Secure boot of kernel image

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Secure boot of kernel image

714 Views
Jayashree
Contributor II

Hello I am currently working on securing the boot process of the kernel image using U-Boot on the S32G3 board (BSP 40). I would appreciate some clarification on the following:

  1. In the event of a kernel image boot failure, what is the recommended recovery mechanism? On the M core side, there are two slots available for an image, allowing for a fallback to a backup or alternate image if the primary image fails. This process is managed based on the SMR (Secure Memory Region) configurations. Is there a similar recovery mechanism for the kernel image? If so, could you please provide further details?



0 Kudos
Reply
2 Replies

516 Views
Jayashree
Contributor II

In a scenario where a previously working system is updated with a new kernel image, and the updated system fails to boot due to a bad hash indicating a verification or integrity issue with the newly flashed kernel.
In such a situation, what would be the recommended recovery procedure?

Is it possible to revert to the previous kernel image safely? If so will the newly updated fip.s32 and ATF  support the previous kernel image

Or would reflashing with a known good kernel be the best course of action?

I would appreciate any guidance on best practices for handling such recovery scenarios.
Thank you

0 Kudos
Reply

696 Views
chenyin_h
NXP Employee
NXP Employee

Hello, @Jayashree 

Thanks for your post.

From my understanding, there seems not such features provided within BSP for kernel booting recovery, and it may be designed and implemented by the user according to the specific requirements.

I apologize for your inconvenience.

 

BR

Chenyin

 

0 Kudos
Reply