Visible to Intel only — GUID: rqx1616551295184
Ixiasoft
3.3.1. Configuration Bitstream Encryption Using the Programming File Generator Graphical Interface
3.3.2. Configuration Bitstream Encryption Using the Programming File Generator Command Line Interface
3.3.3. Partially Encrypted Configuration Bitstream Generation Using the Command Line Interface
3.3.4. Partial Reconfiguration Bitstream Encryption
4.1. Using SDM Provision Firmware
4.2. Authentication Root Key Provisioning
4.3. Using QSPI Factory Default Helper Image on Owned Devices
4.4. Programming Key Cancellation ID Fuses
4.5. Security Setting Fuse Provisioning
4.6. AES Root Key Provisioning
4.7. Converting Owner Root Key, AES Root Key Certificates, and Fuse files to Jam STAPL File Formats
Visible to Intel only — GUID: rqx1616551295184
Ixiasoft
2.1.3. Creating the Signature Chain Root Entry
Convert the root public key into a signature chain root entry, stored on the local file system in the Intel® Quartus® Prime key (.qky) format file, with the make_root operation.
Run the following command to create a signature chain with a root entry, using a root public key from the file system.
quartus_sign --family=stratix10 \
--operation=make_root root_public.pem root.qky
Run the following command to create a signature chain with a root entry, using the root key from the SoftHSM token established in the prior section.
quartus_sign --family=stratix10 --operation=make_root \
--module=softHSM --module_args="--token_label=s10-token \
--user_pin=s10-token-pin \
--hsm_lib=/usr/local/lib/softhsm/libsofthsm2.so" root root.qky