This thread has been locked.

If you have a related question, please click the "Ask a related question" button in the top right corner. The newly created question will be automatically linked to this question.

CC2745R10-Q1: About the PSA API

Part Number: CC2745R10-Q1

Tool/software:

Hello,

My environment is as follows:
Board: CC2745R10-Q1
Debugger: XDS110
SDK: SimpleLink Lowpower f3 ver.9.10.00.83
IDE: IAR Embedded Workbench for ARM 9.60.3.7274

PSA API is basically recognized as a synchronous API, but what if you want to use asynchronous processing or callbacks?

Is it possible to achieve the following sample code example [Single call CBC decryption with plaintext CryptoKey in callback return mode] using the PSA API?
ti/simplelink_lowpower_f3_sdk_9_10_00_83/docs/secure_drivers/doxygen/html/_a_e_s_c_b_c_8h.html

#include <ti/drivers/AESCBC.h>
#include <ti/drivers/cryptoutils/cryptokey/CryptoKeyPlaintext.h>
...
// Test vector 0 from NIST CAPV set CBCMMT256
uint8_t iv[16] =                {0xdd, 0xbb, 0xb0, 0x17, 0x3f, 0x1e, 0x2d, 0xeb,
                                 0x23, 0x94, 0xa6, 0x2a, 0xa2, 0xa0, 0x24, 0x0e};
uint8_t ciphertext[16] =        {0xd5, 0x1d, 0x19, 0xde, 0xd5, 0xca, 0x4a, 0xe1,
                                 0x4b, 0x2b, 0x20, 0xb0, 0x27, 0xff, 0xb0, 0x20};
uint8_t keyingMaterial[32] =    {0x43, 0xe9, 0x53, 0xb2, 0xae, 0xa0, 0x8a, 0x3a,
                                 0xd5, 0x2d, 0x18, 0x2f, 0x58, 0xc7, 0x2b, 0x9c,
                                 0x60, 0xfb, 0xe4, 0xa9, 0xca, 0x46, 0xa3, 0xcb,
                                 0x89, 0xe3, 0x86, 0x38, 0x45, 0xe2, 0x2c, 0x9e};
uint8_t plaintext[sizeof(ciphertext)];
// The plaintext should be the following after the decryption operation:
//  0x07, 0x27, 0x0d, 0x0e, 0x63, 0xaa, 0x36, 0xda
//  0xed, 0x8c, 0x6a, 0xde, 0x13, 0xac, 0x1a, 0xf1
void cbcCallback(AESCBC_Handle handle,
                 int_fast16_t returnValue,
                 AESCBC_OperationUnion *operation,
                 AESCBC_OperationType operationType) {
    if (returnValue != AESCBC_STATUS_SUCCESS) {
        // handle error
    }
    if (operationType == AESCBC_OPERATION_TYPE_DECRYPT ||
        operationType == AESCBC_OPERATION_TYPE_ENCRYPT) {
        // do something with operation->oneStepOperation
    } else {
        // do something with operation->segmentedOperation
    }
}
AESCBC_OneStepOperation operation;
void cbcStartFunction(void) {
    AESCBC_Handle handle;
    AESCBC_Params params;
    CryptoKey cryptoKey;
    int_fast16_t decryptionResult;
    AESCBC_Params_init(&params);
    params.returnBehavior = AESCBC_RETURN_BEHAVIOR_CALLBACK;
    params.callbackFxn = cbcCallback;
    handle = AESCBC_open(0, &params);
    if (handle == NULL) {
        // handle error
    }
    CryptoKeyPlaintext_initKey(&cryptoKey, keyingMaterial, sizeof(keyingMaterial));
    AESCBC_OneStepOperation_init(&operation);
    operation.key               = &cryptoKey;
    operation.input             = ciphertext;
    operation.output            = plaintext;
    operation.inputLength       = sizeof(ciphertext);
    operation.iv                = iv;
    decryptionResult = AESCBC_oneStepDecrypt(handle, &operation);
    if (decryptionResult != AESCBC_STATUS_SUCCESS) {
        // handle error
    }
    // do other things while CBC operation completes in the background
}

Best,

  • Hi !

    You can read the API and documentation for the PSA secure drivers of the F3 SDK, which will guide you towards creating a CryptoKey object. This object can be either plaintext like in the example you shared, or a CryptoKey generated from the PSA API.

    Once you have the CryptoKey, you can use it with the AESCBC functions like you would usually.

    Kind regards,
    Maxence

  • Aditionally, the user guide about PSA has a Simplelink API to PSA API mapping table, which should be really useful.

    For example, in your use case, the psa_cipher_decrypt function is equivalent to calling KeyStore_PSA_initKey and AESCBC_oneStepDecrypt according to the table.

    Kind regards,
    Lea

  • Hello,

    In another Q&A, I received an answer as below that recommended using the PSA API, so I am considering implementing it using only the PSA API.
    I would like to use asynchronous processing and callback processing, but is this possible?
    If so, please tell me how to achieve this.

     CC2745R10-Q1: Please confirm the use of ECDH_generatePublicKey 

    "you can only use PSA and not the SimpleLink APIs. They are not compatible.

    If you are going to use the SimpleLink APIs, then you can't use PSA or Keystore.

    SimpleLink crypto drivers will be deprecated in the future."

    Best,

  • Hi !

    If you look at the code in C:\ti\simplelink_lowpower_f3_sdk_9_11_00_18\source\third_party\psa_crypto\psa_crypto_wrapper.c, you will see that psa_cipher_decrypt is currently using KeyStore_PSA_initKey and AESCBC_oneStepDecrypt for the purposes of the function.

    In the thread you linked, Nima is correct : our PSA implementation is a wrapper around our current SimpleLink secure drivers API for crypto. In the future, this SimpleLink API may change, so using only PSA functions will make your software more future-proof to future SDK updates. 

    As for the synchronicity, our PSA implementation is synchronous, and all operations are blocking. In particular, you can see in the psa_crypto_init function that AESCBC is set in blocking mode : 
      

    Our PSA implementation strictly follows the PSA API specification, which is synchronous. If our PSA implementation were to be asynchronous, we would deviate from the PSA specification. Some people have risen the same concerns as you did, but this is currently not in the scope of PSA nor Mbed-TLS.

    There is currently no way to call crypto functions such as AESCBC in non-blocking mode using only PSA functions.

    The only option to use non-blocking mode is to use the SimpleLink API crypto functions, which should not be used in conjunction with the PSA functions. I will ask Nima about using both KeyStorage and the SimpleLink API.

    Kind regards,
    Maxence