Embedded Security
Note
TL;DR - Hub aggregating all embedded security documentation — covering secure boot (UEFI, i.MX HABv4, SPL), OP-TEE trusted execution, Mend SCA vulnerability scanning, verified boot, and platform-specific security hardening for embedded Linux and Android.
Secure Boot Implementation
Platform / Guide |
What it covers |
|---|---|
UEFI Secureboot with Yocto and GRUB |
x64 UEFI Secureboot, TPM/LUKS auto-decryption, SELinux, Mender A/B updates. See article. |
i.MX6 HABv4 Signed Boot |
PKI tree generation, SRK fusing, signed U-Boot, signed uImage, encrypted boot with DEK blob. See the i.MX6 HABv4 guide. |
i.MX8MM HABv4 Secure Boot |
Extension of i.MX6 HABv4 for i.MX8M Mini platforms. See the i.MX8MM HABv4 guide. |
SPL HABv4 |
Secure Boot for U-Boot SPL (Secondary Program Loader). See the SPL HABv4 guide. |
Verified Boot on i.MX6 |
Authenticated kernel boot flow. See the verified boot on i.MX6 guide. |
Verified Boot on Allwinner A64 |
Authenticated kernel boot on 64-bit Allwinner. See the verified boot on Sunxi64 guide. |
Redundant Boot with U-Boot |
Multi-partition failover for high-availability boot. See guide. |
Trusted Execution Environment
OP-TEE on i.MX6 — trusted application development, secure storage, hardware-backed isolation. See opensource/thirdparty/optee/index.
Vulnerability Scanning
meta-mend — Mend SCA integration in Yocto for CRA compliance. See opensource/products/meta-mend.
MendReport Jenkins library — automated vulnerability analysis in CI/CD. See ci/sharedlibs/whitesource_jenkinslib.
warning-ng Yocto vulnerability scanner — CVE tracking in Jenkins pipelines. See news/warning-ng-jenkins-scanner.
Application Security
React Native vulnerability fixing — security/react_native/solving_vulnerabilities/solving_vulnerabilities.
Tip
Need help securing your embedded product? Amarula Solutions offers secure boot implementation, TEE integration, vulnerability assessment, and CRA compliance consulting for embedded Linux and Android. Contact our security team