Part Number: DRA821U
Hello
I've got a question regarding capabilities and available tools for encrypting (or blobing) and decrytping arbitrary "files" from runtime.
To give some more context, let's imagine the following scenario:
- My Linux OS receives an update containg a new fitImage (with Linux kernel, focus on fitImage with Linux kernel, let's forget abotu tispl for now)
- Linux uses "special Linux tool*" that will encrypt the new fitImage with hardware bound key (or any key saved in secure storage during the provisioning)
- Reboot
- U-BOOT (let's assume U-boot proper after SPL, so already running on Cortex-A) - before loading fitImage, uses a "special U-BOOT tool*" to decrypt (deblob) fitImage
- U-BOOT loades fitImage
By:
- "special Linux tool" - I mean any Linux tool/app/whatever that performs encryption/decryption operation using either hardware-bound key (or programmed by user) in a secure way, e.g. utilizing SoC specific mechanims / DMSC / OPTEE / whatever
- "special U-BOOT tool" - I mean any U-BOOT api / shell command (e.g. I can imagine some shell command like ti_encrypt/ti_decrypt) that is capable of encrypting / decrypting arbitrary payload utilizing SoC specific mechanims / DMSC / OPTEE / whatever
I would be greateful if you could suggest if you provide anything like this, or perhaps you suggest any other solution that would allow me to achieve what I described above.