element14 Community
element14 Community
    Register Log In
  • Site
  • Search
  • Log In Register
  • About Us
  • Community Hub
    Community Hub
    • What's New on element14
    • Feedback and Support
    • Benefits of Membership
    • Personal Blogs
    • Members Area
    • Achievement Levels
  • Learn
    Learn
    • Ask an Expert
    • eBooks
    • element14 presents
    • Learning Center
    • Tech Spotlight
    • STEM Academy
    • Webinars, Training and Events
    • Learning Groups
  • Technologies
    Technologies
    • 3D Printing
    • FPGA
    • Industrial Automation
    • Internet of Things
    • Power & Energy
    • Sensors
    • Technology Groups
  • Challenges & Projects
    Challenges & Projects
    • Design Challenges
    • element14 presents Projects
    • Project14
    • Arduino Projects
    • Raspberry Pi Projects
    • Project Groups
  • Products
    Products
    • Arduino
    • Avnet Boards Community
    • Dev Tools
    • Manufacturers
    • Multicomp Pro
    • Product Groups
    • Raspberry Pi
    • RoadTests & Reviews
  • Store
    Store
    • Visit Your Store
    • Choose another store...
      • Europe
      •  Austria (German)
      •  Belgium (Dutch, French)
      •  Bulgaria (Bulgarian)
      •  Czech Republic (Czech)
      •  Denmark (Danish)
      •  Estonia (Estonian)
      •  Finland (Finnish)
      •  France (French)
      •  Germany (German)
      •  Hungary (Hungarian)
      •  Ireland
      •  Israel
      •  Italy (Italian)
      •  Latvia (Latvian)
      •  
      •  Lithuania (Lithuanian)
      •  Netherlands (Dutch)
      •  Norway (Norwegian)
      •  Poland (Polish)
      •  Portugal (Portuguese)
      •  Romania (Romanian)
      •  Russia (Russian)
      •  Slovakia (Slovak)
      •  Slovenia (Slovenian)
      •  Spain (Spanish)
      •  Sweden (Swedish)
      •  Switzerland(German, French)
      •  Turkey (Turkish)
      •  United Kingdom
      • Asia Pacific
      •  Australia
      •  China
      •  Hong Kong
      •  India
      •  Korea (Korean)
      •  Malaysia
      •  New Zealand
      •  Philippines
      •  Singapore
      •  Taiwan
      •  Thailand (Thai)
      • Americas
      •  Brazil (Portuguese)
      •  Canada
      •  Mexico (Spanish)
      •  United States
      Can't find the country/region you're looking for? Visit our export site or find a local distributor.
  • Translate
  • Profile
  • Settings
Internet of Things
  • Technologies
  • More
Internet of Things
Forum Where do you store/hide your AES keys used for embedded encypt and decrypt?
  • Blog
  • Forum
  • Documents
  • Quiz
  • Events
  • Polls
  • Members
  • Mentions
  • Sub-Groups
  • Tags
  • More
  • Cancel
  • New
Join Internet of Things to participate - click to join for free!
Actions
  • Share
  • More
  • Cancel
Forum Thread Details
  • State Suggested Answer
  • Replies 36 replies
  • Answers 8 answers
  • Subscribers 505 subscribers
  • Views 11336 views
  • Users 0 members are here
  • aes
  • aes_encryption
  • keystore
  • iot
  • aes_decryption
Related

Where do you store/hide your AES keys used for embedded encypt and decrypt?

Jan Cumps
Jan Cumps over 9 years ago

In a scenario where you have two embedded systems talking to each other,

and you want to encrypt/decrypt the data with AES,

where/how do you store the AES key in your firmware sources?

 

If I put my aes-128-ecb in my source code of my firmware like this:

 

    /* Set up the variables */ 
    uint8_t aesKey[16] = { 
            0x5a, 0x69, 0x67, 0x42, 0x65, 0x65, 0x41, 0x6c, 
            0x6c, 0x69, 0x61, 0x6e, 0x63, 0x65, 0x30, 0x39 
    };

 

 

it's  out there for everyone that has access to the version control system, and can leak to the outside world.

 

What's your approach?

  • Sign in to reply
  • Cancel

Top Replies

  • brianonn
    brianonn over 9 years ago +5 suggested
    Definitely don't check any encryption keys into source control. Let's look at the problem: While programming your APIs you see that you needed an AES key for encrypting your shared link. The problem you…
  • clem57
    clem57 over 9 years ago +2
    I would take the AES 256 bit key and encrypt with a private-public key pair RSA 1024 bit. Public is safe out in the open, but the private is stored on a USB medium on a system with a locked keyring. This…
  • Fred27
    Fred27 over 9 years ago +2 suggested
    Would a "good enough" solution be to have this in a separate file that's ignored by source control? It would in theory be accessible by anyone who could get hold of the firmware, but that would be hard…
Parents
  • Workshopshed
    0 Workshopshed over 9 years ago

    I normally store any keys outside the source control and read them from file on startup. But Fred27 approach is a good one too.

    If you are designing your own hardware then you can get specialist hardware to do the job see CryptoMemory or https://www.maximintegrated.com/en/products/digital/memory-products/DS28C22.html

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • Verify Answer
    • Reject Answer
    • Cancel
Reply
  • Workshopshed
    0 Workshopshed over 9 years ago

    I normally store any keys outside the source control and read them from file on startup. But Fred27 approach is a good one too.

    If you are designing your own hardware then you can get specialist hardware to do the job see CryptoMemory or https://www.maximintegrated.com/en/products/digital/memory-products/DS28C22.html

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • Verify Answer
    • Reject Answer
    • Cancel
Children
No Data
element14 Community

element14 is the first online community specifically for engineers. Connect with your peers and get expert answers to your questions.

  • Members
  • Learn
  • Technologies
  • Challenges & Projects
  • Products
  • Store
  • About Us
  • Feedback & Support
  • FAQs
  • Terms of Use
  • Privacy Policy
  • Legal and Copyright Notices
  • Sitemap
  • Cookies

An Avnet Company © 2025 Premier Farnell Limited. All Rights Reserved.

Premier Farnell Ltd, registered in England and Wales (no 00876412), registered office: Farnell House, Forge Lane, Leeds LS12 2NE.

ICP 备案号 10220084.

Follow element14

  • X
  • Facebook
  • linkedin
  • YouTube