<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Vybrid ProcessorsのトピックRe: Vybrid and HAB authentication</title>
    <link>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661614#M5813</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; Please create request in order to get detailed example for i.MX6, which hope - helps.&amp;nbsp; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;A href="https://community.nxp.com/docs/DOC-329745"&gt;https://community.nxp.com/docs/DOC-329745&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Have a great day,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Yuri&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Note: If this post answers your question, please click the Correct Answer &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;button. Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Nov 2016 05:54:26 GMT</pubDate>
    <dc:creator>Yuri</dc:creator>
    <dc:date>2016-11-03T05:54:26Z</dc:date>
    <item>
      <title>Vybrid and HAB authentication</title>
      <link>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661610#M5809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having trouble getting HAB authentication to work on the TWR-VF65GS10 and am wondering what I am missing or what I can try to do to get it to work. The compiler I am using is IAR Embedded Workbench.&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my situation, I have 2 tower boards: one in open state that I am using for reference and the other in closed state with the SRK values generated by the cst 2.3.1 package written to the OCOTP_SRK fuses. I can still debug using JTAG on the closed board.&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a program blink.bin (attached along with linker file sram_iar_a5.icf) that will boot from the SD card and then continuously blink the LEDs on the tower board based on the example in \Freescale\Freescale_MQX_4_2\mqx\examples\bootloader_vybrid. I booted blink.bin from the SD card on the open board and confirmed that it worked but after following the signing steps on blink.bin I cannot get the signed image to boot from the SD card on the closed board.&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far, I have been using AN4581 as a guide.&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From there I generated the PKI tree and SRK table.&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I programmed the fuses and verified with the debugger (OCOTP_SRK#) that they were actually programmed.&lt;/P&gt;&lt;P&gt;(Do I have the order and endianess correct in the example below?)&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;eg.&lt;/P&gt;&lt;P&gt;hexdump -e '/4 "0x"' -e '/4 "%X""\n"' SRK_1_2_3_4_fuse.bin&lt;/P&gt;&lt;P&gt;0x00112233&lt;/P&gt;&lt;P&gt;0x44556677&lt;/P&gt;&lt;P&gt;0x8899AABB&lt;/P&gt;&lt;P&gt;0xCCDDEEFF&lt;/P&gt;&lt;P&gt;0x00112233&lt;/P&gt;&lt;P&gt;0x44556677&lt;/P&gt;&lt;P&gt;0x8899AABB&lt;/P&gt;&lt;P&gt;0xCCDDEEFF&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="166388_166388.png"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/122402i662D551715731AE2/image-size/large?v=v2&amp;amp;px=999" role="button" title="166388_166388.png" alt="166388_166388.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_3.png"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/5114i97E424D325A309EB/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_3.png" alt="pastedImage_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next, I closed the board by programming Bank 0, Word 6, Byte 0 to 0x02 (verified with OCOTP_CFG5).&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next, I took blink.bin and padded with zeros at the end to align it with 0x1000 size to make blink_padded.bin (attached)&lt;/P&gt;&lt;P&gt;(Am I padding the wrong area?).&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I ran the following to generate blink_csf.bin (attached) using blink.csf file (attached) and concatenated blink_padded.bin + blink_csf.bin = blink_signed.bin (attached) :&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thomas@thomas-VirtualBox:~/cst/cst-2.3.1/blink$ ../linux64/cst --o blink_csf.bin &amp;lt; blink.csf&lt;BR /&gt;CSF Processed successfully and signed data available in blink_csf.bin&lt;BR /&gt;thomas@thomas-VirtualBox:~/cst/cst-2.3.1/blink$ cat blink_padded.bin blink_csf.bin &amp;gt; blink_signed.bin&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next on Windows I copied the blink_signed.bin image onto the SD card:&lt;/P&gt;&lt;P&gt;C:\Freescale\Freescale_MQX_4_2\tools\ddcopy&amp;gt;ddcopy.exe infile=blink_signed.bin outdevice=u: seek=0x400 obs=512&lt;BR /&gt;start copying&lt;BR /&gt;done&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I tried to boot using the SD card on the closed board with the jumpers as shown but blink does not seem to be able to run.&lt;/P&gt;&lt;P&gt;(Do I have some jumper(s) in the wrong place?)&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="166389_166389.png"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/122403i29B606DC27F46A01/image-size/large?v=v2&amp;amp;px=999" role="button" title="166389_166389.png" alt="166389_166389.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_4.png"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/5197i423CDF0ACF2E645C/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_4.png" alt="pastedImage_4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I took the same SD card and booted it on the open board and it was able to run so I think it must have something to do with the HAB.&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From AN4581, I understand that iMX6 has a hab_status command that can be enabled in U-Boot to look at the events that were generated. I was able to compile and run U-Boot on the Vybrid tower with the instructions here &lt;A _jive_internal="true" data-containerid="11048" data-containertype="14" data-objectid="95248" data-objecttype="102" href="https://community.nxp.com/docs/DOC-95248"&gt;u-boot on the Vybrid tower board in a few commands&lt;/A&gt; and added #define CONFIG_SECURE_BOOT to vf610twr.h but I don't think there is support for the hab_status command for Vybrid on U-Boot? Is there another way to examine the events that are generated to try to figure out what exactly the HAB is dissatisfied with?&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice would be appreciated.&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Attachment has been moved to: &lt;A _jive_internal="true" href="https://community.nxp.com/docs/DOC-338838"&gt;blink_csf.bin.zip&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Attachment has been moved to: &lt;A _jive_internal="true" href="https://community.nxp.com/docs/DOC-338838"&gt;blink.csf.zip&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Attachment has been moved to: &lt;A _jive_internal="true" href="https://community.nxp.com/docs/DOC-338838"&gt;blink_padded.bin.zip&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Attachment has been moved to: &lt;A _jive_internal="true" href="https://community.nxp.com/docs/DOC-338838"&gt;sram_iar_a5.icf.zip&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Attachment has been moved to: &lt;A _jive_internal="true" href="https://community.nxp.com/docs/DOC-338838"&gt;blink_signed.bin.zip&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Attachment has been moved to: &lt;A _jive_internal="true" href="https://community.nxp.com/docs/DOC-338838"&gt;blink.bin.zip&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Oct 2016 01:49:56 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661610#M5809</guid>
      <dc:creator>twong</dc:creator>
      <dc:date>2016-10-22T01:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Vybrid and HAB authentication</title>
      <link>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661611#M5810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In vybrid reference manual, it states that there is a csf value inside the ivt which points to the csf. In my binaries, the values are 0. I used a hex editor to modify the ivt (7th uint32_t) in the binary to 0x3f060400 (start of ivt 0x3f040400 + padded binary size 0x20000), the address csf should be at in memory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also tried padding the end of the signed file to 0x1000 size.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Changed version value in csf header value from 4.1 to 4.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of the above got it to work though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Oct 2016 00:45:34 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661611#M5810</guid>
      <dc:creator>twong</dc:creator>
      <dc:date>2016-10-25T00:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Vybrid and HAB authentication</title>
      <link>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661612#M5811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears my locked board is preproduction as referenced here &lt;A href="https://community.nxp.com/thread/314356"&gt;https://community.nxp.com/thread/314356&lt;/A&gt;. All the OTPMK values were 0 so I burned in random values to the OTPMK fuses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The closed board still won't boot though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Oct 2016 23:47:18 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661612#M5811</guid>
      <dc:creator>twong</dc:creator>
      <dc:date>2016-10-25T23:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Vybrid and HAB authentication</title>
      <link>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661613#M5812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tried adjusting values so address of CSF is aligned with 0x1000 but closed board still won't boot though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Padded blink.bin to create blink_padded.bin with file size of 0x20C00 = 0x21000 - 0x400 (ivt starts right at the beginning of file in blink.bin, not at byte 0x400 of file in blink.bin)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adjusted blink.csf blocks line to:&lt;/P&gt;&lt;P&gt;Blocks = 0x3f040400 0x000 0x20C00 "/home/thomas/cst/cst-2.3.1/blink/blink_padded.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From CST User guide:&lt;/P&gt;&lt;P&gt;List of one or more data blocks. Each&lt;BR /&gt;block is specified by four parameters:&lt;BR /&gt;source file (must be binary),&lt;BR /&gt;starting load address in memory&lt;BR /&gt;starting offset within the source file&lt;BR /&gt;length (in bytes)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The layout of SD card should be:&lt;/P&gt;&lt;P&gt;-- 0x0&lt;/P&gt;&lt;P&gt;blank&lt;/P&gt;&lt;P&gt;-- 0x400 -- (blink_padded.bin)&lt;/P&gt;&lt;P&gt;ivt, dcd, boot_data&lt;/P&gt;&lt;P&gt;program&lt;/P&gt;&lt;P&gt;padding&lt;/P&gt;&lt;P&gt;-- 0x21000 -- (blink_csf.bin)&lt;/P&gt;&lt;P&gt;csf data&lt;/P&gt;&lt;P&gt;padding&lt;/P&gt;&lt;P&gt;-- 0x22000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SRAM layout should then be:&lt;/P&gt;&lt;P&gt;-- 0x3f040400&lt;/P&gt;&lt;P&gt;ivt, dcd, boot_data&lt;/P&gt;&lt;P&gt;program&lt;/P&gt;&lt;P&gt;padding&lt;/P&gt;&lt;P&gt;-- 0x3f061000&lt;/P&gt;&lt;P&gt;csf data&lt;/P&gt;&lt;P&gt;padding&lt;/P&gt;&lt;P&gt;-- 0x3f062000&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Oct 2016 00:55:48 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661613#M5812</guid>
      <dc:creator>twong</dc:creator>
      <dc:date>2016-10-26T00:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Vybrid and HAB authentication</title>
      <link>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661614#M5813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; Please create request in order to get detailed example for i.MX6, which hope - helps.&amp;nbsp; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;A href="https://community.nxp.com/docs/DOC-329745"&gt;https://community.nxp.com/docs/DOC-329745&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Have a great day,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Yuri&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Note: If this post answers your question, please click the Correct Answer &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;button. Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Nov 2016 05:54:26 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Vybrid-Processors/Vybrid-and-HAB-authentication/m-p/661614#M5813</guid>
      <dc:creator>Yuri</dc:creator>
      <dc:date>2016-11-03T05:54:26Z</dc:date>
    </item>
  </channel>
</rss>

