SDAA376 August   2026 DRA821U-Q1 , DRA829J-Q1 , DRA829V-Q1 , TDA4AH-Q1 , TDA4AL-Q1 , TDA4AP-Q1 , TDA4APE-Q1 , TDA4VE-Q1 , TDA4VH-Q1 , TDA4VL-Q1 , TDA4VM , TDA4VM-Q1 , TDA4VP-Q1 , TDA4VPE-Q1

 

  1.   1
  2.   Abstract
  3.   Trademarks
  4. 1Introduction
    1. 1.1 Why Keywriter is Needed
    2. 1.2 What is Keywriter
  5. 2Keywriter Certificate Blob
    1. 2.1 Certificate Generation Overview
  6. 3Production Deployment Methods
    1. 3.1 OSPI Boot Method
    2. 3.2 eMMC Boot Method
    3. 3.3 eMMC Boot with DFU Backup Method
    4. 3.4 JTAG/Development Boot Method
    5. 3.5 RGMI Ethernet Boot Mode
  7. 4Updates in the Field
    1. 4.1 SWREV (Software Revision)
    2. 4.2 KEYREV (Key Revision)
  8. 5Common Debugging Steps
    1. 5.1 Dry-Run Testing
    2. 5.2 Package Requirements
    3. 5.3 eFuse Programming Setup
    4. 5.4 Verifying Programming Results
    5. 5.5 Boot Failure Troubleshooting
    6. 5.6 Trace Collection Without Wakeup UART
  9. 6Summary
  10. 7References

Certificate Generation Overview

The Keywriter certificate blob uses a layered security approach combining digital signatures and encryption. The OTP configuration data is encrypted with a randomly generated AES-256 session key. This session key is then encrypted using the TI-FEK (TI Field-Encryption Key), verifying only authentic TI firmware with the corresponding private key can decrypt it. The entire certificate is signed using SMPK (Secondary Manufacturer Private Key) for authentication. Optionally, the certificate can be dual-signed by also using BMPK (Backup Manufacturer Private Key) to enable key rotation scenarios. For complete keywriter blob generation flow refer Figure below.

 Certificate Blob Generation Flow: AES Encryption, TI-FEK Key Wrapping, and Dual-Signature AuthenticationFigure 2-1 Certificate Blob Generation Flow: AES Encryption, TI-FEK Key Wrapping, and Dual-Signature Authentication