
Cryptographic schemes handling
UM2262
74/94
UM2262 Rev 6
D.4
X509 certificate-based asymmetric scheme without firmware
encryption
This scheme (SECBOOT_X509_ECDSA_WITHOUT_ENCRYPT_SHA256) is implemented
for firmware verification as illustrated in
Figure 41. X509 asymmetric verification
The X509 certificate-based asymmetric scheme makes use of a chain of X509 certificates to
deliver the public key used to verify the firmware header signature.
In the example provided, two certificates (the Root CA and OEM CA (first intermediate CA))
are embedded inside STSAFE-A100, while the second intermediate CA and leaf certificate
(firmware signing certificate) are delivered as part of the firmware header.