<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>LPC MicrocontrollersのトピックLPC55: Device enters ISP mode instead of booting Signed Master Boot Image (MBI) at 0x0</title>
    <link>https://community.nxp.com/t5/LPC-Microcontrollers/LPC55-Device-enters-ISP-mode-instead-of-booting-Signed-Master/m-p/2328506#M59442</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello NXP Community,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am having trouble with the Secure Boot flow on an LPC55S28. I have a &lt;/SPAN&gt;&lt;SPAN&gt;Primary Image&lt;/SPAN&gt;&lt;SPAN&gt; located at address 0x00000000 which has been processed into a &lt;/SPAN&gt;&lt;SPAN&gt;Signed Master Boot Image (MBI)&lt;/SPAN&gt;&lt;SPAN&gt; using the NXP Secure Provisioning Tool.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Despite the image being signed and the CMPA/CFPA being provisioned, the device ignores the image upon reset and enters &lt;/SPAN&gt;&lt;SPAN&gt;ISP mode&lt;/SPAN&gt;&lt;SPAN&gt; (appearing as a HID/VCOM device).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PFR Configuration (CMPA/CFPA):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have provisioned the PFR with the following values to ensure debug access remains open and the certificate chain is valid:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;SEC_BOOT_EN:&lt;/SPAN&gt;&lt;SPAN&gt; 0x01 (Signed Mode enabled in SECURE_BOOT_CFG).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;ROTKH:&lt;/SPAN&gt;&lt;SPAN&gt; Programmed and verified. The SHA-256 hash read back from the CMPA matches the value provided by the signing tool exactly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;ROT_KEY_EN:&lt;/SPAN&gt;&lt;SPAN&gt; All bits set to 1 (all keys enabled).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;CFPA Version:&lt;/SPAN&gt;&lt;SPAN&gt; Correctly incremented with every write to ensure the anti-rollback counter is satisfied.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;Debug Boundaries:&lt;/SPAN&gt;&lt;SPAN&gt; CC_SOCU_PIN and CC_SOCU_DFLT (CMPA/CFPA) are all set to 0xFE2001DF to maintain SWD/JTAG access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Issue:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The signed .bin file at address 0x0 contains a valid MBI header, yet the ROM refuses to boot and falls back to ISP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Since the device enters ISP mode, does this strictly imply a &lt;/SPAN&gt;&lt;SPAN&gt;trust failure&lt;/SPAN&gt;&lt;SPAN&gt; (ROTKH mismatch), or could an &lt;/SPAN&gt;&lt;SPAN&gt;integrity failure&lt;/SPAN&gt;&lt;SPAN&gt; (Signature/Hash check) also trigger the ISP fallback?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. Is there a specific register (like a ROM status flag) I can inspect while the device is in this ISP state to determine the exact reason the ROM rejected the image?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. If the ROM reaches ISP mode, does it mean the MBI header was at least parsed correctly, or is ISP the default behavior for any failure at address 0x0 when Secure Boot is enabled?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4. Are there any hidden dependencies in the CMPA/CFPA (other than ROTKH, ROT_KEY_EN, and SEC_BOOT_yEN) that must be configured for a standard signed XIP image to be accepted by the ROM?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your help&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 08 Mar 2026 15:09:42 GMT</pubDate>
    <dc:creator>samehgrira</dc:creator>
    <dc:date>2026-03-08T15:09:42Z</dc:date>
    <item>
      <title>LPC55: Device enters ISP mode instead of booting Signed Master Boot Image (MBI) at 0x0</title>
      <link>https://community.nxp.com/t5/LPC-Microcontrollers/LPC55-Device-enters-ISP-mode-instead-of-booting-Signed-Master/m-p/2328506#M59442</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello NXP Community,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am having trouble with the Secure Boot flow on an LPC55S28. I have a &lt;/SPAN&gt;&lt;SPAN&gt;Primary Image&lt;/SPAN&gt;&lt;SPAN&gt; located at address 0x00000000 which has been processed into a &lt;/SPAN&gt;&lt;SPAN&gt;Signed Master Boot Image (MBI)&lt;/SPAN&gt;&lt;SPAN&gt; using the NXP Secure Provisioning Tool.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Despite the image being signed and the CMPA/CFPA being provisioned, the device ignores the image upon reset and enters &lt;/SPAN&gt;&lt;SPAN&gt;ISP mode&lt;/SPAN&gt;&lt;SPAN&gt; (appearing as a HID/VCOM device).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PFR Configuration (CMPA/CFPA):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have provisioned the PFR with the following values to ensure debug access remains open and the certificate chain is valid:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;SEC_BOOT_EN:&lt;/SPAN&gt;&lt;SPAN&gt; 0x01 (Signed Mode enabled in SECURE_BOOT_CFG).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;ROTKH:&lt;/SPAN&gt;&lt;SPAN&gt; Programmed and verified. The SHA-256 hash read back from the CMPA matches the value provided by the signing tool exactly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;ROT_KEY_EN:&lt;/SPAN&gt;&lt;SPAN&gt; All bits set to 1 (all keys enabled).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;CFPA Version:&lt;/SPAN&gt;&lt;SPAN&gt; Correctly incremented with every write to ensure the anti-rollback counter is satisfied.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;Debug Boundaries:&lt;/SPAN&gt;&lt;SPAN&gt; CC_SOCU_PIN and CC_SOCU_DFLT (CMPA/CFPA) are all set to 0xFE2001DF to maintain SWD/JTAG access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Issue:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The signed .bin file at address 0x0 contains a valid MBI header, yet the ROM refuses to boot and falls back to ISP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Since the device enters ISP mode, does this strictly imply a &lt;/SPAN&gt;&lt;SPAN&gt;trust failure&lt;/SPAN&gt;&lt;SPAN&gt; (ROTKH mismatch), or could an &lt;/SPAN&gt;&lt;SPAN&gt;integrity failure&lt;/SPAN&gt;&lt;SPAN&gt; (Signature/Hash check) also trigger the ISP fallback?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. Is there a specific register (like a ROM status flag) I can inspect while the device is in this ISP state to determine the exact reason the ROM rejected the image?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. If the ROM reaches ISP mode, does it mean the MBI header was at least parsed correctly, or is ISP the default behavior for any failure at address 0x0 when Secure Boot is enabled?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4. Are there any hidden dependencies in the CMPA/CFPA (other than ROTKH, ROT_KEY_EN, and SEC_BOOT_yEN) that must be configured for a standard signed XIP image to be accepted by the ROM?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your help&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 15:09:42 GMT</pubDate>
      <guid>https://community.nxp.com/t5/LPC-Microcontrollers/LPC55-Device-enters-ISP-mode-instead-of-booting-Signed-Master/m-p/2328506#M59442</guid>
      <dc:creator>samehgrira</dc:creator>
      <dc:date>2026-03-08T15:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: LPC55: Device enters ISP mode instead of booting Signed Master Boot Image (MBI) at 0x0</title>
      <link>https://community.nxp.com/t5/LPC-Microcontrollers/LPC55-Device-enters-ISP-mode-instead-of-booting-Signed-Master/m-p/2328930#M59444</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/260512"&gt;@samehgrira&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;For first‑time use of the secure boot function on the LPC55S28, I strongly recommend using the Secure Provisioning Tool and referring to the&amp;nbsp; "6.5 LPC55(S)0x/1x/2x/6x device workflow" of the user guide. It describe the steps more detail.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Thank you.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;BR&lt;/DIV&gt;
&lt;DIV&gt;Alice&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 09 Mar 2026 10:50:28 GMT</pubDate>
      <guid>https://community.nxp.com/t5/LPC-Microcontrollers/LPC55-Device-enters-ISP-mode-instead-of-booting-Signed-Master/m-p/2328930#M59444</guid>
      <dc:creator>Alice_Yang</dc:creator>
      <dc:date>2026-03-09T10:50:28Z</dc:date>
    </item>
  </channel>
</rss>

