<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fallback mechanism for failed AB_SWAP update in S32K</title>
    <link>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402604#M60278</link>
    <description>&lt;P&gt;Can you also elaborate on what you mean by 'device goes in recovery mode' if the basic secure boot fails? Does this mean that the core will not be released from reset and there is no fallback or recovery in this case?&lt;BR /&gt;I ask because we want to have the functionality where if the secure boot fails, we boot another image, possibly in the passive bank.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Aug 2026 17:26:49 GMT</pubDate>
    <dc:creator>Shiv_peak</dc:creator>
    <dc:date>2026-08-06T17:26:49Z</dc:date>
    <item>
      <title>Fallback mechanism for failed AB_SWAP update</title>
      <link>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2401970#M60219</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;We are developing an application that uses the AB_SWAP mechanism of the HSE firmware on the S32K342 to perform OTA updates. We are currently activating the passive block once the passive region of the flash is entirely written to.&lt;BR /&gt;We were wondering whether there is a fallback mechanism that we can use to verify/check whether the image we are booting from is corrupted, and if we can fallback to the 'known good' active region that has become the passive region after resetting.&lt;BR /&gt;This arises from the fact that on some occasions, we overwrite the passive region without issuing a reset and midway through we reset the processor, resulting in a corrupted image in the flash.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2026 01:01:53 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2401970#M60219</guid>
      <dc:creator>Shiv_peak</dc:creator>
      <dc:date>2026-08-05T01:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Fallback mechanism for failed AB_SWAP update</title>
      <link>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402093#M60231</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/254999"&gt;@Shiv_peak&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I answered very similar question a couple of days ago, please take a look at:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.nxp.com/t5/S32K/S32K-OTA-Rollback/m-p/2400332/highlight/true#M60125" target="_blank"&gt;https://community.nxp.com/t5/S32K/S32K-OTA-Rollback/m-p/2400332/highlight/true#M60125&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you need more details, just let me know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Lukas&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2026 09:31:03 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402093#M60231</guid>
      <dc:creator>lukaszadrapa</dc:creator>
      <dc:date>2026-08-05T09:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Fallback mechanism for failed AB_SWAP update</title>
      <link>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402216#M60238</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/37795"&gt;@lukaszadrapa&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;Thanks for the clarification. We are still trying to understand which type of secure boot strategy to use in our application. Advance Secure boot seems a bit complicated with having to install the SMR and CR.&lt;/P&gt;&lt;P&gt;On the other hand, Basic Secure boot seems slightly easier to install but the exact implementation and installation details seem unclear.&lt;BR /&gt;I was wondering if you could provide some insight into these options. I am referring to the HSE B Reference Manual and was also wondering if there is any additional documentation I should be referring to for this.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Shiv&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2026 17:27:11 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402216#M60238</guid>
      <dc:creator>Shiv_peak</dc:creator>
      <dc:date>2026-08-05T17:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Fallback mechanism for failed AB_SWAP update</title>
      <link>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402456#M60264</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We provide this application note:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.nxp.com/webapp/Download?colCode=AN13465" target="_blank"&gt;https://www.nxp.com/webapp/Download?colCode=AN13465&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It’s updated version of Secure Boot application note v0.1.1.0 (AN744511) released in 2021 which can be downloaded from: &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.nxp.com/products/S32K3" target="_blank"&gt;https://www.nxp.com/products/S32K3&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Application note can be found here:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Documentation -&amp;gt; Secure Files -&amp;gt; Secure Boot Application note v0.1.1.0 (AN744511)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Associated demo project can be downloaded here:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Design Resources -&amp;gt; Software -&amp;gt; Secure Files -&amp;gt; SecureBootAppNoteDemo (SW745310)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The software was not updated, so use mentioned &lt;SPAN&gt;SW745310 if you are interested. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other examples for secure boot can be found in HSE Demo Examples (recommended):&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.nxp.com/webapp/Download?colCode=S32K3_HSE_DemoExamples" target="_blank"&gt;https://www.nxp.com/webapp/Download?colCode=S32K3_HSE_DemoExamples&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There are examples for all three modes – advanced secure boot, basic secure boot and SHE secure boot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generally, advanced secure boot mode is recommended. Yes, it is not trivial task to configure the secure boot in this mode. However, it provides the best protection and configurability. The advantage is that you can select any signature scheme you want, &amp;nbsp;you can cover multiple regions and you can configure different sanctions if the secure boot fails.&lt;/P&gt;
&lt;P&gt;On other hand, basic secure boot mode always uses only GMAC tag which is calculated using a key derived from ADKP and it can cover one region only. If it fails, the device goes directly to recovery mode.&lt;/P&gt;
&lt;P&gt;I recommend to study following projects in HSE DemoExamples:&lt;/P&gt;
&lt;P&gt;S32K344_Advanced_SecureBoot&lt;/P&gt;
&lt;P&gt;S32K344_Basic_SecureBoot&lt;/P&gt;
&lt;P&gt;These are configuration projects which are supposed to protect application S32K344_SecureBootBlinky which is linked to those projects.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Lukas&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2026 09:20:07 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402456#M60264</guid>
      <dc:creator>lukaszadrapa</dc:creator>
      <dc:date>2026-08-06T09:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Fallback mechanism for failed AB_SWAP update</title>
      <link>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402593#M60277</link>
      <description>&lt;P&gt;Thanks for the clarity Lukas.&lt;BR /&gt;I will look into the application note and the HSE demo examples and revert back in case of any queries.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Shiv&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2026 16:27:03 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402593#M60277</guid>
      <dc:creator>Shiv_peak</dc:creator>
      <dc:date>2026-08-06T16:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Fallback mechanism for failed AB_SWAP update</title>
      <link>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402604#M60278</link>
      <description>&lt;P&gt;Can you also elaborate on what you mean by 'device goes in recovery mode' if the basic secure boot fails? Does this mean that the core will not be released from reset and there is no fallback or recovery in this case?&lt;BR /&gt;I ask because we want to have the functionality where if the secure boot fails, we boot another image, possibly in the passive bank.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2026 17:26:49 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402604#M60278</guid>
      <dc:creator>Shiv_peak</dc:creator>
      <dc:date>2026-08-06T17:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Fallback mechanism for failed AB_SWAP update</title>
      <link>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402764#M60302</link>
      <description>&lt;P&gt;Take a look at section “2.6.1.3 Recovery Mode” in HSE firmware reference manual rev. 2.7.&lt;/P&gt;
&lt;P&gt;In short, there are two modes:&lt;/P&gt;
&lt;P&gt;JTAG based recovery mode – the device just hangs in endless loop in RAM (this piece of code is loaded to RAM by SBAF), so user can connect a debugger and perform some recovery steps.&lt;/P&gt;
&lt;P&gt;Secure recovery mode – this needs to be enabled by attribute HSE_SECURE_RECOVERY_CONFIG_ATTR_ID. Notice that this is OTP attribute programmed to UTEST memory. This starts recovery image which needs to be verified first. So, it is similar to basic secure boot. If the verification fails, it goes to JTAG recovery mode.&lt;/P&gt;
&lt;P&gt;The secure recovery mode can be used for recovery/rollback in runtime. But I do not recommend to run this from passive partition. All the code should be executed from active partition. In AB swap mode, you will have a copy of secure recovery image in both partitions anyway.&lt;/P&gt;
&lt;P&gt;Another option is to put this code to data flash memory if there’s enough space.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2026 07:15:57 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/Fallback-mechanism-for-failed-AB-SWAP-update/m-p/2402764#M60302</guid>
      <dc:creator>lukaszadrapa</dc:creator>
      <dc:date>2026-08-07T07:15:57Z</dc:date>
    </item>
  </channel>
</rss>

