wolfBoot Secure Boot for the Nuvoton NuMaker M2354

wolfBoot now supports the Nuvoton NuMaker-M2354, a development board built on the NuMicro M2354, a Cortex-M23 microcontroller with TrustZone. Signed firmware is verified before it runs, and firmware updates are verified before they are installed.

About the chip

The NuMicro M2354 is a Cortex-M23 microcontroller built for security: 96 MHz, 1 MB of flash in two banks, 256 KB of SRAM, TrustZone, a CRPT accelerator covering AES, SHA, HMAC, ECC and RSA, a separate TRNG, a Key Store with key slots in SRAM, flash and OTP, execute-only memory, and a tamper controller. Nuvoton states that certified variants in the series are compliant with PSA Certified Level 3 and SESIP Level 3, and meet the requirements of the EU Cyber Resilience Act. Power draw is 39.6 uA/MHz in DC-DC mode and under 2 uA in standby.

That combination points at one market: connected products that ship in volume, stay in the field for years, and now have to prove they can be updated securely. Metering, building control, industrial sensing and other long-lived IoT devices all land in that category. Verified boot is the part of that story that has to be right first, because every other guarantee sits on top of it.

What wolfBoot adds

  • Verifies each firmware image before handing control to it, and verifies an update before installing it.
  • Signature algorithms: ECDSA P-256, P-384 and P-521, Ed25519, Ed448, and RSA-2048, RSA-3072 and RSA-4096. Hashes: SHA-256, SHA-384 and SHA3-384. Every one of these builds and fits on this part, with and without TrustZone. The example configurations use ECDSA P-256 with SHA-256.
  • Runs wolfBoot in the TrustZone secure world and starts the application in the non-secure world, so the bootloader and its verification keys stay isolated from application code. Non-secure code reaches wolfBoot services through secure gateway veneers.
  • Signed updates with the previous version retained, so a failed update rolls back.
  • Drives the flash controller, clock tree and console directly, with no vendor BSP dependency.
  • Both configurations, with and without TrustZone, were validated on NuMaker-M2354 hardware, and both run in continuous integration under an emulator that boots a signed image, installs an update, confirms it, and rolls back an unconfirmed one.

Boot time on a Cortex-M23

This is wolfBoot’s first ARMv8-M baseline target. Cortex-M23 supports TrustZone but uses a smaller instruction set than Cortex-M33, so the port adds a dedicated architecture configuration rather than reusing the existing one. Its math comes from wolfSSL’s Thumb-1 SP assembly, the same tier a Cortex-M0 uses. The Thumb-2 Cortex-M assembly that an M33 target would take does not assemble for this core at all. Selecting the right one is worth 4x at boot:

Build Verify and boot Bootloader size
Portable C 2619 ms 19,192 bytes
Thumb-1 assembly 623 ms 22,084 bytes

That figure is one ECDSA P-256 verification plus a SHA-256 over the image, so the saving grows with firmware size while the 2,892 extra bytes do not.

Hardware crypto for the application

wolfBoot verifies in software, which keeps the root of trust self-contained and independent of any engine state the application might leave behind. The application has no such constraint. A separate wolfCrypt port offloads to the M2354’s CRPT engine through the wolfSSL crypto callback interface, covering SHA, AES including AES-GCM and AES-CCM, ECC, RSA, TRNG seeding and Key Store slots, from either TrustZone world. On a NuMaker-M2354 at 96 MHz that is 771 KiB/s to 8.7 MiB/s for SHA-256 and 411 KiB/s to 8.7 MiB/s for AES-128-CBC, measured against the same build with wolfSSL’s own assembly enabled rather than a portable-C baseline. Links are below.

Why it matters

TrustZone draws a boundary inside the chip, and wolfBoot sits on the secure side of it. An application fault or a compromised update cannot reach the code that decides what is allowed to boot, and the keys that decide it are never mapped into the non-secure world. On a part sold on its security certifications, that is the foundation the rest of the claim rests on.

Resources

If you have questions about any of the above, please contact us at facts@wolfssl.com or call us at +1 425 245 8247.

Download wolfSSL Now