Please enable JavaScript to view this site.

winIDEA Help

Version: 9.26.20

Debug security mechanism guard on NXP S32K1xx

In this topic:

•Requirements

•Configuration steps

•Allowing access to the Security Byte (additional steps)

 

Introduction

This topic describes how to allow programming in winIDEA to a specific flash region on S32K1xx devices that stores default protection settings.

 

Warning_orange

If programmed incorrectly, it may result in permanently locking the device.

 

The program flash memory contains a specific region that stores default protection settings (loaded on reset) and security information that allows the SoC to restrict access to the FTFC module.The memory addresses of this region are: 0x0000’0400 to 0x0000’040F.

 

When program in winIDEA is performed, programming this flash region is skipped by default preventing unintentionally permanently locking the device.

 

JTAG Lock procedure requires access to the Flash security byte (0x40C). Depending on how this byte is configured it will determine the functionality in securing the target and finally lock the SoC.

 

To enable Security bit configuration, the winIDEA restriction needs to be disabled. This can be simply achieved by following the winIDEA configuration procedure below.

 

Warning_orange

Extensive knowledge of the S32K1 device and Flash Memory Module handling is required. Refer to the NXP S32K1 microcontroller reference manual and carefully study the Flash Configuration Field Table for restriction access to the FTFC Module and the Flash Security Register field function descriptions before accessing the restricted region.

 

 

Requirements

•winIDEA 9.17.0 or newer

•BlueBox

•Arm HSSTP II Active Probe or CoreSight Debug Adapter

 

 

Configuration steps

To access specific Regions and secure them the follow next steps.

 

1. Open Hardware | Freescale S32K | Configure.

 

2. Select the SKIP 400 40F field and press the Edit button in the Regions section.

 

3. Check the box Allow Programming and confirm the changes.

 

s32k-jtag-lock

 

When the next program occurs, the region will be accessed by winIDEA and the symbol file which has been selected in the workspace.

 

 

Allowing access to the Security Byte (additional steps)

1. Navigate to Hardware | Freescale S32K | Configure | Device section | FLAGS Configuration.

 

2. Uncheck the Release Secure Flags On Program Erase option and confirm the changes.

 

3. Perform program to allow winIDEA to write the determined values to the selected memory address

Unchecking the option Release Secure Flags On Program Erase allows winIDEA to write to that address to the values determined in the next program. If checked, it will still have the SoC as unsecure which is the default settings of the microcontroller.

 

 

Copyright © 2026 TASKING