Question
The BHK mystery on the U5 - who generates it?
For STM32U575/U585, the STM32U5 Customer Webinar says that the 256-bit BHK is “Generated by the secure boot code”. Is the intended implementation to generate 256 bits from the STM32 RNG when the BHK backup registers are uninitialized, or should secure boot restore/derive BHK from a persistent OEM-provisioned secret? Is there ST reference source code implementing the generation, TAMP_BKP[7:0]R write, and BHKLOCK sequence?
