iiuc the constraints leading to this design were basically "we have a hardware AES engine and it can only do ECB or CBC"
iiuc the constraints leading to this design were basically "we have a hardware AES engine and it can only do ECB or CBC"
But if you have ECB you can do better than key wrap.