The measurement specification for all the indices listed in the tables below is: 0x01 (DMTF).
The CoRIM files include the same measurement block definition encoded in base64 format, as outlined below. If the table indicates "Yes" under the "Part of CoRIM" column, the index is included in the CoRIM file; otherwise, it is excluded.
Version 1.0.0
The table below shows the measurements supported starting from firmware version 28.38.xxxx.
|
Index |
Measurement |
Value |
Description |
What is measured? |
Part of CoRIM? |
|---|---|---|---|---|---|
|
1 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-0: IC Security Parameters (Fuse, Straps) |
No |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|||
|
2 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-1: First mutable code |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
3 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-2: Secondary boot sequencing code |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
4 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-3: Runtime Code |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
5 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-4: Hashes manifest |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
Version 1.1.0
The table below shows the measurements supported starting from the firmware releases after April 2025.
|
Index |
Measurement |
Value |
Description |
What is measured? |
Part of CoRIM? |
|---|---|---|---|---|---|
|
1 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-0: IC Security Parameters (Fuse, Straps) |
No |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|||
|
2 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-1: First mutable code |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
3 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-2: Secondary boot sequencing code |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
4 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-3: Runtime Code |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
5 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-4: Hashes manifest |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
6 |
DMTFSpecMeasurementValueType |
0x83 |
Raw bitstream, FW Config |
Measurement Block version
|
Yes |
|
DMTFSpecMeasurementValueSize |
4 |
4-byte unsigned Integer, little endian |
|||
|
7 |
DMTFSpecMeasurementValueType |
0x81 |
Raw bitstream, Device Identifier |
Device Identifier (DID, VID, SVID, SID) as defined by PCISIG and a vendor defined byte.
|
Yes |
|
DMTFSpecMeasurementValueSize |
9 |
Raw bitstream |
Version 1.2.0
The table below shows the measurements supported in future firmware releases. The first release to intercept this definition will be updated.
|
Index |
Measurement |
Value |
Description |
What is measured? |
Part of CoRIM? |
|---|---|---|---|---|---|
|
1 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-0: IC Security Parameters (Fuse, Straps) |
No |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|||
|
2 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-1: First mutable code |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
3 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-2: Secondary boot sequencing code |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
4 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-3: Runtime Code |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
5 |
DMTFSpecMeasurementValueType |
0x01 |
Hash, mutable FW |
M-4: Hashes manifest |
Yes |
|
DMTFSpecMeasurementValueSize |
64 |
SHA2-512 hash |
|
|
|
|
6 |
DMTFSpecMeasurementValueType |
0x83 |
Raw bitstream, FW Config |
Measurement Block version
|
Yes |
|
DMTFSpecMeasurementValueSize |
4 |
4-byte unsigned Integer, little endian |
|||
|
7 |
DMTFSpecMeasurementValueType |
0x83 |
Raw bitstream, FW Config |
Debug tokens runtime status (32-bit):
Each pair consists of:
|
Yes;
The expected value is a clean state (all zero bytes) |
|
DMTFSpecMeasurementValueSize |
4 |
4-byte unsigned Integer, little endian |
|||
|
8 |
DMTFSpecMeasurementValueType |
0x81 |
Raw bitstream, Device Identifier |
Device Identifier (DID, VID, SVID, SID) as defined by PCISIG and a vendor defined byte.
|
Yes |
|
DMTFSpecMeasurementValueSize |
9 |
Raw bitstream |
Last updated: