This thread has been locked.

If you have a related question, please click the "Ask a related question" button in the top right corner. The newly created question will be automatically linked to this question.

[FAQ] How to boot ECDSA key signed Linux SDK on AM6x SoC

Part Number: AM62P

K3 SoC (AM64x, AM62x...) have a set of One-Time Programmable (OTP) efuses which is anchoring Root-of-Trust (RoT) secure boot chain. Linux SDK supports the RSA key signed secure boot [1]. The FAQ discuss how to enable ECDSA key signed u-boot on AM62P Linux SDK [2]
[1] https://software-dl.ti.com/processor-sdk-linux/esd/AM62PX/latest/exports/docs/linux/Foundational_Components_Security.html
[2] https://www.ti.com/tool/download/PROCESSOR-SDK-LINUX-AM62P

  • 1. OTP Keywriter
    - It is used in the factory for programming the user's secure RoT keys, key revision and key count on a HS-FS (High Security - Field Securable) device
    - A HS-FS is converted to HS-SE (High Security - Security Enforced) once the key revision and key count are programmed on HS-FS

    2. Download AM62P OTP Keywriter from AM62x security resource portal
    https://dr-download.ti.com/authenticated/secure/software-development/application-software-framework/MD-W5I8h4voaD/09.01.00.05/otp_keywriter_am62px_11_01_00-linux-x64-installer.run?
    - The portal is access controlled, and send the request to get access to AM62x security resource portal via the link
    https://www.ti.com/drr/opn/AM62X-RESTRICTED-SECURITY

    The specific change when using "./gen_keywr_cert.sh..." command to generate the key certificate to program ECDSA key instead of RSA key is listed below. Refer to AM62P OTP Keywriter user guide for details.
    - change the path of SMPK/BMPK to point to the ECDSA key
    - add "-s-type ec" or "-b-type ec" flag

    I'm attaching two log files from oneshot (SMPK/SMEK/BMPK/BMEK/MSV/KEY_CNT/KEY_REV) key programming with the TI testing key set on AM62P SR 1.2 (HS-FS) to convert HS-FS to HS-SE.
    - am62p_ec_kw_wr_r5.log: r5 log
    - am62p_ec_kw_wr_m4.log: m4 log

    3. AM62P Linux SDK change
    - copy "custMpk.pem/custMpk.key/custMpk.crt" to "$u-boot/arch/arm/mach-k3/keys/", where "custMpk.pem" is the TI testing ECDSA key with "secp384r1" curve, and "custMpk.key/custMpk.crt" are generated with

    cp -p custMpk.pem custMpk.key
    openssl req -batch -new -x509 -key custMpk.key -out custMpk.crt

    - build/sign u-boot as noted in the SDK user guide
    https://software-dl.ti.com/processor-sdk-linux/esd/AM62PX/11_02_08_02/exports/docs/linux/Foundational_Components/U-Boot/BG-Build-K3.html

    I'm attaching the SMPK-H log (ec_smpk-h_se.log) which is parsed from "tiboot3-am62px-hs-evm.bin". The parsed SMPK-H matches the m4 log captured from OTP key programming

    openssl x509 -inform der -in tiboot3-am62px-hs-evm.bin -pubkey -noout > ec_pubkey_tiboot3_se.pem
    openssl ec -pubin -in ec_pubkey_tiboot3_se.pem -outform der | openssl dgst -sha512 > ec_smpk-h_se.log

    I'm attaching the working u-boot log (am62p_sr1.2-se_11.2.8.2_uboot_ec.log) with AM62P Linux SDK 11.2.8.2 on AM62P SR 1.2 (HS-SE), where the the SMPK-H reading from the MMRs is listed in the log

    Starting Keywriter
    Enabled VPP
    
    SYSFW Firmware Version 11.1.9-v11.01.09_am62px_keywrit
    SYSFW Firmware revision 0xb
    SYSFW ABI revision 4.0
    
    keys Certificate found: 0x43c16700
    Keywriter Debug Response:0x0
    Success Programming Keys

    0x420002
    0x820024
    0x4003007
    0x4400B19
    0x409031
    0x800023
    #
    # Decrypting extensions..
    #
    MPK Options:  0x0
    MEK Options:  0x0
    MPK Opt P1:  0x0
    MPK Opt P2:  0x0
    MEK Opt   :  0x0
    * SMPKH Part 1 BCH code: 80b2bc68
    
    * SMPKH Part 2 BCH code: 00bb34bd
    
    * SMPK Hash (part-1,2):
    
    fb356b1f129cb487cdf91e0dce1e9a60386b4358ea8878978d749efe4771758200
    
    bb605771377e6a42fe33091a1d2990aeb7be3eff696bc4b9cb96153fa31582fc00
    
    * SMEK BCH code: a0c6de4e
    
    * SMEK Hash: 92785809a3dfefea57f6bbed642d730ba5d05e601222a72e815bf01ceb3a50f96ab85d282425f684436fabd4c7da624b791da411615035314103cc64e611f532
    
    * BMPKH Part 1 BCH code: c00807d5
    
    * BMPKH Part 2 BCH code: 60311e36
    
    * BMPK Hash (part-1,2):
    
    07b5fd6f33cdba0c745bcc07e50805639713ec517614eac89754da1138d24dac00
    
    5f1600a593b7100f0e1ca3c3a49e59b3622ab0651e08c0ffd2c88b04465cf7c900
    
    * BMEK BCH code: a0da286f
    
    * BMEK Hash: f5fbda1d62b46374de68e763ecd5a72227e7be73ca0d54a6d986ceb784b1bb0d06b6d95a8b399d421e41b7d3e7076220cd3992df255be068bd8924e86ae3a02d
    
    EXT OTP extension programming disabled
    * BCH code & MSV: fe0fac8b
    
    JTAG DISABLE programming disabled
    
    * KEY CNT: 03030000
    
    * KEY REV: 01010000
    
    SWREV extension programming disabled
    
    FW CFG REV extension programming disabled
    
    * KEYWR VERSION:  0x20000
    
    #
    # Programming Keys..
    #
    
    * MSV: 
    [u32] bch + msv:  0x0
    Programmed 2/2 rows successfully
    [u32] bch + msv:  0x8BAC0FFE
    
    * JTAG DISABLE: 
    [u32] JTAG DISABLE:  0x0
    JTAG DISABLE extension programming disabled
    [u32] JTAG DISABLE:  0x0
    
    * SWREV: 
    [u32] SWREV-SBL:  0x1
    [u32] SWREV-SYSFW  :  0x1
    SWREV extension programming disabled
    [u32] SWREV-SBL:  0x1
    [u32] SWREV-SYSFW  :  0x1
    
    * FW CFG REV: 
    [u32] SWREV-FW-CFG-REV:  0x1
    SWREV SEC BCFG extension programming disabled
    [u32] SWREV-FW-CFG-REV:  0x1
    
    * EXT OTP: 
    EXT OTP extension programming disabled
    
    * BMPKH, BMEK: 
    Programmed 11/11 rows successfully
    Programmed 2/2 rows successfully
    Programmed 11/11 rows successfully
    Programmed 2/2 rows successfully
    Programmed 11/11 rows successfully
    Programmed 2/2 rows successfully
    
    * SMPKH, SMEK: 
    Programmed 11/11 rows successfully
    Programmed 2/2 rows successfully
    Programmed 11/11 rows successfully
    Programmed 2/2 rows successfully
    Programmed 11/11 rows successfully
    Programmed 2/2 rows successfully
    
    * KEYCNT: 
    [u32] keycnt:  0x0
    Programmed 2/2 rows successfully
    [u32] keycnt:  0x2
    
    * KEYREV: 
    [u32] keyrev:  0x0
    Programmed 2/2 rows successfully
    [u32] keyrev:  0x1
    

    SHA2-512(stdin)= fb356b1f129cb487cdf91e0dce1e9a60386b4358ea8878978d749efe47717582bb605771377e6a42fe33091a1d2990aeb7be3eff696bc4b9cb96153fa31582fc
    

    U-Boot SPL 2025.01-g7493977a537f-dirty (Jan 30 2026 - 14:19:40 -0600)
    SYSFW ABI: 4.0 (firmware rev 0x000b '11.2.5--v11.02.05 (Fancy Rat)')
    Set clock rates for '/a53@0', CPU: 1250MHz at Speed Grade 'V'
    SPL initial stack usage: 17104 bytes
    Trying to boot from MMC2
    Authentication passed
    Authentication passed
    Authentication passed
    Authentication passed
    Authentication passed
    Starting ATF on ARM64 core...
    
    NOTICE:  BL31: v2.13.0(release):v2.13.0-259-ge0c4d3903b-dirty
    NOTICE:  BL31: Built : 07:01:36, Jul  1 2025
    
    U-Boot SPL 2025.01-g7493977a537f-dirty (Jan 30 2026 - 14:20:42 -0600)
    SYSFW ABI: 4.0 (firmware rev 0x000b '11.2.5--v11.02.05 (Fancy Rat)')
    DM ABI: 3.0 (firmware ver 0x000b 'MSDK.11.02.00.11--v11.02.05' patch_ver: 5)
    SPL initial stack usage: 1984 bytes
    Trying to boot from MMC2
    Authentication passed
    Authentication passed
    
    
    U-Boot 2025.01-g7493977a537f-dirty (Jan 30 2026 - 14:20:42 -0600)
    
    SoC:   AM62PX SR1.2 HS-SE
    Model: Texas Instruments AM62P5 SK
    DRAM:  2 GiB (total 8 GiB)
    Core:  102 devices, 33 uclasses, devicetree: separate
    MMC:   mmc@fa10000: 0, mmc@fa00000: 1
    Loading Environment from nowhere... OK
    In:    serial
    Out:   serial
    Err:   serial
    Net:   eth0: ethernet@8000000port@1
    Warning: ethernet@8000000port@2 (eth1) using random MAC address - 7a:ea:14:e6:5b:21
    , eth1: ethernet@8000000port@2
    
    Hit any key to stop autoboot:  2  0 
    => md.b 0x44234800 0x200
    44234800: fb 35 6b 1f 12 9c b4 87 cd f9 1e 0d ce 1e 9a 60  .5k............`
    44234810: 38 6b 43 58 ea 88 78 97 8d 74 9e fe 47 71 75 82  8kCX..x..t..Gqu.
    44234820: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234830: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234840: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234850: bb 60 57 71 37 7e 6a 42 fe 33 09 1a 1d 29 90 ae  .`Wq7~jB.3...)..
    44234860: b7 be 3e ff 69 6b c4 b9 cb 96 15 3f a3 15 82 fc  ..>.ik.....?....
    44234870: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234880: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234890: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348a0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234900: 07 b5 fd 6f 33 cd ba 0c 74 5b cc 07 e5 08 05 63  ...o3...t[.....c
    44234910: 97 13 ec 51 76 14 ea c8 97 54 da 11 38 d2 4d ac  ...Qv....T..8.M.
    44234920: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234930: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234940: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234950: 5f 16 00 a5 93 b7 10 0f 0e 1c a3 c3 a4 9e 59 b3  _.............Y.
    44234960: 62 2a b0 65 1e 08 c0 ff d2 c8 8b 04 46 5c f7 c9  b*.e........F\..
    44234970: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234980: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234990: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349a0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    => md.l 0x43000030 1
    43000030: 00000243                             C...
    => m