<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>AT%KEYGEN Security</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/127833/at-keygen-security</link><description>Hi, Using the nRF9151 flashed with ncs-serial-modem v1.0.0 we are using at%keygen to generate a CSR for MQTT. I want to know how the firmware generates the private keys and how they are stored in the hardware to make sure that our application is as secure</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Wed, 06 May 2026 12:51:37 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/127833/at-keygen-security" /><item><title>RE: AT%KEYGEN Security</title><link>https://devzone.nordicsemi.com/thread/565970?ContentTypeID=1</link><pubDate>Wed, 06 May 2026 12:51:37 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:4a6e7953-2fbf-4dd1-8aae-9d8b14614aa3</guid><dc:creator>Syed Maysum Abbas Zaidi</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Following up with the clarification from our&amp;nbsp;internal team:&lt;/p&gt;
&lt;p&gt;When AT%KEYGEN generates a private key, the process is hardware assisted within the modem&amp;#39;s secure environment. The private key is then stored encrypted in the modem&amp;#39;s internal secure storage and this is a modem domain mechanism, separate from the application side KMU. So to directly answer your question the KMU is not used for modem credential storage.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Best Regards,&lt;br /&gt;Syed Maysum&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: AT%KEYGEN Security</title><link>https://devzone.nordicsemi.com/thread/565432?ContentTypeID=1</link><pubDate>Fri, 24 Apr 2026 08:00:29 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:83b7a0b1-cda7-4a8a-8bde-53a58cb0da72</guid><dc:creator>Syed Maysum Abbas Zaidi</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Your Welcome,&amp;nbsp;and we will update you regarding the KMU as soon as we get any response from the relevant Team.&lt;/p&gt;
&lt;p&gt;Best Regard,&lt;br /&gt;Syed Maysum&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: AT%KEYGEN Security</title><link>https://devzone.nordicsemi.com/thread/565186?ContentTypeID=1</link><pubDate>Mon, 20 Apr 2026 14:25:28 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:992c963a-a863-4cb4-95cc-8485abe2064e</guid><dc:creator>Vineet.Aggarwal</dc:creator><description>&lt;p&gt;Hi Syed,&lt;br /&gt;&lt;br /&gt;Okay that makes sense, thank you!&lt;br /&gt;&lt;br /&gt;Best,&amp;nbsp;&lt;br /&gt;Vineet&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: AT%KEYGEN Security</title><link>https://devzone.nordicsemi.com/thread/565153?ContentTypeID=1</link><pubDate>Mon, 20 Apr 2026 09:37:51 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:69e749c9-d5f1-4dc5-acce-b5f803f890ae</guid><dc:creator>Syed Maysum Abbas Zaidi</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;When AT%KEYGEN is issued, the nRF9151 modem generates a private key entirely internally, stores it in the modem&amp;#39;s own credential storage (NVM) under the specified sec_tag, and returns only the CSR, the private key never leaves the modem.&amp;nbsp;&lt;a href="https://docs.nordicsemi.com/bundle/ncs-latest/page/nrf/security/key_storage.html#modem_certificate_storage"&gt;It cannot be read back by the application&lt;/a&gt;&amp;nbsp;and the modem uses it internally for TLS operations.&lt;/p&gt;
&lt;p&gt;The modem and application core operate as independent subsystems, so application-side access to modem credentials is not possible. Moreover its recommended to enable&amp;nbsp;&lt;a href="https://docs.nordicsemi.com/bundle/ncs-latest/page/nrf/security/key_storage.html#access_port_protection_ap-protect"&gt;AP-Protect&lt;/a&gt;&amp;nbsp;in production devices to prevent extraction of keys and sensitive data through debug interfaces.&lt;/p&gt;
&lt;p&gt;One point we are still confirming with our engineering team whether the modem uses the KMU internally for its credential storage. We will follow up on this.&lt;/p&gt;
&lt;p&gt;Best Regards,&lt;br /&gt;Syed Maysum&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>