<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>nRF52840 and the Root of Trust</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/25621/nrf52840-and-the-root-of-trust</link><description>Several answers from Nordic employees state the possibility of Secure Boot and a &amp;quot;Root of Trust&amp;quot; feature: 
 use of ARM TrustZone on nrf52840 for secure storage/trusted region 
 Cybersecurity features for NRF52 chips 
 What is the current progress for</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Wed, 03 Oct 2018 13:01:12 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/25621/nrf52840-and-the-root-of-trust" /><item><title>RE: nRF52840 and the Root of Trust</title><link>https://devzone.nordicsemi.com/thread/151452?ContentTypeID=1</link><pubDate>Wed, 03 Oct 2018 13:01:12 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:8487706b-7da0-4b6e-90f5-e176e2014be2</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi Thomas,&lt;/p&gt;
&lt;p&gt;The CC310 core in the nRF52840 does not have any secure flash (only secure RAM), so it cannot hold a private key during power cycles. Therefore, your only option is to store the private key in normal flash and provision CC310 on every boot. The key can still be protected so that it cannot be read by a debugger nor accessed by the application&amp;nbsp;as I have described in &lt;a href="https://devzone.nordicsemi.com/f/nordic-q-a/38351/saving-root-key-on-battery-powered-devices/148018#148018"&gt;this post&lt;/a&gt;, but it does not offer any protection against decapping. This may or may not be secure enough, depending on the use case.&lt;/p&gt;
&lt;p&gt;Einar&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: nRF52840 and the Root of Trust</title><link>https://devzone.nordicsemi.com/thread/151192?ContentTypeID=1</link><pubDate>Tue, 02 Oct 2018 10:12:28 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:bbdde46a-41df-46f7-980f-858196663cc6</guid><dc:creator>Thomas Peter</dc:creator><description>&lt;p&gt;Dear Bj&amp;oslash;rn&lt;/p&gt;
&lt;p&gt;Can you give us an update on the nRF52840 and the Root of Trust?&lt;/p&gt;
&lt;p&gt;We are also working on a project that requires maximum security and trust. Is it possible to securely handle private keys with the nRF52840 and its CryptoCell 310?&lt;/p&gt;
&lt;p&gt;If yes, where and how is the private key held (how is the Root of Trust implemented)?&lt;/p&gt;
&lt;p&gt;Also if yes, is example code available?&lt;/p&gt;
&lt;p&gt;Thank you and best regards&lt;/p&gt;
&lt;p&gt;Thomas&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: nRF52840 and the Root of Trust</title><link>https://devzone.nordicsemi.com/thread/100993?ContentTypeID=1</link><pubDate>Fri, 13 Oct 2017 09:30:25 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:39f5084b-73fe-491c-8fa5-03d77bdc0cb3</guid><dc:creator>Bj&amp;#248;rn Kvaale</dc:creator><description>&lt;p&gt;&lt;strong&gt;Update from the expert:&lt;/strong&gt; &amp;quot;A correction to what I wrote earlier (my mistake mixing some terms). nRF52840 will not have the TrustZone as described in the ARM documentation. That requires Armv8 (M23 or M33) while nRF52840 will have a Cortex M4F. I should have written: “Whether this solution will be Secure Boot as described by ARM, or something ...” instead of referring to Trust Zone. This mix-up has been updated in the answer above.&lt;/p&gt;
&lt;p&gt;Regarding your question: “…what is available with the HW available on nRF52840”. For this the answer is: This is fixed but not yet ready to be published.&amp;quot;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: nRF52840 and the Root of Trust</title><link>https://devzone.nordicsemi.com/thread/100994?ContentTypeID=1</link><pubDate>Thu, 12 Oct 2017 06:27:20 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:38af23ba-1ff8-4943-be5d-dd6228121013</guid><dc:creator>Gregor Bader</dc:creator><description>&lt;p&gt;Hi Bjørn,&lt;/p&gt;
&lt;p&gt;Thank you for this information. For &amp;quot;... what is available with the HW available on nRF52840&amp;quot;, is this already fixed or still under discussion or not yet ready to be published?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: nRF52840 and the Root of Trust</title><link>https://devzone.nordicsemi.com/thread/100992?ContentTypeID=1</link><pubDate>Thu, 12 Oct 2017 06:11:34 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:d881b556-2706-4d57-9676-314fcdcd0056</guid><dc:creator>Bj&amp;#248;rn Kvaale</dc:creator><description>&lt;p&gt;&lt;strong&gt;Got this answer from an expert here at Nordic:&lt;/strong&gt; &amp;quot;Answer to your question is “something in between”, at least in the timeframe of the next few months for when we are releasing nRF52840. We will have some example code showing how to do Root of Trust, but I will not guarantee that we will have a full RoT solution integrated with the rest of our infrastructure in this timeframe.
Whether this solution will be Secure Boot as described by ARM, or something else has not been concluded. The design goal for this implementation would be to give a solution that shows the potential of what is available with the HW available on nRF52840.&lt;/p&gt;
&lt;p&gt;There will as well be documentation describing how to implement a Root of Trust solution using the features available on the nRF52840 chip.&amp;quot;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>