This thread has been locked.

If you have a related question, please click the "Ask a related question" button in the top right corner. The newly created question will be automatically linked to this question.

AM623: Security feature supported device

Part Number: AM623

Customer asks Is there devices to support below features:

a. iRoT with the OCP SPDM profile and compliance with OCP Attestation v1.1 SPDM requirements;
b. Support for TCG DICE identity certificates and a unique, immutable device ID key pair;
c. Use of Caliptra as the root of trust for measurements;
d. PQC support

If not, is there roadmap device to support? or how to implement with available TI ecosystem? is there ready solution.

  • Hey Tony,

    None of our current Sitara devices support these features. PQC is definitely in our plans, but the others are more end equipment specific and will be considered per device as the match for given markets. 

    Thanks,

    Ron

  • Hi, RonB:

        Are there any solutions for using eROT (OCP SPDM Profile and OCP Attestation v1.1 SPDM) on the AM62x, such as CEC1736?

    image.png

  • Hi,

    I don't know of any canned solutions with this configuration. 

    Taking a look at the CEC173x device, it seems to provide an OSPI interface and the AM62x can boot from OSPI. If the interface is compliant with what AM62x supports, this should work. 

    Thanks,
    Ron

  • Hi, RonB:

        AM62x does not support dual QSPI boot. This application scenario is that when the QSPI Flash of CS0 fails to boot, the CPU will try to boot from the QSPI Flash of CS1. The same applies to the CEC1736, which safely manages two QSPI Flashes. If there is a problem with CS0, it will switch to the QSPI Flash of CS1.

  • Louis,

    Update my findings:

    I browsed CEC173x datasheet, did not find the requirement of second QSPI_CS1 as backup. authentication is handled by CEC173x before release AP from reset, backup image can be configured by CEC173x. So I didn't see QSPI_CS1 as backup boot storage is necessary. 

    Please correct me if wrong.