<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DFU Image Encryption</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/124941/dfu-image-encryption</link><description>Hello, 
 
 I’m trying to enable image encryption on nRF54L. When I enable the encryption, MCUBoot firmware size gets bigger and does not fit into 60kb region. When I set the region to much bigger size, MCUBoot fails to start running the firmware. I’ve</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Fri, 05 Dec 2025 16:29:01 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/124941/dfu-image-encryption" /><item><title>RE: DFU Image Encryption</title><link>https://devzone.nordicsemi.com/thread/556367?ContentTypeID=1</link><pubDate>Fri, 05 Dec 2025 16:29:01 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:7c561b58-97ef-46d4-8fda-867869109646</guid><dc:creator>lCannon</dc:creator><description>&lt;p&gt;What versions of the SDK currently have support for encrypted DFU images.&amp;nbsp; I see some documentation for encrypted images in 3.0.2&lt;br /&gt;&lt;a id="" href="https://docs.nordicsemi.com/bundle/ncs-3.0.2/page/mcuboot/encrypted_images.html"&gt;&lt;br /&gt;https://docs.nordicsemi.com/bundle/ncs-3.0.2/page/mcuboot/encrypted_images.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;but no examples.&amp;nbsp; This page discusses a DFU sample with MCUboot with encryption enabled&lt;br /&gt;&lt;a id="" href="https://docs.nordicsemi.com/bundle/ncs-latest/page/nrf/samples/dfu/mcuboot_with_encryption/README.html"&gt;&lt;br /&gt;https://docs.nordicsemi.com/bundle/ncs-latest/page/nrf/samples/dfu/mcuboot_with_encryption/README.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;but the version selection for the SDK does not allow any selection other then latest version.&amp;nbsp; Is this page the best place to start for wokrign with Enrypted DFU packages; if not what would be the place that explains it.&amp;nbsp; What version of SDK should we use to do this?&amp;nbsp; Is there a version out of preview that has support?&lt;br /&gt;Thank you&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: DFU Image Encryption</title><link>https://devzone.nordicsemi.com/thread/551718?ContentTypeID=1</link><pubDate>Thu, 16 Oct 2025 13:22:31 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:4fbd207a-00ae-409a-9803-1396202a5c2d</guid><dc:creator>Vidar Berg</dc:creator><description>&lt;p&gt;Hi Emre,&lt;/p&gt;
&lt;p&gt;Please see my edit in my initial response. I had not noticed that we had introduced support for encryption. Regarding the app not booting, could it be that you have not provisioned the signature key to the KMU?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.nordicsemi.com/bundle/ncs-latest/page/nrf/app_dev/device_guides/nrf54l/kmu_basics.html#provisioning_keys_for_the_bootloader"&gt;https://docs.nordicsemi.com/bundle/ncs-latest/page/nrf/app_dev/device_guides/nrf54l/kmu_basics.html#provisioning_keys_for_the_bootloader&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Vidar&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: DFU Image Encryption</title><link>https://devzone.nordicsemi.com/thread/551708?ContentTypeID=1</link><pubDate>Thu, 16 Oct 2025 12:55:23 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:6ae35d62-157c-46b1-b45d-4a67c6662180</guid><dc:creator>Emre Bayraktar</dc:creator><description>&lt;p&gt;Hi Viar,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;With CONFIG_FPROTECT disabled and image encryption enabled, bootloader project exceeded 60kb region by 900 bytes. I&amp;#39;ve disabled log feature and resulting image fitted into 60kb region and encrypted.hex file is created. But when I flash it to the DK, nothing happens. Are there any extra steps for uploading encrypted image to the nRF54L ?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;When I disable these config commands, blink app works fine.&amp;nbsp;&lt;/p&gt;
&lt;div&gt;
&lt;div&gt;&lt;span&gt;SB_CONFIG_BOOT_ENCRYPTION&lt;/span&gt;&lt;span&gt;=y&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;SB_CONFIG_BOOT_ENCRYPTION_KEY_FILE&lt;/span&gt;&lt;span&gt;=&lt;/span&gt;&lt;span&gt;&amp;quot;/opt/nordic/ncs/V3.1.0/bootloader/mcuboot/enc-x25519-priv.pem&amp;quot;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Thanks &amp;amp; Best Regards,&lt;/p&gt;
&lt;p&gt;Emre.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: DFU Image Encryption</title><link>https://devzone.nordicsemi.com/thread/551449?ContentTypeID=1</link><pubDate>Tue, 14 Oct 2025 13:48:36 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:e51ae2e9-09a0-49c8-8c39-401f8125f538</guid><dc:creator>Vidar Berg</dc:creator><description>&lt;p&gt;Hello Emre,&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration:line-through;"&gt;There is currently no official support for image encryption in the SDK&lt;/span&gt;. Have you checked if you are able to make it work if you disable CONFIG_FPROTECT? If so, we could try to look at optimizing your bootloader project to get it below 62kB.&lt;/p&gt;
&lt;p&gt;Best regards,&lt;/p&gt;
&lt;p&gt;Vidar&lt;/p&gt;
&lt;p&gt;EDIT: Sorry, I was not aware that support had been added:&amp;nbsp;&lt;a id="" href="https://docs.nordicsemi.com/bundle/ncs-latest/page/nrf/app_dev/device_guides/nrf54l/ecies_x25519.html"&gt;https://docs.nordicsemi.com/bundle/ncs-latest/page/nrf/app_dev/device_guides/nrf54l/ecies_x25519.html&lt;/a&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>