Secure boot i.mx7D Series using HABv4

cancel
Showing results for 
Search instead for 
Did you mean: 

Secure boot i.mx7D Series using HABv4

Jump to solution
244 Views
Contributor I

I use  HAB successfully authenticates the signed image .HAB didn't generate any events.I use  fuse prog 1 3 0x2000000  this commond to close the devices.I can load u-boot images that have been signed.But when I load u-boot images that don't have been signed.The devices cann't power on . I can't get any message from the USB port and Serial port.They can't work.What should I do to save my devices.And what's the reason that my devices can't power on.

Labels (1)
Tags (1)
0 Kudos
1 Solution
65 Views
Community Manager
This an automatic process.

We are marking this post as solved, due to the either low activity or any reply marked as correct.

If you have additional questions, please create a new post and reference to this closed post.

NXP Community!

View solution in original post

0 Kudos
4 Replies
66 Views
Community Manager
This an automatic process.

We are marking this post as solved, due to the either low activity or any reply marked as correct.

If you have additional questions, please create a new post and reference to this closed post.

NXP Community!

View solution in original post

0 Kudos
67 Views
NXP TechSupport
NXP TechSupport

Hi longlong

please check AN4581 Secure Boot on i.MX50, i.MX53, i.MX6 and i.MX7 Series using HABv4

https://www.nxp.com/docs/en/application-note/AN4581.pdf 

Note, once burned, fuse can not be restored to original state.

Best regards
igor

0 Kudos
67 Views
NXP Employee
NXP Employee

Hi,

This is normal - once you have closed the device, the secure boot feature will not let anymore the execution passing to u-boot if the signature checking will fail. So, you'll be able to run only u-boot/images signed with the proper keys in sync with the SRK hashes.

Regards,

Marius

0 Kudos
67 Views
Contributor I

I have closed my device and secured my device ,hab_status shows that Secure boot enabled.I have downloaded a signed u-boot.imx ,but why I can download a no signed boot.img .It's not secure.I think a signed u-boot.imx can't load a no signed boot.img.Can you help me.Thank you!

0 Kudos