5.2 Generating the Customer Key Payload
Once Secure Boot mode is enabled on the SAM9X7 Series device, the customer’s secret symmetric key used to cipher boot images and the secret symmetric or root CA public key hash used to sign them must be provisioned in the OTP device’s memory.
For this, a specific customer key message bundle must be generated from the customer’s keying material. Specifically, the symmetric key and/or public key hash are encrypted with the ROM code public key. The output of this process is a “customer key payload” bundle. This is the only format accepted for provisioning the device.
Because the customer’s keying material is encrypted with the device’s ROM code public key before being provisioned, the provisioning process does not need to occur in a fully-trusted environment. Even if the provisioning happens in insecure premises, the confidentiality of the customer’s key is preserved. This design ensures that the customer’s key cannot be exposed or altered during provisioning.
