<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックSecure debug on i.MX93 with NXP keys</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Secure-debug-on-i-MX93-with-NXP-keys/m-p/2400627#M246216</link>
    <description>&lt;P&gt;The current version of the nxpdebugmbox tool from the SPSDK has a parameter --nxp-keys that is described as "Use the ROM NXP keys to authenticate."&lt;/P&gt;&lt;P&gt;Does this mean that NXP can unlock secure debug on all devices?&lt;/P&gt;&lt;P&gt;If yes, is there any fuse to restrict secure debug to the OEM SRK keys?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2026 18:44:57 GMT</pubDate>
    <dc:creator>danielgloeckner</dc:creator>
    <dc:date>2026-07-30T18:44:57Z</dc:date>
    <item>
      <title>Secure debug on i.MX93 with NXP keys</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Secure-debug-on-i-MX93-with-NXP-keys/m-p/2400627#M246216</link>
      <description>&lt;P&gt;The current version of the nxpdebugmbox tool from the SPSDK has a parameter --nxp-keys that is described as "Use the ROM NXP keys to authenticate."&lt;/P&gt;&lt;P&gt;Does this mean that NXP can unlock secure debug on all devices?&lt;/P&gt;&lt;P&gt;If yes, is there any fuse to restrict secure debug to the OEM SRK keys?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 18:44:57 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Secure-debug-on-i-MX93-with-NXP-keys/m-p/2400627#M246216</guid>
      <dc:creator>danielgloeckner</dc:creator>
      <dc:date>2026-07-30T18:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Secure debug on i.MX93 with NXP keys</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Secure-debug-on-i-MX93-with-NXP-keys/m-p/2400651#M246219</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;SPAN&gt;&lt;BR /&gt;No, NXP cannot unlock secure debug on OEM devices with --nxp-keys.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The --nxp-keys flag only authenticates the NXP/ELE internal debug domain (using ROM-embedded NXP keys). The OEM SoC debug domain (Cortex-A55, M33, etc.) is completely separate and can only be unlocked with the OEM's own SRK keys.&lt;/P&gt;
&lt;P&gt;No additional fuse is needed to enforce this, it is architectural by design. Once the device is in OEM_CLOSED lifecycle with the OEM SRK hash fused, the ELE hardware enforces that NXP keys have zero authority over the OEM debug domain.&lt;BR /&gt;&lt;BR /&gt;Best regards/Saludos,&lt;BR /&gt;Aldo.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 22:03:46 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Secure-debug-on-i-MX93-with-NXP-keys/m-p/2400651#M246219</guid>
      <dc:creator>AldoG</dc:creator>
      <dc:date>2026-07-30T22:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Secure debug on i.MX93 with NXP keys</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Secure-debug-on-i-MX93-with-NXP-keys/m-p/2400654#M246220</link>
      <description>But if you have control over the ELE, you have access to the DDR memory and can monitor the inputs and outputs of all crypto operations requested by the OEM domain from the ELE domain. You can decrypt all ELE blobs and have therefore access to all secret data stored on the device. And unless writing to DDR memory is prevented, you can inject code into the OEM domain.</description>
      <pubDate>Thu, 30 Jul 2026 22:22:26 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Secure-debug-on-i-MX93-with-NXP-keys/m-p/2400654#M246220</guid>
      <dc:creator>danielgloeckner</dc:creator>
      <dc:date>2026-07-30T22:22:26Z</dc:date>
    </item>
  </channel>
</rss>

