Secure Boot Implementation without Secure Access Files

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Secure Boot Implementation without Secure Access Files

61 Views
addisonaudette1
Contributor II

Is there a way to run a secure boot on an S32k board without the secure access files? If so - how would that be accomplished?

0 Kudos
Reply
2 Replies

30 Views
Robin_Shen
NXP TechSupport
NXP TechSupport

Hi

Please allow me to directly paste the reply I gave you for Case 00999901 here.

I may not have understood your question. Please correct me if I'm wrong.
It seems you have a misunderstanding about Secure Access Rights.
Once you obtain Secure Access Rights, it doesn't just provide Secure Boot-related materials; it also grants you access to Secure Resources. I suggest you read the Secure Access Rights FAQs for more information.

Based on your description, it seems you have already obtained Secure Access Rights. In that case, you can search for relevant information by clicking Secure on the S32K3 documentation website and entering keywords. For example input boot:

If you do not have Secure Access Rights, you cannot even download RM00286 HSE-B Firmware Reference Manual - V2.7 [RM758227]. S32K3's Secure Boot uses a boot integrity/authenticity verification mechanism based on HSE (Hardware Security Engine). Without this document, it will be very difficult for you to become familiar with HSE.

 
Regarding Secure Boot, I also recommend you read the discussion here: https://community.nxp.com/t5/S32K/S32K3/td-p/1735306
Advanced secure boot mode is recommended. This mode offers more regions to be checked, so you can configure it to cover both bootloader and application.
Basic secure boot mode can check one region only.
 
Best Regards,
Robin
0 Kudos
Reply

3 Views
addisonaudette1
Contributor II

Hello, 

 

I do not have secure access rights. I understand that these secure access files cover more than just the documentation regarding HSE/Secure boot. 

 

I am under the understanding you need secure access rights to get access to:

  • The HSE-B Firmware Reference Manual 
  • The Secure Boot Application Note (AN744511) and its demo project.
  • The HSE Firmware package itself

I also know that the HSE Standard FW library is accessible without secure access rights.

Is it possible to run a secure boot on the board without access to the secure access rights?

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2407066%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ESecure%20Boot%20Implementation%20without%20Secure%20Access%20Files%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2407066%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EIs%20there%20a%20way%20to%20run%20a%20secure%20boot%20on%20an%20S32k%20board%20without%20the%20secure%20access%20files%3F%20If%20so%20-%20how%20would%20that%20be%20accomplished%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2407178%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Secure%20Boot%20Implementation%20without%20Secure%20Access%20Files%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2407178%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CDIV%3E%0A%3CP%3EHi%3C%2FP%3E%0A%3CP%3EPlease%20allow%20me%20to%20directly%20paste%20the%20reply%20I%20gave%20you%20for%20Case%2000999901%20here.%3C%2FP%3E%0A%3CP%3EI%20may%20not%20have%20understood%20your%20question.%20Please%20correct%20me%20if%20I'm%20wrong.%3CBR%20%2F%3EIt%20seems%20you%20have%20a%20misunderstanding%20about%20Secure%20Access%20Rights.%3CBR%20%2F%3EOnce%20you%20obtain%20%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fsupport%2Fsupport%2Fsecure-access-rights%3ASEC-ACCESS%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3ESecure%20Access%20Rights%3C%2FA%3E%2C%20it%20doesn't%20just%20provide%20Secure%20Boot-related%20materials%3B%20it%20also%20grants%20you%20access%20to%20Secure%20Resources.%20I%20suggest%20you%20read%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fsupport%2Fsupport%2Fsecure-access-rights%2Fsecure-access-rights-faqs%3ASEC-ACCESS-FAQS%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20nofollow%22%3ESecure%20Access%20Rights%20FAQs%3C%2FA%3E%20for%20more%20information.%3C%2FP%3E%0A%3CP%3EBased%20on%20your%20description%2C%20it%20seems%20you%20have%20already%20obtained%20%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fsupport%2Fsupport%2Fsecure-access-rights%3ASEC-ACCESS%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3ESecure%20Access%20Rights%3C%2FA%3E.%20In%20that%20case%2C%20you%20can%20search%20for%20relevant%20information%20by%20clicking%20%3CSTRONG%3ESecure%20%3C%2FSTRONG%3Eon%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fproducts%2FS32K3%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3ES32K3%20%3C%2FA%3Edocumentation%20website%20and%20entering%20keywords.%20For%20example%20input%20boot%3A%3C%2FP%3E%0A%3CP%3EIf%20you%20do%20not%20have%20%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fsupport%2Fsupport%2Fsecure-access-rights%3ASEC-ACCESS%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3ESecure%20Access%20Rights%3C%2FA%3E%2C%20you%20cannot%20even%20download%20%3CSTRONG%3ERM00286%20HSE-B%20Firmware%20Reference%20Manual%20-%20V2.7%20%5BRM758227%5D%3C%2FSTRONG%3E.%20S32K3's%20Secure%20Boot%20uses%20a%20boot%20integrity%2Fauthenticity%20verification%20mechanism%20based%20on%20HSE%20(Hardware%20Security%20Engine).%20Without%20this%20document%2C%20it%20will%20be%20very%20difficult%20for%20you%20to%20become%20familiar%20with%20HSE.%3C%2FP%3E%0A%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3ERegarding%20Secure%20Boot%2C%20I%20also%20recommend%20you%20read%20the%20discussion%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2FS32K%2FS32K3%2Ftd-p%2F1735306%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Fcommunity.nxp.com%2Ft5%2FS32K%2FS32K3%2Ftd-p%2F1735306%3C%2FA%3E%3C%2FDIV%3E%0A%3CDIV%3EAdvanced%20secure%20boot%20mode%20is%20recommended.%20This%20mode%20offers%20more%20regions%20to%20be%20checked%2C%20so%20you%20can%20configure%20it%20to%20cover%20both%20bootloader%20and%20application.%3CBR%20%2F%3EBasic%20secure%20boot%20mode%20can%20check%20one%20region%20only.%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3EBest%20Regards%2C%3CBR%20%2F%3ERobin%3C%2FDIV%3E%3C%2FLINGO-BODY%3E