Who is this for?

This is an advanced topic for embedded developers who boot Zephyr from U-Boot on an Arm Cortex-A processor and want U-Boot to verify the Zephyr image before starting it.

What will you learn?

Upon completion of this Learning Path, you will be able to:

  • Identify where U-Boot verifies Zephyr in the Arm Cortex-A boot chain.
  • Build and sign a Flattened Image Tree (FIT) containing Zephyr, and embed the public key in U-Boot without changing its source.
  • Configure U-Boot to verify Zephyr before booting, and optionally test rejection of wrong-key and tampered images.
  • Identify the verification boundary in QEMU and on a development board, and how fusing your key extends trust in production.

Prerequisites

Before starting, you will need the following:

  • One of two targets - QEMU, which needs no hardware, or a Texas Instruments (TI) AM62L EVM with accessories to power it, write an SD card, and attach a serial console
  • A Linux host running Ubuntu 22.04 or 24.04, with about 20 GB of free disk space; QEMU runs on x86_64 or arm64, while the AM62L EVM needs x86_64 for the TI SDK
  • Visual Studio Code with the Workbench for Zephyr extension installed
  • Basic knowledge of U-Boot and the Linux command line

Summary

AI-assisted

This summary was drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.

Close
?
You’ll build a Zephyr image for Arm Cortex-A and configure U-Boot to verify its signed FIT before booting. After choosing QEMU or a TI AM62L evaluation module (EVM), you’ll set up the host tools, build Zephyr, sign the FIT, and embed the trusted public key in U-Boot. You’ll then boot the image, optionally test rejection of untrusted or tampered images, and examine what remains outside the verification boundary.

Frequently asked questions

AI-assisted

These FAQs were drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.

Close
?
Do I need an AM62L EVM to follow this Learning Path?
No. You can use QEMU without hardware. If you have an AM62L EVM, follow its target-specific setup and boot-media instructions instead.
Do I need to patch the U-Boot source to add the trusted key?
No. You’ll generate a public-key node in signature.dtsi and include it when you build U-Boot. For the AM62L EVM, use CONFIG_DEVICE_TREE_INCLUDES. For QEMU, add the node to the control device tree supplied with EXT_DTB. You don’t need to change the U-Boot source files.
How can I check the signed FIT before booting the target?
Use the U-Boot fit_check_sign tool with your signed FIT and built u-boot.dtb. This checks the FIT against the public key in the control device tree before you prepare the boot media.
How do I confirm that verification succeeded on the target?
Look for sha256,rsa2048:key-a+ OK in the U-Boot output, followed by the Zephyr image A banner. You can also run the optional wrong-key and tampered-image tests to check that U-Boot refuses to start either image.
Does this setup authenticate U-Boot as well as Zephyr?
No. In QEMU, you’ll run U-Boot without an earlier stage that authenticates it. On the AM62L EVM, you’ll leave the device in High Security, Field Securable (HS-FS) development state, where earlier stages accept boot files signed with any key. To extend trust to U-Boot in production, you need to provision your key, move the device to High Security, Security Enforced (HS-SE), and sign the earlier boot files.
Next