S32K144 CSEc Application MAC Storage Options for Secure Boot Verification

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

S32K144 CSEc Application MAC Storage Options for Secure Boot Verification

787件の閲覧回数
Kishore_14
Contributor III

Hardware: S32K144EVB-Q100
Software: S32 Design Studio, OpenBLT Bootloader, an5401-csec

We intend to protect only the bootloader using BOOT_DEFINE (16KB protected) and want the bootloader to verify the application MAC on every reset to establish a proper chain of trust.


We currently have a hardcoded CMAC value that we store and verify upon every reset as a proof of concept.

After bootloader verification (BOK=1), we need to verify application on every reset. For this, we need to:

  1. Store application MAC somewhere during programming
  2. Verify application MAC on every reset

We've considered these options but have concerns:

  • CSEc KEY slots (like KEY_2): Can't read back stored keys due to SHE protocol security - keys are write-only. How can we retrieve MAC for comparison?
  • Flash memory: Not suitable because application area gets erased when new application is programmed, so stored MAC would be lost.
  • EEPROM: Is this a good approach? Any recommended EEPROM addresses?

What other approaches would be suitable for storing application MAC that bootloader can reliably read for verification on every reset?

タグ(3)
0 件の賞賛
返信
1 返信

749件の閲覧回数
lukaszadrapa
NXP TechSupport
NXP TechSupport
0 件の賞賛
返信
%3CLINGO-SUB%20id%3D%22lingo-sub-2290022%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ES32K144%20CSEc%20%E3%82%A2%E3%83%97%E3%83%AA%E3%82%B1%E3%83%BC%E3%82%B7%E3%83%A7%E3%83%B3%20MAC%20%E3%82%B9%E3%83%88%E3%83%AC%E3%83%BC%E3%82%B8%20%E3%82%AA%E3%83%97%E3%82%B7%E3%83%A7%E3%83%B3%20(%E3%82%BB%E3%82%AD%E3%83%A5%E3%82%A2%20%E3%83%96%E3%83%BC%E3%83%88%E6%A4%9C%E8%A8%BC%E7%94%A8)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2290022%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CSTRONG%3E%E3%83%8F%E3%83%BC%E3%83%89%E3%82%A6%E3%82%A7%E3%82%A2%3A%3C%2FSTRONG%3E%20S32K144EVB-Q100%3CBR%20%2F%3E%3CSTRONG%3E%E3%82%BD%E3%83%95%E3%83%88%E3%82%A6%E3%82%A7%E3%82%A2%3A%3C%2FSTRONG%3E%20S32%20Design%20Studio%E3%80%81OpenBLT%20%E3%83%96%E3%83%BC%E3%83%88%E3%83%AD%E3%83%BC%E3%83%80%E3%83%BC%E3%80%81an5401-csec%3CBR%20%2F%3E%3CBR%20%2F%3E%E7%A7%81%E3%81%9F%E3%81%A1%E3%81%AF%E3%80%81BOOT_DEFINE%20(16KB%20%E4%BF%9D%E8%AD%B7)%20%E3%82%92%E4%BD%BF%E7%94%A8%E3%81%97%E3%81%A6%E3%83%96%E3%83%BC%E3%83%88%E3%83%AD%E3%83%BC%E3%83%80%E3%81%AE%E3%81%BF%E3%82%92%E4%BF%9D%E8%AD%B7%E3%81%97%E3%80%81%E9%81%A9%E5%88%87%E3%81%AA%E4%BF%A1%E9%A0%BC%E3%83%81%E3%82%A7%E3%83%BC%E3%83%B3%E3%82%92%E7%A2%BA%E7%AB%8B%E3%81%99%E3%82%8B%E3%81%9F%E3%82%81%E3%81%AB%E3%80%81%E3%83%96%E3%83%BC%E3%83%88%E3%83%AD%E3%83%BC%E3%83%80%E3%81%8C%E3%83%AA%E3%82%BB%E3%83%83%E3%83%88%E3%81%94%E3%81%A8%E3%81%AB%E3%82%A2%E3%83%97%E3%83%AA%E3%82%B1%E3%83%BC%E3%82%B7%E3%83%A7%E3%83%B3%20MAC%20%E3%82%92%E6%A4%9C%E8%A8%BC%E3%81%99%E3%82%8B%E3%82%88%E3%81%86%E3%81%AB%E3%81%97%E3%81%9F%E3%81%84%E3%81%A8%E8%80%83%E3%81%88%E3%81%A6%E3%81%84%E3%81%BE%E3%81%99%E3%80%82%3C%2FP%3E%3CP%3E%3CBR%20%2F%3E%E7%8F%BE%E5%9C%A8%E3%80%81%E6%A6%82%E5%BF%B5%E5%AE%9F%E8%A8%BC%E3%81%A8%E3%81%97%E3%81%A6%E3%83%AA%E3%82%BB%E3%83%83%E3%83%88%E3%81%AE%E3%81%9F%E3%81%B3%E3%81%AB%E4%BF%9D%E5%AD%98%E3%81%8A%E3%82%88%E3%81%B3%E6%A4%9C%E8%A8%BC%E3%81%99%E3%82%8B%E3%83%8F%E3%83%BC%E3%83%89%E3%82%B3%E3%83%BC%E3%83%89%E3%81%95%E3%82%8C%E3%81%9F%20CMAC%20%E5%80%A4%E3%81%8C%E3%81%82%E3%82%8A%E3%81%BE%E3%81%99%E3%80%82%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3E%E3%83%96%E3%83%BC%E3%83%88%E3%83%AD%E3%83%BC%E3%83%80%E3%81%AE%E6%A4%9C%E8%A8%BC%20(BOK%3D1)%20%E5%BE%8C%E3%80%81%E3%83%AA%E3%82%BB%E3%83%83%E3%83%88%E3%81%94%E3%81%A8%E3%81%AB%E3%82%A2%E3%83%97%E3%83%AA%E3%82%B1%E3%83%BC%E3%82%B7%E3%83%A7%E3%83%B3%E3%82%92%E6%A4%9C%E8%A8%BC%E3%81%99%E3%82%8B%E5%BF%85%E8%A6%81%E3%81%8C%E3%81%82%E3%82%8A%E3%81%BE%E3%81%99%E3%80%82%E3%81%93%E3%81%AE%E3%81%9F%E3%82%81%E3%81%AB%E3%81%AF%E3%80%81%E6%AC%A1%E3%81%AE%E3%81%93%E3%81%A8%E3%81%8C%E5%BF%85%E8%A6%81%E3%81%A7%E3%81%99%E3%80%82%3C%2FP%3E%3COL%3E%3CLI%3E%E3%83%97%E3%83%AD%E3%82%B0%E3%83%A9%E3%83%9F%E3%83%B3%E3%82%B0%E4%B8%AD%E3%81%AB%E3%82%A2%E3%83%97%E3%83%AA%E3%82%B1%E3%83%BC%E3%82%B7%E3%83%A7%E3%83%B3%E3%81%AEMAC%E3%82%92%E3%81%A9%E3%81%93%E3%81%8B%E3%81%AB%E4%BF%9D%E5%AD%98%E3%81%99%E3%82%8B%3C%2FLI%3E%3CLI%3E%E3%83%AA%E3%82%BB%E3%83%83%E3%83%88%E3%81%94%E3%81%A8%E3%81%AB%E3%82%A2%E3%83%97%E3%83%AA%E3%82%B1%E3%83%BC%E3%82%B7%E3%83%A7%E3%83%B3MAC%E3%82%92%E6%A4%9C%E8%A8%BC%E3%81%99%E3%82%8B%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%E7%A7%81%E3%81%9F%E3%81%A1%E3%81%AF%E4%BB%A5%E4%B8%8B%E3%81%AE%E9%81%B8%E6%8A%9E%E8%82%A2%E3%82%92%E6%A4%9C%E8%A8%8E%E3%81%97%E3%81%BE%E3%81%97%E3%81%9F%E3%81%8C%E3%80%81%E6%87%B8%E5%BF%B5%E3%81%8C%E3%81%82%E3%82%8A%E3%81%BE%E3%81%99%3A%3C%2FP%3E%3CUL%3E%3CLI%3ECSEc%20KEY%20%E3%82%B9%E3%83%AD%E3%83%83%E3%83%88%20(KEY_2%20%E3%81%AA%E3%81%A9)%3A%20SHE%20%E3%83%97%E3%83%AD%E3%83%88%E3%82%B3%E3%83%AB%20%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E3%81%AE%E3%81%9F%E3%82%81%E3%80%81%E4%BF%9D%E5%AD%98%E3%81%95%E3%82%8C%E3%81%9F%E3%82%AD%E3%83%BC%E3%82%92%E8%AA%AD%E3%81%BF%E5%8F%96%E3%82%8B%E3%81%93%E3%81%A8%E3%81%8C%E3%81%A7%E3%81%8D%E3%81%BE%E3%81%9B%E3%82%93%E3%80%82%E3%82%AD%E3%83%BC%E3%81%AF%E6%9B%B8%E3%81%8D%E8%BE%BC%E3%81%BF%E5%B0%82%E7%94%A8%E3%81%A7%E3%81%99%E3%80%82%E6%AF%94%E8%BC%83%E3%81%AE%E3%81%9F%E3%82%81%E3%81%AB%20MAC%20%E3%82%92%E5%8F%96%E5%BE%97%E3%81%99%E3%82%8B%E3%81%AB%E3%81%AF%E3%81%A9%E3%81%86%E3%81%99%E3%82%8C%E3%81%B0%E3%82%88%E3%81%84%E3%81%A7%E3%81%97%E3%82%87%E3%81%86%E3%81%8B%3F%3C%2FLI%3E%3CLI%3E%E3%83%95%E3%83%A9%E3%83%83%E3%82%B7%E3%83%A5%E3%83%A1%E3%83%A2%E3%83%AA%3A%20%E6%96%B0%E3%81%97%E3%81%84%E3%82%A2%E3%83%97%E3%83%AA%E3%82%B1%E3%83%BC%E3%82%B7%E3%83%A7%E3%83%B3%E3%81%8C%E3%83%97%E3%83%AD%E3%82%B0%E3%83%A9%E3%83%A0%E3%81%95%E3%82%8C%E3%82%8B%E3%81%A8%E3%82%A2%E3%83%97%E3%83%AA%E3%82%B1%E3%83%BC%E3%82%B7%E3%83%A7%E3%83%B3%E9%A0%98%E5%9F%9F%E3%81%8C%E6%B6%88%E5%8E%BB%E3%81%95%E3%82%8C%E3%80%81%E4%BF%9D%E5%AD%98%E3%81%95%E3%82%8C%E3%81%A6%E3%81%84%E3%82%8B%20MAC%20%E3%81%8C%E5%A4%B1%E3%82%8F%E3%82%8C%E3%82%8B%E3%81%9F%E3%82%81%E3%80%81%E9%81%A9%E3%81%97%E3%81%A6%E3%81%84%E3%81%BE%E3%81%9B%E3%82%93%E3%80%82%3C%2FLI%3E%3CLI%3EEEPROM%3A%20%E3%81%93%E3%82%8C%E3%81%AF%E8%89%AF%E3%81%84%E3%82%A2%E3%83%97%E3%83%AD%E3%83%BC%E3%83%81%E3%81%A7%E3%81%97%E3%82%87%E3%81%86%E3%81%8B%3F%E6%8E%A8%E5%A5%A8%E3%81%95%E3%82%8C%E3%82%8B%20EEPROM%20%E3%82%A2%E3%83%89%E3%83%AC%E3%82%B9%E3%81%AF%E3%81%82%E3%82%8A%E3%81%BE%E3%81%99%E3%81%8B%3F%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%E3%83%AA%E3%82%BB%E3%83%83%E3%83%88%E3%81%AE%E3%81%9F%E3%81%B3%E3%81%AB%E3%83%96%E3%83%BC%E3%83%88%E3%83%AD%E3%83%BC%E3%83%80%E3%81%8C%E7%A2%BA%E5%AE%9F%E3%81%AB%E8%AA%AD%E3%81%BF%E5%8F%96%E3%81%A3%E3%81%A6%E6%A4%9C%E8%A8%BC%E3%81%A7%E3%81%8D%E3%82%8B%E3%82%A2%E3%83%97%E3%83%AA%E3%82%B1%E3%83%BC%E3%82%B7%E3%83%A7%E3%83%B3%20MAC%20%E3%82%92%E4%BF%9D%E5%AD%98%E3%81%99%E3%82%8B%E3%81%AE%E3%81%AB%E9%81%A9%E3%81%97%E3%81%9F%E4%BB%96%E3%81%AE%E3%82%A2%E3%83%97%E3%83%AD%E3%83%BC%E3%83%81%E3%81%AF%E4%BD%95%E3%81%A7%E3%81%97%E3%82%87%E3%81%86%E3%81%8B%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2290327%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20S32K144%20CSEc%20Application%20MAC%20Storage%20Options%20for%20Secure%20Boot%20Verification%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2290327%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E3%81%93%E3%82%8C%E3%81%AF%E6%AC%A1%E3%81%AE%E3%82%82%E3%81%AE%E3%81%A8%E9%87%8D%E8%A4%87%E3%81%97%E3%81%A6%E3%81%84%E3%82%8B%E3%82%88%E3%81%86%E3%81%A7%E3%81%99%3A%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2FS32K%2FS32K144-CSEc-Application-MAC-Storage-Options-for-Secure-Boot%2Ftd-p%2F2289948%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Fcommunity.nxp.com%2Ft5%2FS32K%2FS32K144-CSEc-Application-MAC-Storage-Options-for-Secure-Boot%2Ftd-p%2F2289948%3C%2FA%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E