id: 4f843281c5df470786b8becde3a1347c
parent_id: c00ce466ea8844049235cbd77149f042
item_type: 1
item_id: 445891dba8674cae8b865a6fd2a3faf1
item_updated_time: 1782806819997
title_diff: "[]"
body_diff: "[{\"diffs\":[[-1,\"# Ford EoL Key Fob Provisioning System (SCP03)\\\nID: 445891dba8674cae8b865a6fd2a3faf1\\\nNotebook ID: 283dd54f183a4ce69366648f091336d1\\\nCreated: 1780901497561\\\nUpdated: 1782802416305\\\nIs Todo: No\\\nTags: rust, scp03, nfc, ford, active-project\\\n\\\n---\\\n\\\n\"],[0,\"# Fo\"]],\"start1\":0,\"start2\":0,\"length1\":243,\"length2\":4},{\"diffs\":[[0,\"fob \"],[-1,\"Station — SCP03 / KLMS Flow Reference\\\"** (event/data\\\n> flow diagram), **\\\"Keyfob Station — KLMS Data Contract & E2E Sequence\\\"** (full\\\n> 5-actor contract + message tables for Enterprise Architect\"],[1,\"Flow 1 — Content Supply: Ford IVSS/GIVIS → Clypeum\\\n> KLMS\\\"** (OEM→supplier content plane), **\\\"Keyfob Flow 2 — Provisioning: Station ↔\\\n> Key Fob ↔ Clypeum\\\"** (real-time provisioning plane), **\\\"Keyfob Station — SCP03 /\\\n> KLMS Flow Reference\\\"** (dev/flashing + production summary\"],[0,\"), a\"]],\"start1\":609,\"start2\":609,\"length1\":201,\"length2\":284},{\"diffs\":[[0,\"yfob\"],[-1,\"\\\n>\"],[0,\" Station\"],[1,\"\\\n>\"],[0,\" — R\"]],\"start1\":901,\"start2\":901,\"length1\":18,\"length2\":18},{\"diffs\":[[0,\" to \"],[-1,\"the KLMS via the `KlmsClient` trait (a DLL in production) and receives back\"],[1,\"Clypeum via a **DLL over mTLS** (`KlmsClient` trait) and receives back a\\\n  **container** with\"],[0,\":\\\n  \"]],\"start1\":1726,\"start2\":1726,\"length1\":83,\"length2\":101},{\"diffs\":[[0,\"    \"],[-1,\"inside the KLMS/\"],[1,\"by Clypeum via the Net\"],[0,\"HSM \"]],\"start1\":1974,\"start2\":1974,\"length1\":24,\"length2\":30},{\"diffs\":[[0,\"cts the \"],[-1,\"KLMS-issued\"],[1,\"container's\"],[0,\" keys.\\\n-\"]],\"start1\":2101,\"start2\":2101,\"length1\":27,\"length2\":27},{\"diffs\":[[0,\"rue`\"],[-1,\"\\\n  (those must arrive pre-encrypted from the KLMS)\"],[0,\".\\\n- \"]],\"start1\":2199,\"start2\":2199,\"length1\":58,\"length2\":8},{\"diffs\":[[0,\"ent`\"],[-1,\" (emulates the KLMS+HSM with the\\\n  dev keys)\"],[0,\" + t\"]],\"start1\":2249,\"start2\":2249,\"length1\":52,\"length2\":8},{\"diffs\":[[0,\"ction** \"],[-1,\"station-side HSM\"],[1,\"NetHSM (master-key AES\"],[0,\" primiti\"]],\"start1\":2479,\"start2\":2479,\"length1\":32,\"length2\":38},{\"diffs\":[[0,\"tive\"],[-1,\"/\"],[1,\"s + \"],[0,\"bundle\"],[-1,\"-\"],[1,\"\\\n  \"],[0,\"decrypt\"],[-1,\"\\\n  backend is KLMS-side (\"],[1,\") is \"],[0,\"Clypeum\"],[-1,\")\"],[1,\"-side\"],[0,\", no\"]],\"start1\":2515,\"start2\":2515,\"length1\":56,\"length2\":45},{\"diffs\":[[0,\"ogy \"],[-1,\"(5 actors)\\\n\\\nThe production design separat\"],[1,\"— two flows\\\n\\\nProduction splits into two **independent plan\"],[0,\"es\"],[-1,\" \"],[0,\"**\"],[-1,\"key generation** from **key use** so the master\\\nkey never comes near the factory floor.\\\n\\\n| Actor | Holds long-term | Does |\\\n|---|---|---|\\\n| **Ford / Clypeum gen side** | **master key** (in gen-HSM) | KDF3 per-fob → static keys; packages +\"],[1,\" (one per companion note):\\\n\\\n### Flow 1 — Content Supply (async, OEM → supplier)\\\n- **Ford IVSS / GIVIS** ships per-fob **content** (FESN, SPID, device cert, device\\\n  private key, BLE IRK) as encrypted **bundles**.\\\n- Clypeum generates a **keypair in the NetHSM** (private key never leaves); Ford\\\n \"],[0,\" enc\"]],\"start1\":2604,\"start2\":2604,\"length1\":292,\"length2\":365},{\"diffs\":[[0,\"pts \"],[-1,\"key **\"],[0,\"bundles\"],[-1,\"**\"],[0,\" to the \"],[-1,\"station-HSM pubkey; audit DB |\\\n| **KLMS** (Clypeum) |\"],[1,\"public key.\\\n- The **Clypeum watchdog** keeps inventory, fetches bundles, and has the **NetHSM\\\n  decrypt** them → caches\"],[0,\" dec\"]],\"start1\":2971,\"start2\":2971,\"length1\":84,\"length2\":142},{\"diffs\":[[0,\"pted\"],[-1,\"-\"],[1,\" **\"],[0,\"package\"],[-1,\" cache (2-wk stock) | **orchestrates** SCP03 Phase-2 via HSM primitives; bundle cache + watchdog; returns session keys + content |\\\n| **Station-side HSM** (YubiHSM 2 / Nitrokey / Utimaco) | **bundle-decryption private key (generated inside it)** | **AES primitives only** (AES-CMAC/AES-CBC) + bundle decrypt; does NOT understand SCP03/KDF3 |\\\n| **Station** | nothing | PC/SC to fob; forwards handshake to KLMS; consumes session \"],[1,\"s** (≥ **2 weeks of production** stock).\\\n- This plane carries **content only** — no SCP03 keys.\\\n\\\n### Flow 2 — Provisioning (real-time, per fob)\\\n- The **same NetHSM also holds the NXP master key** (imported from NXP, never\\\n  exported); it does **AES primitives only**.\\\n- The station sends the fob UID + handshake to Clypeum (DLL/mTLS). The **KLMS\\\n  orchestrates**: looks up cached content, uses the NetHSM to derive **static keys\\\n  (KDF3, master+UID)** → **session keys** + cryptograms + A003 S-DEK encryption.\\\n- Clypeum returns a **container** (session keys + pre-encrypted content); the\\\n  station consumes only ephemeral session keys.\\\n\\\n### Actors & what each holds\\\n\\\n| Actor | Holds long-term | Does |\\\n|---|---|---|\\\n| **Ford IVSS / GIVIS** | per-fob content + signing key | builds + encrypts content bundles to the NetHSM pub\"],[0,\"key\"],[-1,\"s\"],[0,\" |\\\n|\"]],\"start1\":3115,\"start2\":3115,\"length1\":446,\"length2\":846},{\"diffs\":[[0,\"-loaded)\"],[1,\", UID\"],[0,\" | NCJ37\"]],\"start1\":4004,\"start2\":4004,\"length1\":16,\"length2\":21},{\"diffs\":[[0,\"d |\\\n\"],[-1,\"\\\n**Two operational planes:**\\\n- **(A) Async bundle/cache** — gen side ships encrypted key bundles → station-side\\\n  HSM decrypts → KLMS caches decrypted packages. A watchdog keeps ≥ **2 weeks of\\\n  production** in stock, decoupling the line from gen-side latency.\\\n- **(B) Real-time per fob** — KLMS pulls the fob's package from cache, orchestrates\\\n  Phase-2 (static→session) calling the HSM for every AES op, returns session keys +\\\n  pre-encrypted content to the station.\\\n\\\nSee **\\\"KLMS Data Contract & E2E Sequence\\\"** for the full message tables + EA diagram.\\\n\\\n### Key Design Decision: master key stays at the generation side\\\n\\\nThe architecture evolved from a local Nitrokey KDF, to KLMS-HSM session-key\\\noffload, to the curr\"],[1,\"| **Station** | nothing | PC/SC to fob; DLL/mTLS to Clypeum; session-key consumer |\\\n| **Clypeum KLMS** | decrypted-content cache (2-wk stock) | watchdog (Flow 1); orchestrates SCP03 (Flow 2) |\\\n| **NetHSM** (Clypeum-side) | **NXP master key** + **bundle-decryption private key** (both generated/imported inside) | AES primitives (KDF3 + session + cryptograms + A003) **and** bundle decryption |\\\n\\\n### Key Design Decision: master key in the Clypeum NetHSM; cont\"],[0,\"ent s\"],[1,\"up\"],[0,\"pli\"],[-1,\"t:\\\n\\\n- **Master key is never on the factory side.** It\"],[1,\"ed as encrypted bundles\\\n- The **NXP master key\"],[0,\" lives \"],[-1,\"only \"],[0,\"in the \"],[-1,\"generation\\\n  HSM (Ford/Clypeum). KDF3 (Phase 1, master+UID → S-ENC/MAC/DEK) runs there; the\\\n  resulting per-fob static keys are **packaged into encrypted bundles**.\\\n- **The station-side \"],[1,\"NetHSM** (Clypeum-side), imported from NXP,\\\n  never exported. The Net\"],[0,\"HSM \"]],\"start1\":4043,\"start2\":4043,\"length1\":993,\"length2\":605},{\"diffs\":[[0,\"NetHSM does \"],[1,\"**\"],[0,\"AES primitiv\"]],\"start1\":4641,\"start2\":4641,\"length1\":24,\"length2\":26},{\"diffs\":[[0,\"* — \"],[-1,\"it cannot run SCP03. It\\\n  holds the **bundle-decryption private key (generated inside it)** and performs\\\n  `AES-CMAC` / `AES-CBC` on demand. The **KLMS orche\"],[1,\"the **KLMS\\\n  orchestrates** SCP03 (KDF3 master+UID → \"],[0,\"st\"],[-1,\"r\"],[0,\"at\"],[-1,\"es** the Phase-2\\\n  derivation, building each derivation-data block and calling the HSM.\\\n- **The KLMS is the orchestration + cache tier.** It fetches bundles, has the\\\n  HSM decrypt them, caches decrypted packages (watchdog-maintained), and at\\\n  provisioning time runs Phase-2 + card-cryptogram verification + A003 encryption\\\n  — all via HSM primitives — emitting only ephemeral session keys.\\\n\\\n> Net: master key → gen side only; per-fob static keys → HSM key objects on the\\\n> factory side; session keys → station (RAM-only, zeroized)\"],[1,\"ic keys → session keys).\\\n- Per-fob **content** is supplied **separately** by Ford IVSS/GIVIS as encrypted\\\n  bundles (keypair generated in the same NetHSM); the watchdog keeps a 2-week cache.\\\n- Net: master key + static keys never leave the NetHSM; the station receives only\\\n  ephemeral session keys + pre-encrypted A003\"],[0,\". The \"],[-1,\"s\"],[1,\"**S\"],[0,\"tation\"],[-1,\"\\\n>\"],[1,\"↔Clypeum\"],[0,\" bou\"]],\"start1\":4675,\"start2\":4675,\"length1\":716,\"length2\":406},{\"diffs\":[[0,\"boundary\"],[1,\"\\\n \"],[0,\" (`KlmsC\"]],\"start1\":5078,\"start2\":5078,\"length1\":16,\"length2\":18},{\"diffs\":[[0,\"ent`\"],[-1,\" request/response) is unchanged by this revision.\"],[1,\") is unchanged.**\"],[0,\"\\\n\\\n--\"]],\"start1\":5098,\"start2\":5098,\"length1\":57,\"length2\":25},{\"diffs\":[[0,\"30, rev \"],[-1,\"6\"],[1,\"7\"],[0,\")\\\n\\\nAn 11\"]],\"start1\":5160,\"start2\":5160,\"length1\":17,\"length2\":17},{\"diffs\":[[0,\"* (KLMS+\"],[1,\"Net\"],[0,\"HSM emul\"]],\"start1\":6326,\"start2\":6326,\"length1\":16,\"length2\":19},{\"diffs\":[[0,\"ly, \"],[-1,\"KLMS-via-`KlmsClient`\"],[1,\"DLL/mTLS to Clypeum\"],[0,\", no\"]],\"start1\":6916,\"start2\":6916,\"length1\":29,\"length2\":27},{\"diffs\":[[0,\"n place;\"],[-1,\" awaits\"],[0,\" the rea\"]],\"start1\":7528,\"start2\":7528,\"length1\":23,\"length2\":16},{\"diffs\":[[0,\"real\"],[-1,\"\\\n \"],[0,\" DLL\"],[-1,\"/REST interface.\\\n- **KLMS REST client** — serde types + `KlmsClient` trait ready; awaits REST API\\\n  contract + mTLS details.\\\n- **KLMS internals (bundle cache, watchdog, \"],[1,\"\\\n  links the station to Clypeum over mTLS.\\\n- **KLMS internals** — watchdog/content cache (Flow 1) and NetHSM orche\"],[0,\"st\"],[1,\"r\"],[0,\"ation\"],[-1,\"-side HSM primitives, bundle\\\n  decrypt)** — Clypeum's responsibility\"],[1,\"\\\n  (Flow 2) are **Clypeum's**\"],[0,\"; ou\"]],\"start1\":7541,\"start2\":7541,\"length1\":258,\"length2\":163},{\"diffs\":[[0,\"y is the\"],[-1,\"\\\n \"],[0,\" Station\"]],\"start1\":7713,\"start2\":7713,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"Station↔\"],[-1,\"KLMS\"],[1,\"Clypeum\"],[0,\" contrac\"]],\"start1\":7722,\"start2\":7722,\"length1\":20,\"length2\":23},{\"diffs\":[[0,\"the \"],[-1,\"real KLMS link\"],[1,\"station→Clypeum link (mTLS)\"],[0,\" beh\"]],\"start1\":8185,\"start2\":8185,\"length1\":22,\"length2\":35},{\"diffs\":[[0,\". **\"],[-1,\"HSM product + bundle/cache design\"],[1,\"Bundle/content-supply design** — bundle crypto, push/pull, 2-week sizing (Flow 1).\\\n5. **NetHSM product + primitive surface\"],[0,\"** —\"]],\"start1\":8379,\"start2\":8379,\"length1\":41,\"length2\":130},{\"diffs\":[[0,\"maco\"],[-1,\";\"],[0,\"\\\n      \"],[-1,\"bundle crypto + push/pull; 2-week stock sizing (see Data Contract note §7).\\\n5\"],[1,\"for master-key AES primitives + bundle decrypt (Flow 1+2).\\\n6\"],[0,\". **\"]],\"start1\":8544,\"start2\":8544,\"length1\":93,\"length2\":75},{\"diffs\":[[0,\"re d\"],[-1,\"iversified at the generation\\\n> side\"],[1,\"erived from the NXP master\\\n> key inside the Clypeum NetHSM\"],[0,\" and\"]],\"start1\":9914,\"start2\":9914,\"length1\":43,\"length2\":66},{\"diffs\":[[0,\"the \"],[-1,\"factory floor\"],[1,\"station\"],[0,\".\\\n\\\n#\"]],\"start1\":9993,\"start2\":9993,\"length1\":21,\"length2\":15},{\"diffs\":[[0,\"d** \"],[-1,\"from\"],[1,\"in\"],[0,\" the\\\n> \"],[-1,\"KLMS\"],[1,\"container\"],[0,\" (`e\"]],\"start1\":10631,\"start2\":10631,\"length1\":23,\"length2\":26},{\"diffs\":[[0,\"s S-DEK.\"],[1,\" The A003\\\n> plaintext + the other per-fob content come from the Flow 1 content cache.\"],[0,\"\\\n\\\n### DG\"]],\"start1\":10700,\"start2\":10700,\"length1\":16,\"length2\":101},{\"diffs\":[[0,\" to \"],[-1,\"KLMS via `KlmsClient` (DLL).\\\n3. KLMS looks up the cached package, orchestrates Phase-2 via station-side HSM\\\n   AES primitives,\"],[1,\"Clypeum via the DLL (mTLS).\\\n3. Clypeum derives static keys (KDF3 master+UID) + session keys + cryptograms via\\\n   the NetHSM, and\"],[0,\" pre\"]],\"start1\":13587,\"start2\":13587,\"length1\":134,\"length2\":136},{\"diffs\":[[0,\"ncrypts \"],[-1,\"content\"],[1,\"A003\"],[0,\".\\\n4. `es\"]],\"start1\":13725,\"start2\":13725,\"length1\":23,\"length2\":20},{\"diffs\":[[0,\"ter key \"],[-1,\"at\"],[1,\"in\"],[0,\" the \"],[-1,\"generation side\"],[1,\"Clypeum NetHSM; content supplied as encrypted bundles\"],[0,\"\\\n\\\nThe ar\"]],\"start1\":14115,\"start2\":14115,\"length1\":38,\"length2\":76},{\"diffs\":[[0,\"key \"],[-1,\"HSM-based key derivation\"],[1,\"KDF\"],[0,\" → K\"]],\"start1\":14226,\"start2\":14226,\"length1\":32,\"length2\":11},{\"diffs\":[[0,\"KLMS-HSM\"],[-1,\"\\\n\"],[1,\" \"],[0,\"session-\"]],\"start1\":14236,\"start2\":14236,\"length1\":17,\"length2\":17},{\"diffs\":[[0,\"ffload →\"],[-1,\" \"],[1,\"\\\n\"],[0,\"the curr\"]],\"start1\":14258,\"start2\":14258,\"length1\":17,\"length2\":17},{\"diffs\":[[0,\"t **\"],[-1,\"generation-side / factory-side\"],[1,\"two-flow\"],[0,\" spl\"]],\"start1\":14277,\"start2\":14277,\"length1\":38,\"length2\":16},{\"diffs\":[[0,\"- The **\"],[1,\"NXP \"],[0,\"master k\"]],\"start1\":14300,\"start2\":14300,\"length1\":16,\"length2\":20},{\"diffs\":[[0,\"key \"],[-1,\"never leaves the generation HSM** (Ford/Clypeum).\"],[1,\"lives in the NetHSM** (Clypeum-side), imported from NXP,\\\n  never exported. The NetHSM does **AES primitives only** (AES-CMAC/AES-CBC); the\\\n  **KLMS orchestrates** SCP03 —\"],[0,\" KDF\"]],\"start1\":14319,\"start2\":14319,\"length1\":57,\"length2\":178},{\"diffs\":[[0,\"Phase 1,\"],[-1,\"\\\n \"],[0,\" master+\"]],\"start1\":14500,\"start2\":14500,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"MAC/DEK, purpose\"],[1,\"\\\n \"],[0,\" bytes 0x40/0x60\"]],\"start1\":14528,\"start2\":14528,\"length1\":32,\"length2\":34},{\"diffs\":[[0,\"UID)\"],[-1,\" runs\\\n  there; per-fob static keys are packaged into **encrypted bundles**.\\\n- The **station-side HSM (YubiHSM 2 / Nitrokey / Utimaco) does AES primitives\\\n  only\"],[1,\", then Phase-2 session keys + cryptograms,\\\n  and A003 AES-CBC(S-DEK).\\\n- Per-fob **content\"],[0,\"** (\"],[-1,\"AES-CMAC/AES-CBC) and holds the **bundle-decryption private key\\\n  (generated inside it)**. It does NOT understand SCP03/KDF3.\\\n- The **KLMS orchest\"],[1,\"FESN/SPID/certs/device key) is supplied **sepa\"],[0,\"rate\"],[-1,\"s** Phase-2 (static→session) and all AES work, fetching +\\\n  decrypting bundles (via the HSM) and caching decrypted packages behind a\\\n  watchdog (≥2 weeks of stock).\\\n\\\n**Net:** master key → gen side only; per-fob static keys → factory-side HSM key\\\nobjects; session keys → station (ephemeral, zeroized)\"],[1,\"ly** by\\\n  Ford IVSS/GIVIS as encrypted **bundles** (keypair generated in the same NetHSM);\\\n  the watchdog keeps a 2-week cache. (See Flow 1.)\\\n\\\n**Net:** master key + static keys never leave the NetHSM; the station receives\\\nonly ephemeral session keys + pre-encrypted A003\"],[0,\". Th\"]],\"start1\":14581,\"start2\":14581,\"length1\":621,\"length2\":421},{\"diffs\":[[0,\"Station↔\"],[-1,\"KLMS\"],[1,\"Clypeum\"],[0,\" boundar\"]],\"start1\":15004,\"start2\":15004,\"length1\":20,\"length2\":23},{\"diffs\":[[0,\"dary\"],[-1,\"\\\nis \"],[1,\" is\\\n\"],[0,\"unch\"]],\"start1\":15024,\"start2\":15024,\"length1\":12,\"length2\":12},{\"diffs\":[[0,\"CMAC\"],[-1,\"\\\n- D\"],[1,\"; d\"],[0,\"eriv\"]],\"start1\":15569,\"start2\":15569,\"length1\":12,\"length2\":11},{\"diffs\":[[0,\" by \"],[-1,\"the KLMS (Phase 2 only — Phase 1 ran at the gen side);\\\n \"],[1,\"Clypeum (KDF3 Phase 1 + Phase 2) via the NetHSM;\"],[0,\" the app\"],[1,\"\\\n \"],[0,\" rec\"]],\"start1\":15655,\"start2\":15655,\"length1\":72,\"length2\":66},{\"diffs\":[[0,\" / from \"],[-1,\"KLMS\"],[1,\"Clypeum container\"],[0,\" (prod) \"]],\"start1\":16717,\"start2\":16717,\"length1\":20,\"length2\":33},{\"diffs\":[[0,\"m\\\")\\\n\"],[-1,\"Orchestrates Phase-2; fetches + \"],[1,\"Holds the NXP master key + bundle-\"],[0,\"decrypt\"],[-1,\"s\"],[1,\"ion\"],[0,\" key\"],[-1,\" bundles via the station-side \"],[1,\"pair in the Net\"],[0,\"HSM;\"],[-1,\"\\\nca\"],[1,\" or\"],[0,\"ches\"],[-1,\" decrypted packages behind a watchdog\"],[1,\"trates\\\nSCP03 (Flow 2); runs the content watchdog/cache (Flow 1)\"],[0,\"; de\"]],\"start1\":17790,\"start2\":17790,\"length1\":130,\"length2\":145},{\"diffs\":[[0,\"s session keys +\"],[-1,\" \"],[1,\"\\\n\"],[0,\"pre-encrypted\\\npa\"]],\"start1\":17940,\"start2\":17940,\"length1\":33,\"length2\":33},{\"diffs\":[[0,\"pted\"],[-1,\"\\\npayload. Master key lives on the generation side, not the KLM\"],[1,\" content to the station over mTL\"],[0,\"S.\\\n\\\n\"]],\"start1\":17966,\"start2\":17966,\"length1\":70,\"length2\":40},{\"diffs\":[[0,\" No KLMS\"],[-1,\" key diversification\"],[1,\"/NetHSM\"],[0,\" needed \"]],\"start1\":18164,\"start2\":18164,\"length1\":36,\"length2\":23},{\"diffs\":[[0,\"directly\"],[1,\".\"],[0,\"\\\n- Only \"]],\"start1\":18231,\"start2\":18231,\"length1\":16,\"length2\":17},{\"diffs\":[[0,\" channel\"],[1,\".\"],[0,\"\\\n- This \"]],\"start1\":18319,\"start2\":18319,\"length1\":16,\"length2\":17},{\"diffs\":[[0,\"d on fob\"],[1,\"; ships encrypted content bundles (Flow 1)\"],[0,\" |\\\n| Car\"]],\"start1\":18639,\"start2\":18639,\"length1\":16,\"length2\":58},{\"diffs\":[[0,\"|\\\n| \"],[-1,\"Gen side | Ford/\"],[1,\"KLMS | SecOps (\"],[0,\"Clypeum\"],[1,\")\"],[0,\" | H\"]],\"start1\":18779,\"start2\":18779,\"length1\":31,\"length2\":31},{\"diffs\":[[0,\"| Holds \"],[1,\"NXP \"],[0,\"master k\"]],\"start1\":18807,\"start2\":18807,\"length1\":16,\"length2\":20},{\"diffs\":[[0,\"key \"],[-1,\"(gen-HSM); KDF3 (Phase 1); packages + encrypts key bundles |\\\n| KLMS | SecOps (Clypeum) | Orchestrates Phase-2 via station-side HSM primitives; bundle cache + watchdog; delivers session keys + pre-encrypted payload |\\\n| Station-side \"],[1,\"+ bundle keypair (NetHSM); orchestrates SCP03; content cache + watchdog |\\\n| Net\"],[0,\"HSM \"]],\"start1\":18826,\"start2\":18826,\"length1\":239,\"length2\":87},{\"diffs\":[[0,\"/Utimaco\"],[1,\", Clypeum-side\"],[0,\") | AES \"]],\"start1\":18933,\"start2\":18933,\"length1\":16,\"length2\":30},{\"diffs\":[[0,\"ves \"],[-1,\"only; holds\"],[1,\"(KDF3+session+cryptograms+A003) +\"],[0,\" bundle\"],[-1,\"-\"],[1,\" \"],[0,\"decrypt\"],[-1,\"ion\"],[1,\";\"],[0,\" key\"],[-1,\" (generated inside)\"],[1,\"pair + master key never leave\"],[0,\" |\\\n|\"]],\"start1\":18970,\"start2\":18970,\"length1\":60,\"length2\":90},{\"diffs\":[[0,\"SC pipe,\"],[1,\" DLL/mTLS to Clypeum,\"],[0,\" session\"]],\"start1\":19093,\"start2\":19093,\"length1\":16,\"length2\":37},{\"diffs\":[[0,\"dit \"],[-1,\"reporting \"],[0,\"|\\\n| \"]],\"start1\":19171,\"start2\":19171,\"length1\":18,\"length2\":8},{\"diffs\":[[0,\" dev samples\"],[1,\", master-key delivery\"],[0,\" |\\\n\\\n---\\\n\\\n## \"]],\"start1\":19244,\"start2\":19244,\"length1\":24,\"length2\":45},{\"diffs\":[[0,\"st. \"],[-1,\"Runs at the generation side in production\"],[1,\"In production runs in the Clypeum NetHSM (master key)\"],[0,\"; in\"]],\"start1\":19737,\"start2\":19737,\"length1\":49,\"length2\":61},{\"diffs\":[[0,\" DLL\"],[-1,\"/REST\"],[0,\" imp\"]],\"start1\":21434,\"start2\":21434,\"length1\":13,\"length2\":8},{\"diffs\":[[0,\"[ ] \"],[-1,\"Mutual TLS (mTLS) for KLMS↔EoL network\"],[1,\"**DLL interface** + **mTLS** details for the station↔Clypeum\"],[0,\" lin\"]],\"start1\":21464,\"start2\":21464,\"length1\":46,\"length2\":68},{\"diffs\":[[0,\"GI tags\\\n\"],[1,\"- [ ] **Bundle encryption scheme** (RSA-OAEP / ECIES / AES-KW) + push vs pull + signature (Flow 1)\\\n- [ ] **2-week stock sizing** + low-water mark (Flow 1)\\\n- [ ] **NetHSM product** (YubiHSM 2 / Nitrokey / Utimaco) + AES-primitive surface (Flow 2)\\\n\"],[0,\"- [ ] Ke\"]],\"start1\":21724,\"start2\":21724,\"length1\":16,\"length2\":262},{\"diffs\":[[0,\"seconds)\"],[1,\" + single-use\"],[0,\"\\\n- [ ] K\"]],\"start1\":22158,\"start2\":22158,\"length1\":16,\"length2\":29},{\"diffs\":[[0,\"ies\\\n\"],[-1,\"- [ ] **HSM product** (YubiHSM 2 / Nitrokey / Utimaco) for station-side primitives + bundle decrypt\\\n- [ ] **Bundle encryption scheme** (RSA-OAEP / ECIES / AES-KW) + push vs pull delivery\\\n- [ ] **Static-key placement** (HSM key objects vs KLMS RAM) + whether A003 plaintext reaches the KLMS\\\n- [ ] **2-week stock sizing** (line rate × hours × margin)\\\n\"],[0,\"- [x\"]],\"start1\":22224,\"start2\":22224,\"length1\":357,\"length2\":8},{\"diffs\":[[0,\"atic\"],[-1,\", loaded from shared dir\"],[0,\"\\\n- [\"]],\"start1\":22303,\"start2\":22303,\"length1\":32,\"length2\":8},{\"diffs\":[[0,\"ory name\"],[1,\" / package\"],[0,\")\\\n\\\n---\\\n\\\n\"]],\"start1\":22389,\"start2\":22389,\"length1\":16,\"length2\":26},{\"diffs\":[[0,\"rev \"],[-1,\"6: revised\"],[1,\"7: split\"],[0,\" pro\"]],\"start1\":22475,\"start2\":22475,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"ion \"],[-1,\"topology — master key now stays at the generation side; station-side HSM (YubiHSM2/Nitrokey/Utimaco) does AES primitives + bundle decryption only; KLMS orchestrates Phase-2 from a watchdog-maintained cache of decrypted packages (≥2 weeks stock)\"],[1,\"into two planes — **Flow 1** (content supply: Ford IVSS/GIVIS → encrypted bundles → NetHSM-decrypt → Clypeum watchdog cache) and **Flow 2** (provisioning: station forwards handshake via DLL/mTLS; Clypeum derives static+session keys using the NetHSM which holds the NXP master key; returns content+keys container). The master key is in the Clypeum NetHSM; bundles carry content only\"],[0,\". 86\"]],\"start1\":22495,\"start2\":22495,\"length1\":252,\"length2\":389}]"
metadata_diff: {"new":{},"deleted":[]}
encryption_cipher_text: 
encryption_applied: 0
updated_time: 2026-06-30T08:07:45.859Z
created_time: 2026-06-30T08:07:45.859Z
type_: 13