Protect modem certificate

Hi,

I have the following issue, maybe I have an error in thinking:

For Access MQTT the Device has a Certificate in a storage slot, lets say 20. If now someone can gain access to the device, knows about the endpoints and the commands and also finds the slot with the cert, he is able to access at least this device specific endpoint with a new custom firmware and can write everything.

Is there a workflow to prevent this? So for example if a firmware with a non matching mcuboot key is written, it can not access this certificates. I am aware the ota will be blocked with wrong key so what I mean is really the SWD Flash variant.

Thanks for your help and best regards


Daniel

Parents Reply
  • Hello again Daniel, 

    First of all, thank you for bringing this to our attention. The PSIRT team has assessed your PSIRT report. They write that the "official response to the DevZone request is to configure eraseprotect to mitigate this attack vector"

    The team acknowledges the scenario, and will discuss further measures to counter similar scenarios in the future products. That said the ERASPROTECT should be the countermeasure to use in your scenario as this will prevent others from erasing the device and thus programming another custom FW. 

    Let me know if you have any further questions. 

    Kind regards,
    Øyvind

Children
Related