Verifying images in HAB in Linux or OPTEE

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 

Verifying images in HAB in Linux or OPTEE

2,096 次查看
nicholash
Contributor I

Hi, I'm trying to work on an update procedure on an IMX6UL that checks to see if an image will pass the HAB check before updating the images. I'm having trouble accessing the boot ROM from OPTEE so I need to re-implement the authentication function in as a TA in OPTEE or failing that as a regular Linux application, similar to the uboot command hab_auth_img. Is there any code available for this? Is there a way to make the CST do this?

标签 (2)
0 项奖励
回复
5 回复数

1,961 次查看
nicholash
Contributor I

Hi, is there any solution this? This seems like a fairly common use case that will stop people bricking their devices.

0 项奖励
回复

1,961 次查看
Yuri
NXP Employee
NXP Employee

Hello,

 

  I've sent You directly some considerations.

Have a great day,

Yuri

 

 

-------------------------------------------------------------------------------

Note:

- If this post answers your question, please click the "Mark Correct" button. Thank you!

- We are following threads for 7 weeks after the last post, later replies are ignored

 

Please open a new thread and refer to the closed one, if you have a related question at a later point in time.

0 项奖励
回复

105 次查看
lijiangning
Contributor I

We also have the requirement to perform kernel signature verification within OP-TEE. Could you provide the methodology and an implementation (code) for this?

thanks

0 项奖励
回复

1,887 次查看
gcornacchia
Contributor I

Hi Yuri,

I'm trying to use hab checking function for imxull in kernel userspace is there any implementation?

Can you share your considerations?

 

What I would like to achive is a signature checking

 

thank you

标记 (1)
0 项奖励
回复

1,875 次查看
Yuri
NXP Employee
NXP Employee

@gcornacchia 
Hello,

  There is no the hab checking in  userspace.

Regards,
Yuri.

0 项奖励
回复