<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX ProcessorsのトピックRe: Why SRK in eFuse OTP not works?</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184233#M164982</link>
    <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/179728"&gt;@dlliweihua&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; If i.MX8 is not closed, only (SECO) events are generated if an error takes place. &lt;BR /&gt;Image execution is not prevented.&lt;/P&gt;
&lt;PRE style="padding: 0px; margin: 0px; color: #000000; font-size: 13.3333px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;"&gt;Verify SECO events
-------------------------

If the fuses have been written properly, there should be no SECO events after
boot. To validate this, power on the board, and run the following command on
the SCFW terminal:

  &amp;gt;$ seco events&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE style="padding: 0px; margin: 0px; color: #000000; font-size: 13.3333px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;"&gt;After the device successfully boots a signed image without generating any
SECO security events, it is safe to close the device.&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/ahab/guides/mx8_mx8x_secure_boot.txt?h=imx_v2018.03_4.14.78_1.0.0_ga" target="_blank" rel="noopener"&gt;https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/ahab/guides/mx8_mx8x_secure_boot.txt?h=imx_v2018.03_4.14.78_1.0.0_ga&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Yuri.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Nov 2020 05:37:47 GMT</pubDate>
    <dc:creator>Yuri</dc:creator>
    <dc:date>2020-11-17T05:37:47Z</dc:date>
    <item>
      <title>Why SRK in eFuse OTP not works?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184208#M164978</link>
      <description>&lt;P&gt;Hello, NXP experts,&lt;/P&gt;&lt;P&gt;I'm implementing AHBA secure boot on i.MX8DXP and using CST tools(cst-3.3.1) to sign image.&lt;/P&gt;&lt;P&gt;I burned SRK into the fuse OTP, row index from 730 to 745.&lt;/P&gt;&lt;P&gt;According to my understanding, if the used SRK to sign image does not match the SRK in the SRK fuse, the startup verification will fail, but now&amp;nbsp; the image can still boot normally.&lt;/P&gt;&lt;P&gt;Is it my understanding wrong or is there something missing?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;liweihua&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 04:42:45 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184208#M164978</guid>
      <dc:creator>dlliweihua</dc:creator>
      <dc:date>2020-11-17T04:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why SRK in eFuse OTP not works?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184233#M164982</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/179728"&gt;@dlliweihua&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; If i.MX8 is not closed, only (SECO) events are generated if an error takes place. &lt;BR /&gt;Image execution is not prevented.&lt;/P&gt;
&lt;PRE style="padding: 0px; margin: 0px; color: #000000; font-size: 13.3333px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;"&gt;Verify SECO events
-------------------------

If the fuses have been written properly, there should be no SECO events after
boot. To validate this, power on the board, and run the following command on
the SCFW terminal:

  &amp;gt;$ seco events&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE style="padding: 0px; margin: 0px; color: #000000; font-size: 13.3333px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;"&gt;After the device successfully boots a signed image without generating any
SECO security events, it is safe to close the device.&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/ahab/guides/mx8_mx8x_secure_boot.txt?h=imx_v2018.03_4.14.78_1.0.0_ga" target="_blank" rel="noopener"&gt;https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/ahab/guides/mx8_mx8x_secure_boot.txt?h=imx_v2018.03_4.14.78_1.0.0_ga&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Yuri.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 05:37:47 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184233#M164982</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-11-17T05:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why SRK in eFuse OTP not works?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184257#M164986</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/1941"&gt;@Yuri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for your rapid reply.&lt;/P&gt;&lt;P&gt;Do you mean when device is not OEM closed,&lt;/P&gt;&lt;P&gt;if the SRK used to sign boot image is different from the one in fuse OTP,&lt;/P&gt;&lt;P&gt;the device can still booted but the boot is not safe?&lt;/P&gt;&lt;P&gt;My boot loader is ipl, then how to verify seco event?&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;liweihua&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 06:38:44 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184257#M164986</guid>
      <dc:creator>dlliweihua</dc:creator>
      <dc:date>2020-11-17T06:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why SRK in eFuse OTP not works?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184373#M165002</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/179728"&gt;@dlliweihua&lt;/a&gt;&lt;BR /&gt;Hi,&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; when device is not&amp;nbsp; closed, AHAB verifies the image, but, in case of errors,&lt;BR /&gt;it allows further code running. Of course&amp;nbsp; such boot is not safe.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; To review possible events:&amp;nbsp; power on the board, and run the following command &lt;BR /&gt;on the SCFW terminal:&lt;/P&gt;
&lt;P&gt;&amp;gt;$ seco events&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 09:00:00 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184373#M165002</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2020-11-17T09:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why SRK in eFuse OTP not works?</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184378#M165005</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/1941"&gt;@Yuri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;That's ok!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 09:04:41 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Why-SRK-in-eFuse-OTP-not-works/m-p/1184378#M165005</guid>
      <dc:creator>dlliweihua</dc:creator>
      <dc:date>2020-11-17T09:04:41Z</dc:date>
    </item>
  </channel>
</rss>

