One-stop secure boot tool: NXP-MCUBootUtility v1.0.0 is released

Document created by Jay Heng Employee on Dec 31, 2018Last modified by Jay Heng Employee on Mar 4, 2019
Version 3Show Document
  • View in full screen mode

1 Introduction

  NXP-MCUBootUtility is a GUI tool specially designed for NXP MCU secure boot. Its features correspond to the BootROM function in NXP MCU. Currently, it mainly supports i.MXRT series MCU chips, Compared to NXP official security enablement toolset (OpenSSL, CST, sdphost, blhost, elftosb, BD, MfgTool2), NXP-MCUBootUtility is a real one-stop tool, a tool that includes all the features of NXP's official security enablement toolset, and what's more, it supports full graphical user interface operation. With NXP-MCUBootUtility, you can easily get started with NXP MCU secure boot.
  The main features of NXP-MCUBootUtility include:

  • Support i.MXRT1021, i.MXRT1051/1052, i.MXRT1061/1062, i.MXRT1064 SIP
  • Support both UART and USB-HID serial downloader modes
  • Support various user application image file formats (elf/axf/srec/hex/bin)
  • Can validate the range and applicability of user application image
  • Support for converting bare image into bootable image
  • Support for loading bootable image into FlexSPI NOR and SEMC NAND boot devices
  • Support for loading bootable image into LPSPI NOR/EEPROM recovery boot device
  • Support DCD which can help load image to SDRAM
  • Support HAB encryption (Signed only, Signed and Encrypted)
  • Can back up certificate with time stamp
  • Support BEE encryption (SNVS Key, User Keys)
  • Support common eFuse memory operation (eFuse Programmer)
  • Support common boot device memory operation (Flash Programmer)
  • Support for reading back and marking bootable image(NFCB/DBBT/FDCB/EKIB/EPRDB/IVT/Boot Data/DCD/Image/CSF/DEK KeyBlob) from boot device

2 Download

  NXP-MCUBootUtility is developed in Python, and it is open source. The development environment is Python 2.7.15 (32bit), wxPython 4.0.3, pySerial 3.4, pywinusb 0.4.2, bincopy 15.0.0, PyInstaller 3.3.1 (or higher).

  NXP-MCUBootUtility is packaged by PyInstaller, all Python dependencies have been packaged into an executable file (\NXP-MCUBootUtility\bin\NXP-MCUBootUtility.exe), so if you do not want to develop NXP-MCUBootUtility for new feature, there is no need to install any Python software or related libraries.

Note1: Before using NXP-MCUBootUtility, you need to download HAB Code Signing Tool from NXP website,upzip it and put it in the \NXP-MCUBootUtility\tools\cst\ directory, then modify the code to enable AES function and rebuild \NXP-MCUBootUtility\tools\cst\mingw32\bin\cst.exe, or HAB related encryption function can not be used properly。See more details in 《The step-by-step guide to rebuild cst.exe for HAB encryption》

Note2: Before using NXP-MCUBootUtility, you need to rebuild the source in \NXP-MCUBootUtility\tools\image_enc\code directory to generate image_enc.exe and put it in \NXP-MCUBootUtility\tools\image_enc\win directory, or BEE related encryption function can not be used properly。See more details in 《The step-by-step guide to build image_enc.exe for BEE encryption》

3 Installation

  NXP-MCUBootUtility is a pure green free installation tool. After downloading the source code package, double-click "\NXP-MCUBootUtility\bin\NXP-MCUBootUtility.exe" to use it. No additional software is required.
  Before the NXP-MCUBootUtility.exe graphical interface is displayed, a console window will pop up first. The console will work along with the NXP-MCUBootUtility.exe graphical interface. The console is mainly for the purpose of showing error information of NXP-MCUBootUtility.exe. At present, NXP-MCUBootUtility is still in development stage, and the console will be removed when the NXP-MCUBootUtility is fully validated.

 

4 Interface

  The following figure shows the main interface of the NXP-MCUBootUtility tool. The interface consists of six parts.

Attachments

    Outcomes