There are dedicated bits in eFUSEs that correspond to the S-HWRoT boot mode. If any one of these bits are set, then the boot image must be in the encrypted format and the key source is forced to be the eFUSE black key, where as remaining partitions can be either unencrypted or encrypted with any other valid key source.