x07, 0x00, 0x00, 0x00,
0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47
};
const uint8_t chachapoly_plaintext[] =
{
0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D, 0x0E, 0x0F,
0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18, 0x19, 0x1A, 0x1B, 0x1C, 0x1D, 0x1E, 0x1F,
0x20, 0x21, 0x22, 0x23
};
const uint8_t chachapoly_ciphertext[] =
{
0x9F, 0x7A, 0xEB, 0x5E, 0x05, 0xF8, 0x46, 0xBD, 0x1D, 0xEB, 0x85, 0xF0, 0x3A, 0x8C, 0x04, 0xA1,
0xD1, 0xD1, 0x9A, 0x2C, 0x1D, 0x14, 0x78, 0xC9, 0xC5, 0x93, 0xCA, 0x9C, 0x49, 0x9F, 0x1D, 0xBA,
0x6E, 0xBF, 0xE9, 0x1B
};
const uint8_t chachapoly_mac[] =
{
0xC8, 0xB3, 0xFA, 0xDC, 0xF9, 0x1F, 0x78, 0x97,
0xCD, 0xD7, 0x54, 0xE2, 0xFC, 0x0B, 0xE1, 0xE5
};
const import_key_items_symmetric_t chachapoly_testdata =
{
chachapoly_key,
sizeof (chachapoly_key),
chachapoly_iv,
sizeof (chachapoly_iv),
NULL,
0,
chachapoly_mac,
16,
chachapoly_plaintext,
sizeof (chachapoly_plaintext),
chachapoly_ciphertext,
sizeof (chachapoly_ciphertext),
};
void psa_crypto_chachapoly_example (void )
{
enum
{
block_size = 16,
part_size = block_size,
};
const psa_algorithm_t alg = PSA_ALG_CHACHA20_POLY1305;
psa_key_handle_t key_handle = 0;
size_t encr_len = 0;
size_t decr_len = 0;
uint8_t encrypt[200];
uint8_t decrypt[200];
import_key_items_symmetric_t * p_import_key_items = (import_key_items_symmetric_t *) &chachapoly_testdata;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT);
psa_set_key_algorithm(&attributes, alg);
psa_set_key_type(&attributes, PSA_KEY_TYPE_CHACHA20);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
psa_set_key_bits(&attributes, 256);
if (PSA_KEY_LIFETIME_IS_PERSISTENT(PSA_KEY_LIFETIME_VOLATILE))
{
psa_set_key_id(&attributes, (psa_key_id_t) 2);
}
if (PSA_SUCCESS != psa_import_key(&attributes, p_import_key_items->key, p_import_key_items->key_size, &key_handle))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_aead_encrypt(key_handle, alg, p_import_key_items->nonce_iv, p_import_key_items->nonce_iv_size, NULL, 0,
p_import_key_items->plaintext, p_import_key_items->plaintext_size, encrypt, sizeof (encrypt),
&encr_len))
{
debugger_break();
}
if (p_import_key_items->plaintext_size + p_import_key_items->mac_size != encr_len)
{
debugger_break();
}
if (0 != memcmp(p_import_key_items->ciphertext, encrypt, p_import_key_items->plaintext_size))
{
debugger_break();
}
if (0 !=
memcmp(p_import_key_items->mac, &encrypt[p_import_key_items->plaintext_size], p_import_key_items->mac_size))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_aead_decrypt(key_handle, alg, p_import_key_items->nonce_iv, p_import_key_items->nonce_iv_size, NULL, 0,
encrypt, encr_len, decrypt, sizeof (decrypt), &decr_len))
{
debugger_break();
}
if (p_import_key_items->plaintext_size != decr_len)
{
debugger_break();
}
if (0 != memcmp(p_import_key_items->plaintext, decrypt, p_import_key_items->plaintext_size))
{
debugger_break();
}
if (PSA_SUCCESS != psa_destroy_key(key_handle))
{
debugger_break();
}
}
ML-KEM Example
This is an example on using the PSA Crypto API to generate an MLKEM-512 key, encapsulating and decapsulating ciphertext.
void psa_mlkem512_keygen_example (void )
{
size_t bits = PSA_KEY_BITS_ML_KEM_512;
psa_key_handle_t key_handle = 0;
psa_key_id_t output_key_handle = 0;
psa_key_id_t decap_output_key_handle = 0;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_attributes_t shared_secret_attributes = PSA_KEY_ATTRIBUTES_INIT;
uint8_t ciphertext[PSA_ML_KEM_CIPHERTEXT_SIZE(PSA_KEY_BITS_ML_KEM_512)] __ALIGNED(4);
size_t ciphertext_len = PSA_ML_KEM_CIPHERTEXT_SIZE(PSA_KEY_BITS_ML_KEM_512);
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCAPSULATE | PSA_KEY_USAGE_DECAPSULATE);
psa_set_key_algorithm(&attributes, PSA_ALG_ML_KEM);
psa_set_key_type(&attributes, PSA_KEY_TYPE_ML_KEM_KEY_PAIR);
psa_set_key_bits(&attributes, bits);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
if (PSA_SUCCESS != psa_generate_key(&attributes, &key_handle))
{
debugger_break();
}
psa_set_key_usage_flags(&shared_secret_attributes, PSA_KEY_USAGE_ENCAPSULATE | PSA_KEY_USAGE_DECAPSULATE);
psa_set_key_algorithm(&shared_secret_attributes, PSA_ALG_ML_KEM);
psa_set_key_type(&shared_secret_attributes, PSA_KEY_TYPE_RAW_DATA);
psa_set_key_bits(&shared_secret_attributes, PSA_BYTES_TO_BITS(PSA_ML_KEM_SHARED_SECRET_SIZE));
psa_set_key_lifetime(&shared_secret_attributes, PSA_KEY_LIFETIME_VOLATILE);
if (PSA_SUCCESS !=
psa_encapsulate(key_handle, PSA_ALG_ML_KEM, &shared_secret_attributes, &output_key_handle, &ciphertext[0],
ciphertext_len, &ciphertext_len))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_decapsulate(key_handle, PSA_ALG_ML_KEM, &ciphertext[0], ciphertext_len, &shared_secret_attributes,
&decap_output_key_handle))
{
debugger_break();
}
}
uint8_t mlkem_import_keypair[PSA_KEY_EXPORT_ML_KEM_KEY_PAIR_MAX_SIZE] __ALIGNED(4) =
{
0x1E, 0xB4, 0x40, 0x0A, 0x01, 0x62, 0x9D, 0x51, 0x79, 0x74, 0xE2, 0xCD, 0x85, 0xB9, 0xDE, 0xF5,
0x90, 0x82, 0xDE, 0x50, 0x8E, 0x6F, 0x9C, 0x2B, 0x0E, 0x34, 0x1E, 0x12, 0x96, 0x59, 0x55, 0xCA,
0x1A, 0x39, 0x41, 0x11, 0x16, 0x38, 0x03, 0xFE, 0x2E, 0x85, 0x19, 0xC3, 0x35, 0xA6, 0x86, 0x75,
0x56, 0x33, 0x8E, 0xAD, 0xAF, 0xA2, 0x2B, 0x5F, 0xC5, 0x57, 0x43, 0x05, 0x60, 0xCC, 0xD6, 0x93
};
void psa_mlkem512_keypair_import_export_example (void )
{
size_t bits = PSA_KEY_BITS_ML_KEM_512;
psa_key_handle_t key_handle = 0;
psa_key_id_t output_key_handle = 0;
psa_key_id_t decap_output_key_handle = 0;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_attributes_t shared_secret_attributes = PSA_KEY_ATTRIBUTES_INIT;
uint8_t ciphertext[PSA_ML_KEM_CIPHERTEXT_SIZE(PSA_KEY_BITS_ML_KEM_512)] __ALIGNED(4);
size_t ciphertext_len = PSA_ML_KEM_CIPHERTEXT_SIZE(PSA_KEY_BITS_ML_KEM_512);
uint8_t export_keypair[PSA_KEY_GEN_ML_KEM_KEY_PAIR_MAX_SIZE(PSA_KEY_BITS_ML_KEM_512)];
size_t export_keypair_len = 0;
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCAPSULATE | PSA_KEY_USAGE_DECAPSULATE | PSA_KEY_USAGE_EXPORT);
psa_set_key_algorithm(&attributes, PSA_ALG_ML_KEM);
psa_set_key_type(&attributes, PSA_KEY_TYPE_ML_KEM_KEY_PAIR);
psa_set_key_bits(&attributes, bits);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
if (PSA_SUCCESS !=
psa_import_key(&attributes, &mlkem_import_keypair[0], PSA_KEY_GEN_ML_KEM_KEY_PAIR_MAX_SIZE(bits), &key_handle))
{
debugger_break();
}
psa_set_key_usage_flags(&shared_secret_attributes, PSA_KEY_USAGE_ENCAPSULATE | PSA_KEY_USAGE_DECAPSULATE);
psa_set_key_algorithm(&shared_secret_attributes, PSA_ALG_ML_KEM);
psa_set_key_type(&shared_secret_attributes, PSA_KEY_TYPE_RAW_DATA);
psa_set_key_bits(&shared_secret_attributes, PSA_BYTES_TO_BITS(PSA_ML_KEM_SHARED_SECRET_SIZE));
psa_set_key_lifetime(&shared_secret_attributes, PSA_KEY_LIFETIME_VOLATILE);
if (PSA_SUCCESS !=
psa_encapsulate(key_handle, PSA_ALG_ML_KEM, &shared_secret_attributes, &output_key_handle, &ciphertext[0],
ciphertext_len, &ciphertext_len))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_decapsulate(key_handle, PSA_ALG_ML_KEM, &ciphertext[0], ciphertext_len, &shared_secret_attributes,
&decap_output_key_handle))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_export_key(key_handle, &export_keypair[0], PSA_KEY_GEN_ML_KEM_KEY_PAIR_MAX_SIZE(bits), &export_keypair_len))
{
debugger_break();
}
if (0 != memcmp(mlkem_import_keypair, export_keypair, export_keypair_len))
{
debugger_break();
}
}
ML-DSA Example
These are examples on using the PSA Crypto API to generate an MLDSA-44 key, sign and verify a message.
Note There are two ways to use this API. The first uses PSA_ALG_HASH_ML_DSA(hash_alg) which will require the message hash (calculated with the specified hash algorithm) as an input to sign and verify hash functions. See psa_mldsa44_hash_example(). Alternatively, you may use PSA_ALG_HASH_ML_DSA(hash_alg) with sign and verify message functions. In this case, PSA Crypto API will prehash the message for you using the specified hashing algorithm. The second way to use the API is with PSA_ALG_ML_DSA. This will require the use of sign and verify message functions. But this will perform the SHAKE hash calculation using an internal hash implementation as mbedTLS does not currently support SHAKE. Refer to psa_mldsa_message_example().
#define MLDSA_MESSAGE_LEN 512U
static uint8_t mldsa_test_message[MLDSA_MESSAGE_LEN] __ALIGNED(4) =
{
0xF0, 0xA4, 0xA1, 0x8C, 0xCF, 0x98, 0x2E, 0x89, 0x1F, 0x3E, 0x91, 0x73, 0x27, 0x90, 0x1F, 0x73,
0x83, 0x90, 0xE1, 0x7A, 0xB9, 0x5F, 0xF1, 0xFB, 0x7C, 0x76, 0x83, 0x50, 0x38, 0x88, 0x9F, 0x73,
0xAF, 0x0D, 0x24, 0x49, 0x76, 0xDB, 0x62, 0x21, 0x94, 0xFA, 0xDA, 0x41, 0x14, 0x9E, 0x53, 0x4A,
0xCD, 0x96, 0xB9, 0x23, 0x38, 0x52, 0x98, 0x14, 0xEE, 0x18, 0x68, 0x32, 0xB9, 0xC3, 0x83, 0xF9,
0x80, 0xA5, 0x11, 0x7B, 0xDB, 0xED, 0x09, 0x3D, 0xB3, 0x1A, 0xCD, 0x52, 0x73, 0xDF, 0x13, 0xE5,
0xA8, 0x3D, 0x14, 0xBB, 0x82, 0x1F, 0x18, 0xC1, 0x88, 0xFF, 0x36, 0x80, 0x19, 0x16, 0x3C, 0x61,
0x4C, 0x4D, 0x20, 0x27, 0x83, 0xFC, 0x88, 0xE2, 0x52, 0x3C, 0x42, 0x51, 0x14, 0x21, 0x14, 0x25,
0x98, 0x81, 0x48, 0xF5, 0x25, 0xD0, 0x47, 0xA0, 0xCD, 0x95, 0x77, 0x63, 0xCF, 0x5B, 0x79, 0xF6,
0x6B, 0xE1, 0x73, 0x87, 0x04, 0xAC, 0x66, 0xF1, 0x33, 0x39, 0x8B, 0xC9, 0xC0, 0xE5, 0x57, 0x00,
0x63, 0x06, 0xDB, 0x92, 0x0C, 0xA8, 0x43, 0xC0, 0xD5, 0x24, 0xD4, 0xEA, 0xED, 0xBC, 0x1B, 0xDE,
0x05, 0x03, 0x37, 0x6B, 0x22, 0x77, 0x2B, 0x74, 0x14, 0x55, 0x9D, 0x68, 0x90, 0x1C, 0xC5, 0xA1,
0x80, 0x65, 0x20, 0xEB, 0x39, 0x7F, 0xFA, 0xA2, 0x4D, 0x96, 0xFF, 0x2F, 0x20, 0x7B, 0x47, 0xD1,
0xA2, 0x1C, 0xE6, 0x86, 0x87, 0xD7, 0x65, 0x83, 0xF2, 0x15, 0x11, 0x07, 0x4B, 0x90, 0x56, 0xD4,
0x54, 0xF5, 0x65, 0x35, 0x8D, 0xBE, 0xFA, 0xEC, 0x8A, 0xBE, 0x43, 0x88, 0xFB, 0x1D, 0x8A, 0x25,
0x5D, 0xE8, 0xF9, 0xE7, 0xF1, 0x1A, 0x96, 0xE6, 0x9A, 0xAD, 0xA9, 0x34, 0x6C, 0x84, 0x61, 0x90,
0x1E, 0xFA, 0x4D, 0xAA, 0xA1, 0xA4, 0xBA, 0x9B, 0x04, 0xD8, 0xA1, 0x1E, 0xBD, 0x00, 0x31, 0x9B,
0x4A, 0x7D, 0x8B, 0xAC, 0x21, 0x74, 0xCF, 0xA2, 0xA0, 0x06, 0xD9, 0x48, 0x59, 0xFE, 0xC5, 0x2B,
0xDC, 0x01, 0x88, 0x2C, 0xB9, 0xD4, 0xA3, 0xE8, 0x95, 0x1A, 0x5C, 0xC1, 0xBD, 0x36, 0xEC, 0x74,
0xF6, 0x03, 0x33, 0x31, 0xB0, 0x3E, 0x92, 0xA7, 0x27, 0x07, 0x7F, 0x44, 0x8D, 0x4F, 0xB5, 0x60,
0x9A, 0x5E, 0x55, 0xAA, 0x75, 0x28, 0x9F, 0x7D, 0xAF, 0x3B, 0xEA, 0xB3, 0x1C, 0xF7, 0xAA, 0x1F,
0x4B, 0x66, 0x98, 0x0F, 0x5F, 0x5F, 0x8A, 0x31, 0xAC, 0xFE, 0x55, 0x58, 0x52, 0x52, 0x24, 0x7F,
0xCD, 0x78, 0xB9, 0x67, 0x56, 0x38, 0xDB, 0x8E, 0x12, 0x92, 0x91, 0x3A, 0x6F, 0x3E, 0xA5, 0x7C,
0x60, 0xD1, 0x97, 0xB1, 0xCF, 0x83, 0xD8, 0x53, 0xC6, 0xAB, 0xE3, 0x50, 0xB7, 0xB1, 0x10, 0x40,
0x76, 0x5A, 0xF1, 0xC1, 0x74, 0x0A, 0xF1, 0xE3, 0x18, 0x68, 0x92, 0x37, 0xB3, 0x50, 0xDD, 0x8F,
0x4F, 0x0C, 0x0A, 0x63, 0x93, 0x9A, 0xDA, 0xBF, 0x39, 0x2D, 0x71, 0x47, 0x1B, 0xF3, 0xF7, 0xA5,
0xCA, 0x44, 0x8A, 0x4D, 0xCD, 0xF4, 0x89, 0x6A, 0x34, 0x2B, 0x4B, 0xA9, 0x42, 0x12, 0x81, 0x37,
0xF3, 0xFF, 0x44, 0xAE, 0x57, 0xDB, 0x85, 0x00, 0xA7, 0xBF, 0xB6, 0xFD, 0x74, 0x25, 0x0E, 0x63,
0x12, 0xD5, 0x4A, 0x35, 0x88, 0xD0, 0x8E, 0x93, 0xBA, 0x62, 0x3E, 0x18, 0x9B, 0x81, 0x7E, 0xEF,
0x2B, 0xE6, 0x6D, 0x2A, 0x57, 0x09, 0x7B, 0x14, 0x7A, 0x13, 0x1D, 0x5C, 0x88, 0x43, 0xCC, 0x73,
0x43, 0xE6, 0x2B, 0xC0, 0x02, 0xAD, 0x1E, 0x60, 0x29, 0x9B, 0xB7, 0xD2, 0xF0, 0xFF, 0x14, 0xC5,
0x1B, 0x3E, 0x41, 0x41, 0x98, 0x52, 0x4A, 0x3D, 0x96, 0x4C, 0xE2, 0xA6, 0x31, 0xB7, 0x2F, 0x71,
0x34, 0x2E, 0x17, 0xAF, 0x47, 0x99, 0x2E, 0x6C, 0x27, 0x06, 0x7C, 0xA1, 0x47, 0x11, 0x61, 0x5C
};
void psa_mldsa44_hash_example (void )
{
psa_algorithm_t hash_alg = PSA_ALG_SHA3_256;
psa_algorithm_t alg = PSA_ALG_HASH_ML_DSA(hash_alg);
psa_key_handle_t key_handle = 0;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
size_t sign_len;
uint8_t sign[PSA_ML_DSA_SIGNATURE_SIZE(PSA_KEY_BITS_ML_DSA_44)] __ALIGNED(4);
psa_hash_operation_t hash_operation = {0};
uint8_t payload_hash[PSA_HASH_MAX_SIZE] __ALIGNED(4);
size_t payload_hash_len;
unsigned char payload[] = "ASYMMETRIC_INPUT_FOR_SIGN......" ;
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH | PSA_KEY_USAGE_VERIFY_HASH | PSA_KEY_USAGE_EXPORT);
psa_set_key_algorithm(&attributes, alg);
psa_set_key_type(&attributes, PSA_KEY_TYPE_ML_DSA_KEY_PAIR);
psa_set_key_bits(&attributes, PSA_KEY_BITS_ML_DSA_44);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
if (PSA_SUCCESS != psa_generate_key(&attributes, &key_handle))
{
debugger_break();
}
if (PSA_SUCCESS != psa_hash_setup(&hash_operation, hash_alg))
{
debugger_break();
}
if (PSA_SUCCESS != psa_hash_update(&hash_operation, payload, sizeof (payload)))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_hash_finish(&hash_operation, &payload_hash[0], sizeof (payload_hash), &payload_hash_len))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_sign_hash(key_handle, alg, payload_hash, payload_hash_len, sign, sizeof (sign), &sign_len))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_verify_hash(key_handle, alg, payload_hash, payload_hash_len, sign, sign_len))
{
debugger_break();
}
}
void psa_mldsa44_message_example (void )
{
psa_algorithm_t alg = PSA_ALG_ML_DSA;
psa_key_handle_t key_handle = 0;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
size_t sign_len;
uint8_t sign[PSA_ML_DSA_SIGNATURE_SIZE(PSA_KEY_BITS_ML_DSA_44)] __ALIGNED(4);
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes,
PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE | PSA_KEY_USAGE_EXPORT);
psa_set_key_algorithm(&attributes, alg);
psa_set_key_type(&attributes, PSA_KEY_TYPE_ML_DSA_KEY_PAIR);
psa_set_key_bits(&attributes, PSA_KEY_BITS_ML_DSA_44);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
if (PSA_SUCCESS != psa_generate_key(&attributes, &key_handle))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_sign_message(key_handle, alg, mldsa_test_message, sizeof (mldsa_test_message), sign, sizeof (sign),
&sign_len))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_verify_message(key_handle, alg, mldsa_test_message, sizeof (mldsa_test_message), sign, sign_len))
{
debugger_break();
}
}
uint8_t mldsa_import_keypair[PSA_KEY_EXPORT_ML_DSA_KEY_PAIR_MAX_SIZE] __ALIGNED(4) =
{
0x4B, 0xE7, 0xA0, 0x1A, 0x99, 0xA5, 0xE5, 0xBC, 0xFE, 0x3C, 0x06, 0x78, 0x5D, 0x8E, 0x4E, 0xC6,
0x64, 0x08, 0x22, 0x27, 0xD8, 0x67, 0x04, 0xE9, 0xE4, 0x48, 0x62, 0x62, 0x3A, 0x05, 0xC8, 0xB3,
};
void psa_mldsa44_keypair_import_export_example (void )
{
psa_key_id_t key_handle = 0;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
uint8_t sign[PSA_ML_DSA_SIGNATURE_SIZE(PSA_KEY_BITS_ML_DSA_44)] __ALIGNED(4);
size_t sign_len;
uint8_t public_key[PSA_KEY_GEN_ML_DSA_PUB_KEY_SIZE(PSA_KEY_BITS_ML_DSA_44)] __ALIGNED(4);
size_t public_key_len = 0;
psa_algorithm_t alg = PSA_ALG_HASH_ML_DSA(PSA_ALG_SHA3_512);
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE);
psa_set_key_algorithm(&attributes, alg);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
psa_set_key_type(&attributes, PSA_KEY_TYPE_ML_DSA_KEY_PAIR);
psa_set_key_bits(&attributes, PSA_KEY_BITS_ML_DSA_44);
if (PSA_SUCCESS !=
psa_import_key(&attributes, &mldsa_import_keypair[0],
PSA_KEY_GEN_ML_DSA_KEY_PAIR_MAX_SIZE(PSA_KEY_BITS_ML_DSA_44), &key_handle))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_sign_message(key_handle, alg, mldsa_test_message, sizeof (mldsa_test_message), sign, sizeof (sign),
&sign_len))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_verify_message(key_handle, alg, mldsa_test_message, sizeof (mldsa_test_message), sign, sign_len))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_export_public_key(key_handle, &public_key[0], PSA_KEY_GEN_ML_DSA_PUB_KEY_SIZE(PSA_KEY_BITS_ML_DSA_44),
&public_key_len))
{
debugger_break();
}
if (PSA_SUCCESS != psa_destroy_key(key_handle))
{
debugger_break();
}
psa_set_key_type(&attributes, PSA_KEY_TYPE_ML_DSA_PUBLIC_KEY);
if (PSA_SUCCESS != psa_import_key(&attributes, &public_key[0], public_key_len, &key_handle))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_verify_message(key_handle, alg, mldsa_test_message, sizeof (mldsa_test_message), sign, sign_len))
{
debugger_break();
}
}
Migrating to MbedTLS 3.6.0
MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS macro is disabled by default to handle shared memory in a secure manner. Note that this increases heap memory usage and code size. The macro can be enabled if all buffers passed to any PSA function reside in memory that is accessible only to the PSA function during its execution or if it possible otherwise for the user to conclude that the user buffers passed into PSA are secure from modification. Refer to https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2024-03.md for more details.
psa_import_key() now only accepts RSA keys in the PSA standard formats. Applications that need other formats like: PKCS#8, SubjectPublicKey, PEM can call mbedtls_pk_parse_{public,}key() followed by mbedtls_pk_import_into_psa().
const uint8_t RSAKeydata[] = "-----BEGIN RSA PRIVATE KEY-----\n"
"MIIEowIBAAKCAQEAplaPU68h4hW/eAlH2hbQl1WjoDT1znCk0O9cnE9lAnB26IUi"
"78wUAxuTZSlrlKez9FGGIVbUMTy7dTw0ZBanogrKCaAMaRFz5LRv4I8RQzsDxxqe"
"nud9Y6mVRWb9hyutL/yBwDd6jzAwcviAhcatTv0E5wpEJ6ezMDyaiSCbn84hfb0T"
"ZPXQVGhmjii3f0FfFWW9ce70qkuwdkvO6HBrOGVi2++b11As+Uh/7pxyOb7wpE7K"
"X64nohaCtXgNnV8Hr+LOPQRHEbGTCPOfx1davKEIYFvm8hVxqv20csMD5uc8AJCd"
"0cdom13KcOpVXCnrFPNJt0lITOcH/fBzp4xoaQIDAQABAoIBAGc56qKVWeKzempk"
"4AlRBUwVYoEGvNDLiQz8rq12fAoCf1iXXvIP5Q90qokqJlBPrtbdTO8dsnuH5BHC"
"NgUzJf7i0TUd9PWzVgfFjnR+dMkTM6n5NB0LLf6OfEtguc+L5GOWQXNnOpDn5/lB"
"jIj4ng8Z6FP1RAyT/xjdU03sRYfq5OPlDZ8+ck7WwQ8VxSBKsJcZVv+K4r64Vmr1"
"MO1zfBYuwafi4oO9Z9x89Iil9GBcYuCvhLvDoWhnTUxlOTfz+Jt+qwlmVimEz6xs"
"6ew1Ox7e6SInly3IAXe9E84yP9MDmiGkCrVr8s8GUybZ5t/yeZ3g5lPYSQ/FiuHY"
"kvJCH4ECgYEA2IthRDkElOQGqJ9T/LjgcIVLQs0F6i7zZWg6UKv18EmG7uHd6tsZ"
"byFfFiBat80rq6q4AUx2OOE7+LI5MxIvgRgLk14WV8H2OKK/lfxOFb6a4feGM7bH"
"VdERQSMNeGq0bP9IOPxU1EvFp0Vfv7cfGsQhcAPgA8up61jWREhI+fECgYEAxKVT"
"9pKinIwgjsHgmxalaNbnRf+bcqtdS98SB2MuICg8ubcBSrjm4wtGe3oCX/PbM1GV"
"FvEDKl4TyeWFIH4MStsyDHYxwoV2C01bBHEtHTYBnjeIShMruIomsG9GeTrNmyzg"
"dVdSg5/lxYOxuZSXvfcbyIMsW29ddgeICu9RHfkCgYBaljQibhfUkW+Xqs9fsZdy"
"etB5KXuH9AwuJ+P9S3KfCqM/240SaoXBT5yPjQlmSpYyQkCnim0Kbm7AIw56pujo"
"gD6Xb4y5OZLfLnYnMF0aC5qPXRTvHU9WPxeQwDEqZrkDv+der3BtPyV4TDU55klE"
"0TeLvJNCAzkaExfPiM2+gQKBgQC5ceBYq7hGQa+CcTvLhfO/hsrbrE2AOjLllhx+"
"cv3QvaFm0jqZqP20J7H0R/9tVZ7mKo2a8Pa3QbkPsS92kOguv7/XGK+cbhgAWJb4"
"/XI6FfA4sM4KbUHR6hbKVGX1dYroR831WsAp+OTK+4LjLEpdj2fYFDwEjmVpJXka"
"Ns4coQKBgGESrtpJF7OQG4xcXwR2ZiJESPvMKVmtvxRzDrc9gmoiIIIKx1fimwCv"
"RtOz1bQcXMRw21+ZAZpen3ahWh63KC0KxMSNBJTXdczlf2uprVkSPtmAjV4qBgwv"
"tqjmP0lnGc9wkJsVvGmMAAfQOWgxs9h/VH/b+6biEkzaaZLOyABV"
"-----END RSA PRIVATE KEY-----\n" ;
const uint8_t RSAExpectedSignature[256] =
{
0x25, 0xC0, 0x15, 0x64, 0xD3, 0xF7, 0xC1, 0xB7, 0xA8, 0x9B, 0x56, 0x1C, 0xB5, 0xA4, 0xA5, 0x0D, 0x61, 0x52, 0x32,
0x0C, 0x4E, 0xE8, 0xCA, 0x4B, 0x9E, 0xA2, 0x4D, 0x35, 0x0E, 0xB1, 0xA1, 0x5B,
0x5B, 0xD8, 0xC1, 0x93, 0x28, 0x60, 0x90, 0x18, 0x37, 0x88, 0x66, 0xD4, 0xED, 0x37, 0x6B, 0xEC, 0x48, 0xFF, 0x3D,
0xFB, 0x99, 0xB7, 0xEF, 0x3C, 0x8D, 0x25, 0xE9, 0xF3, 0xCF, 0x02, 0x7C, 0x7D,
0xB9, 0x4D, 0x2F, 0x2F, 0x1E, 0x30, 0x48, 0x54, 0x18, 0xE4, 0x51, 0xD5, 0xC1, 0xB7, 0x3B, 0x0D, 0xE4, 0xB4, 0x19,
0x7B, 0x9B, 0xF4, 0x35, 0x82, 0xCC, 0x91, 0x4C, 0x10, 0xE9, 0xB6, 0xF1, 0x0A,
0x23, 0xEB, 0x7D, 0x51, 0x47, 0x36, 0xFE, 0x13, 0xAF, 0x3C, 0x23, 0x9F, 0x7E, 0xFC, 0xCF, 0x7A, 0x7C, 0x2D, 0xDB,
0xD9, 0xDA, 0xEB, 0xF7, 0xB5, 0x6B, 0x8D, 0xE0, 0x18, 0x9A, 0x5B, 0xB7, 0x0A,
0xA3, 0x4E, 0xE1, 0xB7, 0xF7, 0xD1, 0x94, 0xD5, 0x7A, 0xD3, 0x27, 0xE2, 0x1F, 0x3A, 0xEB, 0xF0, 0x83, 0x10, 0x52,
0x51, 0x5F, 0x58, 0xF8, 0x81, 0x42, 0x48, 0x83, 0x2D, 0xF0, 0xA9, 0x7D, 0x79,
0x2B, 0xF1, 0x68, 0xC2, 0x22, 0xC0, 0x0C, 0x72, 0x63, 0x37, 0xBF, 0xEC, 0x72, 0x97, 0xD4, 0xA5, 0x91, 0x2E, 0x1F,
0xA3, 0x78, 0x9A, 0xCE, 0xFE, 0x27, 0x7F, 0x2B, 0x85, 0x7D, 0x22, 0x2C, 0x0D,
0x1E, 0x10, 0xB7, 0xFF, 0x9A, 0xA7, 0x99, 0xD2, 0xB9, 0x40, 0x53, 0xB3, 0xA9, 0x52, 0x5D, 0xBD, 0xC8, 0x12, 0x8D,
0x39, 0xD7, 0x97, 0x03, 0xD2, 0x80, 0x21, 0xC3, 0xA7, 0x8B, 0xE3, 0x3D, 0xF0,
0x4D, 0x4C, 0x4D, 0xC4, 0xC7, 0xE5, 0xE4, 0x35, 0x75, 0xAA, 0x45, 0x3B, 0x9C, 0x64, 0xC1, 0x94, 0x6E, 0x15, 0x0A,
0xE8, 0x84, 0xCD, 0xFC, 0x7A, 0xBC, 0x5C, 0x8C, 0xA8, 0x95, 0x07, 0x79, 0x4E,
};
void psa_rsa2048_pem_format_import_example (void )
{
psa_key_handle_t key_handle = {0};
unsigned char payload[] = "ASYMMETRIC_INPUT_FOR_SIGN" ;
unsigned char signature[PSA_SIGNATURE_MAX_SIZE] = {0};
size_t signature_length = 0U;
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
psa_key_attributes_t read_attributes = PSA_KEY_ATTRIBUTES_INIT;
{
debugger_break();
}
if (PSA_SUCCESS != psa_crypto_init())
{
debugger_break();
}
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH | PSA_KEY_USAGE_VERIFY_HASH);
psa_set_key_algorithm(&attributes, PSA_ALG_RSA_PKCS1V15_SIGN_RAW);
psa_set_key_type(&attributes, PSA_KEY_TYPE_RSA_KEY_PAIR);
psa_set_key_bits(&attributes, RSA_2048_BIT_LENGTH);
mbedtls_pk_context ctx_rsa;
mbedtls_pk_init(&ctx_rsa);
if (PSA_SUCCESS !=
mbedtls_pk_parse_key(&ctx_rsa, RSAKeydata, sizeof (RSAKeydata), NULL, 0, mbedtls_psa_get_random,
MBEDTLS_PSA_RANDOM_STATE))
{
debugger_break();
}
if (PSA_SUCCESS != mbedtls_pk_import_into_psa(&ctx_rsa, &attributes, &key_handle))
{
debugger_break();
}
mbedtls_pk_free(&ctx_rsa);
if (PSA_SUCCESS != psa_get_key_attributes(key_handle, &read_attributes))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_sign_hash(key_handle, PSA_ALG_RSA_PKCS1V15_SIGN_RAW, payload, sizeof (payload), signature, sizeof (signature),
&signature_length))
{
debugger_break();
}
if (0 != memcmp(signature, &RSAExpectedSignature, sizeof (RSAExpectedSignature)))
{
debugger_break();
}
if (PSA_SUCCESS !=
psa_verify_hash(key_handle, PSA_ALG_RSA_PKCS1V15_SIGN_RAW, payload, sizeof (payload), RSAExpectedSignature,
sizeof (RSAExpectedSignature)))
{
debugger_break();
}
if (PSA_SUCCESS != psa_destroy_key(key_handle))
{
debugger_break();
}
mbedtls_psa_crypto_free();
}
◆ RM_PSA_CRYPTO_TRNG_Read()
fsp_err_t RM_PSA_CRYPTO_TRNG_Read
(
uint8_t *const
p_rngbuf ,
uint32_t
num_req_bytes ,
uint32_t *
p_num_gen_bytes
)
Reads requested length of random data from the TRNG. Generate nbytes of random bytes and store them in p_rngbuf buffer.
Return values
FSP_SUCCESS Random number generation successful
FSP_ERR_ASSERTION NULL input parameter(s).
FSP_ERR_CRYPTO_UNKNOWN An unknown error occurred.
Returns See Common Error Codes or functions called by this function for other possible return codes. This function calls:
s_generate_16byte_random_data
◆ mbedtls_platform_setup()
This function initializes the SCE and the TRNG. It must be invoked before the crypto library can be used. This implementation is used if MBEDTLS_PLATFORM_SETUP_TEARDOWN_ALT is defined.
Example:
Return values
0 Initialization was successful.
MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED SCE Initialization error.
◆ mbedtls_platform_teardown()
This implementation is used if MBEDTLS_PLATFORM_SETUP_TEARDOWN_ALT is defined. It is intended to de-initialize any items that were initialized in the mbedtls_platform_setup() function, but currently is only a placeholder function.
Example:
Return values