Hardware Infrastructure & Performance Optimization
Armed to Boot: an enhancement to Arm's Secure Boot chain

Armed to Boot: an enhancement to Arm's Secure Boot chain

1/25/2023 · Derek Chamorro, Ryan Chow

What this post added

This post details Cloudflare's implementation of hardware secure boot for Arm servers, building upon previous work with AMD. It introduces the Arm Trusted Firmware Secure Boot (TBBR) process and highlights its limitations for server environments. The post then describes Cloudflare's partnership with Ampere to develop and implement 'Single Domain Secure Boot' (SDSB) for Ampere Altra Max CPUs. SDSB enhances the boot chain's integrity by incorporating a customer's public key hash into the SoC's eFuse, allowing for end-to-end verification of UEFI firmware.

Read the original post ↗