verified boot

E203896

Verified boot is a security mechanism that ensures a device only runs software that is cryptographically validated as trusted and unmodified during the startup process.

All labels observed (8)

How this entity was disambiguated

Statements (49)

Predicate Object
instanceOf boot integrity mechanism ⓘ
secure boot process ⓘ
security mechanism ⓘ
aimsTo detect unauthorized modifications to boot components ⓘ
enforce integrity of the software stack from power-on ⓘ
benefits overall platform security ⓘ
resistance to persistent compromise ⓘ
canBeImplementedBy Android Verified Boot ⓘ
linked to: verified boot

UEFI secure boot ⓘ
linked to: UEFI
canInclude rollback protection ⓘ
verification of system partitions ⓘ
version checks for boot components ⓘ
ensures bootloader integrity ⓘ
kernel integrity ⓘ
operating system integrity at boot ⓘ
software loaded during boot is cryptographically validated ⓘ
hasPurpose ensure device only runs trusted software at startup ⓘ
prevent execution of tampered software during boot ⓘ
protect system integrity from early-boot malware ⓘ
involves chain of trust ⓘ
measured boot data ⓘ
root of trust ⓘ
verification of each stage of the boot process ⓘ
isRelatedTo firmware security ⓘ
measured boot ⓘ
secure boot ⓘ
trusted computing ⓘ
trusted platform module ⓘ
isUsedIn IoT devices ⓘ
consumer electronics ⓘ
embedded systems ⓘ
enterprise devices ⓘ
mobile operating systems ⓘ
mayStoreKeysIn TPM ⓘ
hardware-backed keystore ⓘ
secure element ⓘ
operatesDuring device startup process ⓘ
system boot sequence ⓘ
prevents booting if critical components are not verified ⓘ
execution of untrusted boot components ⓘ
persistent rootkits from loading at startup ⓘ
reliesOn immutable root of trust in hardware or firmware ⓘ
trusted keys stored in secure storage ⓘ
requires verification of bootloader code ⓘ
verification of critical system files at boot ⓘ
verification of kernel image ⓘ
uses cryptographic signatures ⓘ
hash functions ⓘ
public key cryptography ⓘ

How these facts were elicited

Referenced by (14)

Full triples — surface form annotated when it differs from this entity's canonical label.

ChromiumOS → securityFeature → verified boot ⓘ
Titan M → integratesWith → Android Verified Boot 2.0 ⓘ
subject linked to: Titan M security chip
linked to: verified boot
NetBSD → supportsSecurityFeature → veriexec ⓘ
linked to: verified boot
verified boot → canBeImplementedBy → Android Verified Boot ⓘ
linked to: verified boot
BitLocker (device encryption variant) → requires → Secure Boot ⓘ
linked to: verified boot
UEFI → securityFeature → Secure Boot ⓘ
linked to: verified boot
Pixel security architecture → includes → Android Verified Boot ⓘ
linked to: verified boot
Android N → feature → Direct Boot ⓘ
linked to: verified boot
Android N → securityEnhancement → Direct Boot ⓘ
linked to: verified boot
Unified Kernel Image specification → supports → Secure Boot ⓘ
linked to: verified boot
Unified Kernel Image specification → relatedConcept → UEFI Secure Boot ⓘ
linked to: verified boot
elementary OS → supports → Secure Boot (depending on hardware and configuration) ⓘ
linked to: verified boot
Device Guard → requires → Secure Boot ⓘ
linked to: verified boot
Credential Guard → requires → Secure Boot ⓘ
linked to: verified boot