Smile worked with our team to secure an embedded system, including secure boot, over-the-air (OTA) updates, and full disk encryption. In a complex development environment, their consultants demonstrated remarkable adaptability and delivered a solution that met our expectations within the given timeframe. Their approach, based on identifying our objectives and jointly defining a threat model, resulted in a robust and well-designed security architecture. Throughout the project, they provided sound advice, demonstrating genuine expertise and a keen sense of reliable solutions.
Allen Welkie
Software Team Lead Greenerwave
To fully exploit the potential of its innovations, the company designs high-performance electronic equipment incorporating critical hardware and software components. However, these products are intended to be installed and operated in the field in physically unsecured and potentially hazardous environments.
Faced with the deployment of its equipment in sensitive areas, Greenerwave's strategic priority was to protect its business value, its intellectual property, and to prevent any unauthorized access to the hardware. The challenge lay in thoroughly analyzing the security mechanisms offered by the embedded platform components in order to design and deploy a comprehensive, secure boot and update architecture that would enable confident international commercialization.
The Greenerwave product is based on a Zynq 7000 SoC architecture, requiring simultaneous security across all system layers: the U-Boot firmware, the Yocto Linux generic OS, the FreeRTOS real-time coprocessor, and the FPGA bitstream. The significant complexity lay in the fact that each component had its own hardware-imposed encryption constraints, necessitating impeccable management of the confidentiality of the various security keys.
100%
of the secure chain
3 months
overall achievement
2
experts mobilized
To meet this challenge, Smile assembled a team consisting of an architect and a senior developer who simultaneously conducted technical experimentation and architectural design. Through regular workshops, the experts defined the threat model with the client and drafted a detailed architecture document. The team then completed the full implementation of secure boot under Yocto, the deployment of the RAUC remote update system with A/B redundancy, and an automated factory flashing system via JTAG to configure the hardware keys.
At the project's completion, the entire secure boot chain was successfully deployed. From disk data encryption and application update authentication to redundancy management, all security constraints were addressed. Thanks to this robust and sustainable trust architecture, the Greenerwave embedded product has reached the level of maturity required for confident commercialization.
Securing the boot phase is always a complex issue, but managing the FPGA bitstream and the specific requirements of Greenerwave made it a particularly interesting technical challenge. We are proud to have successfully completed this project.
Jeremy Rosen
Head of Embedded Systems Expertise at Smile