Alternatives to STM32HSM-V2 for STM32H573 secure programming at external CM?
Hello,
We are going to use the STM32H573 MCU (STM32H573IIK3Q) on our board, and we are now preparing for mass production. Production will be done at an external contract manufacturer (not in-house), and we need to provision keys and firmware securely during programming.
My main question: Is the STM32HSM-V2 card strictly required for secure programming at high volume, or are there supported alternatives?
Specifically:
1. As far as I understand, the SFI license mechanism is tied to ST's key hierarchy inside the ROM bootloader, so a third-party/commercial HSM (Thales, nShield, etc.) cannot generate licenses that the chip will accept. Is that correct, or is there any supported way to run SFI with our own HSM infrastructure instead of the ST smartcard?
2. If STM32HSM-V2 is the only option: for volumes well beyond 300 units, V2ML (10K) and V2HL (100K) do not seem to be orderable through distributors. Is the intended path to request them through an ST sales office, and what lead time should we plan for?
3. Our CM uses gang programmers rather than a per-device STM32CubeProgrammer + ST-LINK station. What is the recommended way to integrate SFI into third-party gang programmers (Data I/O, BPM, etc.)? Does the HSM card need to be physically attached to each programming station, and is there a list of programmer vendors with validated SFI support for the H5 series?
Environment: STM32H573IIK3Q, STM32CubeProgrammer (latest), STM32HSM-V2, external CM.
Thank you in advance.
