
1/25/2023 · Derek Chamorro, Ryan Chow
What this post added
This post details Cloudflare's implementation of hardware secure boot for Arm servers, building upon previous work with AMD. It introduces the Arm Trusted Firmware Secure Boot (TBBR) process and highlights its limitations for server environments. The post then describes Cloudflare's partnership with Ampere to develop and implement 'Single Domain Secure Boot' (SDSB) for Ampere Altra Max CPUs. SDSB enhances the boot chain's integrity by incorporating a customer's public key hash into the SoC's eFuse, allowing for end-to-end verification of UEFI firmware.