AnsweredAssumed Answered

Key generation for encrypted boot

Question asked by Frieder Baumgratz on Jan 17, 2017
Latest reply on Jan 18, 2017 by Frieder Baumgratz

Dear NXP community,

 

I am currently working on the encrypted boot for IMX.6 CPUs.

 

Everything works, but I have one problem. I have to encrypt the same image and transfer them to different boards (same CPU). The current state is, that I run the CST Tool and transfer the generated output key (dek.bin) to the board and call the dek_blob function in order to generate the dek_blob.bin (final key).

 

Is there a way I don't need to transfer the dek.bin to the board?

Is is possible to generate the dek_blob.bin on my host computer?

 

Best regards,

 

Frieder

Outcomes