RCW/PCI command integrity via Secure Boot

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

RCW/PCI command integrity via Secure Boot

1,263件の閲覧回数
bradley_gamble
Contributor I

Hello,

I am implementing Secure Boot (ISBC/ESBC) chain of trust on my T1042 device. Reading over the documentation it states that the RCW/PBI commands are executed prior to the CSF/ISBC stages being executes. These RCW/PBI commands are loaded from flash (NAND/NOR/SPI) and executed via the PBL.

These commands must be stored raw on the flash device as they are executed prior to any signature verification. However, what is to stop these commands being used to subvert the boot process? Could a malicious party generate a set of RCW/PBI commands, inject them on to the flash of a device and then use this to disable secure boot, or otherwise corrupt the boot process to run an unauthorised binary?

Kind regards,

0 件の賞賛
返信
1 返信

1,254件の閲覧回数
bpe
NXP Employee
NXP Employee


There is no way to disable Secure Boot if ITS fuse is blown and there are additional access restrictions in Secure Boot mode. See details in T1040RM,  Sections 27.4.2.1 and 26.5.3.1

 

Have a great day,

Platon

0 件の賞賛
返信