SPRUJ17I March 2022 – August 2025 AM2631 , AM2631-Q1 , AM2632 , AM2632-Q1 , AM2634 , AM2634-Q1
The Derivation Object Identifier has the following format:-
derivationKey ::= SEQUENCE {
salt: OCTET STRING -- encryption salt value
info: OCTET STRING –- [optional]information
}The Boot-ROM will leave a derived key in the assets interface for the HSM Runtime. The key is derived using HKDF from the parameters specified here.
salt: The salt is limited to be 32bytes and is used for key derivation
info: The information is optional in which case the size of the information is set to 0 but if specified is limited to 32bytes.
If this extension is not present, derived key will be the same across SBL/hsmRT and application
If this extension is present, derived key will not be the same as SBL/hsmRT