Objectifs
|
- Target: EFR32MG2x Series 2 board
- OS context: bare-metal / Micrium, Zephyr paths mentioned as reference only
- Embedded firmware developers and technical leads with a working knowledge of C/C++.
- Working knowledge of C programming (functions, pointers, memory management)
- Basic familiarity with embedded systems concepts (MCU, firmware, cross-compilation)
- No prior security expertise required
- Cours théorique
- Support PDF (en anglais), imprimé en présentiel ; à distance via Teams.
- Assistance du formateur tout au long de la formation.
- Activités pratiques (40-50% de la durée)
- Exemples de code, exercices et solutions.
- À distance : un PC Linux en ligne par stagiaire, avec carte émulée ou physique selon le cours.
- Présentiel / sur site : un PC (un par binôme au-delà de 6 stagiaires), carte cible et manuel d'installation si nécessaire.
- Machine virtuelle préconfigurée téléchargeable pour refaire les TP après le cours.
- Chaque session débute par un point avec les stagiaires.
- Tout ingénieur ou technicien en systèmes embarqués possédant les prérequis ci-dessus.
- Les prérequis sont évalués avant la formation.
- Les progrès sont évalués par le formateur via les exercices pratiques, et par des quizz pour les sections sans exercices.
- Chaque stagiaire reçoit une attestation de réussite.
- En cas de prérequis manquant, une formation différente ou complémentaire est proposée.
Plan du cours
- EFR32MG21/MG24 core
- Secure Engine (SE)
- Security building blocks on Series 2
- Secure Vault
- Series 2 SE Firmware
- Cyber Resilience ACT Mapping
- TrustZone for ARMv8-M
- Operation states and modes
- Register banking between security states
- Memory model in TrustZone
- System Private Peripheral Bus (PPB)
- Secure and Non-Secure MPU
- Exception handling and the Security Extension
| Exercise : | • | MPU |
| • | Secure App |
- SAU (Security Attribution Unit)
- IDAU / ESAU
- SMU (Security Management Unit)
- Memory partitioning on EFR32MG2x
- Peripheral security attribution
- System Security Controller and wrapper components
- Debug access and TrustZone
| Exercise : | Configure SAU and SMU | |
- Two-image project structure
- NSC (Non-Secure Callable) veneer functions
- Calling conventions across the security boundary
- Secure world services
- TF-M (Trusted Firmware-M)
| Exercise : | Implement a minimal Secure monitor | |
- Purpose of Secure Boot
- Root of Trust and Secure Loader (RTSL)
- Boot chain on Series 2 HSE/VSE devices
- Signature algorithm
- Certificate-based Secure Boot
- OTP memory on Series 2
- Public Sign Key
- Secure Boot Enable flag
- Anti-Rollback Enable flag
- Flash page lock settings
- SE OTP provisioning workflow
- Custom Part Manufacturing Service (CPMS)
| Exercise : | Read current SE OTP configuration with sl_se_read_otp() | |
- Gecko Bootloader architecture
- GBL (Gecko Bootloader image format)
- Enabling Secure Boot in the SSB
- Generating the ECDSA key pair
- Signing an application image
- Signing a GBL upgrade file
- Bootloader version and anti-rollback
- Upgrading a bootloader without Secure Boot to a bootloader with Secure Boot
| Exercise : | Build a Gecko Bootloader with Secure Boot | |
| Exercise : | Anti-rollback | |
- Debug access port
- Three debug lock properties
- Standard debug lock
- Secure debug unlock
- TrustZone debug authentication
- Production lockdown checklist
- Secure OTA pipeline
- GBL file integrity
- OTA path vs Gecko Bootloader integration
- Staged slots
- Encrypted firmware images
- Vulnerability Management (CRA)
Plus d'information
Pour vous enregistrer ou pour toute information supplémentaire, contactez nous par email à l'adresse info@ac6-formation.com.
Les inscriptions aux sessions de formation sont acceptées jusqu'à une semaine avant le début de la formation. Pour une inscription plus tardive nous consulter
Vous pouvez aussi remplir et nous envoyer le bulletin d'inscription
Ce cours peut être dispensé dans notre centre de formation près de Paris ou dans vos locaux, en France ou dans le monde entier.
Les sessions inter-entreprises programmées sont ouvertes dès deux inscrits. Sous condition d'un dossier complet, les inscriptions sont acceptées jusqu'à une semaine avant le début de la formation.
Dernière mise à jour du plan de cours : 20 mai 2026
L'inscription à nos formations est soumise à nos Conditions Générales de Vente