Electronic Components Datasheet Search
  New Zealand  ▼
ALLDATASHEET.CO.NZ

X  

STSAFE-A110 Datasheet(PDF) 14 Page - STMicroelectronics

Part # STSAFE-A110
Description  Authentication, state-of-the-art security for peripherals and IoT devices
PDF  36 Pages
Scroll/Zoom Zoom In 100%  Zoom Out
Manufacturer  STMICROELECTRONICS [STMicroelectronics]
Direct Link  http://www.st.com
Logo STMICROELECTRONICS - STMicroelectronics

STSAFE-A110 Datasheet(HTML) 14 Page - STMicroelectronics

Back Button STSAFE-A110 Datasheet HTML 10Page - STMicroelectronics STSAFE-A110 Datasheet HTML 11Page - STMicroelectronics STSAFE-A110 Datasheet HTML 12Page - STMicroelectronics STSAFE-A110 Datasheet HTML 13Page - STMicroelectronics STSAFE-A110 Datasheet HTML 14Page - STMicroelectronics STSAFE-A110 Datasheet HTML 15Page - STMicroelectronics STSAFE-A110 Datasheet HTML 16Page - STMicroelectronics STSAFE-A110 Datasheet HTML 17Page - STMicroelectronics STSAFE-A110 Datasheet HTML 18Page - STMicroelectronics Next Button
Zoom Inzoom in Zoom Outzoom out
 14 / 36 page
background image
Asymmetric cryptography use cases
STSAFE-A110
14/36
DS13039 Rev 1
3.
The TLS server sends the Server Key Exchange message including the Diffie-Hellman
public key of the TLS server and a signature over the server key exchange parameters.
Upon reception of this message, the local host of the TLS client may use the STSAFE-
A110 for verifying the signature with the Verify Signature command (3) and the same
mechanisms that were applied in step 2.
4.
When the signature is valid, the local host may use the Generate Key command 4 of
the STSAFE-A110 for generating an ephemeral key pair in the STSAFE-A110. The
command data take a reference to the curve that must be used, and the response data
includes the public key of the freshly generated key pair. The Generate Key command
(4) requires a Host C-MAC in the command but this is not illustrated here (see
Section 3.1).
5.
The local host can now use the Establish Key command (5) of the STSAFE-A110 and
give the public key of the TLS server in the command data. The response data contains
the shared secret that is computed with ECDHE using the ephemeral private key in the
STSAFE-A110 and the public key of the TLS server. The shared secret in the response
data is encrypted with the Host’s Cipher key and the Establish key command also
requires a Host C-MAC. The local host must compute the Host C-MAC and decrypt the
response data to obtain the plain-text shared secret that can be used as the pre-master
secret of the TLS handshake protocol. The mechanisms linked to the Host C-MAC and
Host’s Cipher key are not illustrated here (see Section 3.1). The local host can now
derive the pre-master secret to the master secret and apply the expansion algorithm to
obtain the key block; these functions, however, cannot be executed by the STSAFE-
A110.
6.
The TLS server sends the Certificate Request message including the signature and
hash algorithms that are supported by the TLS server. The TLS server also sends the
Server Hello Done message. The TLS client sends the Certificate message including
the X509 certificate chain of the TLS client. This chain may include the X509 certificate
of the static private key of the STSAFE-A110, which can be read from it with a Read
command (6). This command can typically be executed upon setup of the IoT device
and can then be cached by the IoT device so that there is no need any longer to read it
from the STSAFE-A110. In case of long certificates, the Read command may be sent
multiple times but this is not illustrated in Figure 7.
7.
The TLS client sends the Client Key Exchange message including the ephemeral
Diffie-Hellman public key that was obtained in step 5 in the Establish Key response
data from the STSAFE-A110. The TLS client sends the Certificate Verify message
including a signature over all handshake messages that have been exchanged so far.
The local host may use the STSAFE-A110 for generating this signature. The local host
must therefore hash the To Be Signed message and send it to the STSAFE-A110 in the
command data of the Generate Signature command (7). The STSAFE-A110 uses its
static private key for generating the signature that is returned in the response data.
The handshake protocol continues without any further interaction with the STSAFE-A110.
•
The TLS client sends the Change Cipher Spec command.
•
The TLS client sends the Finished command including the verify data computed with
the Pseudo Random Function, the master secret and all handshake messages
exchanged so far.
•
The TLS server sends the Change Cipher Spec command.
•
The TLS server sends its own Finished command that must be verified by the TLS
client.



Html Pages

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36


Datasheet Download

Go To PDF Page


Link URL



Does ALLDATASHEET help your business so far?  [ DONATE ] 

About Alldatasheet   |   Advertisement   |   Contact us   |   Privacy Policy   |   Link to Datasheet    |   Link Exchange   |   Manufacturer List
All Rights Reserved©Alldatasheet.com


Mirror Sites
English : Alldatasheet.com  |   English : Alldatasheet.net  |   Chinese : Alldatasheetcn.com  |   German : Alldatasheetde.com  |   Japanese : Alldatasheet.jp
Russian : Alldatasheetru.com  |   Korean : Alldatasheet.co.kr  |   Spanish : Alldatasheet.es  |   French : Alldatasheet.fr  |   Italian : Alldatasheetit.com
Portuguese : Alldatasheetpt.com  |   Polish : Alldatasheet.pl  |   Vietnamese : Alldatasheet.vn
Indian : Alldatasheet.in  |   Mexican : Alldatasheet.com.mx  |   British : Alldatasheet.co.uk  |   New Zealand : Alldatasheet.co.nz
Family Site : ic2ic.com  |   icmetro.com