Formation Sécurité des SoC sans fil EFR32MG2x | Ac6 Formation

ac6-formation, un département d'Ac6 SAS
FR
FrançaisEnglish
 
go-up

ac6 ac6-formation Processors SiLabs Sécurité des SoC sans fil EFR32MG2x
SI1Sécurité des SoC sans fil EFR32MG2x
TrustZone, Secure Vault, Secure Boot et sécurité OTA sur Silicon Labs Series 2

Objectifs

    • Understand the ARMv8-M TrustZone architecture as implemented on the Cortex-M33 core of the EFR32MG2x Series 2 devices
    • Configure Secure and Non-Secure memory and peripheral partitioning
    • Understand the Silicon Labs Secure Engine (HSE/VSE)
    • Configure and enable Secure Boot with RTSL (Root of Trust and Secure Loader) using the Gecko Bootloader on Series 2 devices
    • Understand OTP provisioning
    • Understand anti-rollback protection and firmware signing with ECDSA-P256
    • Target: EFR32MG2x Series 2 board
    • OS context: bare-metal / Micrium, Zephyr paths mentioned as reference only
  • Embedded firmware developers and technical leads with a working knowledge of C/C++.
    • Working knowledge of C programming (functions, pointers, memory management)
    • Basic familiarity with embedded systems concepts (MCU, firmware, cross-compilation)
    • No prior security expertise required
  • Cours théorique
    • Support PDF (en anglais), imprimé en présentiel ; à distance via Teams.
    • Assistance du formateur tout au long de la formation.
  • Activités pratiques (40-50% de la durée)
    • Exemples de code, exercices et solutions.
    • À distance : un PC Linux en ligne par stagiaire, avec carte émulée ou physique selon le cours.
    • Présentiel / sur site : un PC (un par binôme au-delà de 6 stagiaires), carte cible et manuel d'installation si nécessaire.
  • Machine virtuelle préconfigurée téléchargeable pour refaire les TP après le cours.
  • Chaque session débute par un point avec les stagiaires.
  • Tout ingénieur ou technicien en systèmes embarqués possédant les prérequis ci-dessus.
  • Les prérequis sont évalués avant la formation.
  • Les progrès sont évalués par le formateur via les exercices pratiques, et par des quizz pour les sections sans exercices.
  • Chaque stagiaire reçoit une attestation de réussite.
  • En cas de prérequis manquant, une formation différente ou complémentaire est proposée.

Plan du cours

    • EFR32MG21/MG24 core
    • Secure Engine (SE)
    • Security building blocks on Series 2
    • Secure Vault
    • Series 2 SE Firmware
    • Cyber Resilience ACT Mapping
    • TrustZone for ARMv8-M
    • Operation states and modes
    • Register banking between security states
    • Memory model in TrustZone
    • System Private Peripheral Bus (PPB)
    • Secure and Non-Secure MPU
    • Exception handling and the Security Extension
Exercise :  •  MPU
•  Secure App
    • SAU (Security Attribution Unit)
    • IDAU / ESAU
    • SMU (Security Management Unit)
    • Memory partitioning on EFR32MG2x
    • Peripheral security attribution
    • System Security Controller and wrapper components
    • Debug access and TrustZone
Exercise :  Configure SAU and SMU
    • Two-image project structure
    • NSC (Non-Secure Callable) veneer functions
    • Calling conventions across the security boundary
    • Secure world services
    • TF-M (Trusted Firmware-M)
Exercise :  Implement a minimal Secure monitor
    • Purpose of Secure Boot
    • Root of Trust and Secure Loader (RTSL)
    • Boot chain on Series 2 HSE/VSE devices
    • Signature algorithm
    • Certificate-based Secure Boot
    • OTP memory on Series 2
    • Public Sign Key
    • Secure Boot Enable flag
    • Anti-Rollback Enable flag
    • Flash page lock settings
    • SE OTP provisioning workflow
    • Custom Part Manufacturing Service (CPMS)
Exercise :  Read current SE OTP configuration with sl_se_read_otp()
    • Gecko Bootloader architecture
    • GBL (Gecko Bootloader image format)
    • Enabling Secure Boot in the SSB
    • Generating the ECDSA key pair
    • Signing an application image
    • Signing a GBL upgrade file
    • Bootloader version and anti-rollback
    • Upgrading a bootloader without Secure Boot to a bootloader with Secure Boot
Exercise :  Build a Gecko Bootloader with Secure Boot
Exercise :  Anti-rollback
    • Debug access port
    • Three debug lock properties
    • Standard debug lock
    • Secure debug unlock
    • TrustZone debug authentication
    • Production lockdown checklist
    • Secure OTA pipeline
    • GBL file integrity
    • OTA path vs Gecko Bootloader integration
    • Staged slots
    • Encrypted firmware images
    • Vulnerability Management (CRA)
Plus d'information

Pour vous enregistrer ou pour toute information supplémentaire, contactez nous par email à l'adresse info@ac6-formation.com.

Les inscriptions aux sessions de formation sont acceptées jusqu'à une semaine avant le début de la formation. Pour une inscription plus tardive nous consulter

Vous pouvez aussi remplir et nous envoyer le bulletin d'inscription

Ce cours peut être dispensé dans notre centre de formation près de Paris ou dans vos locaux, en France ou dans le monde entier.

Les sessions inter-entreprises programmées sont ouvertes dès deux inscrits. Sous condition d'un dossier complet, les inscriptions sont acceptées jusqu'à une semaine avant le début de la formation.

Dernière mise à jour du plan de cours : 20 mai 2026

L'inscription à nos formations est soumise à nos Conditions Générales de Vente