Secure boot and Protected Update
Module goal: understand the chain of trust from boot onwards, and how updates are protected against rollback.
Status alpha (content complete, awaiting pilot teaching and feedback) · about 140 minutes
Module agreement: no lab provisions the device’s secure boot or writes the C0 (LcsO) metadata tag. The optional lab that sends a real Protected Update permanently advances the target slot’s version counter, so it needs the instructor’s permission first.
| Lesson | Topic | Time |
|---|---|---|
| sec-iot.m04.l01 | Secure boot and the chain of trust | 70 minutes |
| sec-iot.m04.l02 | Protected Update | 70 minutes |
Module checkpoint
Section titled “Module checkpoint”- a chain-of-trust diagram for the board, from boot through to the application
- can explain the anti-rollback counter and the effect of the manifest lock
TESA Open Knowledge · © 2026 สมาคมสมองกลฝังตัวไทย (TESA) · CC BY-NC 4.0
Content is licensed CC BY-NC 4.0. Reuse it non-commercially and credit the Thai Embedded Systems Association (TESA) every time. · How to cite TESA