This thread has been locked.

If you have a related question, please click the "Ask a related question" button in the top right corner. The newly created question will be automatically linked to this question.

AM6442: AM64x Secure Boot and Firmware Encryption Capabilities for CRA Compliance

Guru 12010 points
Part Number: AM6442

Tool/software:

Hi,

We would like to confirm the following regarding the AM64x device.

Q1: Is it possible to implement secure boot and digital certificate verification with the AM64x + WolfBoot configuration? Can this setup serve as a technically viable basis for CRA (Cyber Resilience Act) compliance?
→ Our understanding is that using the HS (High Security) variant of the AM64x enables hardware-based secure boot (signature verification via ROM code) and key management features (e.g., eFUSE/PK-HASH). This allows secure boot to be implemented solely with the SoC. WolfBoot can enhance this by supporting OTA updates. However, CRA compliance ultimately depends on the broader system design and operational processes, not just the SoC.

Q2: Is it necessary to use the HS-SE variant instead of FS to support encrypted firmware updates (encryption/decryption)?
→ Our understanding is that FS (Functional Safety) variants have limited security functions and do not support full secure boot or firmware encryption features. Therefore, to support secure firmware updates with encryption/decryption, the HS-SE variant is required.

Could you please confirm whether our understanding is correct?

Thanks,

Conor

  • Hello,

    1) We haven't tried WolfBoot on AM64x devices so we cannot provide comments on the queries. However, the understanding about HSSE devices is correct. These devices allow secure boot to be implemented solely with the SoC. Theoretically, secure OTA updates can be implemented as well using the SYSFW. The SYSFW provides API to authenticate a signed blob with the programmed key.

    2) The FS in "HS-FS" stands for Field Securable not Functional Safety. The HSFS devices does not enforce secure boot. These devices must be converted to HS-SE to enforce secure boot from ROM and SYSFW.

    Regards,

    Prashant