Now,I Used “HseLib_HseFwInstall”software witch is supply by NXP engineer to install HSE FW。
Our customer raise a question: how to confirm HSE FW authenticity, because he think HSE FW itself don't have any signature,.it is easy 屏幕截图 2026-09-17 182416.png屏幕截图 2026-09-17 182416.pngto be tampered.
Who can tell me HSE FW weather have some security scheme to comfirm HSE FW authenticity?
Possibly you could create new ticket:
https://www.nxp.com/support/support:SUPPORTHOME
HSE documents are secure files, so following procedure is needed to follow unless you have already done it before:
https://www.nxp.com/docs/en/user-guide/nxp-secure-access-rights-registration.pdf
We could possibly share some presentation.
Thank you for answer this question.Could you tell me how can I find these reference about these contents.In
Hi,
HSE FW is indeed protected — it is not plain unsigned binary.
The FW image is encrypted and signed by NXP before distribution.
NXP pre-programs ROM keys into the HSE subsystem during manufacturing (hardware Root of Trust). These keys are never accessible externally.
During installation, the on-chip Secure BAF uses those ROM keys to authenticate the image before writing it to flash. A tampered image is rejected.
Bottom line: without NXP's private signing key, it is impossible to install a modified HSE FW. The trust is rooted in silicon.