summaryrefslogtreecommitdiff
path: root/doc/SPL/README.spl-secure-boot
blob: f2f8d7888374acee539d9d585d541230750af83a (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
Overview of SPL verified boot on powerpc/mpc85xx & arm/layerscape platforms
===========================================================================

Introduction
------------

This document provides an overview of how SPL verified boot works on powerpc/
mpc85xx & arm/layerscape platforms.

Methodology
-----------

The SPL image is responsible for loading the next stage boot loader, which is
the main u-boot image. For secure boot process on these platforms ROM verifies
SPL image, so to continue chain of trust SPL image verifies U-boot image using
spl_validate_uboot(). This function uses QorIQ Trust Architecture header
(appended to U-boot image) to validate the U-boot binary just before passing
control to it.