Security features of the ARM Cortex-M33

Martin Koloska, Jerome Bassand · Zürcher Hochschule für Angewandte Wissenschaften digital collection (Zurich University of Applied Sciences) · 2025

Historically, security has been less of a focus for embedded systems. Instead, they prioritized functionality, cost and power efficiency while operating under tight resource constraints. The assumption that isolation from the Internet would suffice as a security measure has long shaped their design. However, a near-ubiquitous need for network connectivity, increased attacks on poorly secured Internet of Things devices and the broader availability of hardware and software security features are shifting this landscape. This project aims to create a demonstrator application to test and showcase selected security features of the ARM Cortex-M33, the nRF54L15 development kit, MCUboot and Zephyr RTOS. With a focus on secure device firmware upgrades, communication over Thread and the secure use of keys for encrypting and signing messages and firmware images. Using features provided by the processor, System-on-Chip (SoC) and operating system, a demonstrator setup was developed and comprehensively documented to enable replication by other researchers and developers. The demonstrator serves as a proof-of-concept for practical implementations of embedded security aligned with selected requirements from the EU Cyber Resilience Act. This thesis demonstrates that the targeted security features of the ARM Cortex-M33 and nRF54L15 SoC function as intended and that sufficient resources remain for a meaningful application. Secure communication goals were fully achieved, while partial limitations were observed in the device firmware update process and the implementation of a robust root of trust. MCUboot provides a functional single-stage secure boot mechanism that could be improved if Nordics Secure Immutable Bootloader were fully integrated with the available security hardware. Likewise, hardware-backed firmware downgrade protection remains unutilized due to missing Software Development Kit (SDK) support. Several challenges found stem from the early-stage maturity of the nRF54L15 ecosystem, including incomplete documentation, limited tooling and essential security components only available as experimental features. Despite this, the platform shows promise and ongoing SDK updates indicate rapid progress.

Read the paper · More papers on PaperTik