Fallback mechanism for failed AB_SWAP update

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Fallback mechanism for failed AB_SWAP update

83 Views
Shiv_peak
Contributor I

Hello,
We are developing an application that uses the AB_SWAP mechanism of the HSE firmware on the S32K342 to perform OTA updates. We are currently activating the passive block once the passive region of the flash is entirely written to.
We were wondering whether there is a fallback mechanism that we can use to verify/check whether the image we are booting from is corrupted, and if we can fallback to the 'known good' active region that has become the passive region after resetting.
This arises from the fact that on some occasions, we overwrite the passive region without issuing a reset and midway through we reset the processor, resulting in a corrupted image in the flash. 

0 Kudos
Reply
6 Replies

59 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @Shiv_peak 

 

I answered very similar question a couple of days ago, please take a look at:

https://community.nxp.com/t5/S32K/S32K-OTA-Rollback/m-p/2400332/highlight/true#M60125

 

If you need more details, just let me know.

 

Regards,

Lukas

0 Kudos
Reply

46 Views
Shiv_peak
Contributor I

Hey @lukaszadrapa ,
Thanks for the clarification. We are still trying to understand which type of secure boot strategy to use in our application. Advance Secure boot seems a bit complicated with having to install the SMR and CR.

On the other hand, Basic Secure boot seems slightly easier to install but the exact implementation and installation details seem unclear.
I was wondering if you could provide some insight into these options. I am referring to the HSE B Reference Manual and was also wondering if there is any additional documentation I should be referring to for this.

Regards,
Shiv

0 Kudos
Reply

30 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

We provide this application note:

https://www.nxp.com/webapp/Download?colCode=AN13465

 

It’s updated version of Secure Boot application note v0.1.1.0 (AN744511) released in 2021 which can be downloaded from:

https://www.nxp.com/products/S32K3

Application note can be found here:

Documentation -> Secure Files -> Secure Boot Application note v0.1.1.0 (AN744511)

Associated demo project can be downloaded here:

Design Resources -> Software -> Secure Files -> SecureBootAppNoteDemo (SW745310)

 

The software was not updated, so use mentioned SW745310 if you are interested.

 

Other examples for secure boot can be found in HSE Demo Examples (recommended):

https://www.nxp.com/webapp/Download?colCode=S32K3_HSE_DemoExamples

There are examples for all three modes – advanced secure boot, basic secure boot and SHE secure boot.

 

Generally, advanced secure boot mode is recommended. Yes, it is not trivial task to configure the secure boot in this mode. However, it provides the best protection and configurability. The advantage is that you can select any signature scheme you want,  you can cover multiple regions and you can configure different sanctions if the secure boot fails.

On other hand, basic secure boot mode always uses only GMAC tag which is calculated using a key derived from ADKP and it can cover one region only. If it fails, the device goes directly to recovery mode.

I recommend to study following projects in HSE DemoExamples:

S32K344_Advanced_SecureBoot

S32K344_Basic_SecureBoot

These are configuration projects which are supposed to protect application S32K344_SecureBootBlinky which is linked to those projects.

Regards,

Lukas

0 Kudos
Reply

23 Views
Shiv_peak
Contributor I

Can you also elaborate on what you mean by 'device goes in recovery mode' if the basic secure boot fails? Does this mean that the core will not be released from reset and there is no fallback or recovery in this case?
I ask because we want to have the functionality where if the secure boot fails, we boot another image, possibly in the passive bank.

0 Kudos
Reply

14 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

Take a look at section “2.6.1.3 Recovery Mode” in HSE firmware reference manual rev. 2.7.

In short, there are two modes:

JTAG based recovery mode – the device just hangs in endless loop in RAM (this piece of code is loaded to RAM by SBAF), so user can connect a debugger and perform some recovery steps.

Secure recovery mode – this needs to be enabled by attribute HSE_SECURE_RECOVERY_CONFIG_ATTR_ID. Notice that this is OTP attribute programmed to UTEST memory. This starts recovery image which needs to be verified first. So, it is similar to basic secure boot. If the verification fails, it goes to JTAG recovery mode.

The secure recovery mode can be used for recovery/rollback in runtime. But I do not recommend to run this from passive partition. All the code should be executed from active partition. In AB swap mode, you will have a copy of secure recovery image in both partitions anyway.

Another option is to put this code to data flash memory if there’s enough space.

0 Kudos
Reply

25 Views
Shiv_peak
Contributor I

Thanks for the clarity Lukas.
I will look into the application note and the HSE demo examples and revert back in case of any queries.

Regards,
Shiv

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2401970%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EFallback%20mechanism%20for%20failed%20AB_SWAP%20update%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2401970%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%3CBR%20%2F%3EWe%20are%20developing%20an%20application%20that%20uses%20the%20AB_SWAP%20mechanism%20of%20the%20HSE%20firmware%20on%20the%20S32K342%20to%20perform%20OTA%20updates.%20We%20are%20currently%20activating%20the%20passive%20block%20once%20the%20passive%20region%20of%20the%20flash%20is%20entirely%20written%20to.%3CBR%20%2F%3EWe%20were%20wondering%20whether%20there%20is%20a%20fallback%20mechanism%20that%20we%20can%20use%20to%20verify%2Fcheck%20whether%20the%20image%20we%20are%20booting%20from%20is%20corrupted%2C%20and%20if%20we%20can%20fallback%20to%20the%20'known%20good'%20active%20region%20that%20has%20become%20the%20passive%20region%20after%20resetting.%3CBR%20%2F%3EThis%20arises%20from%20the%20fact%20that%20on%20some%20occasions%2C%20we%20overwrite%20the%20passive%20region%20without%20issuing%20a%20reset%20and%20midway%20through%20we%20reset%20the%20processor%2C%20resulting%20in%20a%20corrupted%20image%20in%20the%20flash.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2402216%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Fallback%20mechanism%20for%20failed%20AB_SWAP%20update%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2402216%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F37795%22%20target%3D%22_blank%22%3E%40lukaszadrapa%3C%2FA%3E%26nbsp%3B%2C%3CBR%20%2F%3EThanks%20for%20the%20clarification.%20We%20are%20still%20trying%20to%20understand%20which%20type%20of%20secure%20boot%20strategy%20to%20use%20in%20our%20application.%20Advance%20Secure%20boot%20seems%20a%20bit%20complicated%20with%20having%20to%20install%20the%20SMR%20and%20CR.%3C%2FP%3E%3CP%3EOn%20the%20other%20hand%2C%20Basic%20Secure%20boot%20seems%20slightly%20easier%20to%20install%20but%20the%20exact%20implementation%20and%20installation%20details%20seem%20unclear.%3CBR%20%2F%3EI%20was%20wondering%20if%20you%20could%20provide%20some%20insight%20into%20these%20options.%20I%20am%20referring%20to%20the%20HSE%20B%20Reference%20Manual%20and%20was%20also%20wondering%20if%20there%20is%20any%20additional%20documentation%20I%20should%20be%20referring%20to%20for%20this.%3CBR%20%2F%3E%3CBR%20%2F%3ERegards%2C%3CBR%20%2F%3EShiv%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2402093%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Fallback%20mechanism%20for%20failed%20AB_SWAP%20update%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2402093%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F254999%22%20target%3D%22_blank%22%3E%40Shiv_peak%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EI%20answered%20very%20similar%20question%20a%20couple%20of%20days%20ago%2C%20please%20take%20a%20look%20at%3A%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2FS32K%2FS32K-OTA-Rollback%2Fm-p%2F2400332%2Fhighlight%2Ftrue%23M60125%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Fcommunity.nxp.com%2Ft5%2FS32K%2FS32K-OTA-Rollback%2Fm-p%2F2400332%2Fhighlight%2Ftrue%23M60125%3C%2FA%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EIf%20you%20need%20more%20details%2C%20just%20let%20me%20know.%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3ERegards%2C%3C%2FP%3E%0A%3CP%3ELukas%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2402604%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Fallback%20mechanism%20for%20failed%20AB_SWAP%20update%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2402604%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3ECan%20you%20also%20elaborate%20on%20what%20you%20mean%20by%20'device%20goes%20in%20recovery%20mode'%20if%20the%20basic%20secure%20boot%20fails%3F%20Does%20this%20mean%20that%20the%20core%20will%20not%20be%20released%20from%20reset%20and%20there%20is%20no%20fallback%20or%20recovery%20in%20this%20case%3F%3CBR%20%2F%3EI%20ask%20because%20we%20want%20to%20have%20the%20functionality%20where%20if%20the%20secure%20boot%20fails%2C%20we%20boot%20another%20image%2C%20possibly%20in%20the%20passive%20bank.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2402456%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Fallback%20mechanism%20for%20failed%20AB_SWAP%20update%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2402456%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CSPAN%3EWe%20provide%20this%20application%20note%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fwebapp%2FDownload%3FcolCode%3DAN13465%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.nxp.com%2Fwebapp%2FDownload%3FcolCode%3DAN13465%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EIt%E2%80%99s%20updated%20version%20of%20Secure%20Boot%20application%20note%20v0.1.1.0%20(AN744511)%20released%20in%202021%20which%20can%20be%20downloaded%20from%3A%20%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fproducts%2FS32K3%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.nxp.com%2Fproducts%2FS32K3%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EApplication%20note%20can%20be%20found%20here%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EDocumentation%20-%26gt%3B%20Secure%20Files%20-%26gt%3B%20Secure%20Boot%20Application%20note%20v0.1.1.0%20(AN744511)%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EAssociated%20demo%20project%20can%20be%20downloaded%20here%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EDesign%20Resources%20-%26gt%3B%20Software%20-%26gt%3B%20Secure%20Files%20-%26gt%3B%20SecureBootAppNoteDemo%20(SW745310)%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EThe%20software%20was%20not%20updated%2C%20so%20use%20mentioned%20%3CSPAN%3ESW745310%20if%20you%20are%20interested.%20%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EOther%20examples%20for%20secure%20boot%20can%20be%20found%20in%20HSE%20Demo%20Examples%20(recommended)%3A%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fwebapp%2FDownload%3FcolCode%3DS32K3_HSE_DemoExamples%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.nxp.com%2Fwebapp%2FDownload%3FcolCode%3DS32K3_HSE_DemoExamples%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EThere%20are%20examples%20for%20all%20three%20modes%20%E2%80%93%20advanced%20secure%20boot%2C%20basic%20secure%20boot%20and%20SHE%20secure%20boot.%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EGenerally%2C%20advanced%20secure%20boot%20mode%20is%20recommended.%20Yes%2C%20it%20is%20not%20trivial%20task%20to%20configure%20the%20secure%20boot%20in%20this%20mode.%20However%2C%20it%20provides%20the%20best%20protection%20and%20configurability.%20The%20advantage%20is%20that%20you%20can%20select%20any%20signature%20scheme%20you%20want%2C%20%26nbsp%3Byou%20can%20cover%20multiple%20regions%20and%20you%20can%20configure%20different%20sanctions%20if%20the%20secure%20boot%20fails.%3C%2FP%3E%0A%3CP%3EOn%20other%20hand%2C%20basic%20secure%20boot%20mode%20always%20uses%20only%20GMAC%20tag%20which%20is%20calculated%20using%20a%20key%20derived%20from%20ADKP%20and%20it%20can%20cover%20one%20region%20only.%20If%20it%20fails%2C%20the%20device%20goes%20directly%20to%20recovery%20mode.%3C%2FP%3E%0A%3CP%3EI%20recommend%20to%20study%20following%20projects%20in%20HSE%20DemoExamples%3A%3C%2FP%3E%0A%3CP%3ES32K344_Advanced_SecureBoot%3C%2FP%3E%0A%3CP%3ES32K344_Basic_SecureBoot%3C%2FP%3E%0A%3CP%3EThese%20are%20configuration%20projects%20which%20are%20supposed%20to%20protect%20application%20S32K344_SecureBootBlinky%20which%20is%20linked%20to%20those%20projects.%3C%2FP%3E%0A%3CP%3ERegards%2C%3C%2FP%3E%0A%3CP%3ELukas%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2402593%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Fallback%20mechanism%20for%20failed%20AB_SWAP%20update%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2402593%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EThanks%20for%20the%20clarity%20Lukas.%3CBR%20%2F%3EI%20will%20look%20into%20the%20application%20note%20and%20the%20HSE%20demo%20examples%20and%20revert%20back%20in%20case%20of%20any%20queries.%3CBR%20%2F%3E%3CBR%20%2F%3ERegards%2C%3CBR%20%2F%3EShiv%3C%2FP%3E%3C%2FLINGO-BODY%3E