Manifest Format

Status: Draft

This document describes the manifest format for boot stage images stored in flash.

OpenTitan secure boot, at a minimum, consists of three boot stages: ROM, ROM_EXT, and the first owner boot stage, e.g. BL0. ROM is stored in the read-only Mask ROM while remaining stages are stored in flash. ROM and ROM_EXT require the manifest described in this document to be at the start of ROM_EXT and first owner boot stage images so that they can verify the integrity and authenticity of the next stage and configure peripherals as needed before handing over execution. Use of this manifest for stages following the first owner boot stage is optional.

The following table lists the fields of the manifest along with their sizes, alignments, and offsets from the start of the manifest in bytes. The last column provides the corresponding C data type of each field for illustration purposes. All manifest fields are stored little-endian and the total size of the manifest is 848 bytes.

Field Size (bytes) Alignment (bytes) Offset (bytes) C Data Type
signature 384 4 0 uint32_t[96]
modulus 384 4 384 uint32_t[96]
exponent 4 4 768 uint32_t
identifier 4 4 772 uint32_t
length 4 4 776 uint32_t
version_major 4 4 780 uint32_t
version_minor 4 4 784 uint32_t
security_vesion 4 4 788 uint32_t
timestamp 8 8 792 uint64_t
binding_value 32 4 800 uint32_t[8]
max_key_version 4 4 832 uint32_t
code_start 4 4 836 uint32_t
code_end 4 4 840 uint32_t
entry_point 4 4 844 uint32_t

Field Descriptions

  • signature: RSASSA-PKCS1-v1_5 signature of the image generated using a 3072-bit RSA private key and the SHA-256 hash function. The signed region of an image starts immediately after this field and extends to the end of the image.

  • modulus: Modulus of the signer’s 3072-bit RSA public key.

  • exponent: Exponent of the signer’s RSA public key. The only values supported by OpenTitan are 3 and 65537.

  • identifier: Image identifier used to identify boot stage images. The value of this field must be 0x4552544f (ASCII: “OTRE”) for a ROM_EXT image and 0x3042544f (ASCII: “OTB0”) for the first owner stage.

  • length: Length of the image (including the manifest) in bytes.

  • version_major: Major version of the image.

  • version_minor: Minor version of the image.

  • security_version: Security version of the image used for anti-rollback protection. Must be a monotonically increasing integer.

  • timestamp: Unix timestamp that gives the creation time of the image, seconds since 00:00:00 on January 1, 1970 UTC (the Unix Epoch).

  • binding_value: Binding value used by the key manager to derive secret values. A change in this value changes the secret value of the key manager, and consequently, the versioned keys and identity seeds generated at subsequent boot stages.

  • max_key_version: Maximum allowed version for keys generated by the key manager at the next boot stage.

  • code_start: Offset of the start of the executable region of the image from the start of the manifest in bytes. Must be 4-byte word aligned.

  • code_end: Offset of the end of the executable region of the image (exclusive) from the start of the manifest in bytes. Note that the range from code_start to code_end must cover all machine instructions, i.e. .vectors, .crt, and .text, in the image. Must be 4-byte word aligned.

  • entry_point: Offset of the first instruction to execute in the image from the start of the manifest in bytes. Must be 4-byte word aligned.