Image attributes field comprises packed information of the boot image attributes and details are available in the following table:
Field Name | Bit Offset | Width | Default Value | Description |
---|---|---|---|---|
Rsvd | [31:22] | 10 | 0x0 | Reserved, must be 0 |
CDI generation | [21:20] | 2 | 0x0 |
0x3 – Generate DICE CDI All others – DICE CDI generation is based on eFuse UDS programmed |
Signed image | [19:18] | 2 | 0x0 |
0x3- Signed image All others – Unsigned image |
Puf Mode | [17:16] | 2 | 0x0 |
0x3 - PUF 4K mode. 0x0 - PUF 12K mode. |
BH Authentication | [15:14] | 2 | 0x0 | 0x3 - Authenticates the boot image, excluding verification of PPK hash and SPK ID. All others: Authentication is decided based on eFUSE RSA/ECDSA bits. |
Rsvd | [13:12] | 2 | 0x0 | Reserved, must be 0 |
DPA CM | [11:10] | 2 | 0x0 |
0x3 - Enabled All others disabled. (eFUSE overrides this) |
BI Integrity selection. | [9:8] | 2 | 0x0 |
0x0, 0x1, 0x2 - Reserved 0x3 - SHA3: used as hash function to perform BI integrity check. |
PUF HD | [7:6] | 2 | 0x0 |
0x3 - PUF HD is part of boot header All other - PUF HD is in eFUSE. |
Rsvd | [5:4] | 2 | 0x0 | Reserved |
Rsvd | [3:0] | 4 | 0x0 | Reserved |