DEK Blob generation for encrypted boot

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 

DEK Blob generation for encrypted boot

875 次查看
spthx
Contributor II

Hi,

I would like to apply HAB (encrypted boot) to a product that uses i.MX8MN.
For encrypted boot, we need to generate a DEK Blob on the device side,
It is generated by calling dek_blob.pta in OP-TEE.

We have confirmed that using a DEK Blob generated with PRIBLOB=01 in CAAM, the device boots successfully from the encrypted image with the DEK Blob merged.
However, if a DEK Blob generated with PRIBLOB=11 is used, the boot fails.

For this reason, it seems that PRIBLOB cannot be set to 11 in order to generate Blobs that support encrypted boot when implementing the software update function.
However, it also seems that this setting is not recommended.

In view of the implementation of the software update function, could you please tell us about the best practice for DEK Blob generation?

Best regards,

 

标签 (1)
0 项奖励
回复
2 回复数

677 次查看
spthx
Contributor II

Thank you.
However, you do not seem to have understood the question.
It did not answer the question.

0 项奖励
回复

736 次查看
Harvey021
NXP TechSupport
NXP TechSupport

Hi,

I reply back to you via system service email regarding the secure case.

 

Regards

Harvey

0 项奖励
回复