MCX A secure/signed mode in rom bootloader?

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 

MCX A secure/signed mode in rom bootloader?

595 次查看
dav1
Contributor V

Lets assume we want to design a system using MCX A-series that uses the ROM bootloader feature for end-customer firmware upgrades. 

Upgrades could happen via web-serial->usb or in-system updates via UART from another mcu, both talking directly to the rom boot code. 

I haven't looked in detail whats available in the newer MCX-series rom implementation, but the questions are:

  • is there a way to require a signed binary when using ROM boot?
    • i.e. write "otp-keys" to flash and force the bootloader to only accept valid binaries to be written

  • are there ways to prevent raw reads from flash while still having erase/write enabled?

 

in my case mcu pick would be: MCXA156VPJ

 

 

ps. fully aware I can write my own 2nd stage BL to achieve this, but the whole point here is to design a simple + brick-proof system.

0 项奖励
回复
2 回复数

564 次查看
Alice_Yang
NXP TechSupport
NXP TechSupport

Hello @dav1 

The MCXA series does not support secure or signed mode in the ROM bootloader.
Please consider using the MCXN series, which does support this feature.

https://www.nxp.com/products/processors-and-microcontrollers/arm-microcontrollers/general-purpose-mc... 

Thank you.

BR

Alice

0 项奖励
回复

430 次查看
dav1
Contributor V

1)

the N-series are too expensive for the application.
what other mcx'es do support secure rom-boot?

 

2)

are you 100% sure there isn't a way to achieve a secure update-path on A-series?

0 项奖励
回复
%3CLINGO-SUB%20id%3D%22lingo-sub-2315623%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EMCX%20A%20ROM%20%E5%BC%95%E5%AF%BC%E5%8A%A0%E8%BD%BD%E7%A8%8B%E5%BA%8F%E4%B8%AD%E7%9A%84%E5%AE%89%E5%85%A8%2F%E7%AD%BE%E5%90%8D%E6%A8%A1%E5%BC%8F%EF%BC%9F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2315623%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E5%81%87%E8%AE%BE%E6%88%91%E4%BB%AC%E8%A6%81%E8%AE%BE%E8%AE%A1%E4%B8%80%E4%B8%AA%E4%BD%BF%E7%94%A8%20MCX%20A%20%E7%B3%BB%E5%88%97%E7%9A%84%E7%B3%BB%E7%BB%9F%EF%BC%8C%E8%AF%A5%E7%B3%BB%E7%BB%9F%E4%BD%BF%E7%94%A8%20ROM%20%E5%BC%95%E5%AF%BC%E5%8A%A0%E8%BD%BD%E5%99%A8%E5%8A%9F%E8%83%BD%E8%BF%9B%E8%A1%8C%E7%BB%88%E7%AB%AF%E5%AE%A2%E6%88%B7%E5%9B%BA%E4%BB%B6%E5%8D%87%E7%BA%A7%E3%80%82%20%3C%2FP%3E%3CP%3E%E5%8D%87%E7%BA%A7%E5%8F%AF%E4%BB%A5%E9%80%9A%E8%BF%87%20web-serial-%26gt%3B%20usb%20%E8%BF%9B%E8%A1%8C%E5%8D%87%E7%BA%A7%EF%BC%8C%E4%B9%9F%E5%8F%AF%E4%BB%A5%E9%80%9A%E8%BF%87%20UART%20%E4%BB%8E%E5%8F%A6%E4%B8%80%E4%B8%AA%20mcu%20%E8%BF%9B%E8%A1%8C%E7%B3%BB%E7%BB%9F%E5%86%85%E6%9B%B4%E6%96%B0%EF%BC%8C%E4%B8%A4%E8%80%85%E9%83%BD%E7%9B%B4%E6%8E%A5%E4%B8%8E%20rom%20%E5%90%AF%E5%8A%A8%E4%BB%A3%E7%A0%81%E9%80%9A%E4%BF%A1%E3%80%82%3C%2FP%3E%3CP%3E%E6%88%91%E8%BF%98%E6%B2%A1%E6%9C%89%E8%AF%A6%E7%BB%86%E4%BA%86%E8%A7%A3%E6%9C%80%E6%96%B0%20MCX%20%E7%B3%BB%E5%88%97%20ROM%20%E7%9A%84%E5%AE%9E%E7%8E%B0%E6%83%85%E5%86%B5%EF%BC%8C%E4%BD%86%E9%97%AE%E9%A2%98%E6%98%AF%EF%BC%9A%3C%2FP%3E%3CUL%3E%3CLI%3E%E4%BD%BF%E7%94%A8ROM%E5%90%AF%E5%8A%A8%E6%97%B6%E6%9C%89%E6%B2%A1%E6%9C%89%E5%8A%9E%E6%B3%95%E9%9C%80%E8%A6%81%E7%AD%BE%E5%90%8D%E7%9A%84%E4%BA%8C%E8%BF%9B%E5%88%B6%E6%96%87%E4%BB%B6%EF%BC%9F%3CBR%20%2F%3E%3CUL%3E%3CLI%3E%E5%8D%B3%E5%B0%86%20%22%20otp-keys%20%22%20%E5%86%99%E5%85%A5%E9%97%AA%E5%AD%98%E5%B9%B6%E5%BC%BA%E5%88%B6%E5%BC%95%E5%AF%BC%E5%8A%A0%E8%BD%BD%E7%A8%8B%E5%BA%8F%E5%8F%AA%E6%8E%A5%E5%8F%97%E6%9C%89%E6%95%88%E7%9A%84%E4%BA%8C%E8%BF%9B%E5%88%B6%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3CLI%3E%E6%98%AF%E5%90%A6%E6%9C%89%E5%8A%9E%E6%B3%95%E5%9C%A8%E5%90%AF%E7%94%A8%E6%93%A6%E9%99%A4%2F%E5%86%99%E5%85%A5%E5%8A%9F%E8%83%BD%E7%9A%84%E5%90%8C%E6%97%B6%E9%98%B2%E6%AD%A2%E4%BB%8E%E9%97%AA%E5%AD%98%E8%BF%9B%E8%A1%8C%E5%8E%9F%E5%A7%8B%E8%AF%BB%E5%8F%96%EF%BC%9F%3C%2FLI%3E%3C%2FUL%3E%3CBR%20%2F%3E%3CP%3E%E5%9C%A8%E6%88%91%E7%9A%84%E6%83%85%E5%86%B5%E4%B8%8B%EF%BC%8CMCU%20%E5%BA%94%E8%AF%A5%E6%98%AFMCXA156VPJ%3C%2FP%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CP%3E%E6%88%91%E5%AE%8C%E5%85%A8%E7%9F%A5%E9%81%93%E6%88%91%E5%8F%AF%E4%BB%A5%E7%BC%96%E5%86%99%E8%87%AA%E5%B7%B1%E7%9A%84%E7%AC%AC%E4%BA%8C%E9%98%B6%E6%AE%B5%20BL%20%E6%9D%A5%E5%AE%9E%E7%8E%B0%E8%BF%99%E4%B8%80%E7%9B%AE%E6%A0%87%EF%BC%8C%E4%BD%86%E8%BF%99%E9%87%8C%E7%9A%84%E9%87%8D%E7%82%B9%E6%98%AF%E8%AE%BE%E8%AE%A1%E4%B8%80%E4%B8%AA%E7%AE%80%E5%8D%95%E4%B8%94%E9%98%B2%E7%A0%96%E7%9A%84%E7%B3%BB%E7%BB%9F%E3%80%82%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2315623%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CLINGO-LABEL%3E%E5%90%AF%E5%8A%A8%20ROM%20%7C%20%E5%90%AF%E5%8A%A8%E9%85%8D%E7%BD%AE%20%7C%20%E9%97%AA%E5%AD%98%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMCXA%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3E%E5%AE%89%E5%85%A8%EF%BC%88Edgelock%20%7C%20%E5%AE%89%E5%85%A8%E5%90%AF%E5%8A%A8%20%7C%20OTP%EF%BC%89%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2316189%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20MCX%20A%20secure%2Fsigned%20mode%20in%20rom%20bootloader%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2316189%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E4%BD%A0%E5%A5%BD%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F83226%22%20target%3D%22_blank%22%3E%40dav1%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%3EMCXA%20%E7%B3%BB%E5%88%97%E4%B8%8D%E6%94%AF%E6%8C%81%20ROM%20%E5%BC%95%E5%AF%BC%E5%8A%A0%E8%BD%BD%E7%A8%8B%E5%BA%8F%E7%9A%84%E5%AE%89%E5%85%A8%E6%88%96%E7%AD%BE%E5%90%8D%E6%A8%A1%E5%BC%8F%E3%80%82%3CBR%20%2F%3E%E8%AF%B7%E8%80%83%E8%99%91%E4%BD%BF%E7%94%A8%20MCXN%20%E7%B3%BB%E5%88%97%EF%BC%8C%E8%AF%A5%E7%B3%BB%E5%88%97%E6%94%AF%E6%8C%81%E6%AD%A4%E5%8A%9F%E8%83%BD%E3%80%82%3C%2FDIV%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fproducts%2Fprocessors-and-microcontrollers%2Farm-microcontrollers%2Fgeneral-purpose-mcus%2Fmcx-arm-cortex-m%2Fmcx-n-series-microcontrollers%3AMCX-N-SERIES%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.nxp.com%2Fproducts%2Fprocessors-and-microcontrollers%2Farm-microcontrollers%2Fgeneral-purpose-mcus%2Fmcx-arm-cortex-m%2Fmcx-n-series-microcontrollers%3AMCX-N-SERIES%3C%2FA%3E%20%3C%2FP%3E%0A%3CP%3E%E8%B0%A2%E8%B0%A2%EF%BC%81%3C%2FP%3E%0A%3CP%3EBR%3C%2FP%3E%0A%3CP%3E%E7%88%B1%E4%B8%BD%E4%B8%9D%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2326451%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20MCX%20A%20secure%2Fsigned%20mode%20in%20rom%20bootloader%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2326451%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E1%EF%BC%89%3C%2FP%3E%3CP%3E%E8%80%8C%20N%20%E7%B3%BB%E5%88%97%E7%9A%84%E4%BB%B7%E6%A0%BC%E5%AF%B9%E4%BA%8E%E8%BF%99%E7%A7%8D%E5%BA%94%E7%94%A8%E6%9D%A5%E8%AF%B4%E8%BF%87%E4%BA%8E%E6%98%82%E8%B4%B5%E3%80%82%3CBR%20%2F%3E%E8%BF%98%E6%9C%89%E5%93%AA%E4%BA%9B%20mcx%20%E6%94%AF%E6%8C%81%E5%AE%89%E5%85%A8%20rom-%E5%90%AF%E5%8A%A8%EF%BC%9F%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E2)%3C%2FP%3E%3CP%3E%E6%82%A8%E6%98%AF%E5%90%A6%20100%25%20%E7%A1%AE%E5%AE%9A%E6%B2%A1%E6%9C%89%E5%8A%9E%E6%B3%95%E5%9C%A8%20A%20%E7%B3%BB%E5%88%97%E4%B8%8A%E5%AE%9E%E7%8E%B0%E5%AE%89%E5%85%A8%E7%9A%84%E6%9B%B4%E6%96%B0%E8%B7%AF%E5%BE%84%EF%BC%9F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E