EMB-210 · Embedded Linux & BSP · Advanced

Secure Boot & Chain of Trust — full syllabus

Establishing and maintaining a verified boot chain from ROM to userspace, including key management reality.

Duration3 full days in person · 6 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 9,000 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Embedded engineers responsible for product security, who must design a verified boot chain that holds in the field — including the day a key is lost or an update is tampered with.

Prerequisites

Course outline

Day 1 — Roots, stages and threat model

  • What a secure boot ROM actually verifies, and its assumptions
  • The stage chain: ROM, TF-A, SPL, U-Boot, kernel — and each handoff contract
  • Image formats for verification: FIT images and their signature nodes
  • Drawing the trust boundaries: a threat model for your product
  • What secure boot does not protect you from

Day 2 — Signing and verifying the chain

  • Key generation and the custody question from day one
  • Signing U-Boot, kernel and device tree: FIT signature flow
  • Kernel lockdown and module signing as chain extensions
  • dm-verity: hashes, the hash tree and a read-only verified rootfs
  • Assembling the verified boot-to-rootfs path end to end

Day 3 — Keys, rollback and measurement

  • Key rotation, revocation and what happens when you lose one
  • Anti-rollback counters and version monotonicity
  • Recovery policy: what a device may do when verification fails
  • Measured boot vs verified boot; TPM basics and the event log
  • Attestation concepts: proving boot state to someone else

Hands-on labs

  1. Lab: Build and sign a FIT image (kernel plus device tree), then verify it under U-Boot with a required signature policy
  2. Lab: Negative test — tamper with one byte of the kernel and one of the device tree, and document exactly where boot stops
  3. Lab: Set up a dm-verity rootfs, flip a bit in a data block and observe the I/O error reach userspace
  4. Lab: Rehearse a key rotation: move the chain to a new key without bricking devices already in the field (in simulation)
  5. Lab: Boot with a (virtualised) TPM attached, read the measurement log and explain what each event proves

Capstone project

Construct a recoverable verified boot chain on the lab board or an emulated target: ROM-stage assumptions documented, signed bootloader and FIT kernel, dm-verity rootfs, a key-handling plan covering rotation and loss, and a recovery policy — validated by negative tests (tampered kernel, stale version, corrupted rootfs) whose outcomes you capture as the evidence pack.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
15 Nov – 17 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 3 of 14 SAR 8,100until 16 OctSAR 9,000
22 Nov – 24 Nov 20263 full days Kuwait CityIn person · Al Hamra Tower 8 of 14 KWD 670until 23 OctKWD 740
29 Nov – 1 Dec 20263 full days MuscatIn person · Knowledge Oasis Muscat 3 of 14 OMR 830until 30 OctOMR 920
29 Nov – 6 Dec 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 17 of 20 US$1,580until 30 OctUS$1,750
30 Nov – 2 Dec 20263 full days OttawaIn person · Kanata North Tech Park 8 of 14 CAD 2,930until 31 OctCAD 3,260
7 Dec – 9 Dec 20263 full days TorontoIn person · MaRS Discovery District 3 of 14 CAD 2,930until 7 NovCAD 3,260
7 Dec – 14 Dec 20266 half-days Europe bandLive online · 09:00–13:00 CET 6 of 20 US$1,580until 7 NovUS$1,750
14 Dec – 16 Dec 20263 full days LondonIn person · Shoreditch Works 8 of 14 GBP 1,680until 14 NovGBP 1,870
14 Dec – 16 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 3 of 14 EUR 1,990until 14 NovEUR 2,210
14 Dec – 21 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 11 of 20 US$1,580until 14 NovUS$1,750

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.