Security - Security - 2026.1 English - UG1273

Versal Adaptive SoC Design Guide (UG1273)

Document ID
UG1273
Release Date
2026-06-24
Version
2026.1 English

Versal adaptive SoC significantly enhances its security architecture from previous generations. The root of trust starts with the BootROM, which verifies the security state of the device. If all checks pass, the BootROM authenticates and then loads the PLM firmware. If you chose to encrypt the PLM, the BootROM also decrypts the PLM after authentication. The RCU in the PMC runs the BootROM.

After the PLM firmware starts running, the PLM ensures the secure loading of the remaining firmware and software. For security-related information, including usage instructions, refer to the following documents:

  • Versal Adaptive SoC Security Manual (UG1508)
  • Versal AI Edge Series Gen 2 and Prime Series Gen 2 Security Manual (UG1724)

These are available in the Design Security Lounge (registration required) on the AMD website.

The following table highlights the possible secure boot configurations for Versal adaptive SoC and shows a comparison with Zynq UltraScale+ MPSoC.

Table 1. Cumulative Secure Boot Operations
Boot Type Operations Hardware Crypto Engines
Authentication Decryption Integrity (Checksum Verification) Zynq UltraScale+ MPSoC Versal Adaptive SoC
Non-secure No No No

Yes

Does not use built-in engines

Yes

Does not use built-in engines

Hardware Root-of-Trust (HWRoT) Yes Optional Integrity via Asymmetric Authentication

Yes

RSA, SHA3

N/A
Asymmetric Hardware Root-of-Trust (A-HWRoT) Yes Optional Integrity via Asymmetric Authentication N/A Yes

RSA/ECDSA, SHA3, SHAKE-256

(AES-GCM and PUF optional)

LMS and LMS + HSS 1

Symmetric Hardware Root-of-Trust (S-HWRoT) Yes via GCM and eFUSEs

Yes

Must use PUF KEK

Integrity via Symmetric Authentication N/A Yes

AES-GCM, PUF

A-HWRoT + S-HWRoT Yes

Yes

Must use PUF KEK

Integrity via Asymmetric and Symmetric Authentication N/A Yes

RSA/ECDSA, SHA3, AES-GCM, PUF

LMS and LMS + HSS 1

Checksum Verification No No Yes Yes

SHA3

Yes

SHA3

  1. This applies to Versal AI Edge Series Gen 2 and Versal Prime Series Gen 2.