Embedded Security

Note

TL;DR - Hub aggregating all embedded security documentation — covering secure boot (UEFI, i.MX HABv4, SPL), OP-TEE trusted execution, Mend SCA vulnerability scanning, verified boot, and platform-specific security hardening for embedded Linux and Android.

Secure Boot Implementation

Platform / Guide

What it covers

UEFI Secureboot with Yocto and GRUB

x64 UEFI Secureboot, TPM/LUKS auto-decryption, SELinux, Mender A/B updates. See article.

i.MX6 HABv4 Signed Boot

PKI tree generation, SRK fusing, signed U-Boot, signed uImage, encrypted boot with DEK blob. See the i.MX6 HABv4 guide.

i.MX8MM HABv4 Secure Boot

Extension of i.MX6 HABv4 for i.MX8M Mini platforms. See the i.MX8MM HABv4 guide.

SPL HABv4

Secure Boot for U-Boot SPL (Secondary Program Loader). See the SPL HABv4 guide.

Verified Boot on i.MX6

Authenticated kernel boot flow. See the verified boot on i.MX6 guide.

Verified Boot on Allwinner A64

Authenticated kernel boot on 64-bit Allwinner. See the verified boot on Sunxi64 guide.

Redundant Boot with U-Boot

Multi-partition failover for high-availability boot. See guide.

Trusted Execution Environment

Vulnerability Scanning

Application Security

Tip

Need help securing your embedded product? Amarula Solutions offers secure boot implementation, TEE integration, vulnerability assessment, and CRA compliance consulting for embedded Linux and Android. Contact our security team