Technical guide describing secure boot implementation, key generation, and image formats for ADSP‑BF70x Blackfin+ processors.
This guide explains the secure boot architecture of the ADSP‑BF70x Blackfin+ processor family, covering the required hardware blocks, cryptographic algorithms, and protection types such as integrity, authenticity, confidentiality, anti‑cloning and anti‑rollback. It also provides step‑by‑step procedures for generating keys, creating boot loader streams, and programming OTP memory.
The document includes command‑line examples for the signtool utility, details of secure boot image header formats, supported image types (BLp, BLw, BLx), and instructions for programming the boot image and keys into external flash and OTP memory.
| Secure boot feature | Disabled by default |
|---|---|
| Rollback counter size | 32‑bit counter in OTP memory |
| Maximum boot image size | 0x10000000 bytes |
| AES confidentiality key size | 128‑bit |
| Signature algorithm | ECDSA‑224 with SHA‑2 |
Secure boot is enabled via the Lock API and, once enabled, it cannot be disabled.
The processor uses ECDSA with a 224‑bit SHA‑2 hash for integrity and authenticity.
A 128‑bit AES key is wrapped with a Key Encryption Key (KEK) and stored in the secure header.
The public key must be pre‑programmed into the processor’s OTP memory using the OTP Program API.