cancel
Showing results for 
Search instead for 
Did you mean: 

Correct forum for MOOC - Security?

KDesr.1
Associate III

I've been watching the MOOC - Security series and had some questions.  There is a link in the info block to a forum for any questions, but the link no longer works.  

https://www.youtube.com/watch?v=g7ykhnmh7sA

Is this the right place?

I got to the end of  "Security Part4 - STM32 security in practice - 15 Secure firmware update" and had some questions since there isn't any lab video for this module like there are for the modules that came before it.

1 ACCEPTED SOLUTION

Accepted Solutions
Issamos
Lead II

Hello @KDesr.1 

Yes, you are right, this is the security forum. You can post all your questions with needed details and ST users and employees will help you.

For the link on the description, I think ST should update it @mƎALLEm 

Best Regards.

II

View solution in original post

3 REPLIES 3
Issamos
Lead II

Hello @KDesr.1 

Yes, you are right, this is the security forum. You can post all your questions with needed details and ST users and employees will help you.

For the link on the description, I think ST should update it @mƎALLEm 

Best Regards.

II

KDesr.1
Associate III

Great!  Thank!

 

The link for the slides is at the bottom of this page and still works:

https://www.st.com/content/st_com/en/support/learning/stm32-education/stm32-moocs/STM32_security_in_practice.html

 

P.87

" Another option is to have the firmware encrypted with predefined symmetric key before uploading for update service

• Firmware will always be stored on the updating server in encrypted format and stays encrypted during downloading regardless of the communication channel encryption state

• The symmetric key to decrypt the firmware need to be provisioned in the device beforehand • The symmetric key need to be protected for its confidentiality and integrity "

 

Ok, in this scenario, I assume all devices/unit of the same product/part# would have the same symmetric key in a protected part of the flash and kept secret on the development side, correct?  It would have to be the same key for all units if the update package is already sitting there waiting to be downloaded, yes?

This is a new question. I think you should create a new post for it. 

Best Regards.

II