]> git.baikalelectronics.ru Git - arm-tf.git/commit
dualroot: add chain of trust for Platform owned SPs
authorManish Pandey <manish.pandey2@arm.com>
Fri, 31 Jul 2020 15:25:17 +0000 (16:25 +0100)
committerManish Pandey <manish.pandey2@arm.com>
Wed, 12 Aug 2020 13:30:31 +0000 (14:30 +0100)
commit2947412d547307019c919e8131353538511f83d9
treefbe092970dbdc94dd4be01c4e1aeec9478e15249
parent23d5f03ad00a7a815555d52a15f34fdcc958cccd
dualroot: add chain of trust for Platform owned SPs

For dualroot CoT there are two sets of SP certificates, one owned by
Silicon Provider(SiP) and other owned by Platform. Each certificate can
have a maximum of 4 SPs.

This patch reduces the number of SiP owned SPs from 8 to 4 and adds
the remaining 4 to Plat owned SP.
Plat owned SP certificate is signed using Platform RoT key and
protected against anti-rollback using the Non-trusted Non-volatile
counter.

Change-Id: Idc3ddd87d6d85a5506a7435f45a6ec17c4c50425
Signed-off-by: Manish Pandey <manish.pandey2@arm.com>
drivers/auth/dualroot/cot.c
include/common/tbbr/tbbr_img_def.h
include/drivers/auth/auth_mod.h