Chapter 32: Device Security
XILINX CONFIDENTIAL — DISCLOSED UNDER NDA
Zynq-7000 EPP Technical Reference Manual www.xilinx.com 5
UG585 (DRAFT) February 15, 2012
33.2.1 External Boot Devices
Zynq-7000 secure boot mode is restricted to NOR, NAND, or Quad SPI FLASH as the external boot device. A secure
boot from JTAG or any other external interface is not allowed.
33.2.2 Secure Boot Image
Figure 2 Secure Boot Image Format
The secure boot image format is show in Figure 2. The secure boot image consists of a boot ROM header, a FSBL
partition (required), and any number, including zero of succeeding partitions. The boot ROM header identifies the
boot image as secure or non-secure at offset 0x028. The value stored in the boot header at offset 0x028 determines the
key source, see Table 1.