---
title: Secure/Trusted Booting
description: "Read our latest blog post for embedded computing security best practices: Use Secure/Trusted Booting to verify every driver and other software components."
image: https://blog.dedicatedcomputing.com/hubfs/DC_Blog-Secure-TrustedBooting.png
---

[![Exit](https://blog.dedicatedcomputing.com/hubfs/img/ico-exit.svg)](https://blog.dedicatedcomputing.com/secure-trusted-booting#)

# Secure/Trusted Booting

 Posted by *Dedicated Computing* on Apr 1, 2019 4:19:34 PM

![DC_Blog-Secure-TrustedBooting](https://blog.dedicatedcomputing.com/hubfs/DC_Blog-Secure-TrustedBooting.png)

![](https://blog.dedicatedcomputing.com/hs-fs/hubfs/Imported_Blog_Media/BrownWade_200X256.jpg?width=84&height=104&name=BrownWade_200X256.jpg)

*By Wade Brown, Senior Research and Design Engineer, Dedicated Computing*

Secure boot is a component of the UEFI firmware package and does not exist in legacy BIOS implementations. The intended use of this component is to protect against boot kits (as opposed to root kits, which target the OS). The general boot path is: computer starts, UEFI loads, seeks first bootable device and loads it's boot sector. Depending on the architecture, the boot sector points to software (i.e. first stage boot loader) that will eventually load and execute. On a non-secure boot enabled system, the software is loaded and executed without verification.

UEFI provides non-volatile, private storage space that can be used to store public key infrastructure (PKI) based certificates. With secure boot enabled, the UEFI firmware will verify the boot loader has been digitally signed, has not been modified and the signature matches one of the certificates stored in NVRAM. If the boot loader fails verification, it will not be loaded and executed, and the boot process stops.

A boot loader implementing the Trusted Boot methodology, only concerns itself with the verification of the next software component. For example, in Windows and Linux operating systems, this next component is often called the "kernel."The kernel, in turn, can use Trusted Boot to verify every driver and other software components. In this manner, an anti-virus engine can be loaded before any other 3rd party driver/software. Trusted Boot normally uses a hardware component called a Trusted Platform Module (TPM), which is a small microprocessor dedicated to cryptographic functions, including integrated PKI keys.

###### Share this Blog on These Platforms:

[![Share on LinkedIn](https://blog.dedicatedcomputing.com/hubfs/icon-linkedin-green.svg)](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.dedicatedcomputing.com%2Fsecure-trusted-booting%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on Twitter](https://blog.dedicatedcomputing.com/hubfs/icon-twitter-green.svg)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fblog.dedicatedcomputing.com%2Fsecure-trusted-booting%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fblog.dedicatedcomputing.com%2Fsecure-trusted-booting%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=Secure%2FTrusted%20Booting) [![Share on Email](https://blog.dedicatedcomputing.com/hubfs/icon-mail-green.svg)](mailto:?subject=Check%20out%20https%3A%2F%2Fblog.dedicatedcomputing.com%2Fsecure-trusted-booting%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fblog.dedicatedcomputing.com%2Fsecure-trusted-booting%3Futm_medium%3Dsocial%26utm_source%3Demail)

#### Related Posts

<https://blog.dedicatedcomputing.com/announces-its-m1000-ai-edge-acceleration-platform>

###### [Dedicated Computing Announces Its M1000 AI Edge Acceleration Platform Based on NVIDIA’s IGX Platform](https://blog.dedicatedcomputing.com/announces-its-m1000-ai-edge-acceleration-platform)

<https://blog.dedicatedcomputing.com/announcing-m1000-high-performance-ai>

###### [DC Announces M1000 High-Performance AI](https://blog.dedicatedcomputing.com/announcing-m1000-high-performance-ai)

<https://blog.dedicatedcomputing.com/dedicated-computing-announces-edge-ai-offering-for-video-analytics-product-inspection-and-advanced-robotics>

###### [Dedicated Computing Announces Edge AI Offering for Video Analytics, Product Inspection, and Advanced Robotics](https://blog.dedicatedcomputing.com/dedicated-computing-announces-edge-ai-offering-for-video-analytics-product-inspection-and-advanced-robotics)

<https://blog.dedicatedcomputing.com/dedicated-computing-starts-its-esg-journey-on-world-environment-day>

###### [Dedicated Computing starts its ESG Journey on World Environment Day](https://blog.dedicatedcomputing.com/dedicated-computing-starts-its-esg-journey-on-world-environment-day)

<https://blog.dedicatedcomputing.com/support-for-nvidia-rtx-a4500-a5500>

###### [DC Adds Support for NVIDIA RTX A4500 and RTX A5500](https://blog.dedicatedcomputing.com/support-for-nvidia-rtx-a4500-a5500)

<https://blog.dedicatedcomputing.com/provides-resources-with-nvidia-for-kickstarting-edge-ai-0>

###### [Dedicated Computing Provides Resources with NVIDIA for Kickstarting Edge AI Development](https://blog.dedicatedcomputing.com/provides-resources-with-nvidia-for-kickstarting-edge-ai-0)

### DC News Signup

### Recent Posts:

### Categories:

- [AI (2)](https://blog.dedicatedcomputing.com/tag/ai)
- [AI in manufacturing (1)](https://blog.dedicatedcomputing.com/tag/ai-in-manufacturing)
- [All-in-One (5)](https://blog.dedicatedcomputing.com/tag/all-in-one)
- [Artificial Intelligence (13)](https://blog.dedicatedcomputing.com/tag/artificial-intelligence)
- [artificial intelligence in manufacturing (10)](https://blog.dedicatedcomputing.com/tag/artificial-intelligence-in-manufacturing)

![](https://www.webtraxs.com/webtraxs.php?id=dedicatedcomputing&st=img)