SPRUJ17H March 2022 – October 2024 AM2631 , AM2631-Q1 , AM2632 , AM2632-Q1 , AM2634 , AM2634-Q1
ROM expectations from the certificate for HS-FS and HS-SE devices is as follows:
Device Type | Validation requirements for SBL | Validation requirements for HSM RT | ||||
Certificate Verification | Image Integrity | Image Decryption | Certificate Verification | Image Integrity | Image Decryption | |
HSFS | No authentication, only Dummy certificate for metadata | It’s supported, but not mandatory, SBL can boot with or without image integrity. Based on the certificate extension Image integrity will be carried out. SHA512 only supported. | Not supported on HS-FS devices for SBL. Boot fails if encrypted images are loaded. | Authentication is must and it’s with TI root of trust (RoT). RSA4K only supported. | It’s mandatory, ensure that certificate extension is present. SHA512 only supported. | It’s optional. HSMRt can boot without image decryption. Certificate extension for Image decryption will decide this feature. AES256-CBC only supported. |
HSSE | Authentication is must and it’s with Customer root of trust (RoT). RSA4K only supported. | It’s mandatory, ensure that certificate extension is present. SHA512 only supported. | It’s optional. SBL can boot without image decryption. Certificate extension for Image decryption will decide this feature. AES256-CBC only supported. | Authentication is must and it’s with Customer root of trust (RoT). RSA4K only supported. | It’s mandatory, ensure that certificate extension is present. SHA512 only supported. | It’s optional. HSMRt can boot without image decryption. Certificate extension for Image decryption will decide this feature. AES256-CBC only supported. |