Several customers asked us if they can use Secure Element to add secure boot function to the host which does not have secure boot function.
For host FW verification use case, NXP provides the following application note for such use case.
EdgeLockTM SE05x to enhance the MCU boot sequence security
In this application note, I see following description.
"Note: The host device must ensure that the bootloader is not alterable ; otherwise a skilled attacker might be able to bypass the whole secure boot process."
My understanding is, to achieve this, the bootloader which uses Secure Element itself should be verified using secure boot function in the host. Am I right?
Or do we know any customer who accepts to use Secure Element for host FW verification with the host without secure boot?
Hello Schinji,
If the bootloader is not alterable then there is no need to verify using secure boot function in host.
We suggest in AN to use Secure element for host FW verification but don't know exactly which customers are using it.
Kind regards,
Parth