SPRUJ17I March 2022 – August 2025 AM2631 , AM2631-Q1 , AM2632 , AM2632-Q1 , AM2634 , AM2634-Q1
ROM expectations from the certificate for HS-FS and HS-SE devices is as follows:
|
Device Type |
Validation requirements for SBL |
Validation requirements for HSM RT |
||||
|---|---|---|---|---|---|---|
|
Certificate Verification |
Image Integrity |
Image Decryption |
Certificate Verification |
Image Integrity |
Image Decryption |
|
HSFS | No authentication, only Dummy certificate for metadata | It’s supported, but not mandatory, SBL can boot with or without image integrity. Based on the certificate extension Image integrity will be carried out. SHA512 only supported. | Not supported on HS-FS devices for SBL. Boot fails if encrypted images are loaded. | Authentication is must and it’s with TI root of trust (RoT). RSA4K only supported. | It’s mandatory, ensure that certificate extension is present. SHA512 only supported. | It’s optional. HSMRt can boot without image decryption. Certificate extension for Image decryption will decide this feature. AES256-CBC only supported. |
HSSE | Authentication is must and it’s with Customer root of trust (RoT). RSA4K only supported. | It’s mandatory, ensure that certificate extension is present. SHA512 only supported. | It’s optional. SBL can boot without image decryption. Certificate extension for Image decryption will decide this feature. AES256-CBC only supported. | Authentication is must and it’s with Customer root of trust (RoT). RSA4K only supported. | It’s mandatory, ensure that certificate extension is present. SHA512 only supported. | It’s optional. HSMRt can boot without image decryption. Certificate extension for Image decryption will decide this feature. AES256-CBC only supported. |