AM62L: Security Manager registers

Part Number: AM62L

Hi,

I've enabled secure boot on my device, and am trying to read the values from OTP to verify exactly how my device is configured.

It doesn't appear to be possible to directly read the OTP memory, so instead I'm reading registers in the Security Manager block (WKUP_DMSC0_SECMGR). I'm currently using the "K3 Security Hardware Architecture" (SPRUIM0B) as a reference, as I can't find a document specific to the AM62L.

Reading registers in the first 0x1000 bytes of the register block works fine, so I can check the status along with the programmed SMPKH and BMPKH values. But any register read past an offset of 0x1000 results in a synchronous abort exception, which means I cannot read for example the SECMGR_CUST_KEY_REV register (there are other values too that only seem to exist in the region that I can't access).

Do these registers exist on the AM62L? Is there any up to date documentation describing what values I can read?

Thanks

Matt

  • Hi Matt,

    On AM6xx family SoC (including AM62L) HS-SE, SMPK-H/BMPK-H are accessible via SM registers. But rest of secure key material are firewall protected to be accessible only by ROM/TIFS firmware.

    I'm attaching two sample logs
    1/. reading SMPK-H/BMPK-H @u-boot
    2/. SoC_UID dump (AM62L SR1.1 HS-SE), where KEY_CNT/KEY_REV are listed.

    - read/write the extended OTP @u-boot on AM62L
    https://software-dl.ti.com/processor-sdk-linux/esd/AM62LX/12_00_00_07_04/exports/docs/linux/Foundational_Components/U-Boot/UG-Programming-OTPs.html#programming-user-otp-fuses

    Best,
    -Hong

    NOTICE:  bl1_plat_arch_setup arch setup 
    NOTICE:  Booting Trusted Firmware
    NOTICE:  BL1: v2.12.0(release):11.01.14-1-g6c8ef6729
    NOTICE:  BL1: Built : 17:20:39, Nov 13 2025
    NOTICE:  BL1: dram_class: 11
    NOTICE:  lpddr4: post start - PI training status=0x27c0a000 
    NOTICE:  bl1_platform_setup DDR init done
    NOTICE:  k3_bl1_handoff ENTERING WFI - end of bl1
    NOTICE:  BL31: v2.12.0(release):11.01.14-1-g6c8ef6729
    NOTICE:  BL31: Built : 17:20:40, Nov 13 2025
    NOTICE:  SYSFW ABI: 4.0 (firmware rev 0x000b '11.1.12-v11.01.12 (Fancy Rat)')
    ERROR:   Agent 0 Protocol 0x10 Message 0x7: not supported
    
    U-Boot SPL 2025.01-gc779c758475c-dirty (Nov 13 2025 - 14:20:45 -0600)
    SPL initial stack usage: 1984 bytes
    Trying to boot from MMC2
    ERROR:   Agent 0 Protocol 0x10 Message 0x7: not supported
    
    
    U-Boot 2025.01-gc779c758475c-dirty (Nov 13 2025 - 14:20:45 -0600)
    
    SoC:   AM62LX SR1.1 HS-SE
    Model: Texas Instruments AM62L3 Evaluation Module
    DRAM:  2 GiB
    ERROR:   Agent 0 Protocol 0x10 Message 0x7: not supported
    Core:  82 devices, 31 uclasses, devicetree: separate
    MMC:   mmc@fa10000: 0, mmc@fa00000: 1
    Loading Environment from nowhere... OK
    In:    serial@2800000
    Out:   serial@2800000
    Err:   serial@2800000
    Net:   eth0: ethernet@8000000port@1
    Warning: ethernet@8000000port@2 (eth1) using random MAC address - fe:18:36:7d:ca:ed
    , eth1: ethernet@8000000port@2
    Hit any key to stop autoboot:  2  0 
    => md.b 0x44234800 0x200
    44234800: 1f 60 02 b0 7c d9 b0 b7 c4 7d 9c a8 d1 aa e5 7b  .`..|....}.....{
    44234810: 8e 87 84 a1 2f 63 6b 2b 76 0d 7d 98 a1 8f 18 97  ..../ck+v.}.....
    44234820: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234830: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234840: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234850: 60 df d0 f2 3e 2b 0c b1 0e c7 ed c7 c6 ed ac 3d  `...>+.........=
    44234860: 9b df ef e0 ed dc 3f ff 7f e9 ad 87 51 95 52 7d  ......?.....Q.R}
    44234870: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234880: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234890: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348a0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442348f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234900: 38 4b e2 78 a7 a5 0e b2 5a fd ff ac 2e 8b d3 06  8K.x....Z.......
    44234910: f8 2a 3b 51 a7 70 f8 05 6c 9d de b9 f3 1b 0d 3d  .*;Q.p..l......=
    44234920: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234930: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234940: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234950: 3e a0 06 3e 6d e3 12 7a 47 c8 a1 44 3f c7 e1 0d  >..>m..zG..D?...
    44234960: ad ff b5 16 01 ae ae b4 99 d6 07 e0 28 74 cd 80  ............(t..
    44234970: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234980: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    44234990: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349a0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    442349f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    => 

    -----------------------
    SoC ID Header Info:
    -----------------------
    NumBlocks            : 2
    -----------------------
    SoC ID Public ROM Info:
    -----------------------
    SubBlockId           : 1
    SubBlockSize         : 26
    DeviceName           : am62l
    DeviceType           : HSSE
    DMSC ROM Version     : [0, 1, 1, 0]
    R5 ROM Version       : [0, 1, 1, 0]
    -----------------------
    SoC ID Secure ROM Info:
    -----------------------
    Sec SubBlockId       : 2
    Sec SubBlockSize     : 166
    Sec Prime            : 0
    Sec Key Revision     : 1
    Sec Key Count        : 2
    Sec TI MPK Hash      : fe73d96bbf79f784d9aee9fc5698d1093936556f93abf79f3ec7ce923079c478f837b12296da2a81a2fa024cb9d2423a14511488622a9ca591e5ee057175b142
    Sec Cust MPK Hash    : 1f6002b07cd9b0b7c47d9ca8d1aae57b8e8784a12f636b2b760d7d98a18f189760dfd0f23e2b0cb10ec7edc7c6edac3d9bdfefe0eddc3fff7fe9ad875195527d
    Sec Unique ID        : b8f145f085fc5f6e736d0405c5420b0aab085c8a8dfe3bae81dc72eae1d2edcc
    

  • Hi Hong,

    Thanks, the SoC_UID dump has the info I am looking for in it. How can this be accessed?

    The use-case here is that if the KEY_REV ever needs to be incremented to switch from using the SMPK to the BMPK, we would want to check the existing KEY_CNT and KEY_REV first before writing anything.

    Thanks

    Matt