mcxn947 加密区域可以指定范围么,程序内部如何访问flash加密区 Can encryption and signing be applied to a specified range of flash space? How does the program's own read/write behavior within the encrypted flash region differ from before (is the data read back ciphertext? is the data written plaintext?)? During OTA upgrades, how can the architecture be made to match the chip's encryption/decryption without conflicts? Re: mcxn947 加密区域可以指定范围么,程序内部如何访问flash加密区 Hello,
To be clear first: once encryption is enabled, when a program running on the chip writes to flash, the data it writes is plaintext, but what is ultimately stored in flash is ciphertext; when the ciphertext in flash is read by a program running on the chip, it comes out as plaintext.
Correct
Based on above viewpoint :
Then, the SB file read by your Secure Provisioning software is ciphertext, and what is sent over serial ISP to the chip’s factory ISP ROM bootloader must also be ciphertext (otherwise there would be a logical flaw). The factory ISP ROM bootloader decrypts the ciphertext received over serial into plaintext, and then writes the plaintext data into flash, but ultimately the data stored in flash is encrypted again, becoming ciphertext.
In other words, during ISP programming, the factory ISP ROM bootloader first decrypts and then encrypts, going through a decrypt-then-encrypt round trip.
Let me put more light into this:
yes SB file is encrypted and must be decrypted by ROM before writing to Flash. But SB file is encrypted completely independently, to protect the firmware between the OEM and manufacturing facility.
Programming flash, either internal or external, is different story and either is not used at all or is used with different algorithm, initial vector, etc.
Regards,
Libor Re: mcxn947 加密区域可以指定范围么,程序内部如何访问flash加密区 To be clear first: once encryption is enabled, when a program running on the chip writes to flash, the data it writes is plaintext, but what is ultimately stored in flash is ciphertext; when the ciphertext in flash is read by a program running on the chip, it comes out as plaintext. Based on above viewpoint : Then, the SB file read by your Secure Provisioning software is ciphertext, and what is sent over serial ISP to the chip’s factory ISP ROM bootloader must also be ciphertext (otherwise there would be a logical flaw). The factory ISP ROM bootloader decrypts the ciphertext received over serial into plaintext, and then writes the plaintext data into flash, but ultimately the data stored in flash is encrypted again, becoming ciphertext. In other words, during ISP programming, the factory ISP ROM bootloader first decrypts and then encrypts, going through a decrypt-then-encrypt round trip. Re: mcxn947 加密区域可以指定范围么,程序内部如何访问flash加密区 Hi,
For MCXN devices:
Can encryption and signing be applied to a specified range of flash space?
SEC tool:
- signs whole application
- encryption region is configured once in the product lifetime, you need to make a reserve for future updates (increased size of app)
How does the program's own read/write behavior within the encrypted flash region differ from before (is the data read back ciphertext? is the data written plaintext?)?
Encryption/decryption is on-the-fly. App reading from flash does not need to care, it is transparent. About writing to encrypted flash region from the application itself, you need to investigate, I'm not sure if there are any caveats.
During OTA upgrades, how can the architecture be made to match the chip's encryption/decryption without conflicts?
As mentioned above, you need to specify reasonable size of memory region for encryption. If you application exceeds the encrypted region, OTA will work, only the part of the app that will be outside of encrypted area will still work, only your IP won't be protected by the encryption.
Regards,
Libor
View full article