HSE_KF_ACCESS_DEBUG_PROT attribute actual intention

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

HSE_KF_ACCESS_DEBUG_PROT attribute actual intention

Jump to solution
2,047 Views
ale_di_vi
Contributor I

Hello,

In our company we are working on a project having MWCT2015S microcontroller.

We store keys in the HSE_B secure memory setting the HSE_KF_ACCESS_DEBUG_PROT attribute so that the keys cannot be accessed (i.e. used) when a debugger is connected. Some of the keys may need to be updated once the product is in field (vehicle usage).

The question is: what does the sentence "cannot be used" include? Does it refer only to prevent keys usage for cryptographic operations OR it means that they cannot completely handled when a debugger is connected?

So, is it possible to update debug protected keys when the debugger is connected?

ale_di_vi_0-1730275963982.png

 

Thank you in advance and best regards,

Alessandro Di Vincenzo

Tags (1)
0 Kudos
Reply
1 Solution
2,022 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @ale_di_vi 

here is an explanation from SHE specification:

lukaszadrapa_0-1730467558420.pnglukaszadrapa_0-1730467558420.png

Regards,

Lukas

View solution in original post

0 Kudos
Reply
4 Replies
2,023 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @ale_di_vi 

here is an explanation from SHE specification:

lukaszadrapa_0-1730467558420.pnglukaszadrapa_0-1730467558420.png

Regards,

Lukas

0 Kudos
Reply
1,998 Views
ale_di_vi
Contributor I
Hi Lukas,
We don't store the key in its SHE-format. Can I consider this statement valid also for the non-SHE keys managed according to table 31 in chapter 7.1.4.2 from the HSE_B RM?
Thank you in advance,
Alessandro
0 Kudos
Reply
1,958 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

It looks like you have older version of the manual. I recommend to download the latest one which is version 2.3.

It's the same for non-SHE keys. If you are importing a key first time (i.e. to empty slot), it can be loaded in plain. However, if you are updating a key, it is mandatory to use encryption and/or authentication (Table 47 and 48 in RM v2.3). So, this is also trusted operation as described in the SHE, there's no difference.

Regards,
Lukas

0 Kudos
Reply
1,944 Views
ale_di_vi
Contributor I
Ok, got it: debug protection flag is not a problem for key update.
Thank you Lukas
0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-1984546%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EHSE_KF_ACCESS_DEBUG_PROT%20attribute%20actual%20intention%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1984546%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EIn%20our%20company%20we%20are%20working%20on%20a%20project%20having%20MWCT2015S%20microcontroller.%3C%2FP%3E%3CP%3EWe%20store%20keys%20in%20the%20HSE_B%20secure%20memory%20setting%20the%26nbsp%3BHSE_KF_ACCESS_DEBUG_PROT%20attribute%20so%20that%20the%20keys%20cannot%20be%20accessed%20(i.e.%20used)%20when%20a%20debugger%20is%20connected.%20Some%20of%20the%20keys%20may%20need%20to%20be%20updated%20once%20the%20product%20is%20in%20field%20(vehicle%20usage).%3C%2FP%3E%3CP%3EThe%20question%20is%3A%20what%20does%20the%20sentence%20%22cannot%20be%20used%22%20include%3F%20Does%20it%20refer%20only%20to%26nbsp%3Bprevent%20keys%20usage%20for%20cryptographic%20operations%20OR%20it%20means%20that%20they%20cannot%20completely%20handled%20when%20a%20debugger%20is%20connected%3F%3C%2FP%3E%3CP%3ESo%2C%20is%20it%20possible%20to%20update%20debug%20protected%20keys%20when%20the%20debugger%20is%20connected%3F%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22ale_di_vi_0-1730275963982.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22ale_di_vi_0-1730275963982.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F307659i9CF4C31A2CD07B5C%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22ale_di_vi_0-1730275963982.png%22%20alt%3D%22ale_di_vi_0-1730275963982.png%22%20%2F%3E%3Cspan%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3Eale_di_vi_0-1730275963982.png%3C%2Fspan%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EThank%20you%20in%20advance%20and%20best%20regards%2C%3C%2FP%3E%3CP%3EAlessandro%20Di%20Vincenzo%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1989972%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ERe%3A%20HSE_KF_ACCESS_DEBUG_PROT%20attribute%20actual%20intention%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1989972%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EOk%2C%20got%20it%3A%20debug%20protection%20flag%20is%20not%20a%20problem%20for%20key%20update.%3CBR%20%2F%3EThank%20you%20Lukas%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1989793%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ERe%3A%20HSE_KF_ACCESS_DEBUG_PROT%20attribute%20actual%20intention%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1989793%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EIt%20looks%20like%20you%20have%20older%20version%20of%20the%20manual.%20I%20recommend%20to%20download%20the%20latest%20one%20which%20is%20version%202.3.%3C%2FP%3E%0A%3CP%3EIt's%20the%20same%20for%20non-SHE%20keys.%20If%20you%20are%20importing%20a%20key%20first%20time%20(i.e.%20to%20empty%20slot)%2C%20it%20can%20be%20loaded%20in%20plain.%20However%2C%20if%20you%20are%20updating%20a%20key%2C%20it%20is%20mandatory%20to%20use%20encryption%20and%2For%20authentication%20(Table%2047%20and%2048%20in%20RM%20v2.3).%20So%2C%20this%20is%20also%20trusted%20operation%20as%20described%20in%20the%20SHE%2C%20there's%20no%20difference.%3C%2FP%3E%0A%3CP%3ERegards%2C%3CBR%20%2F%3ELukas%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1986965%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ERe%3A%20HSE_KF_ACCESS_DEBUG_PROT%20attribute%20actual%20intention%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1986965%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EHi%20Lukas%2C%3CBR%20%2F%3EWe%20don't%20store%20the%20key%20in%20its%20SHE-format.%20Can%20I%20consider%20this%20statement%20valid%20also%20for%20the%20non-SHE%20keys%20managed%20according%20to%20table%2031%20in%20chapter%207.1.4.2%20from%20the%20HSE_B%20RM%3F%3CBR%20%2F%3EThank%20you%20in%20advance%2C%3CBR%20%2F%3EAlessandro%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1986287%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ERe%3A%20HSE_KF_ACCESS_DEBUG_PROT%20attribute%20actual%20intention%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1986287%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F218511%22%20target%3D%22_blank%22%3E%40ale_di_vi%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ehere%20is%20an%20explanation%20from%20SHE%20specification%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22lukaszadrapa_0-1730467558420.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22lukaszadrapa_0-1730467558420.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F308178iC38BE088C86EA433%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22lukaszadrapa_0-1730467558420.png%22%20alt%3D%22lukaszadrapa_0-1730467558420.png%22%20%2F%3E%3Cspan%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3Elukaszadrapa_0-1730467558420.png%3C%2Fspan%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3ERegards%2C%3C%2FP%3E%0A%3CP%3ELukas%3C%2FP%3E%3C%2FLINGO-BODY%3E