An embedded device that boots any firmware presented to it, without verifying who created it, is a device that an attacker can repurpose entirely. In automotive systems, industrial controllers, and medical devices, the consequences of unauthorised firmware range from commercial theft to safety-critical failure. Secure boot is the mechanism that closes this attack surface by cryptographically verifying firmware integrity and authenticity before execution.
The Asymmetric Cryptography Foundation
Secure boot relies on asymmetric cryptography — digital signature schemes — rather than symmetric encryption. Asymmetric schemes use a key pair: a private signing key that remains exclusively in the build infrastructure, and a public verification key stored on the device. The build system signs each firmware image with the private key. The bootloader verifies the signature at boot time using the stored public key. Crucially, the public key cannot produce valid signatures, even if an attacker extracts it from every device in the field, they cannot forge a valid firmware signature.
| Scheme | Key Size | Signature Size | Verification Speed | MCU Footprint |
|---|---|---|---|---|
| RSA-2048 | 2048 bits | 256 bytes | Moderate | Higher |
| RSA-4096 | 4096 bits | 512 bytes | Slower | Higher |
| ECDSA P-256 | 256 bits | 64 bytes | Fast | Lower |
| ECDSA P-384 | 384 bits | 96 bytes | Moderate | Lower |
ECDSA P-256 has become the preferred choice for resource-constrained embedded secure boot due to its smaller key and signature sizes and faster verification compared to RSA at equivalent security strength.
PKI Architecture for Embedded Firmware Signing
A production embedded PKI involves more than a single key pair. A two-level structure provides operational flexibility. The Root Certificate Authority holds the root private key in an offline, air-gapped HSM and is used only to sign Code Signing Certificates. The Code Signing Certificate is the operational key used in the build pipeline. The device stores only the Root CA public key. At boot time, the bootloader verifies the CSC against the Root CA public key, then verifies the firmware image signature against the CSC. This chain allows the operational CSC to be rotated without changing anything on deployed devices.
HSM Integration for Private Key Protection
Hardware Security Modules store private keys in tamper-resistant hardware that physically destroys key material if tampering is detected. The signing operation is performed inside the HSM — the private key never leaves the HSM boundary. For automotive programmes, nShield or Utimaco HSMs are commonly used. For on-device key protection, SHE on Renesas and Infineon MCUs and the dedicated security subsystem on NXP S32K3 provide HSM-accelerated signature verification and protected public key storage.
Key Rotation and Revocation
For the two-level PKI structure, rotating the operational Code Signing Certificate requires no field device update, since devices store only the Root CA public key. Revocation of a compromised CSC is handled by issuing a Certificate Revocation List signed by the Root CA — devices performing chain verification check the CRL before accepting a CSC, blocking signatures from the revoked key. CRL distribution requires the same secure OTA channel used for firmware delivery.
Implementing Secure Boot with RAPIDSEA
RAPIDSEA's bootloader suite implements asymmetric secure boot with ECDSA P-256 and RSA-2048/4096 signature verification, hardware-backed key storage using SHE, HSM, and platform-specific security peripherals across Renesas, NXP, and Infineon MCU families, and two-level certificate chain verification. The Flint IDE bootloader configurator provides graphical selection of signature algorithm, key storage mechanism, and certificate chain depth. Anti-rollback counter integration uses OTP fuse or secure NVM storage, with monotonic counter verification performed before firmware execution.
Conclusion
Secure boot PKI and key management form the cryptographic foundation that makes OTA firmware delivery trustworthy in adversarial environments. Correct implementation requires the right signature scheme, a PKI structure supporting key rotation, HSM-backed key protection, and a revocation mechanism for deployed fleets. RAPIDSEA's bootloader delivers production-validated secure boot across all these dimensions.
Ready to implement secure boot? Contact our team to request an evaluation build or book a technical demo.
