SPRUJ55D September 2023 – July 2025 AM263P2 , AM263P2-Q1 , AM263P4 , AM263P4-Q1
The Derivation Object Identifier has the following format:-
derivationKey ::= SEQUENCE {
salt: OCTET STRING -- encryption salt value
info: OCTET STRING –- [optional]information
}The Boot-ROM will leave a derived key in the assets interface for the HSM Runtime. The key is derived using HKDF from the parameters specified here.
salt: The salt is limited to be 32bytes and is used for key derivation
info: The information is optional in which case the size of the information is set to 0 but if specified is limited to 32bytes.
If this extension is not present, derived key will be the same across SBL/hsmRT and application
If this extension is present, derived key will not be the same as SBL/hsmRT