Analog Devices ADSP-BF70x Blackfin+ Processors Secure Booting Guide

Technical guide describing secure boot implementation, key generation, and image formats for ADSP‑BF70x Blackfin+ processors.


Analog Devices ADSP-BF70x Blackfin+ Processors Secure Booting Guide - cover page
Brand
Analog Devices
Category
Other
Document type
Application Note
Language
English
Pages
16
File format
PDF
File size
559 KB
Published
29 September, 2026
Updated
29 September, 2026
MD5 checksum
15FF8A6AB497BA33FB36628338C41CC1

About this manual

This guide explains the secure boot architecture of the ADSP‑BF70x Blackfin+ processor family, covering the required hardware blocks, cryptographic algorithms, and protection types such as integrity, authenticity, confidentiality, anti‑cloning and anti‑rollback. It also provides step‑by‑step procedures for generating keys, creating boot loader streams, and programming OTP memory.

The document includes command‑line examples for the signtool utility, details of secure boot image header formats, supported image types (BLp, BLw, BLx), and instructions for programming the boot image and keys into external flash and OTP memory.

What's inside

  • Introduction
  • Secure Boot and Protection Types
  • Secure Boot Image Types
  • Secure Boot Header Format
  • Developing a Secure Boot System
  • Key Generation and Management
  • Signtool Utility Usage
  • Unsupported Boot Stream Blocks
  • Signing and Encrypting the Boot Image
  • Programming Secure Boot Stream and OTP Keys

Specifications

Secure boot featureDisabled by default
Rollback counter size32‑bit counter in OTP memory
Maximum boot image size0x10000000 bytes
AES confidentiality key size128‑bit
Signature algorithmECDSA‑224 with SHA‑2

Frequently asked questions

How is secure boot enabled on the processor?

Secure boot is enabled via the Lock API and, once enabled, it cannot be disabled.

What cryptographic algorithm provides integrity and authenticity protection?

The processor uses ECDSA with a 224‑bit SHA‑2 hash for integrity and authenticity.

Which key is used to encrypt the boot image in the wrapped format?

A 128‑bit AES key is wrapped with a Key Encryption Key (KEK) and stored in the secure header.

How can the public key be programmed into the processor?

The public key must be pre‑programmed into the processor’s OTP memory using the OTP Program API.

Download PDF (559 KB)

More Analog Devices Manuals


View all Analog Devices manuals →