Secure BootΒΆ
Secure Boot in BCA is the process of booting a software image from a verified trusted source while guaranteeing it has not been tampered with. It is implemented as a Chain of Trust where each stage verifies the cryptographic signature of the next before transferring execution to it.
All BCA reference design images are built with Secure Boot enabled in production flavour by the meta-bunker layer. Manual configuration is required for key generation and device-locking.
The first link of the chain is anchored in hardware. Once a device is fused it enters the closed state and will only execute software signed with the corresponding private keys.
Enabling Secure Boot in a Custom BuildΒΆ
Note
The BCA reference design already inherits the appropriate BitBake classes. The following applies only to teams building outside the reference design or integrating meta-bunker into a custom layer stack.
Secure Boot images are built by adding the appropriate BitBake class to conf/local.conf:
# bootloader + kernel FIT signing + U-Boot hardening
INHERIT += "bca-signed"
# additionally enables root filesystem protection
INHERIT += "bca-signed-full"
Key ManagementΒΆ
The private keys used to sign each stage must be stored securely and backed up in physically separate locations. Loss of these keys permanently prevents future firmware updates on all devices closed with the corresponding eFuse values. Target platforms, typically, support multiple root key slots, allowing one-at-a-time revocation without bricking the device fleet. Consider allocating at least two keys: a production key and a recovery key kept offline.
eFuse programming can be performed via the U-Boot console during manufacturing, or at scale via the BCA update mechanism once a device is provisioned (where supported), using a fuse-programming package.