The latest authentication methods support secure booting to prevent unauthorized or modified code from running on AMD devices. This approach ensures that images and customer IP are protected through encryption.
For device-specific hardware security features, see the following documents:
- Zynq 7000 SoC Technical Reference Manual (UG585)
- Zynq UltraScale+ Device Technical Reference Manual (UG1085)
- Spartan UltraScale+ FPGAs Configuration User Guide (UG860)
- Versal Adaptive SoC Technical Reference Manual (AM011)
-
Versal AI Edge Series Gen 2 and Prime Series Gen 2 Technical
Reference Manual (AM026)
Note: For additional information, see Versal Adaptive SoC Security Manual (UG1508). This manual requires an active NDA to be downloaded from the Design Security Lounge.
See Using Encryption and Using Authentication for more information about encrypting and authenticating content when using Bootgen.
Bootgen usage of a hardware security module (HSM) increases key handling security for the following reasons:
- HSM signs the BIF
- Private keys stays protected within the HSM and are not exposed to either the customer or to the machine running Bootgen.
The HSM is a secure key/signature generation device which generates private keys, signs partitions using the private key, and provides the public part of the authentication key pair to Bootgen. The private keys do not leave the HSM. See Using HSM Mode for more information.