The Isolated Key Generator (IKG) is a module that derives symmetric and asymmetric keys from the unique seed and optional personalization string.
After IKG has been enabled, CRACEN performs an IKG health test. The CTRDRBGBUSY field of the IKG.STATUS is cleared when the operation has completed. IKG is started by writing to the IKG.START register. The generated IKG keys are valid as long as CRACEN remains enabled. For details on enabling and disabling CRACEN, see ENABLE.
The IKG derives the following keys from seed upon request:
- One 256-bit ECC P-256 key
- Two 256-bit AES keys
Note: The IKG generated keys are not directly accessible to the CPU but are used by the PKE and
AES engines. The IKG generated AES keys are not the same as protected keys in protected RAM, but can be used by the same AES engine.