I'm implementing Secure Boot on the QorIQ T1023 SoC. I have to write the hash of the pubkey into the fuse box.
Is it possible to prototype secure boot with a "temporary" pubkey and to change the pubkey hash later on? I.e. can I write the pubkey hash to the fuse box multiple times?
There is a "Write Protect" bit (SFP_OSPR.WP) which suggest that it might be possible.
Solved! Go to Solution.
Blowing a fuse is an irreversible action. Per T1023 HW specification,
the chip allows two fuse programming cycles, so you don't have to blow
all necessary fuses at once, but that doesn't mean there is a way
to "unblow" a fuse. If you are working in a development environment
and don't want to permanently program the SRK hash, you have an option
to put it into SFP mirror registers one each boot, while the core is
held in reset. Note that this method will not work with OTPMK, which
_must_ be blown, and it will not work if you blown ITS fuse.
Details can be found in QorIQ SDK online documentation:
Have a great day,
Platon
-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------
Blowing a fuse is an irreversible action. Per T1023 HW specification,
the chip allows two fuse programming cycles, so you don't have to blow
all necessary fuses at once, but that doesn't mean there is a way
to "unblow" a fuse. If you are working in a development environment
and don't want to permanently program the SRK hash, you have an option
to put it into SFP mirror registers one each boot, while the core is
held in reset. Note that this method will not work with OTPMK, which
_must_ be blown, and it will not work if you blown ITS fuse.
Details can be found in QorIQ SDK online documentation:
Have a great day,
Platon
-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------