Cybersecurity & CRA
Secure boot and secure OTA updates
Two mechanisms that decide whether a device can be trusted and fixed: it runs only firmware you signed, and it can receive verified updates for its whole support period.
· by BCF Embedded engineering team
Secure boot: the chain of trust
Each stage verifies the next before handing over control.
- 01
Root of trust
Immutable boot code or a hardware security feature holds the first verification key.
- 02
Bootloader
Verifies the signature of the firmware image before starting it.
- 03
Application
Runs only after verification; debug access is locked in production.
Secure OTA updates
- Images signed with keys stored in a controlled environment
- Signature and version checks on the device before installation
- A/B slots or recovery mode for safe rollback after a failed update
- Protection against downgrading to vulnerable versions
Platform examples
Implementation details depend on the platform's security features. On STM32 and Nordic nRF devices we use the vendor's secure boot options where available; on Embedded Linux the bootloader and update framework carry the chain of trust.
Discuss your project
Describe your device and goal. An engineer replies within one business day.
Prefer e-mail?
[email protected]- Reply within one business day
- NDA available before any technical deep-dive
Our offices
Opole (Headquarters): ul. Technologiczna 2, 45-837 Opole
Wrocław (Office): ul. Strzegomska 42B, 53-611 Wrocław
Warsaw (Office): ul. Żurawia 6/12, 00-503 Warsaw