Hi @Yuri .
I appreciate your response. Just to clarify my question a little more please see the notes below
1. In figure 5, the CSF without the DEK blob is of size 0x2000. In the community thread, it clearly (and correctly) says: "** (CSF bin data + padding + dek_blob.bin) has to have size 0x2000 ". This includes DEK blob. I think there might be a mistake in AN12056.
2. I understand the process. my question is: is there any security benefit of signing the entire image again in a second step? during the first encryption step, parts of the image are already signed, and the main binary is encrypted.
Thank you for your time!