<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: image file (zImage / u-boot ... etc) signing in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/image-file-zImage-u-boot-etc-signing/m-p/1086371#M159282</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; use Appendix G (Extending the root of trust) of "Secure Boot on i.MX 50, i.MX 53, i.MX 6 and i.MX 7 Series using HABv4" Application Note, Rev. 2, 05/2018.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.nxp.com/docs/en/application-note/AN4581.pdf" title="https://www.nxp.com/docs/en/application-note/AN4581.pdf"&gt;https://www.nxp.com/docs/en/application-note/AN4581.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Apr 2020 08:41:43 GMT</pubDate>
    <dc:creator>Yuri</dc:creator>
    <dc:date>2020-04-28T08:41:43Z</dc:date>
    <item>
      <title>image file (zImage / u-boot ... etc) signing</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/image-file-zImage-u-boot-etc-signing/m-p/1086370#M159281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I read the description of HAB here&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://variwiki.com/index.php?title=High_Assurance_Boot" title="http://variwiki.com/index.php?title=High_Assurance_Boot"&gt;High Assurance Boot - Variscite Wiki&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But there seems to be a part that is not exactly explained.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Taking zImage as an example, it seems that the signing data is added after the image data of the compiled zImage.&lt;/P&gt;&lt;P&gt;Does the added signing data contain only RSA-encrypted data of hash data of a key such as SRK, but not the hash data of the compiled zImage?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that HAB does not boot if the signing data part of the signed zImage is damaged even if 1 bit. Then, if the image data part of zImage is damaged even if 1 bit, not the signing data part of signed zImage, does HAB not boot even in this case?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_2.png"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/106653i16B4300295871940/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_2.png" alt="pastedImage_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, when you try to update to a new image file, can compare the signed data of the file you want to update, such as checking the signed image file in HAB, and perform a Hash compare?&lt;BR /&gt;In other words, is it possible to implement so that the HAB can do it in the user application area in the same way as checking the signed image?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Change a single bit in the authentication block of the image, and confirm that this modified image is rejected when loaded into the device.&lt;BR /&gt;2. Change a single bit in the firmware block of the image, and confirm that this modified image is rejected when loaded into the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above two functions need to be implemented, but when a file that is not booted is to be installed on the device, files with changes in signing data or image data must be rejected by the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Apr 2020 04:25:33 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/image-file-zImage-u-boot-etc-signing/m-p/1086370#M159281</guid>
      <dc:creator>cjej1004</dc:creator>
      <dc:date>2020-04-28T04:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: image file (zImage / u-boot ... etc) signing</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/image-file-zImage-u-boot-etc-signing/m-p/1086371#M159282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; use Appendix G (Extending the root of trust) of "Secure Boot on i.MX 50, i.MX 53, i.MX 6 and i.MX 7 Series using HABv4" Application Note, Rev. 2, 05/2018.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.nxp.com/docs/en/application-note/AN4581.pdf" title="https://www.nxp.com/docs/en/application-note/AN4581.pdf"&gt;https://www.nxp.com/docs/en/application-note/AN4581.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yuri.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Apr 2020 08:41:43 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/image-file-zImage-u-boot-etc-signing/m-p/1086371#M159282</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-04-28T08:41:43Z</dc:date>
    </item>
  </channel>
</rss>

