| 数据搜索系统,热门电子元器件搜索 |
|
ST33TPHF20SPI 数据表(PDF) 39 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
ST33TPHF20SPI 数据表(HTML) 39 Page - STMicroelectronics |
|
39 / 47 page ![]() FIPS140-2 SECURITY POLICY Page 39 of 47 NON-PROPRIETARY DOCUMENT FW integrity FW integrity is verified by computing an EDC (CRC-16 ISO 13239) and comparing it to reference values. FW integrity is verified during boot sequence before execution of one of the code block (CML, AFL and TPM) and during full self-tests execution. If failure is detected during boot sequence, TPM enters an infinite reset loop that can be exit only by power-off/power-on sequence. In failure is detected during self-tests, status is set to FAIL and error is returned. HW integrity HW integrity is guaranteed via check of HW sensors. If failure is detected during boot sequence, status is set to FAIL and error is returned. 4.2 Asymmetric cryptography self-tests list Table 22 : Asymmetric cryptography self-tests list Algorithm tested Test description RSA A known key is loaded (2048 bits length). Signature RSASSA-PKCS1-v1_5 is generated on known data (20 bytes). Output of signature is compared to a reference signature. Signature verification is performed on the generated signature. ECDH A known private key d (32 bytes length) is used with a known point P of NIST P-256 curve to compute P = dQ. Q is compare to known reference point. ECDSA A known private key (256 bits) is used to generate ECDSA signature based on NIST P- 256 curve. Output of signature is compared to a reference signature. Signature verification is performed on the generated signature. 4.3 Conditional tests list Table 23 : TPM conditional tests Algorithm tested Test description FW integrity FW integrity is verified by computing an EDC (CRC-16 ISO 13239) and comparing it to reference values. Hash-DRBG Each 32 bytes of generated data are compared to the previous generated data. If data are equal, status is set to FAIL and error is returned. NDRNG TPM performs AIS31 statistical test verification on NDRNG output and continuous HW self-tests (AS09.42) on NDRNG 48-bits output sequence. If test fails, TRNG_ERR bit is raised in SEC_STAT register. Status is set to FAIL and error is returned. FW load During field upgrade procedure, several checks are performed before authorizing the FW to be upgraded: - Verification of signature (RSASSA-PSS) on the first data blob to ensure authentication of the FW - Verification of digest (SHA256) on each subsequent blob to guarantee integrity of the full FW. RSA key generation A new RSA key is generated or retrieved from pre-computed keys (done in BKG). Depending on the key purpose (signing or encrypting) indicated in sign attribute of the key, en/decryption or signing/verification is done on known data (16 bytes). ECC key generation On each ECC key generation, an ECDSA signature is generated and verified on curve NIST P-256. |
|
链接网址 |
| ALLDATASHEET是否为您带来帮助? [ DONATE ] |
关于 Alldatasheet | 广告服务 | 联系我们 | 隐私政策 | 数据表链接 | 链接交换 | 制造商名单 All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |