5 / 7 Powered by LESI
IV. Crypto module
Keep your software safe from stealing with
this MaticControl crypto module. Most
microcontrollers are not designed to protect
against snoopers, but a cryptoauthentication chip can be used to lock away
private keys securely.
Once the private key is saved inside, it can’t be read out, all you can do is send it challengeresponse queries. That means that even if someone gets hold of your hardware and can read
back the firmware, they won’t be able to extract it!
The ATECC608 is the latest crypto-auth chip from Microchip and to make working with the it
as easy as possible, we’ve put it on a PCB . This allows you to use it with Raspberry Pi or other
similarly equipped boards without needing to solder.
ATECC608 uses I2C to send/receive commands. It will work with 3.3V or 5V power/logic
micros, so it’s ready to get to work with a range of development boards. Once you ‘lock’ the
chip with your details, you can use it for ECDH and AES-128 encrypt/decrypt/signing. There’s
also hardware support for random number generation, and SHA-256/HMAC hash functions to
greatly speed up a slower micro’s cryptography commands.
For our surprise this chip does not have a public datasheet, but it is compatible with the
ATECC508 earlier version which does, so please refer to that complete datasheet as well as
the ATECC608 summary sheet.
Some quick notes from the official Microchip datasheet:
Applications
The ATECC508A device is a member of the Microchip CryptoAuthentication™ family of crypto
engine authentication devices with highly secure hardware-based key storage.
The ATECC508A device has a flexible command set that allows use in many applications,
including the following:
• Network/IoT Node Protection - Authenticates node IDs, ensures the integrity of messages,
and supports key agreement to create session keys for message encryption.
• Anti-Counterfeiting - Validates that a removable, replaceable, or consumable client is
authentic. Examples of clients could be system accessories, electronic daughter cards, or other
spare parts. It can also be used to validate a software/firmware module or memory storage
element.
• Protecting Firmware or Media - Validates code stored in flash memory at boot to prevent
unauthorized modifications, encrypt downloaded program files as a common broadcast, or
uniquely encrypt code images to be usable on a single system only.
• Storing Secure Data - Stores secret keys for use by crypto accelerators in standard