<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S32K3 HSE NvM Key update in S32K</title>
    <link>https://community.nxp.com/t5/S32K/S32K3-HSE-NvM-Key-update/m-p/2169487#M52673</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/229151"&gt;@strofald&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is described in section "6.2.3 Key import" in HSE firmware reference manual v2.6. See Table 47 and Table 48. These tables show the difference when importing/updating empty slot and "non-empty" slot. If a slot is non-empty, authentication is mandatory, encryption is optional. &lt;BR /&gt;Authentication means that a container needs to be authenticated by Ka. In other words, you need to know another key (Ka) to be able to update your key. It is not simple operation and it is not supported by Crypto driver. Easiest options is to erase the key (you need to have super user rights) and then import the key again as usual. &lt;BR /&gt;Attached is SW example which shows how to erase the key. It's updated SW example from RTD, just this functionality was added. &lt;BR /&gt;Demo environment:&lt;BR /&gt;RTD: SW32K3_S32M27x_RTD_4.4_4.0.0_P20,&lt;BR /&gt;EB Tresos: 29.0.0&lt;/P&gt;
&lt;P&gt;If you have SHE key, you need to follow memory update protocol described by SHE specification. That means you need to calculate new M1-M5 values with increased key counter and with knowledge of previous key or MASTER_ECU_KEY.&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Lukas&lt;/P&gt;</description>
    <pubDate>Mon, 15 Sep 2025 07:53:58 GMT</pubDate>
    <dc:creator>lukaszadrapa</dc:creator>
    <dc:date>2025-09-15T07:53:58Z</dc:date>
    <item>
      <title>S32K3 HSE NvM Key update</title>
      <link>https://community.nxp.com/t5/S32K/S32K3-HSE-NvM-Key-update/m-p/2168969#M52644</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using Crypto_43_HSE module v6.0.0.&lt;BR /&gt;After formatting of key catalogs I am able to load a NvM key the first time, but if I try to update it again (through a subsequente call of KeyElementSet) i get the NOT_ALLOWED response code from the HSE.&lt;BR /&gt;From the HSE user manual I can see that&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="strofald_1-1757684481972.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/356745i5E6950387F2ED55A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="strofald_1-1757684481972.png" alt="strofald_1-1757684481972.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;What does 'Authenticated' mean? Does it mean that we need to use the SHE protocol to do so? Do you have any example that explains how to do so?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2025 13:42:07 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K3-HSE-NvM-Key-update/m-p/2168969#M52644</guid>
      <dc:creator>strofald</dc:creator>
      <dc:date>2025-09-12T13:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: S32K3 HSE NvM Key update</title>
      <link>https://community.nxp.com/t5/S32K/S32K3-HSE-NvM-Key-update/m-p/2169487#M52673</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/229151"&gt;@strofald&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is described in section "6.2.3 Key import" in HSE firmware reference manual v2.6. See Table 47 and Table 48. These tables show the difference when importing/updating empty slot and "non-empty" slot. If a slot is non-empty, authentication is mandatory, encryption is optional. &lt;BR /&gt;Authentication means that a container needs to be authenticated by Ka. In other words, you need to know another key (Ka) to be able to update your key. It is not simple operation and it is not supported by Crypto driver. Easiest options is to erase the key (you need to have super user rights) and then import the key again as usual. &lt;BR /&gt;Attached is SW example which shows how to erase the key. It's updated SW example from RTD, just this functionality was added. &lt;BR /&gt;Demo environment:&lt;BR /&gt;RTD: SW32K3_S32M27x_RTD_4.4_4.0.0_P20,&lt;BR /&gt;EB Tresos: 29.0.0&lt;/P&gt;
&lt;P&gt;If you have SHE key, you need to follow memory update protocol described by SHE specification. That means you need to calculate new M1-M5 values with increased key counter and with knowledge of previous key or MASTER_ECU_KEY.&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Lukas&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 07:53:58 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K3-HSE-NvM-Key-update/m-p/2169487#M52673</guid>
      <dc:creator>lukaszadrapa</dc:creator>
      <dc:date>2025-09-15T07:53:58Z</dc:date>
    </item>
  </channel>
</rss>

