RMASK and WMASK, which smelled not useful to you, are there exactly to prevent this from happening.
RMASK and WMASK, which smelled not useful to you, are there exactly to prevent this from happening.
the key managed here
https://github.com/conorpp/u2f-zero/blob/master/firmware/src...
and here
https://github.com/conorpp/u2f-zero/blob/master/firmware/src...
just means that the "actual key" (unmasked) only lives in MCU memory for a short time -- the time from when the mask is applied and then until return to caller and memory is cleared, in the enrollment case I linked. In the authenticate case, it lives quite a bit longer because the stack space used for key storage isn't zero'd.
The atecc508 doesn't use or know how to use the mask. The actual key used for the encryption is passed in the clear over i2c.
(note that the key derivation you suggest is wrong because of the extra xor masking.)
http://ww1.microchip.com/downloads/en/DeviceDoc/20005927A.pd...