User manual

Table Of Contents
Zynq-7000 AP SoC Technical Reference Manual www.xilinx.com 172
UG585 (v1.11) September 27, 2016
Chapter 6: Boot and Configuration
matched, the BootROM performs a BootROM Header search if the boot mode is either Quad-SPI,
NAND, or NOR. If the boot mode is SD card, the BootROM lockdowns the system and generates an
error code.
Encryption Status — 0x028
Encryption Status determines if the boot is secure (the boot image is encrypted) or non-secure
mode. Valid values for this field are:
0xA5C3C5A3 Encrypted FSBL/User code (requires eFUSE key source).
0x3A5C3C5A Encrypted FSBL/User code (requires battery-backed RAM key source).
•Not
0xA5C3C5A3 or 0x3A5C3C5A. Non-encrypted FSBL/User code (no key).
The eFuse states and the encryption status word determines the source of the encryption key, if any.
The valid combination are shown in Table 6-6.
FSBL/User Defined — 0x02C
This word may be used by the FSBL or User code. Refer to UG821, Zynq-7000 All Programmable SoC
Software Developers Guide for more information. The BootROM does not interpret or use this field.
Source Offset — 0x030
This parameter contains the number of bytes from the beginning of the valid BootROM Header to
where the FSLB/User code image resides. This offset must be aligned to a 64-byte boundary and must be
at or above address offset
0x8C0 from the beginning of the BootROM Header.
Length of Image — 0x034
This word contains the byte count of the load image to transfer to the OCM. For non-secure mode,
the Length of Image equals the Total Image Length parameter and has a maximum value of 192 KB.
For secure mode, the Length of Image is set equal to the length of the image after it has gone
through the authentication and decryption process steps. In this case, the Length of Image is always
less than 192 KB because of the encryption overhead.
A value of zero with a Quad-SPI or NOR flash mode causes the BootROM to execute the FSBL/User
code from the associated flash device without copying the image to OCM (execute-in-place).
Table 6-6: BootROM Requirements for Encryption Status Word
eFuse States (described in Table 32-2, page 771)
eFuse Secure Boot
Not Blown Not Blown Blown
BBRAM Key Disable
Not Blown Blown Don’t Care
Encryption Status Word
Non-secure
Okay Okay Lockdown
Secure with BBRAM Key
Okay Lockdown Lockdown
Secure with eFuse Key
Okay Okay Okay