Boot Time Security - 2021.1 English

Zynq UltraScale+ MPSoC Software Developer Guide (UG1137)

Document ID
UG1137
Release Date
2021-07-13
Version
2021.1 English

This section details the various boot image formats for authentication and encryption.

Important: For Zynq MPSoC, when RSA_EN eFUSE is not programmed and BOOT.BIN does not have BH_AUTH enabled, FSBL can load bin as non-secure even if the partitions are authenticated. It is a new feature in 2021.1, which is disabled by default. To enable it, set FSBL_UNPROVISIONED_AUTH_SIGN_EXCLUDE_VAL to 0 in xfsbl_config.h