<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic S32K148 - SECRET KEY in S32K</title>
    <link>https://community.nxp.com/t5/S32K/S32K148-SECRET-KEY/m-p/1206284#M9467</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;This chip is pre-provisioned with a cryptographic&amp;nbsp;key at the NXP fab/plant, called the MCU SECRET KEY.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It&amp;nbsp;allows NXP to execute a mass-erase on the chip if the on-board application gets&amp;nbsp;corrupted and the chip cannot be accessed using the normal process.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The method to use this key is not well documented as far as I know and I assume part of it confidential.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My customer expressed a concern that this key may be abused to brick the product (i.e. a tool for denial of service).&amp;nbsp;&lt;/P&gt;&lt;P&gt;This may happen if the method to use this key becomes public domain information because of academic research or a breach at NXP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The customer asked if there is any official statement from NXP regarding this secret key and the possibility of abuse it?&lt;/P&gt;&lt;P&gt;Please advise back, Thanks in advance.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Shai&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jan 2021 21:26:59 GMT</pubDate>
    <dc:creator>shai_b</dc:creator>
    <dc:date>2021-01-04T21:26:59Z</dc:date>
    <item>
      <title>S32K148 - SECRET KEY</title>
      <link>https://community.nxp.com/t5/S32K/S32K148-SECRET-KEY/m-p/1206284#M9467</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;This chip is pre-provisioned with a cryptographic&amp;nbsp;key at the NXP fab/plant, called the MCU SECRET KEY.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It&amp;nbsp;allows NXP to execute a mass-erase on the chip if the on-board application gets&amp;nbsp;corrupted and the chip cannot be accessed using the normal process.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The method to use this key is not well documented as far as I know and I assume part of it confidential.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My customer expressed a concern that this key may be abused to brick the product (i.e. a tool for denial of service).&amp;nbsp;&lt;/P&gt;&lt;P&gt;This may happen if the method to use this key becomes public domain information because of academic research or a breach at NXP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The customer asked if there is any official statement from NXP regarding this secret key and the possibility of abuse it?&lt;/P&gt;&lt;P&gt;Please advise back, Thanks in advance.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Shai&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 21:26:59 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K148-SECRET-KEY/m-p/1206284#M9467</guid>
      <dc:creator>shai_b</dc:creator>
      <dc:date>2021-01-04T21:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: S32K148 - SECRET KEY</title>
      <link>https://community.nxp.com/t5/S32K/S32K148-SECRET-KEY/m-p/1208844#M9526</link>
      <description>&lt;P&gt;Hello Shai,&lt;/P&gt;
&lt;P&gt;The information you have is incorrect.&lt;/P&gt;
&lt;P&gt;The key you are referring to is unique for each device and is unknown to NXP or any device user, as it is generated "on chip" and never exposed.&lt;/P&gt;
&lt;P&gt;Furthermore, it cannot be used to "mass erase" the device.&lt;/P&gt;
&lt;P&gt;If you want / need more information, please send a private message.&lt;/P&gt;
&lt;P&gt;Hope this clarifies.&lt;/P&gt;
&lt;P&gt;-Fabrice&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 09:24:58 GMT</pubDate>
      <guid>https://community.nxp.com/t5/S32K/S32K148-SECRET-KEY/m-p/1208844#M9526</guid>
      <dc:creator>FabricePoulard</dc:creator>
      <dc:date>2021-01-08T09:24:58Z</dc:date>
    </item>
  </channel>
</rss>

