mirror of
https://gitee.com/Vancouver2017/luban-lite.git
synced 2025-12-16 00:58:55 +00:00
863 lines
92 KiB
HTML
863 lines
92 KiB
HTML
<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="zh-cn" lang="zh-cn" data-whc_version="26.1">
|
||
<head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/><meta name="viewport" content="width=device-width, initial-scale=1.0"/><meta http-equiv="X-UA-Compatible" content="IE=edge"/><meta name="description" content="硬件授权认证是一种基于身份认证原理以及硬件安全密钥实现的安全功能,可以让软件或者第三方合作伙伴对芯片的合法性进行认证。 根据使用的硬件密钥,需要烧录对应的 eFuse,可设置的 eFuse 信息如下所示: 表 1 . eFuse 信息 用途 位数 地址 禁止位 禁写 禁读 归属 备注 DIS RD 64 0~7 0~1 V - CSTM eFuse 读禁止配置区域 DIS WR 64 8~F ..."/><meta name="DC.rights.owner" content="(C) 版权 2025"/><meta name="copyright" content="(C) 版权 2025"/><meta name="generator" content="DITA-OT"/><meta name="DC.type" content="topic"/><meta name="DC.relation" content="../../../topics/sdk/secure/chapter-secure.html"/><meta name="DC.relation" content="../../../topics/sdk/secure/firmware_encryption_with_spienc.html"/><meta name="DC.relation" content="../../../topics/sdk/secure/spi_flash_enc_function.html"/><meta name="DC.contributor" content="yan.wang"/><meta name="DC.contributor" content="yan.wang"/><meta name="DC.date.modified" content="2025-05-16"/><meta name="DC.format" content="HTML5"/><meta name="DC.identifier" content="hw_authentication"/><meta name="DC.language" content="zh-CN"/><title>硬件授权认证</title><!-- Generated with build number 2025051600. --><meta name="wh-path2root" content="../../../"/><meta name="wh-toc-id" content="hw_authentication-d3752e1470"/><meta name="wh-source-relpath" content="topics/sdk/secure/hw_authorization.dita"/><meta name="wh-out-relpath" content="topics/sdk/secure/hw_authorization.html"/>
|
||
|
||
<link rel="stylesheet" type="text/css" href="../../../webhelp/app/commons.css?buildId=2024041900"/>
|
||
<link rel="stylesheet" type="text/css" href="../../../webhelp/app/topic.css?buildId=2024041900"/>
|
||
|
||
<script src="../../../webhelp/app/options/properties.js?buildId=20250519091401"></script>
|
||
<script src="../../../webhelp/app/localization/strings.js?buildId=2024041900"></script>
|
||
<script src="../../../webhelp/app/search/index/keywords.js?buildId=20250519091401"></script>
|
||
<script defer="defer" src="../../../webhelp/app/commons.js?buildId=2024041900"></script>
|
||
<script defer="defer" src="../../../webhelp/app/topic.js?buildId=2024041900"></script>
|
||
<link rel="stylesheet" type="text/css" href="../../../webhelp/template/css/aic-styles-web-internal.css?buildId=2024041900"/><link rel="stylesheet" type="text/css" href="../../../webhelp/template/css/notes.css?buildId=2024041900"/><link rel="stylesheet" type="text/css" href="../../../webhelp/template/css/aic-common.css?buildId=2024041900"/><link rel="stylesheet" type="text/css" href="../../../webhelp/template/css/aic-images.css?buildId=2024041900"/><link rel="stylesheet" type="text/css" href="../../../webhelp/template/css/footnote.css?buildId=2024041900"/><link rel="stylesheet" type="text/css" href="../../../webhelp/template/css/aic-highlight-changes.css?buildId=2024041900"/><link rel="stylesheet" type="text/css" href="../../../webhelp/template/css/search-in-header.css?buildId=2024041900"/><link rel="stylesheet" type="text/css" href="../../../webhelp/template/css/topic-body-list.css?buildId=2024041900"/></head>
|
||
|
||
<body id="hw_authentication" class="wh_topic_page frmBody">
|
||
<a href="#wh_topic_body" class="sr-only sr-only-focusable">
|
||
跳转到主要内容
|
||
</a>
|
||
|
||
|
||
|
||
|
||
<header class="navbar navbar-default wh_header">
|
||
<div class="container-fluid">
|
||
<div xmlns:whc="http://www.oxygenxml.com/webhelp/components" class="wh_header_flex_container navbar-nav navbar-expand-md navbar-dark">
|
||
<div class="wh_logo_and_publication_title_container">
|
||
<div class="wh_logo_and_publication_title">
|
||
|
||
<a href="https://www.artinchip.com" class=" wh_logo d-none d-sm-block "><img src="../../../company-logo.png" alt=" RTOS SDK 使用指南 SDK 指南文件 "/></a>
|
||
<div class=" wh_publication_title "><a href="../../../index.html"><span class="booktitle"> <span class="ph mainbooktitle">RTOS SDK 使用指南</span> <span class="ph booktitlealt">SDK 指南文件</span> </span></a></div>
|
||
|
||
</div>
|
||
|
||
|
||
</div>
|
||
|
||
<div class="wh_top_menu_and_indexterms_link collapse navbar-collapse" id="wh_top_menu_and_indexterms_link">
|
||
|
||
|
||
|
||
|
||
</div>
|
||
<div class=" wh_search_input navbar-form wh_topic_page_search search " role="form">
|
||
|
||
|
||
|
||
<form id="searchForm" method="get" role="search" action="../../../search.html"><div><input type="search" placeholder="搜索 " class="wh_search_textfield" id="textToSearch" name="searchQuery" aria-label="搜索查询" required="required"/><button type="submit" class="wh_search_button" aria-label="搜索"><span class="search_input_text">搜索</span></button></div></form>
|
||
|
||
|
||
|
||
</div></div>
|
||
</div>
|
||
</header>
|
||
|
||
|
||
|
||
|
||
|
||
|
||
<div class="container-fluid" id="wh_topic_container">
|
||
<div class="row">
|
||
|
||
<nav class="wh_tools d-print-none navbar-expand-md" aria-label="Tools">
|
||
|
||
<div data-tooltip-position="bottom" class=" wh_breadcrumb "><ol class="d-print-none"><li><span class="home"><a href="../../../index.html"><span>主页</span></a></span></li><li><div class="topicref" data-id="concept_rcx_czh_pzb"><div class="title"><a href="../../../topics/sdk/chapter-app.html">应用场景</a><div class="wh-tooltip"><p class="shortdesc">描述了 SDK 在不同应用场景中的配置和使用,包括系统更新、OTA、安全方案等。</p></div></div></div></li><li><div class="topicref" data-id="id"><div class="title"><a href="../../../topics/sdk/secure/chapter-secure.html">安全方案</a></div></div></li><li class="active"><div class="topicref" data-id="hw_authentication"><div class="title"><a href="../../../topics/sdk/secure/hw_authorization.html">硬件授权认证 </a></div></div></li></ol></div>
|
||
|
||
|
||
|
||
<div class="wh_right_tools">
|
||
<button class="wh_hide_highlight" aria-label="切换搜索突出显示" title="切换搜索突出显示"></button>
|
||
<button class="webhelp_expand_collapse_sections" data-next-state="collapsed" aria-label="折叠截面" title="折叠截面"></button>
|
||
<div class=" wh_navigation_links "><span id="topic_navigation_links" class="navheader">
|
||
|
||
<span class="navprev"><a class="- topic/link link" href="../../../topics/sdk/secure/firmware_encryption_with_spienc.html" title="固件加密-SPIENC" aria-label="上一主题: 固件加密-SPIENC" rel="prev"></a></span>
|
||
<span class="navnext"><a class="- topic/link link" href="../../../topics/sdk/secure/spi_flash_enc_function.html" title="SPI Flash 防抄板方案" aria-label="下一主题: SPI Flash 防抄板方案" rel="next"></a></span> </span></div>
|
||
|
||
|
||
|
||
<div class=" wh_print_link print d-none d-md-inline-block "><button onClick="window.print()" title="打印此页" aria-label="打印此页"></button></div>
|
||
|
||
<button type="button" id="wh_toc_button" class="custom-toggler navbar-toggler collapsed wh_toggle_button navbar-light" aria-expanded="false" aria-label="Toggle publishing table of content" aria-controls="wh_publication_toc">
|
||
<span class="navbar-toggler-icon"></span>
|
||
</button>
|
||
</div>
|
||
|
||
</nav>
|
||
</div>
|
||
|
||
|
||
|
||
|
||
<div class="wh_content_area">
|
||
<div class="row">
|
||
|
||
<nav id="wh_publication_toc" class="col-lg-3 col-md-3 col-sm-12 d-md-block d-none d-print-none" aria-label="Table of Contents Container">
|
||
<div id="wh_publication_toc_content">
|
||
|
||
<div class=" wh_publication_toc " data-tooltip-position="right"><span class="expand-button-action-labels"><span id="button-expand-action" role="button" aria-label="Expand"></span><span id="button-collapse-action" role="button" aria-label="Collapse"></span><span id="button-pending-action" role="button" aria-label="Pending"></span></span><ul role="tree" aria-label="Table of Contents"><li role="treeitem"><div data-tocid="revinfo_linux-d3752e463" class="topicref" data-id="revinfo_linux" data-state="leaf"><span role="button" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/revinfo/revinfo_rtos.html" id="revinfo_linux-d3752e463-link">修订记录</a></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="id-d3752e480" class="topicref" data-id="id" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action id-d3752e480-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/env/sdk-compile.html" id="id-d3752e480-link">SDK 编译</a><div class="wh-tooltip"><p class="shortdesc">介绍不同编译环境下 SDK 的详细编译流程。</p></div></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="id-d3752e604" class="topicref" data-id="id" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action id-d3752e604-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/advanced/sdk-usage.html" id="id-d3752e604-link">使用指南</a><div class="wh-tooltip"><p class="shortdesc">命令详解,编译选项,镜像和分区配置,添加应用和驱动等的详细使用说明。</p></div></div></div></li><li role="treeitem" aria-expanded="true"><div data-tocid="concept_rcx_czh_pzb-d3752e1004" class="topicref" data-id="concept_rcx_czh_pzb" data-state="expanded"><span role="button" tabindex="0" aria-labelledby="button-collapse-action concept_rcx_czh_pzb-d3752e1004-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/chapter-app.html" id="concept_rcx_czh_pzb-d3752e1004-link">应用场景</a><div class="wh-tooltip"><p class="shortdesc">描述了 SDK 在不同应用场景中的配置和使用,包括系统更新、OTA、安全方案等。</p></div></div></div><ul role="group" class="navbar-nav nav-list"><li role="treeitem"><div data-tocid="id-d3752e1021" class="topicref" data-id="id" data-state="leaf"><span role="button" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/usb/udisk.html" id="id-d3752e1021-link">挂载 U 盘 </a></div></div></li><li role="treeitem"><div data-tocid="id-d3752e1035" class="topicref" data-id="id" data-state="leaf"><span role="button" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/sdmc/sdcard.html" id="id-d3752e1035-link">挂载 SD 卡</a></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="id-d3752e1049" class="topicref" data-id="id" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action id-d3752e1049-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/burnsys/burnsys_user_guide.html" id="id-d3752e1049-link">系统更新</a></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="id-d3752e1163" class="topicref" data-id="id" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action id-d3752e1163-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/ota/ota_guide.html" id="id-d3752e1163-link">OTA 方案</a></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="id-d3752e1283" class="topicref" data-id="id" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action id-d3752e1283-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/xip/xip_user_guide.html" id="id-d3752e1283-link">XIP 方案 </a></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="id-d3752e1372" class="topicref" data-id="id" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action id-d3752e1372-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/app/dm.html" id="id-d3752e1372-link">动态加载 (DM-APP)</a></div></div></li><li role="treeitem" aria-expanded="true"><div data-tocid="id-d3752e1442" class="topicref" data-id="id" data-state="expanded"><span role="button" tabindex="0" aria-labelledby="button-collapse-action id-d3752e1442-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/secure/chapter-secure.html" id="id-d3752e1442-link">安全方案</a></div></div><ul role="group" class="navbar-nav nav-list"><li role="treeitem"><div data-tocid="id-d3752e1456" class="topicref" data-id="id" data-state="leaf"><span role="button" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/secure/firmware_encryption_with_spienc.html" id="id-d3752e1456-link">固件加密-SPIENC</a></div></div></li><li role="treeitem" class="active"><div data-tocid="hw_authentication-d3752e1470" class="topicref" data-id="hw_authentication" data-state="leaf"><span role="button" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/secure/hw_authorization.html" id="hw_authentication-d3752e1470-link">硬件授权认证 </a></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="spi-flash-enc-function-d3752e1484" class="topicref" data-id="spi-flash-enc-function" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action spi-flash-enc-function-d3752e1484-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/secure/spi_flash_enc_function.html" id="spi-flash-enc-function-d3752e1484-link">SPI Flash 防抄板方案</a></div></div></li></ul></li><li role="treeitem"><div data-tocid="mkfs_partition_image-d3752e1636" class="topicref" data-id="mkfs_partition_image" data-state="leaf"><span role="button" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/app/mkfs_partition_image.html" id="mkfs_partition_image-d3752e1636-link">制作分区镜像</a></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="id-d3752e1650" class="topicref" data-id="id" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action id-d3752e1650-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/burnsys/burner_offline_lite.html" id="id-d3752e1650-link">离线烧录</a></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="usb_display-d3752e1706" class="topicref" data-id="usb_display" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action usb_display-d3752e1706-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/app/usb-display.html" id="usb_display-d3752e1706-link">USB Display 方案</a></div></div></li><li role="treeitem"><div data-tocid="backtrace-d3752e1833" class="topicref" data-id="backtrace" data-state="leaf"><span role="button" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/app/backtrace.html" id="backtrace-d3752e1833-link">Backtrace 栈回溯</a></div></div></li></ul></li><li role="treeitem" aria-expanded="false"><div data-tocid="id-d3752e1848" class="topicref" data-id="id" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action id-d3752e1848-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/peripheral/peripheral-intro.html" id="id-d3752e1848-link">外设移植</a><div class="wh-tooltip"><p class="shortdesc"><span class="ph">CTP、U 盘、SD 卡、有线和无线网络</span>等外设的介绍和使用说明。</p></div></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="id-d3752e2022" class="topicref" data-id="id" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action id-d3752e2022-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/bringup/chapter-bringup.html" id="id-d3752e2022-link">BringUp</a><div class="wh-tooltip"><p class="shortdesc">主要描述板卡的各项配置,使 SDK 的环境和板卡匹配,并确保 SDK 编译后的固件能够在板子上正常运行。</p></div></div></div></li><li role="treeitem" aria-expanded="false"><div data-tocid="id-d3752e2418" class="topicref" data-id="id" data-state="not-ready"><span role="button" tabindex="0" aria-labelledby="button-expand-action id-d3752e2418-link" class="wh-expand-btn"></span><div class="title"><a href="../../../topics/sdk/chapter-advanced-app.html" id="id-d3752e2418-link">高级应用</a><div class="wh-tooltip"><p class="shortdesc">系统、存储、多媒体、接口、安全等模块的详细配置和设计说明。</p></div></div></div></li></ul></div>
|
||
|
||
</div>
|
||
</nav>
|
||
|
||
|
||
<div class="col-lg-7 col-md-9 col-sm-12" id="wh_topic_body">
|
||
<button id="wh_close_publication_toc_button" class="close-toc-button d-none" aria-label="Toggle publishing table of content" aria-controls="wh_publication_toc" aria-expanded="true">
|
||
<span class="close-toc-icon-container">
|
||
<span class="close-toc-icon"></span>
|
||
</span>
|
||
</button>
|
||
<button id="wh_close_topic_toc_button" class="close-toc-button d-none" aria-label="Toggle topic table of content" aria-controls="wh_topic_toc" aria-expanded="true">
|
||
<span class="close-toc-icon-container">
|
||
<span class="close-toc-icon"></span>
|
||
</span>
|
||
</button>
|
||
|
||
<div class=" wh_topic_content body "><main role="main"><article class="- topic/topic topic" role="article" aria-labelledby="ariaid-title1">
|
||
<span class="edit-link" style="font-size:12px; opacity:0.6; text-align:right; vertical-align:middle"><a target="_blank" href="http://aicdocco/taskstopics/sdk/secure/hw_authorization.dita">Edit online</a></span><h1 class="- topic/title title topictitle1" id="ariaid-title1">硬件授权认证 </h1>
|
||
<div class="date inPage">16 May 2025</div><div style="color: gray;">
|
||
Read time: 9 minute(s)
|
||
</div>
|
||
<div class="- topic/body body">
|
||
<p class="- topic/p p" data-ofbid="d54351e28__20250519091507">硬件授权认证是一种基于身份认证原理以及硬件安全密钥实现的安全功能,可以让软件或者第三方合作伙伴对芯片的合法性进行认证。 </p>
|
||
<div class="- topic/p p" data-ofbid="d54351e31__20250519091507">根据使用的硬件密钥,需要烧录对应的 eFuse,可设置的 eFuse 信息如下所示:<div class="table-container"><table class="- topic/table table frame-all" id="hw_authentication__table_upq_qk4_fdc" data-ofbid="hw_authentication__table_upq_qk4_fdc" data-cols="8"><caption class="- topic/title title tablecap" data-caption-side="top" data-is-repeated="true"><span class="table--title-label">表<span class="table--title-label-number"> 1</span><span class="table--title-label-punctuation">. </span></span><span class="table--title">eFuse 信息</span></caption><colgroup><col style="width:10.1401483924155%"/><col style="width:10.1401483924155%"/><col style="width:10.1401483924155%"/><col style="width:10.1401483924155%"/><col style="width:8.408903544929927%"/><col style="width:8.244023083264635%"/><col style="width:9.480626545754328%"/><col style="width:33.30585325638912%"/></colgroup><thead class="- topic/thead thead">
|
||
<tr class="- topic/row">
|
||
<th class="- topic/entry entry colsep-1 rowsep-1" id="hw_authentication__table_upq_qk4_fdc__entry__1"><p class="- topic/p p" data-ofbid="d54351e62__20250519091507">用途</p></th>
|
||
<th class="- topic/entry entry colsep-1 rowsep-1" id="hw_authentication__table_upq_qk4_fdc__entry__2"><p class="- topic/p p" data-ofbid="d54351e66__20250519091507">位数</p></th>
|
||
<th class="- topic/entry entry colsep-1 rowsep-1" id="hw_authentication__table_upq_qk4_fdc__entry__3"><p class="- topic/p p" data-ofbid="d54351e70__20250519091507">地址</p></th>
|
||
<th class="- topic/entry entry colsep-1 rowsep-1" id="hw_authentication__table_upq_qk4_fdc__entry__4"><p class="- topic/p p" data-ofbid="d54351e74__20250519091507">禁止位</p></th>
|
||
<th class="- topic/entry entry colsep-1 rowsep-1" id="hw_authentication__table_upq_qk4_fdc__entry__5"><p class="- topic/p p" data-ofbid="d54351e78__20250519091507">禁写</p></th>
|
||
<th class="- topic/entry entry colsep-1 rowsep-1" id="hw_authentication__table_upq_qk4_fdc__entry__6"><p class="- topic/p p" data-ofbid="d54351e83__20250519091507">禁读</p></th>
|
||
<th class="- topic/entry entry colsep-1 rowsep-1" id="hw_authentication__table_upq_qk4_fdc__entry__7"><p class="- topic/p p" data-ofbid="d54351e87__20250519091507">归属</p></th>
|
||
<th class="- topic/entry entry colsep-0 rowsep-1" id="hw_authentication__table_upq_qk4_fdc__entry__8"><p class="- topic/p p" data-ofbid="d54351e91__20250519091507">备注</p></th>
|
||
</tr>
|
||
</thead><tbody class="- topic/tbody tbody">
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__1"><p class="- topic/p p" data-ofbid="d54351e101__20250519091507">DIS RD</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__2"><p class="- topic/p p" data-ofbid="d54351e105__20250519091507">64</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__3"><p class="- topic/p p" data-ofbid="d54351e109__20250519091507">0~7</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__4"><p class="- topic/p p" data-ofbid="d54351e113__20250519091507">0~1</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__5"><p class="- topic/p p" data-ofbid="d54351e117__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__6"><p class="- topic/p p" data-ofbid="d54351e122__20250519091507">-</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__7"><p class="- topic/p p" data-ofbid="d54351e126__20250519091507">CSTM</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__8"><p class="- topic/p p" data-ofbid="d54351e130__20250519091507">eFuse 读禁止配置区域</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__1"><p class="- topic/p p" data-ofbid="d54351e137__20250519091507">DIS WR</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__2"><p class="- topic/p p" data-ofbid="d54351e141__20250519091507">64</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__3"><p class="- topic/p p" data-ofbid="d54351e145__20250519091507">8~F</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__4"><p class="- topic/p p" data-ofbid="d54351e149__20250519091507">2~3</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__5"><p class="- topic/p p" data-ofbid="d54351e153__20250519091507">-</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__6"><p class="- topic/p p" data-ofbid="d54351e158__20250519091507">-</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__7"><p class="- topic/p p" data-ofbid="d54351e162__20250519091507">-</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__8"><p class="- topic/p p" data-ofbid="d54351e166__20250519091507">eFuse 写禁止配置区域</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__1"><p class="- topic/p p" data-ofbid="d54351e173__20250519091507">PSK0</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__2"><p class="- topic/p p" data-ofbid="d54351e177__20250519091507">64</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__3"><p class="- topic/p p" data-ofbid="d54351e181__20250519091507">70~77</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__4"><p class="- topic/p p" data-ofbid="d54351e185__20250519091507">28~29</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__5"><p class="- topic/p p" data-ofbid="d54351e189__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__6"><p class="- topic/p p" data-ofbid="d54351e194__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__7"><p class="- topic/p p" data-ofbid="d54351e198__20250519091507">CSTM</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__8"><p class="- topic/p p" data-ofbid="d54351e202__20250519091507">安全,连接到 CE,合作伙伴密钥</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__1"><p class="- topic/p p" data-ofbid="d54351e209__20250519091507">PSK1</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__2"><p class="- topic/p p" data-ofbid="d54351e213__20250519091507">64</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__3"><p class="- topic/p p" data-ofbid="d54351e217__20250519091507">78~7F</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__4"><p class="- topic/p p" data-ofbid="d54351e221__20250519091507">30~31</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__5"><p class="- topic/p p" data-ofbid="d54351e225__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__6"><p class="- topic/p p" data-ofbid="d54351e230__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__7"><p class="- topic/p p" data-ofbid="d54351e234__20250519091507">CSTM</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__8"><p class="- topic/p p" data-ofbid="d54351e238__20250519091507">安全,连接到 CE,合作伙伴密钥</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__1"><p class="- topic/p p" data-ofbid="d54351e245__20250519091507">PSK2</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__2"><p class="- topic/p p" data-ofbid="d54351e249__20250519091507">64</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__3"><p class="- topic/p p" data-ofbid="d54351e253__20250519091507">80~87</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__4"><p class="- topic/p p" data-ofbid="d54351e257__20250519091507">32~33</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__5"><p class="- topic/p p" data-ofbid="d54351e261__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__6"><p class="- topic/p p" data-ofbid="d54351e266__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__7"><p class="- topic/p p" data-ofbid="d54351e270__20250519091507">CSTM</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__8"><p class="- topic/p p" data-ofbid="d54351e274__20250519091507">安全,连接到 CE,合作伙伴密钥</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__1"><p class="- topic/p p" data-ofbid="d54351e282__20250519091507">PSK3</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__2"><p class="- topic/p p" data-ofbid="d54351e286__20250519091507">64</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__3"><p class="- topic/p p" data-ofbid="d54351e290__20250519091507">88~8F</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__4"><p class="- topic/p p" data-ofbid="d54351e294__20250519091507">34~35</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__5"><p class="- topic/p p" data-ofbid="d54351e298__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__6"><p class="- topic/p p" data-ofbid="d54351e303__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__7"><p class="- topic/p p" data-ofbid="d54351e307__20250519091507">CSTM</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1" headers="hw_authentication__table_upq_qk4_fdc__entry__8"><p class="- topic/p p" data-ofbid="d54351e311__20250519091507">安全,连接到 CE,合作伙伴密钥</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-0" headers="hw_authentication__table_upq_qk4_fdc__entry__1"><p class="- topic/p p" data-ofbid="d54351e318__20250519091507">PNK</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-0" headers="hw_authentication__table_upq_qk4_fdc__entry__2"><p class="- topic/p p" data-ofbid="d54351e322__20250519091507">64</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-0" headers="hw_authentication__table_upq_qk4_fdc__entry__3"><p class="- topic/p p" data-ofbid="d54351e326__20250519091507">B8~BF</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-0" headers="hw_authentication__table_upq_qk4_fdc__entry__4"><p class="- topic/p p" data-ofbid="d54351e330__20250519091507">46~47</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-0" headers="hw_authentication__table_upq_qk4_fdc__entry__5"><p class="- topic/p p" data-ofbid="d54351e334__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-0" headers="hw_authentication__table_upq_qk4_fdc__entry__6"><p class="- topic/p p" data-ofbid="d54351e339__20250519091507">V</p></td>
|
||
<td class="- topic/entry entry colsep-1 rowsep-0" headers="hw_authentication__table_upq_qk4_fdc__entry__7"><p class="- topic/p p" data-ofbid="d54351e343__20250519091507">AIC</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-0" headers="hw_authentication__table_upq_qk4_fdc__entry__8"><p class="- topic/p p" data-ofbid="d54351e347__20250519091507">安全,连接到 CE,型号唯一密钥</p></td>
|
||
</tr>
|
||
</tbody></table></div></div>
|
||
<section class="- topic/section section" id="hw_authentication__section_i1s_j1q_wcc" data-ofbid="hw_authentication__section_i1s_j1q_wcc"><h2 class="- topic/title title sectiontitle">身份认证原理</h2>
|
||
|
||
<div class="- topic/p p" data-ofbid="d54351e359__20250519091507">下图展示了 RSA 的认证流程: <ul class="- topic/ul ul" id="hw_authentication__ul_dfn_xk4_fdc" data-ofbid="hw_authentication__ul_dfn_xk4_fdc">
|
||
<li class="- topic/li li" data-ofbid="d54351e363__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e365__20250519091507">芯片拥有一个 RSA 私钥:RSA-PRIV</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e369__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e371__20250519091507">软件拥有对应的 RSA 公钥:RSA-PUB</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e375__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e377__20250519091507">软件指定一笔数据:Nonce</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e381__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e383__20250519091507">芯片通过私钥:RSA-PRIV 对 Nonce 进行加密,并返回加密结果给软件</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e387__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e389__20250519091507">软件通过公钥:RSA-PUB 对 加密的 Nonce 进行解密,解密结果和 Nonce 匹配则认证成功</p>
|
||
</li>
|
||
</ul></div>
|
||
<br/><div class="imagecenter"><img class="- topic/image image imagecenter" id="hw_authentication__image_fsb_drt_vcc" src="../../../images/secure/identification.png" alt="identification"/></div><br/>
|
||
<div class="- topic/div div"><strong class="+ topic/ph hi-d/b ph b">RSA 私钥存储</strong><div class="- topic/p p" data-ofbid="d54351e403__20250519091507">RSA 私钥:RSA-PRIV 较大,通常不直接保存在 芯片的 eFuse 中,而是通过额外的 PSK(Protection
|
||
Secure Key)进行加密后保存。 eFuse 中仅保存 PSK ,而 RSA 私钥则通过 PSK 加密后直接发布。具体步骤为:<ul class="- topic/ul ul" id="hw_authentication__ul_xfg_fl4_fdc" data-ofbid="hw_authentication__ul_xfg_fl4_fdc">
|
||
<li class="- topic/li li" data-ofbid="d54351e407__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e409__20250519091507">通过 AES/DES 加密的方式,将 RSA 私钥加密。</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e413__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e415__20250519091507">使用时,通过 PSK 将 RSA 私钥解密到安全 SRAM,软件不可读写</p>
|
||
</li>
|
||
</ul></div></div>
|
||
|
||
</section>
|
||
<section class="- topic/section section" id="hw_authentication__id4" data-ofbid="hw_authentication__id4"><h2 class="- topic/title title sectiontitle">软件授权认证</h2>
|
||
|
||
<p class="- topic/p p" data-ofbid="d54351e426__20250519091507">芯片身份认证可在软件授权认证中应用,特别是在需要确保软件仅能运行在特定芯片或硬件平台上时。通过芯片身份认证,软件厂商可以确保其软件和算法只在合法、授权的硬件上运行,从而保护知识产权并防止未经授权的使用。</p>
|
||
<p class="- topic/p p" data-ofbid="d54351e429__20250519091507">在实际应用中,设备可能会集成了不同厂商的软件和算法。软件厂商会有相关知识产权保护、软件授权上的需求,确保能够限定自身的软件只能运行在指定芯片型号上。</p>
|
||
<p class="- topic/p p" data-ofbid="d54351e432__20250519091507">通过 PSK (Partner Secret Key) 机制,可以实现芯片身份认证在软件授权认证中的应用,具体步骤如下:</p>
|
||
<div class="- topic/p p" data-ofbid="d54351e435__20250519091507">
|
||
<ol class="- topic/ol ol arabic simple" id="hw_authentication__ol_osb_drt_vcd" data-ofbid="hw_authentication__ol_osb_drt_vcd">
|
||
<li class="- topic/li li" data-ofbid="d54351e439__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e441__20250519091507">设备厂商将一个 eFuse PSK 区域分配给合作伙伴。</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e445__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e447__20250519091507">软件厂商将自己的密钥烧录到 PSK 区域,并且设置为软件不可读写。</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e451__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e453__20250519091507">软件厂商生成 RSA 密钥对,并且使用 PSK 将 RSA 私钥 (RSA-PRIV) 加密,生成加密的 RSA 私钥
|
||
(RSA-PRIV-e)。</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e457__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e459__20250519091507">将加密后的 RSA 私钥 (RSA-PRIV-e) 以及对应的 RSA 公钥集成到软件中。</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e463__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e465__20250519091507">需要进行授权检查时,软件设置 CE 使用 PSK,将加密的 RSA 私钥解密到安全 SRAM。</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e470__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e472__20250519091507">认证软件使用安全 SRAM 中的 RSA 私钥对一段随机数 (Nonce) 进行加密,生成加密数据 (EncNonce) 返回给认证软件。</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e476__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e478__20250519091507">认证软件使用对应的 RSA 公钥 (RSA-PUB) 对 EncNonce 进行解密,还原出原始的 Nonce 数据。比较解密后的 Nonce
|
||
与原始 Nonce 是否一致,以验证软件的合法性。</p>
|
||
<p class="- topic/p p" data-ofbid="d54351e481__20250519091507">如果结果正确,说明该芯片是合法授权的芯片。</p>
|
||
</li>
|
||
</ol>
|
||
</div>
|
||
<figure class="- topic/fig fig fignone" data-ofbid="d54351e488__20250519091507">
|
||
<br/><div class="imagecenter"><img class="- topic/image image imagecenter" id="hw_authentication__image_psb_drt_vcc" src="../../../images/secure/sw_certification.png" width="480" alt="sw_certification"/></div><br/>
|
||
</figure>
|
||
<div class="- topic/note note note note_note" id="hw_authentication__note_vp5_qn3_ddc" data-ofbid="hw_authentication__note_vp5_qn3_ddc"><span class="note__title">注:</span>
|
||
<ul class="- topic/ul ul" id="hw_authentication__ul_xcr_ygl_jdc" data-ofbid="hw_authentication__ul_xcr_ygl_jdc">
|
||
<li class="- topic/li li" data-ofbid="d54351e501__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e503__20250519091507">D13x 共有四组 PSK 开放给终端厂商使用。</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e507__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e509__20250519091507">D211 共有五组保护密钥,一组是 PNK,出厂烧录。另外四组是 PSK,由终端厂商自行烧录。</p>
|
||
</li>
|
||
</ul>
|
||
</div>
|
||
</section>
|
||
<section class="- topic/section section" id="hw_authentication__id8" data-ofbid="hw_authentication__id8"><h2 class="- topic/title title sectiontitle">烧写保护密钥</h2>
|
||
|
||
<div class="- topic/p p" data-ofbid="d54351e521__20250519091507">用户可以根据实际情况烧录对应的密钥,以 PSK0 为例。<ol class="- topic/ol ol" id="hw_authentication__ol_dsx_5l4_fdc" data-ofbid="hw_authentication__ol_dsx_5l4_fdc">
|
||
<li class="- topic/li li" data-ofbid="d54351e525__20250519091507">
|
||
<div class="- topic/p p" data-ofbid="d54351e527__20250519091507">在开发板平台命令行执行下列命令,烧录 PSK0 到 eFuse
|
||
中。<pre class="+ topic/pre pr-d/codeblock pre codeblock language-c" id="hw_authentication__codeblock_edb_x11_wcc" data-ofbid="hw_authentication__codeblock_edb_x11_wcc">efuse writestr <span class="hl-number">0x70</span> PASSWORD</pre></div>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e533__20250519091507">
|
||
<div class="- topic/p p" data-ofbid="d54351e535__20250519091507">禁止 PSK0
|
||
读写。<pre class="+ topic/pre pr-d/codeblock pre codeblock language-c" id="hw_authentication__codeblock_iwj_dn4_fdc" data-ofbid="hw_authentication__codeblock_iwj_dn4_fdc">efuse writehex <span class="hl-number">0x00</span> <span class="hl-number">00000030</span>
|
||
efuse writehex <span class="hl-number">0x08</span> <span class="hl-number">00000030</span>
|
||
</pre></div>
|
||
</li>
|
||
</ol><div class="- topic/note note note note_note" id="hw_authentication__note_ll2_1n4_fdc" data-ofbid="hw_authentication__note_ll2_1n4_fdc"><span class="note__title">注:</span>
|
||
<ul class="- topic/ul ul" id="hw_authentication__ul_t1f_1n4_fdc" data-ofbid="hw_authentication__ul_t1f_1n4_fdc">
|
||
<li class="- topic/li li" data-ofbid="d54351e545__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e547__20250519091507">PSK 存储用于解密 RSA 私钥的密码。</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e551__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e553__20250519091507">PSK 烧录到 eFuse 后就不可以被看到,因此必须妥善保管。</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e557__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e559__20250519091507">PSK 只能烧录一次,不可更改。</p>
|
||
</li>
|
||
</ul>
|
||
</div></div>
|
||
</section>
|
||
<section class="- topic/section section" id="hw_authentication__rsa" data-ofbid="hw_authentication__rsa"><h2 class="- topic/title title sectiontitle">生成 RSA 密钥</h2>
|
||
|
||
<p class="- topic/p p" data-ofbid="d54351e572__20250519091507">RSA 算法需要有密钥对(私钥和公钥),详细的密钥生成流程如下:</p>
|
||
<ol class="- topic/ol ol" id="hw_authentication__ol_bjv_gn4_fdc" data-ofbid="hw_authentication__ol_bjv_gn4_fdc">
|
||
<li class="- topic/li li" data-ofbid="d54351e577__20250519091507">在主机端执行以下命令生成 RSA
|
||
私钥和公钥:<pre class="+ topic/pre pr-d/codeblock pre codeblock language-c" id="hw_authentication__codeblock_wlb_tb1_wcc" data-ofbid="hw_authentication__codeblock_wlb_tb1_wcc">openssl genrsa -out rsa_private_key.pem <span class="hl-number">2048</span></pre><p class="- topic/p p" data-ofbid="d54351e581__20250519091507">结果:生成一对公钥和私钥,保存在
|
||
<span class="+ topic/ph sw-d/filepath ph filepath">rsa_private_key.pem</span> 文件中。 </p></li>
|
||
<li class="- topic/li li" data-ofbid="d54351e587__20250519091507">执行下列命令从密钥对中提取公钥:<pre class="+ topic/pre pr-d/codeblock pre codeblock language-c" id="hw_authentication__codeblock_kvs_pn4_fdc" data-ofbid="hw_authentication__codeblock_kvs_pn4_fdc">openssl rsa -in rsa_private_key.pem -pubout -out rsa_public_key.pem</pre><p class="- topic/p p" data-ofbid="d54351e591__20250519091507">在实际使用时,通常私钥保密存储,公钥需要发送给其它相关方,因此需要提取公钥。</p></li>
|
||
<li class="- topic/li li" data-ofbid="d54351e594__20250519091507">执行以下命令将生成的公钥和私钥转换为 DER
|
||
二进制。<pre class="+ topic/pre pr-d/codeblock pre codeblock language-c" id="hw_authentication__codeblock_llq_mn4_fdc" data-ofbid="hw_authentication__codeblock_llq_mn4_fdc">openssl base64 -d -in rsa_public_key.pem -out rsa_public_key.der
|
||
openssl base64 -d -in rsa_private_key.pem -out rsa_private_key.der
|
||
</pre><p class="- topic/p p" data-ofbid="d54351e598__20250519091507">DER 是 ASN.1 密钥结构描述的二进制编码实现。</p></li>
|
||
<li class="- topic/li li" data-ofbid="d54351e601__20250519091507">使用 PSK0
|
||
加密私钥。<pre class="+ topic/pre pr-d/codeblock pre codeblock language-c" id="hw_authentication__codeblock_pyj_sn4_fdc" data-ofbid="hw_authentication__codeblock_pyj_sn4_fdc">./tools/scripts/encrypt_rsa_key.py -h -d psk0.bin -r rsa_private_key.der
|
||
</pre><p class="- topic/p p" data-ofbid="d54351e605__20250519091507">通过上述命令,得到加密过的私钥文件
|
||
<span class="+ topic/ph sw-d/filepath ph filepath">rsa_private_key_encrypted.der</span>。</p></li>
|
||
<li class="- topic/li li" data-ofbid="d54351e611__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e613__20250519091507">使用 <span class="+ topic/keyword sw-d/cmdname keyword cmdname">xxd -i rsa_private_key_encrypted.der</span> 和 <span class="+ topic/keyword sw-d/cmdname keyword cmdname">xxd -i
|
||
rsa_public_key.der</span> 命令,将加密私钥和公钥转成 C 语言数组格式,方便在代码中直接使用。</p>
|
||
<p class="- topic/p p" data-ofbid="d54351e622__20250519091507"><code class="+ topic/ph pr-d/codeph ph codeph">xxd</code> 是 Linux 的一个 16 进制处理命令。</p>
|
||
</li>
|
||
</ol>
|
||
<p class="- topic/p p" data-ofbid="d54351e629__20250519091507">完成上述所有操作后,编译镜像并直接使用 AiBurn 工具进行烧录,重启后在开发板平台执行
|
||
<code class="+ topic/ph pr-d/codeph ph codeph">aic_hw_authorization_test</code> 即可进行测试,当显示 <samp class="+ topic/ph sw-d/systemoutput ph systemoutput sysout">App xxx
|
||
running.</samp> 则表示授权认证成功,否则授权认证失败。</p>
|
||
</section>
|
||
<section class="- topic/section section" id="hw_authentication__section_dd5_144_fdc" data-ofbid="hw_authentication__section_dd5_144_fdc"><h2 class="- topic/title title sectiontitle">源码说明</h2>
|
||
|
||
<div class="table-container"><table class="- topic/table table colwidths-given docutils align-default frame-all" id="hw_authentication__table_wyg_c44_fdc" data-ofbid="hw_authentication__table_wyg_c44_fdc" data-cols="2"><caption></caption><colgroup><col style="width:54.54545454545454%"/><col style="width:45.45454545454545%"/></colgroup><thead class="- topic/thead thead">
|
||
<tr class="- topic/row">
|
||
<th class="- topic/entry entry colsep-1 rowsep-1" id="hw_authentication__table_wyg_c44_fdc__entry__1"><p class="- topic/p p" data-ofbid="d54351e657__20250519091507">相关模块</p></th>
|
||
<th class="- topic/entry entry colsep-0 rowsep-1" id="hw_authentication__table_wyg_c44_fdc__entry__2"><p class="- topic/p p" data-ofbid="d54351e661__20250519091507">源码路径</p></th>
|
||
</tr>
|
||
</thead><tbody class="- topic/tbody tbody">
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-0" headers="hw_authentication__table_wyg_c44_fdc__entry__1"><p class="- topic/p p" data-ofbid="d54351e671__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">Hardware authorization</div>
|
||
</div>
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-0" headers="hw_authentication__table_wyg_c44_fdc__entry__2"><p class="- topic/p p" data-ofbid="d54351e681__20250519091507"><span class="+ topic/ph sw-d/filepath ph filepath">packages/artinchip/aic-authorization/</span></p></td>
|
||
</tr>
|
||
</tbody></table></div>
|
||
</section>
|
||
<section class="- topic/section section" id="hw_authentication__id11" data-ofbid="hw_authentication__id11"><h2 class="- topic/title title sectiontitle">接口设计</h2>
|
||
|
||
<div class="table-container"><table class="- topic/table table colwidths-given docutils align-default frame-all" data-ofbid="d54351e695__20250519091507" data-cols="2"><caption class="- topic/title title tablecap" data-caption-side="top" data-is-repeated="true"><span class="table--title-label">表<span class="table--title-label-number"> 2</span><span class="table--title-label-punctuation">. </span></span><span class="table--title">aic_rsa_priv_enc</span></caption><colgroup><col style="width:16.666666666666664%"/><col style="width:83.33333333333334%"/></colgroup><tbody class="- topic/tbody tbody">
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e711__20250519091507">函数原型 </p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e715__20250519091507">int aic_rsa_priv_enc(int flen, unsigned char *from, unsigned
|
||
char *to, struct ak_options *opts)</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e722__20250519091507">功能说明 </p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e726__20250519091507">使用私钥进行加密。</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e733__20250519091507">参数定义 </p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e737__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">int flen</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入数据长度</div>
|
||
</div>
|
||
<div class="- topic/div div">from</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入需要被加密的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">to</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输出加密后的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">opts</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">一些其它参数</div>
|
||
</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e784__20250519091507">返回值 </p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e788__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">成功返回加密后数据长度,失败返回-1</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e801__20250519091507">注意事项 </p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e805__20250519091507">-</p></td>
|
||
</tr>
|
||
</tbody></table></div>
|
||
<div class="table-container"><table class="- topic/table table colwidths-given docutils align-default frame-all" id="hw_authentication__table_shx_h44_fdc" data-ofbid="hw_authentication__table_shx_h44_fdc" data-cols="2"><caption class="- topic/title title tablecap" data-caption-side="top" data-is-repeated="true"><span class="table--title-label">表<span class="table--title-label-number"> 3</span><span class="table--title-label-punctuation">. </span></span><span class="table--title">aic_rsa_pub_dec</span></caption><colgroup><col style="width:16.666666666666664%"/><col style="width:83.33333333333334%"/></colgroup><tbody class="- topic/tbody tbody">
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e828__20250519091507">函数原型
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e832__20250519091507">int aic_rsa_pub_dec(int flen, unsigned char *from, unsigned
|
||
char *to, struct ak_options *opts)</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e839__20250519091507">功能说明
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e843__20250519091507">使用公钥进行解密。</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e850__20250519091507">参数定义
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e854__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">int flen</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入数据长度</div>
|
||
</div>
|
||
<div class="- topic/div div">from</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入需要被解密的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">to</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输出解密后的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">opts</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">一些其它参数</div>
|
||
</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e901__20250519091507">返回值
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e905__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">成功返回解密后数据长度,失败返回-1</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e918__20250519091507">注意事项
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e922__20250519091507">-</p></td>
|
||
</tr>
|
||
</tbody></table></div>
|
||
<div class="table-container"><table class="- topic/table table colwidths-given docutils align-default frame-all" id="hw_authentication__table_ims_h44_fdc" data-ofbid="hw_authentication__table_ims_h44_fdc" data-cols="2"><caption class="- topic/title title tablecap" data-caption-side="top" data-is-repeated="true"><span class="table--title-label">表<span class="table--title-label-number"> 4</span><span class="table--title-label-punctuation">. </span></span><span class="table--title">aic_rsa_pub_enc</span></caption><colgroup><col style="width:16.666666666666664%"/><col style="width:83.33333333333334%"/></colgroup><tbody class="- topic/tbody tbody">
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e945__20250519091507">函数原型
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e949__20250519091507">int aic_rsa_pub_enc(int flen, unsigned char *from, unsigned
|
||
char *to, struct ak_options *opts)</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e956__20250519091507">功能说明
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e960__20250519091507">使用公钥进行加密。</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e967__20250519091507">参数定义
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e971__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">int flen</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入数据长度</div>
|
||
</div>
|
||
<div class="- topic/div div">from</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入需要被加密的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">to</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输出加密后的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">opts</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">一些其它参数</div>
|
||
</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1018__20250519091507">返回值
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1022__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">成功返回加密后数据长度,失败返回-1</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e1035__20250519091507">注意事项
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e1039__20250519091507">-</p></td>
|
||
</tr>
|
||
</tbody></table></div>
|
||
<div class="table-container"><table class="- topic/table table colwidths-given docutils align-default frame-all" id="hw_authentication__table_mcn_h44_fdc" data-ofbid="hw_authentication__table_mcn_h44_fdc" data-cols="2"><caption class="- topic/title title tablecap" data-caption-side="top" data-is-repeated="true"><span class="table--title-label">表<span class="table--title-label-number"> 5</span><span class="table--title-label-punctuation">. </span></span><span class="table--title">aic_rsa_priv_dec</span></caption><colgroup><col style="width:16.666666666666664%"/><col style="width:83.33333333333334%"/></colgroup><tbody class="- topic/tbody tbody">
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1062__20250519091507">函数原型
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1066__20250519091507">int aic_rsa_priv_dec(int flen, unsigned char *from, unsigned
|
||
char *to, struct ak_options *opts)</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1073__20250519091507">功能说明
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1077__20250519091507">使用私钥进行解密。</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1084__20250519091507">参数定义
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1088__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">int flen</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入数据长度</div>
|
||
</div>
|
||
<div class="- topic/div div">from</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入需要被解密的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">to</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输出解密后的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">opts</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">一些其它参数</div>
|
||
</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1135__20250519091507">返回值
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1139__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">成功返回解密后数据长度,失败返回-1</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e1152__20250519091507">注意事项
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e1156__20250519091507">-</p></td>
|
||
</tr>
|
||
</tbody></table></div>
|
||
<div class="table-container"><table class="- topic/table table colwidths-given docutils align-default frame-all" id="hw_authentication__table_y5f_h44_fdc" data-ofbid="hw_authentication__table_y5f_h44_fdc" data-cols="2"><caption class="- topic/title title tablecap" data-caption-side="top" data-is-repeated="true"><span class="table--title-label">表<span class="table--title-label-number"> 6</span><span class="table--title-label-punctuation">. </span></span><span class="table--title">aic_hwp_rsa_priv_enc</span></caption><colgroup><col style="width:16.666666666666664%"/><col style="width:83.33333333333334%"/></colgroup><tbody class="- topic/tbody tbody">
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1180__20250519091507">函数原型
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1184__20250519091507">int aic_hwp_rsa_priv_enc(int flen, unsigned char *from,
|
||
unsigned char *to, struct ak_options *opts, char *algo)</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1191__20250519091507">功能说明
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1195__20250519091507">使用经过 <code class="+ topic/ph pr-d/codeph ph codeph">保护密钥加密过的私钥</code> 进行加密。</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1205__20250519091507">参数定义
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1209__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">flen</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入数据长度</div>
|
||
</div>
|
||
<div class="- topic/div div">from</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入需要被加密的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">to</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输出加密后的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">opts</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">一些其它参数</div>
|
||
</div>
|
||
<div class="- topic/div div">algo</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">指定选用烧录在 eFuse 中的保护密钥</div>
|
||
<div class="- topic/div div">PNK_PROTECTED_RSA</div>
|
||
<div class="- topic/div div">PSK0_PROTECTED_RSA</div>
|
||
<div class="- topic/div div">PSK1_PROTECTED_RSA</div>
|
||
<div class="- topic/div div">PSK2_PROTECTED_RSA</div>
|
||
<div class="- topic/div div">PSK3_PROTECTED_RSA</div>
|
||
</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1281__20250519091507">返回值
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1285__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">成功返回加密后数据长度,失败返回-1</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e1298__20250519091507">注意事项
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e1302__20250519091507">-</p></td>
|
||
</tr>
|
||
</tbody></table></div>
|
||
<div class="table-container"><table class="- topic/table table colwidths-given docutils align-default frame-all" id="hw_authentication__table_xtx_g44_fdc" data-ofbid="hw_authentication__table_xtx_g44_fdc" data-cols="2"><caption class="- topic/title title tablecap" data-caption-side="top" data-is-repeated="true"><span class="table--title-label">表<span class="table--title-label-number"> 7</span><span class="table--title-label-punctuation">. </span></span><span class="table--title">aic_hwp_rsa_priv_dec</span></caption><colgroup><col style="width:16.666666666666664%"/><col style="width:83.33333333333334%"/></colgroup><tbody class="- topic/tbody tbody">
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1325__20250519091507">函数原型
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1329__20250519091507">int aic_hwp_rsa_priv_dec(int flen, unsigned char *from,
|
||
unsigned char *to, struct ak_options *opts, char *algo)</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1336__20250519091507">功能说明
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1340__20250519091507">使用经过 <code class="+ topic/ph pr-d/codeph ph codeph">保护密钥加密过的私钥</code> 进行解密。</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1350__20250519091507">参数定义
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1354__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">flen</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入数据长度</div>
|
||
</div>
|
||
<div class="- topic/div div">from</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输入需要被解密的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">to</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">输出解密后的数据</div>
|
||
</div>
|
||
<div class="- topic/div div">opts</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">一些其它参数</div>
|
||
</div>
|
||
<div class="- topic/div div">algo</div>
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">指定选用烧录在 eFuse 中的保护密钥</div>
|
||
<div class="- topic/div div">PNK_PROTECTED_RSA</div>
|
||
<div class="- topic/div div">PSK0_PROTECTED_RSA</div>
|
||
<div class="- topic/div div">PSK1_PROTECTED_RSA</div>
|
||
<div class="- topic/div div">PSK2_PROTECTED_RSA</div>
|
||
<div class="- topic/div div">PSK3_PROTECTED_RSA</div>
|
||
</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1426__20250519091507">返回值
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-1"><p class="- topic/p p" data-ofbid="d54351e1430__20250519091507">
|
||
<div class="- topic/div div">
|
||
<div class="- topic/div div">成功返回解密后数据长度,失败返回-1</div>
|
||
</div>
|
||
</p></td>
|
||
</tr>
|
||
<tr class="- topic/row">
|
||
<td class="- topic/entry entry colsep-1 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e1443__20250519091507">注意事项
|
||
</p></td>
|
||
<td class="- topic/entry entry colsep-0 rowsep-0"><p class="- topic/p p" data-ofbid="d54351e1447__20250519091507">-</p></td>
|
||
</tr>
|
||
</tbody></table></div>
|
||
</section>
|
||
<section class="- topic/section section" id="hw_authentication__id12" data-ofbid="hw_authentication__id12"><h2 class="- topic/title title sectiontitle">示例</h2><div class="- topic/div div" id="hw_authentication__section_bww_m44_fdc">
|
||
<strong class="+ topic/ph hi-d/b ph b">参数配置</strong>
|
||
<div class="- topic/p p" data-ofbid="d54351e1463__20250519091507">在 <span class="- topic/ph ph">Luban-Lite</span> 根目录下执行 <span class="+ topic/keyword sw-d/cmdname keyword cmdname">scons --menuconfig</span>,进入
|
||
menuconfig 的功能配置界面,按如下选择: <pre class="+ topic/pre pr-d/codeblock pre codeblock language-c" id="hw_authentication__codecell6" data-ofbid="hw_authentication__codecell6">Board options --->
|
||
[*] Using Crypto Engine
|
||
Local packages options --->
|
||
ArtInChip packages options --->
|
||
[*] aic-authorization --->
|
||
[*] aic authorization test
|
||
</pre></div></div><div class="- topic/div div" id="hw_authentication__section_cww_m44_fdc">
|
||
<strong class="+ topic/ph hi-d/b ph b">密钥更改</strong>
|
||
<p class="- topic/p p" data-ofbid="d54351e1478__20250519091507">用 <code class="+ topic/ph pr-d/codeph ph codeph">xxd -i rsa_private_key_encrypted.der</code> 转换私钥 为 C 语言数组格式,并替换
|
||
rsa_private_key2048_encrypted_der 用 <code class="+ topic/ph pr-d/codeph ph codeph">xxd -i rsa_public_key.der</code>
|
||
转换公钥 为 C 语言数组格式 ,并替换 rsa_public_key2048_der
|
||
替换文件路径:packages/artinchip/aic-authorization/test/test_aic_hw_authorization.h</p></div><strong class="+ topic/ph hi-d/b ph b">授权测试</strong><ul class="- topic/ul ul" id="hw_authentication__ul_dww_m44_fdc" data-ofbid="hw_authentication__ul_dww_m44_fdc">
|
||
<li class="- topic/li li" data-ofbid="d54351e1490__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e1492__20250519091507">编译镜像并烧录镜像</p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e1496__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e1498__20250519091507">重启后在开发板平台执行 <code class="+ topic/ph pr-d/codeph ph codeph">aic_hw_authorization_test</code></p>
|
||
</li>
|
||
<li class="- topic/li li" data-ofbid="d54351e1504__20250519091507">
|
||
<p class="- topic/p p" data-ofbid="d54351e1506__20250519091507">显示 <code class="+ topic/ph pr-d/codeph ph codeph">App xxx running.</code> 则表示授权认证成功,否则授权认证失败。</p>
|
||
</li>
|
||
</ul><div class="- topic/div div" id="hw_authentication__section_eww_m44_fdc">
|
||
<strong class="+ topic/ph hi-d/b ph b">示例代码</strong>
|
||
<p class="- topic/p p" data-ofbid="d54351e1518__20250519091507">授权的检查可以在 APP/中间件 启动时进行,或者在运行时随机进行。</p><div class="- topic/p p" data-ofbid="d54351e1520__20250519091507">测试用例位于
|
||
<span class="+ topic/ph sw-d/filepath ph filepath">packages/artinchip/aic-authorization/test/</span>,部分代码如下:<pre class="+ topic/pre pr-d/codeblock pre codeblock language-c" id="hw_authentication__codeblock_mzv_p44_fdc" data-ofbid="hw_authentication__codeblock_mzv_p44_fdc"><strong class="hl-keyword">int</strong> app_hw_authorization_check(<strong class="hl-keyword">unsigned</strong> <strong class="hl-keyword">char</strong> *from, <strong class="hl-keyword">int</strong> flen,
|
||
<strong class="hl-keyword">unsigned</strong> <strong class="hl-keyword">char</strong> *esk, <strong class="hl-keyword">int</strong> esk_len,
|
||
<strong class="hl-keyword">unsigned</strong> <strong class="hl-keyword">char</strong> *pk, <strong class="hl-keyword">int</strong> pk_len, <strong class="hl-keyword">char</strong> *algo)
|
||
{
|
||
<strong class="hl-keyword">struct</strong> ak_options opts = { <span class="hl-number">0</span> };
|
||
uint8_t *inbuf = NULL, *outbuf = NULL;
|
||
uint8_t esk_buf[esk_len];
|
||
uint8_t pk_buf[pk_len];
|
||
size_t pagesize = <span class="hl-number">2048</span>;
|
||
<strong class="hl-keyword">int</strong> ret = <span class="hl-number">0</span>, rlen;
|
||
|
||
inbuf = aicos_malloc_align(<span class="hl-number">0</span>, pagesize * <span class="hl-number">2</span>, CACHE_LINE_SIZE);
|
||
<strong class="hl-keyword">if</strong> (inbuf == NULL) {
|
||
printf(<span class="hl-string">"Failed to allocate inbuf.\n"</span>);
|
||
ret = -ENOMEM;
|
||
<strong class="hl-keyword">goto</strong> out;
|
||
}
|
||
outbuf = aicos_malloc_align(<span class="hl-number">0</span>, pagesize * <span class="hl-number">2</span>, CACHE_LINE_SIZE);
|
||
<strong class="hl-keyword">if</strong> (outbuf == NULL) {
|
||
printf(<span class="hl-string">"Failed to allocate outbuf.\n"</span>);
|
||
ret = -ENOMEM;
|
||
<strong class="hl-keyword">goto</strong> out;
|
||
}
|
||
|
||
<em class="hl-comment">// 1. Set RSA key parameters</em>
|
||
memcpy(esk_buf, esk, esk_len);
|
||
memcpy(pk_buf, pk, pk_len);
|
||
opts.esk_buf = esk_buf;
|
||
opts.esk_len = esk_len;
|
||
opts.pk_buf = pk_buf;
|
||
opts.pk_len = pk_len;
|
||
|
||
<em class="hl-comment">// 2. Nonce private key encryption</em>
|
||
rlen = aic_hwp_rsa_priv_enc(flen, from, outbuf, &opts, algo);
|
||
<strong class="hl-keyword">if</strong> (rlen < <span class="hl-number">0</span>) {
|
||
printf(<span class="hl-string">"aic_hwp_rsa_priv_enc failed.\n"</span>);
|
||
<strong class="hl-keyword">goto</strong> out;
|
||
}
|
||
memcpy(inbuf, outbuf, rlen);
|
||
memset(outbuf, <span class="hl-number">0</span>, <span class="hl-number">2</span> * pagesize);
|
||
|
||
<em class="hl-comment">// 3. EncNonce public key decryption</em>
|
||
rlen = aic_rsa_pub_dec(rlen, inbuf, outbuf, &opts);
|
||
<strong class="hl-keyword">if</strong> (rlen < <span class="hl-number">0</span>) {
|
||
printf(<span class="hl-string">"aic_rsa_pub_dec failed.\n"</span>);
|
||
<strong class="hl-keyword">goto</strong> out;
|
||
}
|
||
|
||
<em class="hl-comment">// 4. compare Nonce and DecNonce</em>
|
||
<strong class="hl-keyword">if</strong> (memcmp(from, outbuf, rlen)) {
|
||
hexdump_msg(<span class="hl-string">"Expect"</span>, (<strong class="hl-keyword">unsigned</strong> <strong class="hl-keyword">char</strong> *)from, rlen, <span class="hl-number">1</span>);
|
||
hexdump_msg(<span class="hl-string">"Got Result"</span>, (<strong class="hl-keyword">unsigned</strong> <strong class="hl-keyword">char</strong> *)outbuf, rlen, <span class="hl-number">1</span>);
|
||
printf(<span class="hl-string">"App %s stop.\n"</span>, algo);
|
||
ret = -<span class="hl-number">1</span>;
|
||
} <strong class="hl-keyword">else</strong> {
|
||
printf(<span class="hl-string">"App %s running.\n"</span>, algo);
|
||
ret = <span class="hl-number">0</span>;
|
||
}
|
||
|
||
out:
|
||
<strong class="hl-keyword">if</strong> (inbuf)
|
||
aicos_free_align(<span class="hl-number">0</span>, inbuf);
|
||
<strong class="hl-keyword">if</strong> (outbuf)
|
||
aicos_free_align(<span class="hl-number">0</span>, outbuf);
|
||
|
||
<strong class="hl-keyword">return</strong> ret;
|
||
}</pre><pre class="+ topic/pre pr-d/codeblock pre codeblock language-c" id="hw_authentication__codeblock_adj_n44_fdc" data-ofbid="hw_authentication__codeblock_adj_n44_fdc"><strong class="hl-keyword">int</strong> aic_hw_authorization_test(<strong class="hl-keyword">int</strong> argc, <strong class="hl-keyword">char</strong> **argv)
|
||
{
|
||
<strong class="hl-keyword">int</strong> ret = <span class="hl-number">0</span>;
|
||
<strong class="hl-keyword">int</strong> esk_len, pk_len;
|
||
<strong class="hl-keyword">unsigned</strong> <strong class="hl-keyword">char</strong> *esk, *pk, nonce[<span class="hl-number">16</span>] = { <span class="hl-number">0</span> }, nlen = <span class="hl-number">16</span>;
|
||
<strong class="hl-keyword">char</strong> *algo;
|
||
|
||
esk = rsa_private_key2048_encrypted_der;
|
||
esk_len = rsa_private_key2048_encrypted_der_len;
|
||
pk = rsa_public_key2048_der;
|
||
pk_len = rsa_public_key2048_der_len;
|
||
<strong class="hl-keyword">while</strong> (<span class="hl-number">1</span>) {
|
||
ret = aic_rng_get_bytes(nonce, <span class="hl-number">16</span>);
|
||
<strong class="hl-keyword">if</strong> (ret != nlen)
|
||
pr_err(<span class="hl-string">"aic rng get bytes failed.\n"</span>);
|
||
|
||
algo = PSK0_PROTECTED_RSA;
|
||
ret = app_hw_authorization_check(nonce, nlen, esk, esk_len, pk, pk_len, algo);
|
||
<strong class="hl-keyword">if</strong> (ret < <span class="hl-number">0</span>) {
|
||
printf(<span class="hl-string">"Application %s not authorization.\n"</span>, algo);
|
||
}
|
||
|
||
aic_mdelay(<span class="hl-number">2</span> * <span class="hl-number">1000</span>);
|
||
}
|
||
|
||
<strong class="hl-keyword">return</strong> <span class="hl-number">0</span>;
|
||
}</pre></div>
|
||
</div></section>
|
||
|
||
</div>
|
||
</article></main></div>
|
||
|
||
|
||
|
||
|
||
|
||
|
||
</div>
|
||
|
||
<nav role="navigation" id="wh_topic_toc" aria-label="On this page" class="col-lg-2 d-none d-lg-block navbar d-print-none">
|
||
<div id="wh_topic_toc_content">
|
||
|
||
<div class=" wh_topic_toc "><div class="wh_topic_label">在本页上</div><ul><li class="section-item"><div class="section-title"><a href="#hw_authentication__section_i1s_j1q_wcc" data-tocid="hw_authentication__section_i1s_j1q_wcc">身份认证原理</a></div></li><li class="section-item"><div class="section-title"><a href="#hw_authentication__id4" data-tocid="hw_authentication__id4">软件授权认证</a></div></li><li class="section-item"><div class="section-title"><a href="#hw_authentication__id8" data-tocid="hw_authentication__id8">烧写保护密钥</a></div></li><li class="section-item"><div class="section-title"><a href="#hw_authentication__rsa" data-tocid="hw_authentication__rsa">生成 RSA 密钥</a></div></li><li class="section-item"><div class="section-title"><a href="#hw_authentication__section_dd5_144_fdc" data-tocid="hw_authentication__section_dd5_144_fdc">源码说明</a></div></li><li class="section-item"><div class="section-title"><a href="#hw_authentication__id11" data-tocid="hw_authentication__id11">接口设计</a></div></li><li class="section-item"><div class="section-title"><a href="#hw_authentication__id12" data-tocid="hw_authentication__id12">示例</a></div></li></ul></div>
|
||
|
||
</div>
|
||
</nav>
|
||
|
||
</div>
|
||
</div>
|
||
|
||
|
||
|
||
</div>
|
||
<footer class="navbar navbar-default wh_footer">
|
||
<div class=" footer-container mx-auto ">
|
||
<title>footer def</title>
|
||
<style>
|
||
.p1 {
|
||
font-family: FangZhengShuSong, Times, serif;
|
||
}
|
||
.p2 {
|
||
font-family: Arial, Helvetica, sans-serif;
|
||
}
|
||
.p3 {
|
||
font-family: "Lucida Console", "Courier New", monospace;
|
||
}
|
||
</style>
|
||
<div class="webhelp.fragment.footer">
|
||
<p class="p1">Copyright © 2019-2025 广东匠芯创科技有限公司. All rights reserved.</p>
|
||
</div>
|
||
<div>
|
||
<div class="generation_time">
|
||
Update Time: 2025-05-19
|
||
</div>
|
||
</div>
|
||
|
||
</div>
|
||
</footer>
|
||
|
||
<div id="go2top" class="d-print-none">
|
||
<span class="oxy-icon oxy-icon-up"></span>
|
||
</div>
|
||
|
||
<div id="modal_img_large" class="modal">
|
||
<span class="close oxy-icon oxy-icon-remove"></span>
|
||
<div id="modal_img_container"></div>
|
||
<div id="caption"></div>
|
||
</div>
|
||
|
||
|
||
<script src="${pd}/publishing/publishing-styles-AIC-template/js/custom.js" defer="defer"></script>
|
||
|
||
|
||
</body>
|
||
</html> |