<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: Hab encrpyted image boot for rt1050</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Hab-encrpyted-image-boot-for-rt1050/m-p/975504#M145189</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A _jive_internal="true" data-content-finding="Community" data-userid="322065" data-username="jimhuang@alltekmarine.com" href="https://community.nxp.com/people/jimhuang@alltekmarine.com"&gt;JingHuan Huang&lt;/A&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Sorry for our later reply!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Before answer your question, I highly recommend you read the AN12079(how to use I.MXRT Security Boot) at first, then it will make you more clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;A class="link-titled" href="https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=AN12079&amp;amp;appType=moderated" title="https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=AN12079&amp;amp;appType=moderated"&gt;https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=AN12079&amp;amp;appType=moderated&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Now, answer your questions:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;1. CA&amp;nbsp;step&amp;nbsp;issue: The BootRom can verify CA by the public key, Where the public key be stored to provide BootRom?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;Answer: Public key is stored in the RT eFUSE SRK area.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;2.&amp;nbsp;&lt;SPAN&gt;Dek&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;step&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;issue: DEK is generated from random numbers by&amp;nbsp;the Code Signing Tool (CTS). When I upgrade boot image, I have to used dek to generated dek blok and attached to boot image, I'm not sure, can it run?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt; Answer: Dek.bin is the random number, I think you also can use the old dek.bin, but if you want to use the new dek.bin, it's also OK, just do the new operation steps. I suggest you use the new dek when you use the new app code.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #545454; "&gt;3.&amp;nbsp;After mass production, We need to maintain private key, public key and dek, is it right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #545454; "&gt;Answer: Yes, if you want to program more product, it's better to maintain it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #545454; "&gt;Wish it helps you!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #545454; "&gt;If you still have questions about it, please kindly let me know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Have a great day,&lt;BR /&gt;Kerry&lt;/P&gt;&lt;P style="min- padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;/P&gt;&lt;P style="min- padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt; Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Dec 2019 08:58:37 GMT</pubDate>
    <dc:creator>kerryzhou</dc:creator>
    <dc:date>2019-12-18T08:58:37Z</dc:date>
    <item>
      <title>Hab encrpyted image boot for rt1050</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Hab-encrpyted-image-boot-for-rt1050/m-p/975503#M145188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to create hab encrypted image boot for the rt1050 evkb, I have some trouble about c&lt;SPAN style="color: #545454; background-color: #ffffff; font-size: 14px;"&gt;ertificate authority and the dek.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff; font-size: 14px;"&gt;HAB Security Boot&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;1. CA&amp;nbsp;step&amp;nbsp;issue: The BootRom can verify CA by the public key, Where the public key be stored to provide BootRom?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;2.&amp;nbsp;&lt;SPAN&gt;Dek&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;step&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;issue: DEK is generated from random numbers by&amp;nbsp;the Code Signing Tool (CTS). When I upgrade boot image, I have to used dek to generated dek blok and attached to boot image, I'm not sure, can it run?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;&lt;SPAN style="background-color: #ffffff; "&gt;3.&amp;nbsp;After mass production, We need to maintain private key, public key and dek, is it right?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;&lt;SPAN style="background-color: #ffffff; "&gt;Best Regard,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;&lt;SPAN style="background-color: #ffffff; "&gt;Jim&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Dec 2019 06:52:00 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Hab-encrpyted-image-boot-for-rt1050/m-p/975503#M145188</guid>
      <dc:creator>jimhuang2</dc:creator>
      <dc:date>2019-12-13T06:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Hab encrpyted image boot for rt1050</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Hab-encrpyted-image-boot-for-rt1050/m-p/975504#M145189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A _jive_internal="true" data-content-finding="Community" data-userid="322065" data-username="jimhuang@alltekmarine.com" href="https://community.nxp.com/people/jimhuang@alltekmarine.com"&gt;JingHuan Huang&lt;/A&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Sorry for our later reply!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Before answer your question, I highly recommend you read the AN12079(how to use I.MXRT Security Boot) at first, then it will make you more clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;A class="link-titled" href="https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=AN12079&amp;amp;appType=moderated" title="https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=AN12079&amp;amp;appType=moderated"&gt;https://www.nxp.com/webapp/sps/download/mod_download.jsp?colCode=AN12079&amp;amp;appType=moderated&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Now, answer your questions:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;1. CA&amp;nbsp;step&amp;nbsp;issue: The BootRom can verify CA by the public key, Where the public key be stored to provide BootRom?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;Answer: Public key is stored in the RT eFUSE SRK area.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; background-color: #ffffff;"&gt;2.&amp;nbsp;&lt;SPAN&gt;Dek&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;step&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;issue: DEK is generated from random numbers by&amp;nbsp;the Code Signing Tool (CTS). When I upgrade boot image, I have to used dek to generated dek blok and attached to boot image, I'm not sure, can it run?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt; Answer: Dek.bin is the random number, I think you also can use the old dek.bin, but if you want to use the new dek.bin, it's also OK, just do the new operation steps. I suggest you use the new dek when you use the new app code.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #545454; "&gt;3.&amp;nbsp;After mass production, We need to maintain private key, public key and dek, is it right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #545454; "&gt;Answer: Yes, if you want to program more product, it's better to maintain it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #545454; "&gt;Wish it helps you!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #545454; "&gt;If you still have questions about it, please kindly let me know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Have a great day,&lt;BR /&gt;Kerry&lt;/P&gt;&lt;P style="min- padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;/P&gt;&lt;P style="min- padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt; Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2019 08:58:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Hab-encrpyted-image-boot-for-rt1050/m-p/975504#M145189</guid>
      <dc:creator>kerryzhou</dc:creator>
      <dc:date>2019-12-18T08:58:37Z</dc:date>
    </item>
  </channel>
</rss>

