
UM2262 Rev 6
85/94
UM2262
SBSFU with STM32 and STSAFE-A100
93
As explained above, the STM32, STSAFE-A100, and firmware image must be provisioned
with some keys and or certificates:
•
STM32: pairing keys must be inserted inside the SBSFU application code (inside the
part that is executed inside the protected environment) to be able to communicate
securely with an STSAFE-A100 component
•
STSAFE-A100:
–
Pairing keys must be provisioned inside the STSAFE-A100 to be able to
communicate securely with an STM32 component.
–
Root CA Cert and OEM CA Cert must be provisioned inside the STSAFE-A100 to
be able to verify OEM Divisional CA Cert and Firmware Signing Cert that are
received as part of the header of the new firmware image to be installed on the
STM32
•
Firmware image: OEM Divisional CA Cert and Firmware Signing Cert must be inserted
in the header of the new firmware image to be installed on the STM32
Figure 50. Pairing key and certificate provisioning overview