SDAA376 August 2026 DRA821U-Q1 , DRA829J-Q1 , DRA829V-Q1 , TDA4AH-Q1 , TDA4AL-Q1 , TDA4AP-Q1 , TDA4APE-Q1 , TDA4VE-Q1 , TDA4VH-Q1 , TDA4VL-Q1 , TDA4VM , TDA4VM-Q1 , TDA4VP-Q1 , TDA4VPE-Q1
The Keywriter certificate blob uses a layered security approach combining digital signatures and encryption. The OTP configuration data is encrypted with a randomly generated AES-256 session key. This session key is then encrypted using the TI-FEK (TI Field-Encryption Key), verifying only authentic TI firmware with the corresponding private key can decrypt it. The entire certificate is signed using SMPK (Secondary Manufacturer Private Key) for authentication. Optionally, the certificate can be dual-signed by also using BMPK (Backup Manufacturer Private Key) to enable key rotation scenarios. For complete keywriter blob generation flow refer Figure below.