User manual

Table Of Contents
Zynq-7000 AP SoC Technical Reference Manual www.xilinx.com 765
UG585 (v1.11) September 27, 2016
Chapter 32
Device Secure Boot
32.1 Introduction
Zynq-7000 AP SoC devices support the ability to perform a secure boot to load authenticated and
encrypted PS images and PL bitstreams.
32.1.1 Block Diagram
Figure 32-1 is a block diagram showing the different systems involved in a secure boot.
32.1.2 Features
Zynq-7000 AP SoC devices provide the following secure boot features:
Advanced Encryption Standard
°
AES-CBC with 256-bit key (FIPS197)
°
Encryption key stored on-chip in either eFuse or Battery-backed RAM (BBRAM)
Keyed-hashed message authentication code (HMAC, FIPS198-1)
°
SHA-256 authentication engine (FIPS180-4)
RSA public key authentication (FIPS186-3)
°
2048-bit public key