跳转到主要内容

概览

描述

Topics

-Support for RSIP-E11A security engine with RA4L1.
 - Key Wrapping
 - Encryption of images available for Secure Factory Programming
-Support for encryption of external flash memory area in Secure Factory Programming function

Security Key Management Tool is a support tool for key management systems and secure functions using Renesas security IP.
Note: When used with the Secure Boot and Secure Update Samples included with RX TSIP driver FIT V.1.21, V.1.20 (R20AN0371XJ0121, R20AN0371XJ0120) and RX RSIP CM driver FIT V.1.00, Security Key Management Tool V.1.07 should be used.

特性

  • Compliant with key-management systems that use security IP modules incorporated in Renesas MCUs and MPUs
     
  • Wrapping of user application keys and DLM keys for secure key injection and secure key updating
  • Key data files can be output in a variety of file formats
  • Generate data for using security functions with Renesas security IP
  • See details for functions

发布信息

Supported Device FamilySecurity IP
RASCE9 (Protected Mode, Compatibility Mode), SCE7, SCE5, SCE5_B, RSIP-E51A, RSIP-E11A
RXTSIP, TSIP-Lite, RSIP-E11A
RZRZ/T2M RSIP, RZ/T2ME RSIP, RZ/T2L RSIP, RZ/N2L RSIP
SynergySCE7, SCE5

目标设备

下载

类型 文档标题 日期
软件和工具 - 其他 登录后下载 ZIP 19.62 MB 日本語
软件和工具 - 其他 登录后下载 ZIP 19.46 MB 日本語
软件和工具 - 其他 登录后下载 ZIP 19.26 MB 日本語
软件和工具 - 其他 登录后下载 ZIP 258.32 MB 日本語
软件和工具 - 其他 登录后下载 ZIP 159.30 MB 日本語
软件和工具 - 其他 登录后下载 ZIP 221.26 MB 日本語
6 items

文档

类型 文档标题 日期
手册 - 开发工具 PDF 5.26 MB English , 日本語
工具新闻 - 注意事项 PDF 139 KB 日本語
2 items

Additional Details

Functions

Output key data files for use in the installation and updating of secure keys

The Security Key Management Tool supports the following functions required for using Renesas security IP modules to inject and update secure keys.

  • Generating User Factory Programming Key (UFPK) files in the Renesas Key Wrap Service format
  • Wrapping DLM/AL Keys by using the UFPK for the injection of secure keys*
  • Wrapping user keys by using the UFPK for the injection of secure keys
  • Wrapping user keys by using the Key Update Key (KUK) for the updating of secure keys

* Only MCU families/security engines that support DLM/AL Keys are supported.

Output files support a variety of file formats

Wrapped key files can be output for different purposes in the file formats listed below.

FormatUse Case
Renesas key file*1Factory key injection
Motorola HEXFactory key injection
C source filesField key update, prototype key injection*2
Binary dataField key update

*1 Only MCU families/security engines that support key injection functionality in the boot firmware are supported.
*2 Not supported for RA RSIP-E51A and SCE9 Protected Mode.

Example of using the Security Key Management Tool during secure key installation

图像
Securiuty-key-en

For more information about secure key injection and update on Renesas devices, please see www.renesas.com/iot-security.

Data generation for using security features with Renesas security IP

In addition to secure key injection and updating, it generates data for use in the following functions of the device.
Please refer to the hardware user's manual or application note of your MCU/MPU for the functions supported by your device.

  • Generate Key Certificate and Code Certificate for FSBL
  • Encrypt code/data for use with Decryption On-The-Fly
  • Prepare a file for use with Secure Factory Programming
  • Prepare a file for use with the TSIP UPDATE solution