Secure Boot
Secure boot is a start-up process in which a device verifies the digital signature of each boot stage, from bootloader to firmware or operating system, against a hardware-anchored root of trust before running it.
Secure boot is a process in which a device verifies the digital signature of each piece of software in its start-up sequence, from bootloader to operating system or firmware, before running it. Verification starts from code or keys anchored in hardware, the root of trust, and each stage checks the next, forming a chain of trust. If a signature is invalid, the device refuses to run the component or falls back to a known-good image.
Secure boot prevents attackers from implanting persistent malicious code, such as bootkits or modified firmware, that would survive reboots and evade operating-system security tools. It is standard on modern PCs through UEFI Secure Boot and is increasingly built into PLCs, industrial PCs, gateways and edge devices, where physical access by unauthorised people cannot always be prevented. IEC 62443-4-2 includes requirements for the integrity of the boot process in embedded, host and network devices.
Secure boot protects only what is verified at start-up; it does not stop attacks on running software, so it is combined with signed updates, runtime protections and monitoring. Key management is critical, as a leaked signing key or a vulnerable signed bootloader can undermine the chain and must be handled through revocation. On some platforms secure boot must be enabled and configured explicitly, so asset owners should confirm its status during commissioning.
Key points
- Each boot stage verifies the signature of the next, forming a chain of trust
- Blocks bootkits and modified firmware that would persist across reboots
- UEFI Secure Boot is the common implementation on PCs and industrial PCs
- IEC 62443-4-2 includes requirements for integrity of the boot process
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.