User manual

Table Of Contents
Zynq-7000 AP SoC Technical Reference Manual www.xilinx.com 178
UG585 (v1.11) September 27, 2016
Chapter 6: Boot and Configuration
A timing window calculator that also takes into account PVT variations provides a quick way to assess
if the design is exposed to the risk of a secure lock down as described above. The calculator is
available through AR# 63149
. PS_POR_B must be de-asserted outside the Secure Lock Down window
shown in the calculator to avoid the risk.
Note: Tslw(min) and Tslw(max) values can be negative in some cases. This indicates that PS_POR_B
needs to be de-asserted before the last PL power supply starts to ramp.
AES Decryption and HMAC Authentication
AES decryption requires the image to be accessed by DMA through the PCAP interface and then be
written to OCM memory. HMAC authentication requires another pass through the PCAP interface to
access the HMAC unit.
RSA Authentication Time
The BootROM can authenticate a secure or non-secure FSBL prior to execution using the RSA public
key authentication. This feature is enabled by triggering the RSA Authentication Enable fuse in the
eFuse array.
The RSA authentication time takes about 56 ms for a 128 KB FSBL using a 33.33 MHz PS_CLK, and
default register settings (that is, the CPU divider value 4). Under these conditions, the CPU runs at
215 MHz. The CPU divider value can be changed to divide by 2 by the register initialization
parameters. This cuts the authentication time in half (28 ms) because the CPU runs at 433 MHz.
BootROM and Image Copy Time
The image copy time and execute time vary greatly depending on the configuration of the boot
interface. Table 6-8 lists the BootROM times for the primary boot modes with default and optimized
register values. All values assume a 33.33 MHz PS_CLK clock and are for a 128 KB FSBL/User code
image size.
The boot times in Table 6-8 include the time from the deassertion of the PS_POR_B signal until the
BootROM branches to the FSBL image copied into the OCM. This includes PLL lock time, BootROM
execution time, PL initialization time, and the time to copy the FSBL to the OCM. For secure boot, it
also includes the time to decrypt and authenticate the FSBL through the AES/SHA unit. The PL T
POR
,
Table 6-8: BootROM Times for the Master Boot Modes
Boot Mode
Non-Secure Boot Secure Boot
Default Regs (ms) Reg-Init (ms) Default Regs (ms) Reg- Init (ms)
Quad-SPI (4-bit) 98.4 16 100 24
Quad-SPI (8-bit)72127420
NAND x81145212060
NAND x1692509256
NOR72127222
SD card 216 196 216 204