HAB

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
228 Views
Abhay2080
Contributor III

I am working on signing the firmware and preparing it for secure boot.

Suppose the development team provides me with a firmware image that already contains the FCB/FCFB, IVT, Boot Data, and other required boot components. My responsibility is only to sign the image and provide the signed firmware back to the development team.

I am using the CST (Code Signing Tool) to generate the signed firmware. I have created the csf.txt file and used cst.exe to generate csf.bin.

My question is: If I simply append csf.bin to the existing firmware image, will the firmware actually be considered signed?

My understanding is that the IVT contains a pointer to the CSF, so if I simply append csf.bin without updating the IVT to point to the CSF location, the ROM may not know where to find the CSF.

So, what is the correct procedure for signing an existing firmware image that already contains the FCB/FCFB, IVT, Boot Data, and other boot components?

I would like to understand the proper flow for generating the final signed firmware image that can be used for secure boot.

Tags (2)
0 Kudos
Reply
1 Solution
183 Views
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @Abhay2080 ,

The flow is something like below:

  1. Dev team sets csf = 0x60000000 + sizeof(firmware.bin) in the IVT during the build. This is a linker/build-time constant.
  2. CST reads firmware.bin (which already has the correct csf pointer), computes the SHA-256 hash over the [Authenticate Data] blocks (which includes the IVT with its pre-set csf value), and produces csf.bin.
  3. cat firmware.bin csf.bin places csf.bin at exactly byte offset sizeof(firmware.bin) — which maps to AHB address 0x60020000 — exactly where the IVT's csf field already points.
  4. HAB at boot reads csf from IVT → jumps to 0x60020000 → finds the CSF → authenticates.

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

View solution in original post

0 Kudos
Reply
1 Reply
184 Views
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @Abhay2080 ,

The flow is something like below:

  1. Dev team sets csf = 0x60000000 + sizeof(firmware.bin) in the IVT during the build. This is a linker/build-time constant.
  2. CST reads firmware.bin (which already has the correct csf pointer), computes the SHA-256 hash over the [Authenticate Data] blocks (which includes the IVT with its pre-set csf value), and produces csf.bin.
  3. cat firmware.bin csf.bin places csf.bin at exactly byte offset sizeof(firmware.bin) — which maps to AHB address 0x60020000 — exactly where the IVT's csf field already points.
  4. HAB at boot reads csf from IVT → jumps to 0x60020000 → finds the CSF → authenticates.

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2410104%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EHAB%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2410104%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%20class%3D%22%22%3E%3CSPAN%3EI%20am%20working%20on%20signing%20the%20firmware%20and%20preparing%20it%20for%20secure%20boot.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%3ESuppose%20the%20development%20team%20provides%20me%20with%20a%20firmware%20image%20that%20already%20contains%20the%20FCB%2FFCFB%2C%20IVT%2C%20Boot%20Data%2C%20and%20other%20required%20boot%20components.%20My%20responsibility%20is%20only%20to%20sign%20the%20image%20and%20provide%20the%20signed%20firmware%20back%20to%20the%20development%20team.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%3EI%20am%20using%20the%20CST%20(Code%20Signing%20Tool)%20to%20generate%20the%20signed%20firmware.%20I%20have%20created%20the%20%3C%2FSPAN%3E%3CSPAN%3Ecsf.txt%3C%2FSPAN%3E%3CSPAN%3E%20file%20and%20used%20%3C%2FSPAN%3E%3CSPAN%3Ecst.exe%3C%2FSPAN%3E%3CSPAN%3E%20to%20generate%20%3C%2FSPAN%3E%3CSPAN%3Ecsf.bin%3C%2FSPAN%3E%3CSPAN%3E.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%3EMy%20question%20is%3A%20%3C%2FSPAN%3E%3CSTRONG%3E%3CSPAN%3EIf%20I%20simply%20append%20%3C%2FSPAN%3E%3C%2FSTRONG%3E%3CSTRONG%3E%3CSPAN%3Ecsf.bin%3C%2FSPAN%3E%3C%2FSTRONG%3E%3CSTRONG%3E%3CSPAN%3E%20to%20the%20existing%20firmware%20image%2C%20will%20the%20firmware%20actually%20be%20considered%20signed%3F%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%3EMy%20understanding%20is%20that%20the%20IVT%20contains%20a%20pointer%20to%20the%20CSF%2C%20so%20if%20I%20simply%20append%20%3C%2FSPAN%3E%3CSPAN%3Ecsf.bin%3C%2FSPAN%3E%3CSPAN%3E%20without%20updating%20the%20IVT%20to%20point%20to%20the%20CSF%20location%2C%20the%20ROM%20may%20not%20know%20where%20to%20find%20the%20CSF.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%3ESo%2C%20what%20is%20the%20correct%20procedure%20for%20signing%20an%20existing%20firmware%20image%20that%20already%20contains%20the%20FCB%2FFCFB%2C%20IVT%2C%20Boot%20Data%2C%20and%20other%20boot%20components%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20would%20like%20to%20understand%20the%20proper%20flow%20for%20generating%20the%20final%20signed%20firmware%20image%20that%20can%20be%20used%20for%20secure%20boot.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2410251%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20HAB%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2410251%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F261235%22%20target%3D%22_blank%22%3E%40Abhay2080%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%0A%3CP%20class%3D%22p8i6j01%20paragraph%22%3EThe%20flow%20is%20something%20like%20below%3A%3C%2FP%3E%0A%3COL%20class%3D%22p8i6j02%22%3E%0A%3CLI%20class%3D%22p8i6j0a%22%3E%3CSTRONG%3EDev%20team%20sets%20%3CCODE%20class%3D%22p8i6j0f%22%3Ecsf%3C%2FCODE%3E%20%3D%20%3CCODE%20class%3D%22p8i6j0f%22%3E0x60000000%20%2B%20sizeof(firmware.bin)%3C%2FCODE%3E%3C%2FSTRONG%3E%20in%20the%20IVT%20during%20the%20build.%20This%20is%20a%20linker%2Fbuild-time%20constant.%3C%2FLI%3E%0A%3CLI%20class%3D%22p8i6j0a%22%3E%3CSTRONG%3ECST%20reads%20%3CCODE%20class%3D%22p8i6j0f%22%3Efirmware.bin%3C%2FCODE%3E%3C%2FSTRONG%3E%20(which%20already%20has%20the%20correct%20%3CCODE%20class%3D%22p8i6j0f%22%3Ecsf%3C%2FCODE%3E%20pointer)%2C%20computes%20the%20SHA-256%20hash%20over%20the%20%3CCODE%20class%3D%22p8i6j0f%22%3E%5BAuthenticate%20Data%5D%3C%2FCODE%3E%20blocks%20(which%20includes%20the%20IVT%20with%20its%20pre-set%20%3CCODE%20class%3D%22p8i6j0f%22%3Ecsf%3C%2FCODE%3E%20value)%2C%20and%20produces%20%3CCODE%20class%3D%22p8i6j0f%22%3Ecsf.bin%3C%2FCODE%3E.%3C%2FLI%3E%0A%3CLI%20class%3D%22p8i6j0a%22%3E%3CSTRONG%3E%3CCODE%20class%3D%22p8i6j0f%22%3Ecat%20firmware.bin%20csf.bin%3C%2FCODE%3E%3C%2FSTRONG%3E%20places%20%3CCODE%20class%3D%22p8i6j0f%22%3Ecsf.bin%3C%2FCODE%3E%20at%20exactly%20byte%20offset%20%3CCODE%20class%3D%22p8i6j0f%22%3Esizeof(firmware.bin)%3C%2FCODE%3E%20%E2%80%94%20which%20maps%20to%20AHB%20address%20%3CCODE%20class%3D%22p8i6j0f%22%3E0x60020000%3C%2FCODE%3E%20%E2%80%94%20exactly%20where%20the%20IVT's%20%3CCODE%20class%3D%22p8i6j0f%22%3Ecsf%3C%2FCODE%3E%20field%20already%20points.%3C%2FLI%3E%0A%3CLI%20class%3D%22p8i6j0a%22%3E%3CSTRONG%3EHAB%20at%20boot%3C%2FSTRONG%3E%20reads%20%3CCODE%20class%3D%22p8i6j0f%22%3Ecsf%3C%2FCODE%3E%20from%20IVT%20%E2%86%92%20jumps%20to%20%3CCODE%20class%3D%22p8i6j0f%22%3E0x60020000%3C%2FCODE%3E%20%E2%86%92%20finds%20the%20CSF%20%E2%86%92%20authenticates.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CBR%20%2F%3E%0A%3CP%3EHave%20a%20great%20day%2C%3CBR%20%2F%3EKan%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E-------------------------------------------------------------------------------%3CBR%20%2F%3ENote%3A%3CBR%20%2F%3E-%20If%20this%20post%20answers%20your%20question%2C%20please%20click%20the%20%22Mark%20Correct%22%20button.%20Thank%20you!%3CBR%20%2F%3E-%20We%20are%20following%20threads%20for%207%20weeks%20after%20the%20last%20post%2C%20later%20replies%20are%20ignored%3CBR%20%2F%3EPlease%20open%20a%20new%20thread%20and%20refer%20to%20the%20closed%20one%2C%20if%20you%20have%20a%20related%20question%20at%20a%20later%20point%20in%20time.%3CBR%20%2F%3E-------------------------------------------------------------------------------%3C%2FP%3E%3C%2FLINGO-BODY%3E