The following section describe how the PKA engine is used to accelerate asymmetric cryptographic algorithms.
The PKA engine supports pipelined operations; the pipeline depth is one opcode, thus the next operation can be set up while the previous operation is executing. Register PKA_PIPE will indicate if the pipeline is ready for a new opcode and register PKA_DONE will indicate when the PKA operation has been completed and no operation is waiting in the pipeline.
- Enable CRYPTOCELL subsystem as described in Cryptographic flow.
- Initialize the PKA engine to accommodate the maximum bit size of all intended operations
- Configure registers PKA_L[n] (n=0..7) for all required
operand bit sizes. The desired operand length is selected using field
LENin register OPCODE. - Define the PKA SRAM memory map partitioning using register MEMORY_MAP[n] (n=0..31)
for register
N,Np,T0, andT1, as well as any other virtual registers intended to be used in the operations. The PKA SRAM memory map partitioning must allow for the max operand bit size plus an additional 64 bits reserved for PKA engine internal calculations.
- Configure registers PKA_L[n] (n=0..7) for all required
operand bit sizes. The desired operand length is selected using field
- For all operations
- Load the PKA SRAM virtual registers
NandNpas required - Load the remaining PKA SRAM virtual registers as required
- Execute the operation by writing register OPCODE
- Prepare the next opcode once register PKA_PIPE is ready.
- Handle any status bits in register PKA_STATUS
- Re-use intermediate results of the previous operation as needed.
- Load the PKA SRAM virtual registers
- Wait for the operation to complete by either polling register PKA_DONE,
or by unmasking the interrupt for field
PKA_MASKin register IMR - Read the result from the result register.