Backdoor Key Verify Failed in S32k146

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Backdoor Key Verify Failed in S32k146

Jump to solution
2,168 Views
xiongsl
Contributor I

Hi,

I'm trying to unlock MCU to unsecure using backdoor key but it fails, can you help me to analyze the reason, thanks!

1. I refer to the APIs in S32K1 SDK: FLASH_DRV_SecurityBypass and the return value is success!But it can't be debugged.

2. The value of 0x40C is 0xBF(0xAF)

3. JFlash using S32K146 (allow secure)

0 Kudos
Reply
1 Solution
2,114 Views
Robin_Shen
NXP TechSupport
NXP TechSupport

Hi

Be careful not to let the Segger J-Link reset the MCU after unsecure using backdoor key. For more detail please refer to the discussion in Unlock flash on S32K144W from firmware

36.5.12.2.1 Un-securing the MCU using backdoor key access.png36.5.12.2.1 Un-securing the MCU using backdoor key access.png


Best Regards,
Robin
-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!

- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

 

View solution in original post

0 Kudos
Reply
1 Reply
2,115 Views
Robin_Shen
NXP TechSupport
NXP TechSupport

Hi

Be careful not to let the Segger J-Link reset the MCU after unsecure using backdoor key. For more detail please refer to the discussion in Unlock flash on S32K144W from firmware

36.5.12.2.1 Un-securing the MCU using backdoor key access.png36.5.12.2.1 Un-securing the MCU using backdoor key access.png


Best Regards,
Robin
-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!

- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

 

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-1949189%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EBackdoor%20Key%20Verify%20Failed%20in%20S32k146%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1949189%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%EF%BC%8C%3C%2FP%3E%3CP%3EI'm%20trying%20to%20unlock%20MCU%20to%20unsecure%20using%20backdoor%20key%20but%20it%20fails%2C%20can%20you%20help%20me%20to%20analyze%20the%20reason%2C%20thanks!%3C%2FP%3E%3CP%3E1.%20I%20refer%20to%20the%20APIs%20in%20S32K1%20SDK%3A%26nbsp%3BFLASH_DRV_SecurityBypass%26nbsp%3Band%20the%20return%20value%20is%20success!But%20it%20can't%20be%20debugged.%3C%2FP%3E%3CP%3E2.%26nbsp%3BThe%20value%20of%200x40C%20is%200xBF(0xAF)%3C%2FP%3E%3CP%3E3.%26nbsp%3BJFlash%20using%20S32K146%20(allow%20secure)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1949787%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ERe%3A%20Backdoor%20Key%20Verify%20Failed%20in%20S32k146%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1949787%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%3C%2FP%3E%0A%3CP%3EBe%20careful%20not%20to%20let%20the%20Segger%20J-Link%20reset%20the%20MCU%20after%20unsecure%20using%20backdoor%20key.%20For%20more%20detail%20please%20refer%20to%20the%20discussion%20in%20%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2FS32K%2FUnlock-flash-on-S32K144W-from-firmware%2Ftd-p%2F1744546%22%20target%3D%22_self%22%3EUnlock%20flash%20on%20S32K144W%20from%20firmware%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%2236.5.12.2.1%20Un-securing%20the%20MCU%20using%20backdoor%20key%20access.png%22%20style%3D%22width%3A%20629px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%2236.5.12.2.1%20Un-securing%20the%20MCU%20using%20backdoor%20key%20access.png%22%20style%3D%22width%3A%20629px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F297819iDB729D2880629147%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%2236.5.12.2.1%20Un-securing%20the%20MCU%20using%20backdoor%20key%20access.png%22%20alt%3D%2236.5.12.2.1%20Un-securing%20the%20MCU%20using%20backdoor%20key%20access.png%22%20%2F%3E%3Cspan%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3E36.5.12.2.1%20Un-securing%20the%20MCU%20using%20backdoor%20key%20access.png%3C%2Fspan%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3EBest%20Regards%2C%3CBR%20%2F%3ERobin%3CBR%20%2F%3E-------------------------------------------------------------------------------%3CBR%20%2F%3ENote%3A%3CBR%20%2F%3E-%20If%20this%20post%20answers%20your%20question%2C%20please%20click%20the%20%22Mark%20Correct%22%20button.%20Thank%20you!%3C%2FP%3E%0A%3CP%3E-%20We%20are%20following%20threads%20for%207%20weeks%20after%20the%20last%20post%2C%20later%20replies%20are%20ignored%3CBR%20%2F%3EPlease%20open%20a%20new%20thread%20and%20refer%20to%20the%20closed%20one%2C%20if%20you%20have%20a%20related%20question%20at%20a%20later%20point%20in%20time.%3CBR%20%2F%3E-------------------------------------------------------------------------------%3C%2FP%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E