EMB-210 · Embedded Linux & BSP · Advanced
Secure Boot & Chain of Trust — full syllabus
Establishing and maintaining a verified boot chain from ROM to userspace, including key management reality.
Who this course is for
Embedded engineers responsible for product security, who must design a verified boot chain that holds in the field — including the day a key is lost or an update is tampered with.
Prerequisites
- Embedded boot concepts (SPL, U-Boot) as in EMB-201
- Basic public-key cryptography: signatures, hashes, certificates
- Linux block device and initramfs basics
Course outline
Day 1 — Roots, stages and threat model
- What a secure boot ROM actually verifies, and its assumptions
- The stage chain: ROM, TF-A, SPL, U-Boot, kernel — and each handoff contract
- Image formats for verification: FIT images and their signature nodes
- Drawing the trust boundaries: a threat model for your product
- What secure boot does not protect you from
Day 2 — Signing and verifying the chain
- Key generation and the custody question from day one
- Signing U-Boot, kernel and device tree: FIT signature flow
- Kernel lockdown and module signing as chain extensions
- dm-verity: hashes, the hash tree and a read-only verified rootfs
- Assembling the verified boot-to-rootfs path end to end
Day 3 — Keys, rollback and measurement
- Key rotation, revocation and what happens when you lose one
- Anti-rollback counters and version monotonicity
- Recovery policy: what a device may do when verification fails
- Measured boot vs verified boot; TPM basics and the event log
- Attestation concepts: proving boot state to someone else
Hands-on labs
- Lab: Build and sign a FIT image (kernel plus device tree), then verify it under U-Boot with a required signature policy
- Lab: Negative test — tamper with one byte of the kernel and one of the device tree, and document exactly where boot stops
- Lab: Set up a dm-verity rootfs, flip a bit in a data block and observe the I/O error reach userspace
- Lab: Rehearse a key rotation: move the chain to a new key without bricking devices already in the field (in simulation)
- Lab: Boot with a (virtualised) TPM attached, read the measurement log and explain what each event proves
Capstone project
Construct a recoverable verified boot chain on the lab board or an emulated target: ROM-stage assumptions documented, signed bootloader and FIT kernel, dm-verity rootfs, a key-handling plan covering rotation and loss, and a recovery policy — validated by negative tests (tampered kernel, stale version, corrupted rootfs) whose outcomes you capture as the evidence pack.
What you leave with
- A signed, verified boot chain you assembled and attacked yourself
- FIT signing and U-Boot verification in working order
- dm-verity rootfs construction and failure behaviour
- A key-management plan covering custody, rotation and loss
- Negative-test evidence that the chain fails closed, not open
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 15 Nov – 17 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 3 of 14 | SAR 8,100until 16 Oct | ||
| 22 Nov – 24 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 8 of 14 | KWD 670until 23 Oct | ||
| 29 Nov – 1 Dec 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 3 of 14 | OMR 830until 30 Oct | ||
| 29 Nov – 6 Dec 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 17 of 20 | US$1,580until 30 Oct | ||
| 30 Nov – 2 Dec 20263 full days | OttawaIn person · Kanata North Tech Park | 8 of 14 | CAD 2,930until 31 Oct | ||
| 7 Dec – 9 Dec 20263 full days | TorontoIn person · MaRS Discovery District | 3 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 14 Dec 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 6 of 20 | US$1,580until 7 Nov | ||
| 14 Dec – 16 Dec 20263 full days | LondonIn person · Shoreditch Works | 8 of 14 | GBP 1,680until 14 Nov | ||
| 14 Dec – 16 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 3 of 14 | EUR 1,990until 14 Nov | ||
| 14 Dec – 21 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 11 of 20 | US$1,580until 14 Nov |
Book a seat, or bring this course to your team
Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.
Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.