Skip to content

Secure boot and Protected Update

Module goal: understand the chain of trust from boot onwards, and how updates are protected against rollback.

Status alpha (content complete, awaiting pilot teaching and feedback) · about 140 minutes

Module agreement: no lab provisions the device’s secure boot or writes the C0 (LcsO) metadata tag. The optional lab that sends a real Protected Update permanently advances the target slot’s version counter, so it needs the instructor’s permission first.

Lesson Topic Time
sec-iot.m04.l01 Secure boot and the chain of trust 70 minutes
sec-iot.m04.l02 Protected Update 70 minutes
  • a chain-of-trust diagram for the board, from boot through to the application
  • can explain the anti-rollback counter and the effect of the manifest lock

TESA Open Knowledge · © 2026 สมาคมสมองกลฝังตัวไทย (TESA) · CC BY-NC 4.0

Content is licensed CC BY-NC 4.0. Reuse it non-commercially and credit the Thai Embedded Systems Association (TESA) every time. · How to cite TESA