rt1189 Boot Flow

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

rt1189 Boot Flow

Jump to solution
107 Views
yanyanwang
Contributor I

1. As shown in the figure, does the "Authenticate Image" process verify the hash value during the SHA-512 hashing stage? 

yanyanwang_0-1786097643048.png

2. If I set the hash value, will the BootROM verify the image integrity? And if the BootROM verification fails, will it enter recovery mode?

 

0 Kudos
Reply
1 Solution
9 Views
Gavin_Jia
NXP TechSupport
NXP TechSupport

Please find answers to your two questions below:

1. Can a signed-only (non-encrypted) image go through the BootROM verification flow? Yes. In the RT1180 AHAB, signing (authentication) is the mandatory part of secure boot, ensuring image authenticity and integrity, while encryption (OTFAD/IEE) is an independent, optional anti-cloning feature and is NOT a prerequisite for verification. Therefore, a signed-only image will go through the full AHAB signature verification flow normally, this is also the standard approach in NXP's official SPSDK rt118x_secure_boot example.

2. With oem_close (OEM_CLOSED) enabled, will it still enter the verification flow? Yes, and verification becomes mandatory.

Recommendation: Before performing oem_close, please program the signed image in the OEM_OPEN state first and confirm it boots successfully with no ELE events, then close the device (SRKH is irreversible once fused) to avoid bricking the part.

(Please refer to: i.MX RT1180 Security Reference Manual. After signing the NDA through your company account, submit a request to the online technic sales representative.)

View solution in original post

0 Kudos
Reply
4 Replies
60 Views
Gavin_Jia
NXP TechSupport
NXP TechSupport

Hi @yanyanwang ,

A1: Yes. RT1180 uses AHAB with two authentication layers:

  • Signature layer: ECDSA (SHA-256 / SHA-384) verifies the Container header and image array entry (which stores each image's Hash).
  • Hash layer: The ROM re-computes the digest of the loaded image body and compares it against the Hash stored in the image array entry.

The SHA hashing stage in your figure is exactly this mandatory integrity check, which does verify the hash value.

A2:The ROM always computes and compares the hash, but whether a failure is enforced depends on the device life cycle: the out-of-fab default is the Open configuration, where authentication runs but all authentication errors are ignored and the image still executes. Only after the device is moved to OEM_CLOSED will a hash mismatch actually block boot.

Whether it enters recovery depends on the Recovery Boot fuse. if enabled, a primary-boot authentication failure triggers a re-load and re-authentication from the recovery device; if not enabled, the flow falls through to Serial Downloader / Fatal Mode / reset loop.

Best regards,
Gavin

0 Kudos
Reply
26 Views
yanyanwang
Contributor I

yanyanwang_0-1786444750281.pngyanyanwang_1-1786444764361.png

As shown in the figure above, if I only sign the image and do not encrypt it, will it be able to go through the bootrom verification flow? Additionally, with oem_close enabled, will it still be able to enter the bootrom verification flow?

 
 
0 Kudos
Reply
10 Views
Gavin_Jia
NXP TechSupport
NXP TechSupport

Please find answers to your two questions below:

1. Can a signed-only (non-encrypted) image go through the BootROM verification flow? Yes. In the RT1180 AHAB, signing (authentication) is the mandatory part of secure boot, ensuring image authenticity and integrity, while encryption (OTFAD/IEE) is an independent, optional anti-cloning feature and is NOT a prerequisite for verification. Therefore, a signed-only image will go through the full AHAB signature verification flow normally, this is also the standard approach in NXP's official SPSDK rt118x_secure_boot example.

2. With oem_close (OEM_CLOSED) enabled, will it still enter the verification flow? Yes, and verification becomes mandatory.

Recommendation: Before performing oem_close, please program the signed image in the OEM_OPEN state first and confirm it boots successfully with no ELE events, then close the device (SRKH is irreversible once fused) to avoid bricking the part.

(Please refer to: i.MX RT1180 Security Reference Manual. After signing the NDA through your company account, submit a request to the online technic sales representative.)

0 Kudos
Reply
54 Views
yanyanwang
Contributor I
1. Is hash verification enabled only when the signature authentication feature is enabled? How can hash verification be enabled independently? How can the device be transitioned into the OEM_CLOSED lifecycle state?

2. I will enable the Recovery Boot fuse.

3. My goal is to use an unencrypted image. The Boot ROM should calculate and verify the image hash. If the hash verification fails, the Boot ROM should enter the recovery boot flow and boot the recovery image from the LPSPI NOR Flash.
0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2402874%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3Ert1189%20Boot%20Flow%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2402874%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E1.%20As%20shown%20in%20the%20figure%2C%20does%20the%20%22Authenticate%20Image%22%20process%20verify%20the%20hash%20value%20during%20the%20SHA-512%20hashing%20stage%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22yanyanwang_0-1786097643048.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22yanyanwang_0-1786097643048.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22yanyanwang_0-1786097643048.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22yanyanwang_0-1786097643048.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22yanyanwang_0-1786097643048.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F393976i18C9549847FCED8B%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22yanyanwang_0-1786097643048.png%22%20alt%3D%22yanyanwang_0-1786097643048.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E2.%26nbsp%3BIf%20I%20set%20the%20hash%20value%2C%20will%20the%20BootROM%20verify%20the%20image%20integrity%3F%20And%20if%20the%20BootROM%20verification%20fails%2C%20will%20it%20enter%20recovery%20mode%3F%3C%2FP%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2403165%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20rt1189%20Boot%20Flow%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2403165%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E1.%20Is%20hash%20verification%20enabled%20only%20when%20the%20signature%20authentication%20feature%20is%20enabled%3F%20How%20can%20hash%20verification%20be%20enabled%20independently%3F%20How%20can%20the%20device%20be%20transitioned%20into%20the%20OEM_CLOSED%20lifecycle%20state%3F%3CBR%20%2F%3E%3CBR%20%2F%3E2.%20I%20will%20enable%20the%20Recovery%20Boot%20fuse.%3CBR%20%2F%3E%3CBR%20%2F%3E3.%20My%20goal%20is%20to%20use%20an%20unencrypted%20image.%20The%20Boot%20ROM%20should%20calculate%20and%20verify%20the%20image%20hash.%20If%20the%20hash%20verification%20fails%2C%20the%20Boot%20ROM%20should%20enter%20the%20recovery%20boot%20flow%20and%20boot%20the%20recovery%20image%20from%20the%20LPSPI%20NOR%20Flash.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2403139%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20rt1189%20Boot%20Flow%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2403139%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F258318%22%20target%3D%22_blank%22%3E%40yanyanwang%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%0A%3CDIV%3E%0A%3CP%3EA1%3A%20Yes.%20RT1180%20uses%20AHAB%20with%20two%20authentication%20layers%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ESignature%20layer%3A%20ECDSA%20(SHA-256%20%2F%20SHA-384)%20verifies%20the%20Container%20header%20and%20image%20array%20entry%20(which%20stores%20each%20image's%20Hash).%3C%2FLI%3E%0A%3CLI%3EHash%20layer%3A%20The%20ROM%20re-computes%20the%20digest%20of%20the%20loaded%20image%20body%20and%20compares%20it%20against%20the%20Hash%20stored%20in%20the%20image%20array%20entry.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EThe%20SHA%20hashing%20stage%20in%20your%20figure%20is%20exactly%20this%20mandatory%20integrity%20check%2C%20which%20does%20verify%20the%20hash%20value.%3C%2FP%3E%0A%3CP%3EA2%3A%3CSPAN%3EThe%20ROM%20%3C%2FSPAN%3Ealways%20computes%20and%20compares%20the%20hash%3CSPAN%3E%2C%20but%20%3C%2FSPAN%3Ewhether%20a%20failure%20is%20enforced%20depends%20on%20the%20device%20life%20cycle%3CSPAN%3E%3A%20the%20out-of-fab%20default%20is%20the%20%3C%2FSPAN%3EOpen%3CSPAN%3E%20configuration%2C%20where%20authentication%20runs%20but%20%3C%2FSPAN%3Eall%20authentication%20errors%20are%20ignored%20and%20the%20image%20still%20executes%3CSPAN%3E.%20Only%20after%20the%20device%20is%20moved%20to%20%3C%2FSPAN%3EOEM_CLOSED%3CSPAN%3E%20will%20a%20hash%20mismatch%20actually%20block%20boot.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EWhether%20it%20enters%20recovery%20depends%20on%20the%20Recovery%20Boot%20fuse.%26nbsp%3Bif%20enabled%2C%20a%20primary-boot%20authentication%20failure%20triggers%20a%20re-load%20and%20re-authentication%20from%20the%20recovery%20device%3B%20if%20not%20enabled%2C%20the%20flow%20falls%20through%20to%20Serial%20Downloader%20%2F%20Fatal%20Mode%20%2F%20reset%20loop.%3C%2FP%3E%0A%3CP%3EBest%20regards%2C%3CBR%20%2F%3EGavin%3C%2FP%3E%0A%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2403646%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20rt1189%20Boot%20Flow%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2403646%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22yanyanwang_0-1786444750281.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22yanyanwang_0-1786444750281.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F394177i5836537C926E6A78%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22yanyanwang_0-1786444750281.png%22%20alt%3D%22yanyanwang_0-1786444750281.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22yanyanwang_1-1786444764361.png%22%20style%3D%22width%3A%20289px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22yanyanwang_1-1786444764361.png%22%20style%3D%22width%3A%20289px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F394178i91DD6DBA4C879564%2Fimage-dimensions%2F289x119%3Fv%3Dv2%22%20width%3D%22289%22%20height%3D%22119%22%20role%3D%22button%22%20title%3D%22yanyanwang_1-1786444764361.png%22%20alt%3D%22yanyanwang_1-1786444764361.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CP%20class%3D%22%22%3EAs%20shown%20in%20the%20figure%20above%2C%20if%20I%20only%20sign%20the%20image%20and%20do%20not%20encrypt%20it%2C%20will%20it%20be%20able%20to%20go%20through%20the%20bootrom%20verification%20flow%3F%20Additionally%2C%20with%26nbsp%3Boem_close%26nbsp%3Benabled%2C%20will%20it%20still%20be%20able%20to%20enter%20the%20bootrom%20verification%20flow%3F%3C%2FP%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E