Image attributes field comprises packed information of the boot image attributes and details are available in the following table:
| Field Name | Bit Offset | Width | Default Value | Description |
|---|---|---|---|---|
| Rsvd | [31:22] | 10 | 0x0 | Reserved, must be 0 |
| CDI generation | [21:20] | 2 | 0x0 |
0x3 – Generate DICE CDI All others – DICE CDI generation is based on eFuse UDS programmed |
| Signed image | [19:18] | 2 | 0x0 |
0x3- Signed image All others – Unsigned image |
| Puf Mode | [17:16] | 2 | 0x0 |
0x3 - PUF 4K mode. 0x0 - PUF 12K mode. |
| BH Authentication | [15:14] | 2 | 0x0 | 0x3 - Authenticates the boot image, excluding verification of PPK hash and SPK ID. All others: Authentication is decided based on eFUSE RSA/ECDSA bits. |
| Rsvd | [13:12] | 2 | 0x0 | Reserved, must be 0 |
| DPA CM | [11:10] | 2 | 0x0 |
0x3 - Enabled All others disabled. (eFUSE overrides this) |
| BI Integrity selection. | [9:8] | 2 | 0x0 |
0x0, 0x1, 0x2 - Reserved 0x3 - SHA3: used as hash function to perform BI integrity check. |
| PUF HD | [7:6] | 2 | 0x0 |
0x3 - PUF HD is part of boot header All other - PUF HD is in eFUSE. |
| Rsvd | [5:4] | 2 | 0x0 | Reserved |
| Rsvd | [3:0] | 4 | 0x0 | Reserved |