LTE Module Series
SC20 Secure Boot User Guide
SC20_Secure_Boot_User_Guide Confidential / Released 8 / 15
4. SBL1 #1 transfers execution to QSEE/TZ.
5. QSEE/TZ sets up secure environment and brings RPM out of RESET to start execution of RPM
firmware.
6. QSEE/TZ jumps to HLOS APPSBL to start execution.
SBL1 segment#2 is equal to DDR driver + SDI equivalent copied to RPM code RAM.
DDR is initialized by SBL1 segment#2 and part of the SDI functionality included in SBL1 segment#2.
7. HLOS APPSBL loads and authenticates the HLOS kernel.
8. HLOS kernel:
a. Loads the Modem Boot Authenticator (MBA) to DDR via PIL.
b. Brings modem DSP Q6 out of RESET.
c. Loads the AMSS modem image to DDR via PIL.
c’. Modem PBL copies the MBA from DDR to modem TCM, authenticates MBA and finally jumps to
MBA image.
c”. MBA authenticates modem image and then jumps to modem.
d. HLOS loads the Pronto image to DDR via PIL.
d’. HLOS brings Pronto out of RESET and Pronto image starts execution.