<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>i.MX Processors中的主题 Re: Encrypted + signed uImage using HAB</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Encrypted-signed-uImage-using-HAB/m-p/519678#M84241</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem is that the decryption block size was not a multiple of they Data Encryption Key length. Fixing that solved the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Jun 2016 07:34:52 GMT</pubDate>
    <dc:creator>jdepedro</dc:creator>
    <dc:date>2016-06-16T07:34:52Z</dc:date>
    <item>
      <title>Encrypted + signed uImage using HAB</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Encrypted-signed-uImage-using-HAB/m-p/519677#M84240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;I am trying to use the i.MX6 HAB to validate and descrypt a uImage. I am using a closed device, and a signed and encrypted U-Boot which works just fine.&lt;/P&gt;&lt;P&gt;I have been able to use signed uImage (signing the complete range).&lt;/P&gt;&lt;P&gt;I now want to be able to use signed and encrypted uImages. In order to do that, the following must be taken into account:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;U-Boot reads the uImage header before loading it to RAM (that is, before the uImage is descrypted). That menas the uImage header (0x40) cannot be encrypted.&lt;/LI&gt;&lt;LI&gt;According to HAB requirements, the following data must be authenticated (cannot be encrypted, as encryption and signature rangse cannot overlap):&lt;UL&gt;&lt;LI&gt;IVT: In my case 0x4C3000-0x4C3020&lt;/LI&gt;&lt;LI&gt;DCD (if provided): Not provided in my case&lt;/LI&gt;&lt;LI&gt;Boot data (initial byte if provided): Not provided in my case&lt;/LI&gt;&lt;LI&gt;Entry point (inital word) : 0x12001000-0x12001004 in my case.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I would like to encrypt the max amount of data. Taking into account these requirements, I have created this CSF description file:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Header]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Version = 4.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hash Algorithm = sha256&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engine Configuration = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Certificate Format = X509&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Signature Format = CMS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engine = CAAM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install SRK]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "../crts/SRK_1_2_3_4_table.bin"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source index = 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install CSFK]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "../crts/CSF4_1_sha256_2048_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate CSF]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install Key]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Target index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "../crts/IMG4_1_sha256_2048_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x124c3000 0x4c3000 0x20 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12001000 0x1000 0x4 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12000000 0x0 0x40 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Install Secret Key]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Target index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key = "dek.bin"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key Length = 128&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blob address = 0x124c5020&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Decrypt Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Bytes = 16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12000040 0x40 0xFC0 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Decrypt Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Bytes = 16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12002000 0x2000 0x10 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice that in the last Decrpyt data block ,the size should be larger than 0x10 (should be 0x4c3000 - 0x1004&amp;nbsp; = 0x4c1ffc) which I have also tried. I used 0x10 trying to avoid the problem (didn't work).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That CSF file, generates this error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authenticate image from DDR location 0x12000000...&lt;/P&gt;&lt;P&gt;hab_rvt_entry success :smileyhappy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ivt_offset = 0x4c3000, ivt addr = 0x124c3000&lt;/P&gt;&lt;P&gt;Dumping IVT&lt;/P&gt;&lt;P&gt;124c3000: 402000d1 12001000 00000000 00000000&amp;nbsp;&amp;nbsp;&amp;nbsp; .. @............&lt;/P&gt;&lt;P&gt;124c3010: 00000000 124c3000 124c3020 00000000&amp;nbsp;&amp;nbsp;&amp;nbsp; .....0L. 0L.....&lt;/P&gt;&lt;P&gt;Dumping CSF Header&lt;/P&gt;&lt;P&gt;124c3020: 415000d4 000c00be 00031703 50000000&amp;nbsp;&amp;nbsp;&amp;nbsp; ..PA...........P&lt;/P&gt;&lt;P&gt;124c3030: 020c00be 01000009 90040000 000c00ca&amp;nbsp;&amp;nbsp;&amp;nbsp; ................&lt;/P&gt;&lt;P&gt;124c3040: 001dc501 e4070000 010c00be 000000bb&amp;nbsp;&amp;nbsp;&amp;nbsp; ................&lt;/P&gt;&lt;P&gt;124c3050: 20504c12 001400ca 001da300 e8090000&amp;nbsp;&amp;nbsp;&amp;nbsp; .LP ............&lt;/P&gt;&lt;P&gt;--- Status before ---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secure boot enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HAB Configuration: 0xcc, HAB State: 0x99&lt;/P&gt;&lt;P&gt;No HAB Events Found!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--- ------------- ----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Calling authenticate_image in ROM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ivt_offset = 0x4c3000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; start = 0x12000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bytes = 0x4c5020&lt;/P&gt;&lt;P&gt;load_addr: 0&lt;/P&gt;&lt;P&gt;hab_rvt_exit() success :smileyhappy:&lt;/P&gt;&lt;P&gt;--- status after ---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secure boot enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HAB Configuration: 0xcc, HAB State: 0x99&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- HAB Event 1 -----------------&lt;/P&gt;&lt;P&gt;event data:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xdb 0x00 0x1c 0x41 0x33 0x18 0xc0 0x1d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xca 0x00 0x14 0x00 0x00 0xa3 0x1d 0x00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x09 0xe8 0x12 0x00 0x00 0x40&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00 0x00 0x0f 0xc0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;STS = HAB_FAILURE (0x33)&lt;/P&gt;&lt;P&gt;RSN = HAB_INV_SIGNATURE (0x18)&lt;/P&gt;&lt;P&gt;CTX = HAB_CTX_COMMAND (0xC0)&lt;/P&gt;&lt;P&gt;ENG = HAB_ENG_CAAM (0x1D)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--- ------------ ---&lt;/P&gt;&lt;P&gt;Authenticate uImage Fail, Please check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HAB_INV_SIGNATURE means that the signature is not correct.&amp;nbsp; From the HAB event we can interpret that the following block causes the error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Decrypt Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Bytes = 16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12000040 0x40 0xFC0 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tested other configurations which worked fine:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Only signing the image (commenting the encryption blocks) works fine. That is using the following CSF:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;[Header]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Version = 4.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hash Algorithm = sha256&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engine Configuration = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Certificate Format = X509&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Signature Format = CMS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engine = CAAM&lt;/P&gt;&lt;P&gt;[Install SRK]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "../crts/SRK_1_2_3_4_table.bin"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source index = 3&lt;/P&gt;&lt;P&gt;[Install CSFK]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "../crts/CSF4_1_sha256_2048_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;[Authenticate CSF]&lt;/P&gt;&lt;P&gt;[Install Key]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Target index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "../crts/IMG4_1_sha256_2048_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x124c3000 0x4c3000 0x20 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12001000 0x1000 0x4 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12000000 0x0 0x40 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;#[Install Secret Key]&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Target index = 0&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Key = "dek.bin"&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Key Length = 128&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Blob address = 0x124c5020&lt;/P&gt;&lt;P&gt;#[Decrypt Data]&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Bytes = 16&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12000040 0x40 0xFC0 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;#[Decrypt Data]&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Bytes = 16&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12002000 0x2000 0x10 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Commenting the first encryption range, also works properly, that is, using this CSF:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;[Header]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Version = 4.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hash Algorithm = sha256&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engine Configuration = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Certificate Format = X509&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Signature Format = CMS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Engine = CAAM&lt;/P&gt;&lt;P&gt;[Install SRK]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "../crts/SRK_1_2_3_4_table.bin"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source index = 3&lt;/P&gt;&lt;P&gt;[Install CSFK]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "../crts/CSF4_1_sha256_2048_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;[Authenticate CSF]&lt;/P&gt;&lt;P&gt;[Install Key]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Target index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File = "../crts/IMG4_1_sha256_2048_65537_v3_usr_crt.pem"&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x124c3000 0x4c3000 0x20 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12001000 0x1000 0x4 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;[Authenticate Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12000000 0x0 0x40 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;[Install Secret Key]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Target index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key = "dek.bin"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key Length = 128&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blob address = 0x124c5020&lt;/P&gt;&lt;P&gt;#[Decrypt Data]&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Bytes = 16&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12000040 0x40 0xFC0 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;[Decrypt Data]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verification index = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Bytes = 16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks = 0x12002000 0x2000 0x10 "zImage-pad-ivt.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This menas the problem has to be with the commented Decryot data block in the CSF descrption file above. I don't see anything wrong with it, as far as I can see there are no overlap between signature and encryption ranges. I don't understand why this does not work. Could you provide some help on this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jun 2016 14:16:23 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Encrypted-signed-uImage-using-HAB/m-p/519677#M84240</guid>
      <dc:creator>jdepedro</dc:creator>
      <dc:date>2016-06-13T14:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted + signed uImage using HAB</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Encrypted-signed-uImage-using-HAB/m-p/519678#M84241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem is that the decryption block size was not a multiple of they Data Encryption Key length. Fixing that solved the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2016 07:34:52 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Encrypted-signed-uImage-using-HAB/m-p/519678#M84241</guid>
      <dc:creator>jdepedro</dc:creator>
      <dc:date>2016-06-16T07:34:52Z</dc:date>
    </item>
  </channel>
</rss>

