Although not recommended, if secure
flash boot is performed on CPU2/CM and not on CPU1, then a dummy load must be
performed from CPU1 for the Z1 OTP CMACKEY before releasing CPU2/CM out of reset.
The dummy load is done by reading the 0x78018-0x7801F locations of CPU1 USER
OTP.
Similarly, if using the CMAC
Authentication APIs without running the secure flash boot mode on CPU1, then a dummy
load must be performed from CPU1 for the Z1 OTP CMACKEY before calling the
APIs.
While using Secure Flash Boot on
CPU1, it is recommended not to have a normal (non-secure) Flash Boot mode to the
same sector configured in the BOOTDEF table.
For authenticating flash code beyond
16 KB:
The 128-bit golden CMAC tag
must be stored inside of the memory address range that the calculation is
performed on.
The starting address of the
golden CMAC tag must align to a 32-bit boundary.
As the boot mode settings reside in
the One Time Programmable (OTP), it is recommended to make use of the emulation boot
mode for trials before freezing the boot related configuration. More information
regarding the Emulation boot is provided in the ROM Code and Peripheral
Booting chapter of the TMS320F2838x Technical Reference Manual [1].