Clarification on Secure Manager External Flash Support
Hello ST Team,
We are evaluating STM32TRUSTEE-SM (Secure Manager) on STM32H5F4 devices and would like clarification regarding the external flash support architecture.
From the STM32TRUSTEE-SM documentation and wiki pages, we understand that:
Secure Manager provides an External Flash Profile.
An External Flash Driver is referenced as part of the Secure Manager configuration flow.
External firmware and data confidentiality can be enabled through OTFDEC.
OTFDEC-based secure external memory access is described together with the OCTOSPI peripheral.
Secure Manager supports firmware download slots located in external flash memory.
However, we need clarification on the supported external memory architecture and driver model.
Questions
1. External Flash Interface Support restricted to memories connected through the OCTOSPI peripheral, or are other external memory interfaces also supported? Specifically, does the External Flash Profile support:
Octal SPI NOR Flash, Quad SPI NOR Flash, Standard SPI NOR Flash
2. Driver Framework
The Secure Manager documentation refers to an External Flash Driver.
Could you please clarify:
Is source code for the external flash driver provided as part of the Secure Manager package?
Is there a documented API/interface specification that custom flash drivers must implement?
Are OEMs expected to develop their own external flash driver when using a flash memory different from the one used in ST reference projects?
Are there example drivers available for supported flash devices?
3. Encryption Capabilities
In the documentation related to external flash protection and OTFDEC, we can see references to AES-128 encryption.
Could you please clarify:
Is external firmware/data protection through OTFDEC limited to AES-128 only?
Is AES-256 supported for external flash encryption/decryption?
If AES-256 is not currently supported, are there any planned enhancements or recommended approaches for customers requiring AES-256 protection of external firmware?
4. Documentation Reference
If Secure Manager external flash support is limited to OCTOSPI-managed memories, could you please point us to the relevant documentation section describing this requirement?
Our Use Case We are currently evaluating Secure Manager for a custom STM32H5-based product and need to understand the flexibility of the External Flash Profile before finalizing the hardware architecture and flash memory selection.
Thank you for your support.
RJ
