Key rolling is a security feature that enhances the encryption of data by using multiple keys to encrypt different blocks of data. Versal AI Edge Series Gen 2 and Versal Prime Series Gen 2 devices use AES-GCM for encryption. This mode supports the rolling keys feature. The entire encrypted image is divided into smaller blocks or modules. Each block is encrypted using a unique key. By default, key rolling is applied to every 32 KB chunk of data.
Each successive block key is encrypted (wrapped) using the key from the previous block. This ensures that each block has a unique encryption key.
all: {
id_code = 0x04ca8093
extended_id_code = 0x01
id = 0x2
metaheader {
encryption = aes,
keysrc = bbram_red_key,
aeskeyfile = efuse_red_metaheader_key.nky,
dpacm_enable
}
image {
name = pmc_subsys, id = 0x1c000001
partition {
id = 0x01, type = bootloader,
encryption = aes,
keysrc = bbram_red_key,
aeskeyfile = bbram_red_key.nky,
dpacm_enable,
blocks = 4096(2);1024;2048(2);4096(*),
file = plm.elf
}
partition {
id = 0x09, type = pmcdata, load = 0xf2000000,
aeskeyfile = pmcdata.nky,
file = pmc_data.cdo
}
}
image {
name = lpd, id = 0x4210002
partition {
id = 0x0C, type = cdo,
encryption = aes,
keysrc = bbram_red_key,
aeskeyfile = key1.nky,
dpacm_enable,
blocks = 8192(20);4096(*),
file = lpd_data.cdo
}
partition {
id = 0x0B, core = psm,
encryption = aes,
keysrc = bbram_red_key,
aeskeyfile = key2.nky,
dpacm_enable,
blocks = 4096(2);1024;2048(2);4096(*),
file = psm_fw.elf
}
}
image {
name = fpd, id = 0x420c003
partition {
id = 0x08, type = cdo,
encryption = aes,
keysrc = bbram_red_key,
aeskeyfile = key5.nky,
dpacm_enable,
blocks = 8192(20);4096(*),
file = fpd_data.cdo
}
}
}
Note:
- Number of keys in the key file should always be equal to the number of blocks to be encrypted.
- If the number of keys are less than the number of blocks to be encrypted, Bootgen returns an error.
- If the number of keys are more than the number of blocks to be encrypted, Bootgen ignores the extra keys.