I am working on IMXRT1024 core and want to test HAB without burning fuses. And as per datasheet every fuses have their shadow register and CPU/ROM read from that shadow register.
I am thinking to write those shadow register and create a scenario such that boot ROM thinks Boards is HAB enabled. But again since boot rom execution is very beginning can you suggest is there any way to leverage the shadow register and create a testing setup?
Q.2 -> If suppose in a closed board HAB authentication fails how can i get the audit report?
Hello @Abhay2080,
Please refer to Kan Li's response in this thread. It describes several approaches for testing HAB without programming the fuses.
Regarding your second question, I highly recommend using the Secure Provisioning Tool, as it greatly simplifies the process of creating a HAB-enabled image. The tool automatically generates the CSF and prepares the image so that HAB can properly authenticate it during the boot sequence, which is why this is standard tool to handle applications just like this one. You can follow the Booting an Authenticated (HAB) Image flow to achieve this.
Please keep in mind that burning fuses can only be done once, after that the processor can only execute authenticated images.
BR
Habib
Hello @Abhay2080,
Please follow the approach recommended by Kan Li. HAB authentication is performed even when the device is in the Open security configuration, as described in the chapter 9.3.6 "Boot Security Settings" of the RM. Therefore, it is also possible to review the HAB event logs generated by the ROM boot to verify that the HAB authentication process is executing correctly.
The main purpose of the shadow registers is to provide a software-accessible representation of the OTP fuse values loaded by the device, as shown the figure 23-1 "OCOTP System Level Block Diagram" of the RM.
Regarding the audit logs, I understand that you are referring to the HAB event log generated by the ROM during the boot authentication process. Is my understanding correct? If so, in this community post Gavin Jia explains two methods for observe this log. In particular, the response to question 2 directly addresses the customer's inquiry.
BR
Habib
Yeah, I already went through Kan Li's response, but it does not include anything about the shadow registers. So, my question is simply whether it is possible to use the shadow registers and test them.
Regarding the audit logs, I just need them for logging purposes. I understand that using SPT properly will enable us to create HAB successfully.