s32k3 hse basic secure boot protect problem?

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 
已解决

s32k3 hse basic secure boot protect problem?

跳至解决方案
948 次查看
victory
Contributor V

Hi Nxp,

    i'm checking the hse basic secure boot function.  i am wondering if it could be dis-functional (someone modified flash and run another program),  here is my question:

1. if IVT set both CM7_0 and APPBL address, how MCU determine jump to CM7 start address or APPBL start address?

2. is BSB activated by IVT BOOTSEQ bit, if not  how to activated BSB?

3. how to enable HSE check IVT GMAC?

4. based on Q2, if someone changed the IVT, not set the BOOTSEQ bit, then he could run its own program, hse will not check ivt anymore?

0 项奖励
回复
1 解答
906 次查看
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @victory 

it depends on BOOT_SEQ:

lukaszadrapa_0-1724946115013.pnglukaszadrapa_1-1724946120491.png

 

To check IVT GMAC, it's necessary to enable IVT_AUTH:

lukaszadrapa_2-1724946254679.png

 

lukaszadrapa_3-1724946261729.png

This eliminate problems with IVT changes.

Regards,

Lukas

在原帖中查看解决方案

0 项奖励
回复
1 回复
907 次查看
lukaszadrapa
NXP TechSupport
NXP TechSupport

Hi @victory 

it depends on BOOT_SEQ:

lukaszadrapa_0-1724946115013.pnglukaszadrapa_1-1724946120491.png

 

To check IVT GMAC, it's necessary to enable IVT_AUTH:

lukaszadrapa_2-1724946254679.png

 

lukaszadrapa_3-1724946261729.png

This eliminate problems with IVT changes.

Regards,

Lukas

0 项奖励
回复