This thread has been locked.

If you have a related question, please click the "Ask a related question" button in the top right corner. The newly created question will be automatically linked to this question.

AM6412: How to switch to BMPK in the field when the SMPK is compromised

Part Number: AM6412

Tool/software:

TI team,

I am working on programming the SMPKH and BMPKH to enable secure boot on AM64x devices. My understanding is that we will need to update the KEYREV to 2 to enable authentication using the BMPK if the SMPK is compromised.

I am looking for guidance/recommendations on how to accomplish this in the field where we might have thousands of devices.

  1. Can the KEYREV be updated via other mechanisms besides the OTP keywriter running on the R5?
  2. Is possible to update the KEYREV from Linux or OPTEE?
  3. Anything else needs to be updated besides the KEYREV to enable authentication using the BMPK?
  4. What are TI's recommendation methods?

Thanks

Anh-Tuan