Secure storage in the nRF Connect SDK

The nRF Connect SDK implements secure storage through the PSA Certified Secure Storage API. The implementation is designed to securely store and manage sensitive data, such as cryptographic keys, device credentials, and configuration data.

The following implementations of the PSA Secure Storage API are available:

Note

In the nRF Connect SDK, the PSA Protected Storage is one of the available data storage options. It does not currently support storing data to external flash.

The table below gives an overview of the secure storage support for the products and their features.

Secure storage product support

Product

Backend

Confidentiality

Integrity

Authenticity

Isolation

nRF91 Series with TF-M

TF-M’s Internal Trusted Storage service and Protected Storage service

Yes

Yes

Yes

Yes

nRF91 Series without TF-M

Secure Storage subsystem

Yes

Yes

Yes

No [1]

nRF54L Series with TF-M

TF-M’s Internal Trusted Storage service and Protected Storage service

Yes

Yes

Yes

Yes

nRF54L Series without TF-M

Secure Storage subsystem

Yes

Yes

Yes

No [1]

nRF5340 with TF-M

TF-M’s Internal Trusted Storage service and Protected Storage service

Yes

Yes

Yes

Yes

nRF5340 without TF-M

Secure Storage subsystem

Yes

Yes

Yes

No [1]

nRF52840

Secure Storage subsystem

Yes

Yes

Yes

No [1]

nRF52833

Secure Storage subsystem

No [2]

Yes

No

No [1]

nRF52832

Secure Storage subsystem

No [2]

Yes

No

No [1]

Notes for confidentiality partial support