Visible to Intel only — GUID: iup1569385458190
Ixiasoft
Visible to Intel only — GUID: iup1569385458190
Ixiasoft
2.4. Authentication
- Use the PACSign tool to create a root entry hash bitstream.
- Use the fpgasupdate tool to program the bitstream onto the Intel® FPGA PAC.
$ sudo fpgasupdate [--log-level=<level>] file [bdf]
On subsequent boots of the Intel® FPGA PAC D5005, the Intel® MAX® 10 BMC RoT programs the Intel Stratix 10 FPGA with the Intel FIM, reads the root entry hash from the on-board flash, and transmits the hash to the Intel Stratix 10 Secure Device Manager (SDM). The SDM then performs authentication of the AFU signature before loading the AFU.
All key operations are done using PACSign. PACSign is a standalone tool that is not required to be run on a machine with the Intel FPGA PAC installed. Key creation, signing, and cancellation bitstream creation are not runtime operations and can be performed at any time. The signing process prepends the signature to the AFU image file. The BMC RoT does not need access to the HSM at any point to verify a signature.