Hi Nordic Team,
I am evaluating the security architecture of an nRF54L15-based product and reviewing the latest errata for Revision 2.
While reviewing the errata, I found several items that appear security-related
- SPU Locking (Anomaly #10)
- Does anomaly #10 affect the security guarantees of TrustZone isolation in production systems?
- If an attacker gains arbitrary code execution in the non-secure application, can this anomaly be leveraged to modify secure/non-secure memory or peripheral attribution?
- What is the recommended mitigation when using TF-M and secure services?
- KMU Provisioning (Anomaly #13)
- I am intend to use hardware-protected storage for device credentials, Is there any risk of key corruption or unintended key-slot modification due to this anomaly?
- Does NCS/TF-M already implement the recommended workaround?
- DPPI/PPIB Security Attribution (Anomaly #26)
- Can this anomaly result in secure tasks/events being triggered from the non-secure domain?
- Are there known TrustZone configurations where this becomes a security concern?
- Is this fully handled by existing NCS drivers, or does the application developer need additional precautions?
- EGU Security Attribution (Anomaly #59)
- Can this anomaly lead to unintended interaction between secure and non-secure software partitions?
- Are there recommended restrictions on EGU usage in TrustZone-enabled applications?
- Does TF-M already account for this limitation?
- Soft Reset Behavior (Anomaly #63)
- Are any security-sensitive resources (SPU state, KMU state, secure RAM, peripheral configuration) known to survive a software reset?
- Is a full power-on reset required for security-critical recovery procedures?
- Others:
- Are anomalies #10, #13, #26, #59 and #63 expected to be resolved in a future nRF54L15 silicon revision?
-
Do any of these anomalies impact:
- PSA Certified evaluations
- SESIP evaluations
- Common Criteria evaluations
- Other security certifications or assurance programs (E.g. EU CRA, etc..)?
I would appreciate any clarification regarding the practical impact of these anomalies on TrustZone isolation, secure key storage, secure boot, secure DFU, and overall platform security.
Thank you for your support.
Best Regards.