| Electronic Components Datasheet Search |
|
STSAFE-A110 Datasheet(PDF) 14 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
STSAFE-A110 Datasheet(HTML) 14 Page - STMicroelectronics |
|
14 / 36 page ![]() Asymmetric cryptography use cases STSAFE-A110 14/36 DS13039 Rev 1 3. The TLS server sends the Server Key Exchange message including the Diffie-Hellman public key of the TLS server and a signature over the server key exchange parameters. Upon reception of this message, the local host of the TLS client may use the STSAFE- A110 for verifying the signature with the Verify Signature command (3) and the same mechanisms that were applied in step 2. 4. When the signature is valid, the local host may use the Generate Key command 4 of the STSAFE-A110 for generating an ephemeral key pair in the STSAFE-A110. The command data take a reference to the curve that must be used, and the response data includes the public key of the freshly generated key pair. The Generate Key command (4) requires a Host C-MAC in the command but this is not illustrated here (see Section 3.1). 5. The local host can now use the Establish Key command (5) of the STSAFE-A110 and give the public key of the TLS server in the command data. The response data contains the shared secret that is computed with ECDHE using the ephemeral private key in the STSAFE-A110 and the public key of the TLS server. The shared secret in the response data is encrypted with the Host’s Cipher key and the Establish key command also requires a Host C-MAC. The local host must compute the Host C-MAC and decrypt the response data to obtain the plain-text shared secret that can be used as the pre-master secret of the TLS handshake protocol. The mechanisms linked to the Host C-MAC and Host’s Cipher key are not illustrated here (see Section 3.1). The local host can now derive the pre-master secret to the master secret and apply the expansion algorithm to obtain the key block; these functions, however, cannot be executed by the STSAFE- A110. 6. The TLS server sends the Certificate Request message including the signature and hash algorithms that are supported by the TLS server. The TLS server also sends the Server Hello Done message. The TLS client sends the Certificate message including the X509 certificate chain of the TLS client. This chain may include the X509 certificate of the static private key of the STSAFE-A110, which can be read from it with a Read command (6). This command can typically be executed upon setup of the IoT device and can then be cached by the IoT device so that there is no need any longer to read it from the STSAFE-A110. In case of long certificates, the Read command may be sent multiple times but this is not illustrated in Figure 7. 7. The TLS client sends the Client Key Exchange message including the ephemeral Diffie-Hellman public key that was obtained in step 5 in the Establish Key response data from the STSAFE-A110. The TLS client sends the Certificate Verify message including a signature over all handshake messages that have been exchanged so far. The local host may use the STSAFE-A110 for generating this signature. The local host must therefore hash the To Be Signed message and send it to the STSAFE-A110 in the command data of the Generate Signature command (7). The STSAFE-A110 uses its static private key for generating the signature that is returned in the response data. The handshake protocol continues without any further interaction with the STSAFE-A110. • The TLS client sends the Change Cipher Spec command. • The TLS client sends the Finished command including the verify data computed with the Pseudo Random Function, the master secret and all handshake messages exchanged so far. • The TLS server sends the Change Cipher Spec command. • The TLS server sends its own Finished command that must be verified by the TLS client. |
|
Link URL |
| Does ALLDATASHEET help your business so far? [ DONATE ] |
About Alldatasheet | Advertisement | Contact us | Privacy Policy | Link to Datasheet | Link Exchange | Manufacturer List All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |