SWCU195A December 2024 – May 2025 CC2744R7-Q1 , CC2745P10-Q1 , CC2745R10-Q1 , CC2745R7-Q1 , CC2755R10
This is the process in which new keys for either SSB or Application can be added to the Key Ring in SCFG. When a new key is added, there will be two active keys of a given type in the Key Ring until a target is verified with the new key.
At that point, the old key will be made invalid, and no more updates for a given target with the old key will be accepted.
To trigger a Key Update, follow these steps:
Set the address in which the Key Update image is located by calling HapiSbSetUpdateImageAddress( address )
Call HapiSbSetId( 3 )
Reset the device
Old keys cannot be added again, as Secure Boot keeps a record of old keys in the Key Ring.
Key Update images must be signed with the key that corresponds to the key specified by scfg.secBootCfg.keyUpdateKeyHash.
Refer to the Secure Boot SDK example for instructions on how to create Key Update images.