Re: Anyone have experience with adding op-tee to fsl-community-bsp for imx8mm?
On Tue, Jul 13, 2021 at 11:21 AM Brian Hutchinson <b.hutchman@...> wrote:
Latest OP-TEE from NXP supports generating HUK for closed devices, so
that should be all you need. You might need to configure the OP-TEE to
enable RPMB, but that should be all you need to be able to access it.
The main problem with RPMB is that you will have to generate and write
a key in order to protect the RPMB access, and for this you will have
to close your device (HUK is only available when the device is closed
and booted in secure mode), and compile and boot a specific OP-TEE
binary that has the capability of writing the RPMB key on first access
(CFG_RPMB_WRITE_KEY=y). The current OP-TEE implementation derives the
RPMB key out of HUK, which forces it to be specific to the device and
makes it available only when the device is in secure mode.
might be useful for understanding how that access is made and how to
close/fuse your board.