Group policy
- group Key policies
Defines
-
PSA_KEY_USAGE_EXPORT
Whether the key may be exported.
A public key or the public part of a key pair may always be exported regardless of the value of this permission flag.
If a key does not have export permission, implementations shall not allow the key to be exported in plain form from the cryptoprocessor, whether through psa_export_key() or through a proprietary interface. The key may however be exportable in a wrapped form, i.e. in a form where it is encrypted by another key.
-
PSA_KEY_USAGE_COPY
Whether the key may be copied.
This flag allows the use of psa_copy_key() to make a copy of the key with the same policy or a more restrictive policy.
For lifetimes for which the key is located in a secure element which enforce the non-exportability of keys, copying a key outside the secure element also requires the usage flag PSA_KEY_USAGE_EXPORT. Copying the key inside the secure element is permitted with just PSA_KEY_USAGE_COPY if the secure element supports it. For keys with the lifetime PSA_KEY_LIFETIME_VOLATILE or PSA_KEY_LIFETIME_PERSISTENT, the usage flag PSA_KEY_USAGE_COPY is sufficient to permit the copy.
-
PSA_KEY_USAGE_DERIVE_PUBLIC
Whether the key may be used the public side of a key agreement or PAKE.
This macro can be used when checking a key’s capabilities, for example with mbedtls_pk_can_do_psa().
Note
Currently, no API function requires this flag. Key agreement functions (psa_raw_key_agreement(), psa_key_agreement(), psa_key_derivation_key_agreement()) and psa_pake_input() take the public key in exported form, not as a key object, so no usage flag is involved. For PAKE algorithms with a verifier role such as SPAKE2+, psa_pake_setup() requires PSA_KEY_USAGE_DERIVE even when passing a public key in the verifier role.
Note
The value of this macro is determined by a draft version of the PSA Cryptography API, and may change before this draft is finalized.
-
PSA_KEY_USAGE_ENCRYPT
Whether the key may be used to encrypt a message.
This flag allows the key to be used for a symmetric encryption operation, for an AEAD encryption-and-authentication operation, or for an asymmetric encryption operation, if otherwise permitted by the key’s type and policy.
For a key pair, this concerns the public key.
-
PSA_KEY_USAGE_DECRYPT
Whether the key may be used to decrypt a message.
This flag allows the key to be used for a symmetric decryption operation, for an AEAD decryption-and-verification operation, or for an asymmetric decryption operation, if otherwise permitted by the key’s type and policy.
For a key pair, this concerns the private key.
-
PSA_KEY_USAGE_SIGN_MESSAGE
Whether the key may be used to sign a message.
This flag allows the key to be used for a MAC calculation operation or for an asymmetric message signature operation, if otherwise permitted by the key’s type and policy.
For a key pair, this concerns the private key.
-
PSA_KEY_USAGE_VERIFY_MESSAGE
Whether the key may be used to verify a message.
This flag allows the key to be used for a MAC verification operation or for an asymmetric message signature verification operation, if otherwise permitted by the key’s type and policy.
For a key pair, this concerns the public key.
-
PSA_KEY_USAGE_SIGN_HASH
Whether the key may be used to sign a message.
This flag allows the key to be used for a MAC calculation operation or for an asymmetric signature operation, if otherwise permitted by the key’s type and policy.
For a key pair, this concerns the private key.
-
PSA_KEY_USAGE_VERIFY_HASH
Whether the key may be used to verify a message signature.
This flag allows the key to be used for a MAC verification operation or for an asymmetric signature verification operation, if otherwise permitted by the key’s type and policy.
For a key pair, this concerns the public key.
-
PSA_KEY_USAGE_DERIVE
Whether the key may be used to derive other keys or produce a password hash.
This flag allows the key to be used for a key derivation operation or for a key agreement operation, if otherwise permitted by the key’s type and policy.
If this flag is present on all keys used in calls to psa_key_derivation_input_key() for a key derivation operation, then it permits calling psa_key_derivation_output_bytes() or psa_key_derivation_output_key() at the end of the operation.
-
PSA_KEY_USAGE_VERIFY_DERIVATION
Whether the key may be used to verify the result of a key derivation, including password hashing.
This flag allows the key to be used:
This flag allows the key to be used in a key derivation operation, if otherwise permitted by the key’s type and policy.
If this flag is present on all keys used in calls to psa_key_derivation_input_key() for a key derivation operation, then it permits calling psa_key_derivation_verify_bytes() or psa_key_derivation_verify_key() at the end of the operation.
Typedefs
-
typedef uint32_t psa_key_usage_t
Encoding of permitted usage on a key.
Values of this type are generally constructed as bitwise-ors of macros called
PSA_KEY_USAGE_xxx.Note
Values of this type are encoded in the persistent key store. Any changes to existing values will require bumping the storage format version and providing a translation when reading the old format.
-
PSA_KEY_USAGE_EXPORT