SHE-key attribute flags

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

SHE-key attribute flags

Jump to solution
1,697 Views
ale_di_vi
Contributor I

Hi,

I'm working in a project having the CSEc module (microcontroller S32K144). I know that, in order to update SHE-keys, 5 flags must be configured in order to generate the key in the M-format (Write Protection, Boot Protection, Debugger Usage Protection, Wildcard Protection and Key Usage Flag).

In some documents, I read also about Verify Only flag: if set when the key is used for CMAC, it can be used only to verify CMAC, otherwise the key can be used for verification and generation.

The question is: the flags are actually 5? what about the Verify Only flag?

Thank you in advance

0 Kudos
Reply
1 Solution
1,666 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @ale_di_vi 

This is an extension to SHE specification. Search for "SFE" keyword (Security Flag Extension) in the reference manual and in the application note AN5401. This is a screenshot from the reference manual, description of Program Partition command:

lukaszadrapa_0-1696930974908.png

 

If you don't want to use this extension, just keep SFE as 0 when running Program Partition command.

Regards,

Lukas

View solution in original post

0 Kudos
Reply
2 Replies
1,667 Views
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @ale_di_vi 

This is an extension to SHE specification. Search for "SFE" keyword (Security Flag Extension) in the reference manual and in the application note AN5401. This is a screenshot from the reference manual, description of Program Partition command:

lukaszadrapa_0-1696930974908.png

 

If you don't want to use this extension, just keep SFE as 0 when running Program Partition command.

Regards,

Lukas

0 Kudos
Reply
1,633 Views
ale_di_vi
Contributor I
Ok, now it is clear.
Many thanks!
0 Kudos
Reply