Secure Boot V2 and Flash Encryption
Posted: Thu Sep 05, 2024 2:00 pm
Hello everbody.
I intend to use Flash encryption in combination with Secure Boot V2. I would like to know if the FW Image must be signed before it will be encrypted and flashed. Basically I want to use the flash encryption in Release mode.
For me something was not clear enough:
So as far as I understood, with OTA-Update there is no restrictions, so we can send FW Images in plaintext. However the image should be signed correctly before the send process. Then it will be verified and encrypted
Via serial it is not possible to flash images in plaintext in the release mode. One must sign it correctly, pre-encreypt it and then flash it.
I appreciate your help to clarify the problem
Best regards
I intend to use Flash encryption in combination with Secure Boot V2. I would like to know if the FW Image must be signed before it will be encrypted and flashed. Basically I want to use the flash encryption in Release mode.
For me something was not clear enough:
So as far as I understood, with OTA-Update there is no restrictions, so we can send FW Images in plaintext. However the image should be signed correctly before the send process. Then it will be verified and encrypted
Via serial it is not possible to flash images in plaintext in the release mode. One must sign it correctly, pre-encreypt it and then flash it.
I appreciate your help to clarify the problem
Best regards