HAB Secure Boot Implementation on i.MX6

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 

HAB Secure Boot Implementation on i.MX6

134 次查看
RIthul
Contributor I

I’m working on enabling HAB (High Assurance Boot) on an i.MX6D board. U-Boot is signed and is in Open mode, but during the boot process, I see the following log:

selecting dtb file for el....
Using boot/uImage-imx6.dtb...
48129 bytes read in 4 ms (11.5 MiB/s)
hab fuse not enabled

Authenticate image from DDR location 0x12800000...
bad magic magic=0xff length=0xffff version=0xff
bad length magic=0xff length=0xffff version=0xff
bad version magic=0xff length=0xffff version=0xff
Error: Invalid IVT structure

and also, this output:

=> hab_status

 

Secure boot disabled
prefetch abort
pc : [<00007b50>]          lr : [<8ef790d9>]
reloc pc : [<88891b50>]    lr : [<178030d9>]
sp : 8df68a28  ip : 8ef79249     fp : 00000001
r10: 8effb030  r9 : 8df75ea0     r8 : 00000000
r7 : 8ef976f9  r6 : 8df7a6a8     r5 : 00000000  r4 : 8eff876c
r3 : 00007b55  r2 : 00000001     r1 : 8df68a34  r0 : 8df68a30
Flags: nzCv  IRQs off  FIQs off  Mode SVC_32 (T)
Code: f004 fe4d 4604 4620 (b004) e562 
Resetting CPU ...

The system continues to boot, but HAB reports this Error: Invalid IVT structure, my questions are:

 

  • Do we need to sign the kernel image also for HAB secure boot in open mode?
  • What is the recommended memory map and IVT placement for signing.
  • why is this Error: Invalid IVT structure.

 

标签 (2)
标记 (1)
0 项奖励
回复
0 回复数
%3CLINGO-SUB%20id%3D%22lingo-sub-2248587%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%E5%9C%A8%20i.MX6%20%E4%B8%8A%E5%AE%9E%E7%8E%B0%20HAB%20%E5%AE%89%E5%85%A8%E5%90%AF%E5%8A%A8%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2248587%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E6%88%91%E6%AD%A3%E5%9C%A8%E5%8A%AA%E5%8A%9B%E5%9C%A8%20%3CSTRONG%3Ei.MX6D%3C%2FSTRONG%3E%20%E6%9D%BF%E4%B8%8A%E5%90%AF%E7%94%A8%20%3CSTRONG%3EHAB%EF%BC%88%E9%AB%98%E5%BA%A6%E4%BF%9D%E8%AF%81%E5%90%AF%E5%8A%A8%EF%BC%89%3C%2FSTRONG%3E%E3%80%82U-Boot%20%E5%B7%B2%E7%AD%BE%E5%90%8D%E5%B9%B6%E5%A4%84%E4%BA%8E%E5%BC%80%E6%94%BE%E6%A8%A1%E5%BC%8F%EF%BC%8C%E4%BD%86%E5%9C%A8%E5%90%AF%E5%8A%A8%E8%BF%87%E7%A8%8B%E4%B8%AD%EF%BC%8C%E6%88%91%E7%9C%8B%E5%88%B0%E4%BB%A5%E4%B8%8B%E6%97%A5%E5%BF%97%EF%BC%9A%3C%2FP%3E%3CP%3E%3CSTRONG%3E%E6%AD%A3%E5%9C%A8%E4%B8%BA%E7%94%B5%E5%AD%90%E9%82%AE%E4%BB%B6%E9%80%89%E6%8B%A9%20dtb%20%E6%96%87%E4%BB%B6...%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%20%E6%AD%A3%E5%9C%A8%E4%BD%BF%E7%94%A8%20%E5%90%AF%E5%8A%A8%2FuImage-imx6.dtb...%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%20%E5%9C%A8%204%20%E6%AF%AB%E7%A7%92%20(11.5%20MiB%2Fs)%20%E5%86%85%E8%AF%BB%E5%8F%96%2048129%20%E5%AD%97%E8%8A%82%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%20%E6%9C%AA%E5%90%AF%E7%94%A8%20hab%20%E7%86%94%E4%B8%9D%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%3CSTRONG%3EAuthenticate%20image%20from%20DDR%20location%3C%2FSTRONG%3E0x12800000...%3CBR%20%2F%3E%3CSTRONG%3Ebad%20magic%20magic%3D0xff%20length%3D0xffff%20version%3D0xff%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3Ebad%20length%20magic%3D0xff%20length%3D0xffff%20version%3D0xff%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3Ebad%20version%20magic%3D0xff%20length%3D0xffff%20version%3D0xff%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3EError%EF%BC%9AInvalid%20IVT%20structure%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSTRONG%3Eand%20also%2C%20this%20output%EF%BC%9A%3C%2FP%3E%3CP%3E%3CSTRONG%3E%3D%26gt%3B%20hab_status%3C%2FSTRONG%3E%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%3CSTRONG%3E%E5%AE%89%E5%85%A8%E5%90%AF%E5%8A%A8%E7%A6%81%E7%94%A8%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%20%E9%A2%84%E5%8F%96%E4%B8%AD%E6%AD%A2%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%20%E7%94%B5%E8%84%91%EF%BC%9A%5B%26lt%3B%26lt%3B00007b50%26gt%3B%3CSTRONG%3E%20%26lt%3B88891b50%26gt%3B%26lt%3B178030d9%26gt%3B%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E00007b%2050%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3E%20%3C%2FSTRONG%3E%26gt%3B%5D%20lr%EF%BC%9A%5B%5D%20rel%20oc%20pc%EF%BC%9A%5B%5D%20lr%EF%BC%9A%5B%5D%20sp%EF%BC%9A8df%2068a28%20ip%EF%BC%9A8ef79%20249%20fp%EF%BC%9A00000001%20r10%EF%BC%9A8effb030%20r9%EF%BC%9A8df75ea0%20r8%EF%BC%9A00000000%20r%207%EF%BC%9A8ef976f9%20r6%EF%BC%9A8df7a6a8%20r5%EF%BC%9A00000000%20r4%EF%BC%9A8eff876c%20r%203%EF%BC%9A00007b55%20r2%EF%BC%9A00000001%20r1%EF%BC%9A8df68a34%20r0%EF%BC%9A8df68a30%20%E6%A0%87%E5%BF%97%EF%BC%9AnzCV%20Irqs%20%E5%85%B3%E9%97%AD%E5%B8%B8%E8%A7%81%E9%97%AE%E9%A2%98%E5%85%B3%E9%97%AD%E6%A8%A1%E5%BC%8F%20SVCC_32%20(T)%20%E4%BB%A3%E7%A0%81%EF%BC%9Af004%20fe4d%204604%204620%20(b00%204)%20e56%202%20%E9%87%8D%E7%BD%AE%20CPU...%26lt%3B8ef790d9%26gt%3B%3C%2FSTRONG%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3E%E7%B3%BB%E7%BB%9F%E7%BB%A7%E7%BB%AD%E5%90%AF%E5%8A%A8%EF%BC%8C%E4%BD%86%E6%98%AF%20HAB%20%E6%8A%A5%E5%91%8A%E4%BA%86%E8%BF%99%E4%B8%AA%E9%94%99%E8%AF%AF%EF%BC%9A%3CSTRONG%3EIVT%20%E7%BB%93%E6%9E%84%E6%97%A0%E6%95%88%3C%2FSTRONG%3E%EF%BC%8C%E6%88%91%E7%9A%84%E9%97%AE%E9%A2%98%E6%98%AF%EF%BC%9A%3C%2FP%3E%3CBR%20%2F%3E%3CUL%3E%3CLI%3E%3CSTRONG%3E%E4%B8%BA%E4%BA%86%E5%9C%A8%E5%BC%80%E6%94%BE%E6%A8%A1%E5%BC%8F%E4%B8%8B%E5%AE%89%E5%85%A8%E5%90%AF%E5%8A%A8%20HAB%EF%BC%8C%E6%88%91%E4%BB%AC%E8%BF%98%E9%9C%80%E8%A6%81%E5%AF%B9%E5%86%85%E6%A0%B8%E6%98%A0%E5%83%8F%E8%BF%9B%E8%A1%8C%E7%AD%BE%E5%90%8D%E5%90%97%EF%BC%9F%3C%2FSTRONG%3E%3C%2FLI%3E%3CLI%3E%3CSTRONG%3E%E5%BB%BA%E8%AE%AE%E9%87%87%E7%94%A8%E4%BB%80%E4%B9%88%E5%86%85%E5%AD%98%E6%98%A0%E5%B0%84%E5%92%8C%20IVT%20%E4%BD%8D%E7%BD%AE%E8%BF%9B%E8%A1%8C%E7%AD%BE%E5%90%8D%E3%80%82%3C%2FSTRONG%3E%3C%2FLI%3E%3CLI%3E%3CSTRONG%3E%E4%B8%BA%E4%BB%80%E4%B9%88%E4%BC%9A%E5%87%BA%E7%8E%B0%E9%94%99%E8%AF%AF%EF%BC%9F%E6%97%A0%E6%95%88%E7%9A%84%20IVT%20%E7%BB%93%E6%9E%84%E3%80%82%3C%2FSTRONG%3E%3C%2FLI%3E%3C%2FUL%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2248587%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CLINGO-LABEL%3Ei.MX6%20%E5%8F%8C%E6%A0%B8%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ELinux%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E