Root of Trust
🚧 Documentation is under development
The RidgeRun Platform Security Manual guide is currently under active development. Some sections may be incomplete or change without notice.
Questions? Contact RidgeRun or email to support@ridgerun.com.
- Introduction
- General Security Concepts
- Getting Started
- Contact Us
- Sponsor your Favorite Feature
Root of Trust
Many embedded system security techniques rely on verifying software modules or drivers using cryptographic keys so that the system can determine whether they are authorized to execute. To determine whether a particular piece of software can be trusted, the system must have a trusted reference against which the software can be verified. This is where the concept of a Root of Trust comes in.
The Root of Trust can be defined as the foundation of a system's security and trustworthiness. It provides the trusted reference used during verification processes to determine whether software or other system components can be trusted.
The Root of Trust needs to be immutable and tamper-resistant to ensure that the system remains secure and trustworthy over time. For this reason, a system's Root of Trust is usually established through hardware or trusted firmware, using mechanisms such as cryptographic keys, secure hardware, and programmable fuses.
It is important to keep this in mind because establishing the Root of Trust of a system is often a one-time, irreversible process. This means that if a mistake is made when provisioning the Root of Trust, it may affect other security mechanisms implemented later and could leave the system in an unusable state. For example, when Secure Boot is enabled, the system will boot only if the software is correctly signed with a cryptographic key trusted by the system. If the Root of Trust is provisioned with the wrong key, or if the corresponding signing key is lost, it may no longer be possible to boot newly signed software or recover the system through the normal secure boot process.
In the case of NVIDIA Jetson, the Root of Trust can be established using security fuses that are programmed during the key provisioning process. These fuses are located within the SoC and cannot be restored to their original state after they have been programmed.
As an example of a hardware Root of Trust you can see the EdgeLock Secure Enclave provides a silicon-level Root of Trust in NXP's SoCs such as the i.MX95. A block diagram of the EdgeLock Secure Enclave is shown below.
