GREENERWAVE

Design and development of a secure boot and update system on the Zynq 7000 platform and Linux

Smile worked with our team to secure an embedded system, including secure boot, over-the-air (OTA) updates, and full disk encryption. In a complex development environment, their consultants demonstrated remarkable adaptability and delivered a solution that met our expectations within the given timeframe. Their approach, based on identifying our objectives and jointly defining a threat model, resulted in a robust and well-designed security architecture. Throughout the project, they provided sound advice, demonstrating genuine expertise and a keen sense of reliable solutions.

Allen Welkie

Software Team Lead Greenerwave

The context

Greenerwave has established itself as a pioneering and leading player in the development of wave formation technology solutions.

To fully exploit the potential of its innovations, the company designs high-performance electronic equipment incorporating critical hardware and software components. However, these products are intended to be installed and operated in the field in physically unsecured and potentially hazardous environments.

The need

Protecting business value and ensuring secure access

Faced with the deployment of its equipment in sensitive areas, Greenerwave's strategic priority was to protect its business value, its intellectual property, and to prevent any unauthorized access to the hardware. The challenge lay in thoroughly analyzing the security mechanisms offered by the embedded platform components in order to design and deploy a comprehensive, secure boot and update architecture that would enable confident international commercialization.

The Challenge

Building a chain of trust on a complex architecture

The Greenerwave product is based on a Zynq 7000 SoC architecture, requiring simultaneous security across all system layers: the U-Boot firmware, the Yocto Linux generic OS, the FreeRTOS real-time coprocessor, and the FPGA bitstream. The significant complexity lay in the fact that each component had its own hardware-imposed encryption constraints, necessitating impeccable management of the confidentiality of the various security keys.

100%

of the secure chain

3 months

overall achievement

2

experts mobilized

Our approach

Agile development combining architecture and implementation

To meet this challenge, Smile assembled a team consisting of an architect and a senior developer who simultaneously conducted technical experimentation and architectural design. Through regular workshops, the experts defined the threat model with the client and drafted a detailed architecture document. The team then completed the full implementation of secure boot under Yocto, the deployment of the RAUC remote update system with A/B redundancy, and an automated factory flashing system via JTAG to configure the hardware keys.

The result

A market-ready, cyber-resilient embedded platform

At the project's completion, the entire secure boot chain was successfully deployed. From disk data encryption and application update authentication to redundancy management, all security constraints were addressed. Thanks to this robust and sustainable trust architecture, the Greenerwave embedded product has reached the level of maturity required for confident commercialization.

Securing the boot phase is always a complex issue, but managing the FPGA bitstream and the specific requirements of Greenerwave made it a particularly interesting technical challenge. We are proud to have successfully completed this project.

Jeremy Rosen

Head of Embedded Systems Expertise at Smile

Insights

More success stories

See more

Board Bring-up, Drivers and Industrialization: Yocto at the service of High-Fidelity Audio

  • Security
  • Embedded & IoT

Boost the marketing of Orphie cameras by making the solution sovereign against industrial espionage via a cyber-secure Yocto architecture.

  • Embedded & IoT

Bring-up of a custom card designed to secure and modernize an energy control platform.

  • Embedded & IoT

Embedded Linux Redesign (Yocto) & Cybersecurity for Control Systems

  • Embedded & IoT
  • Cybersecurity

Support in the development of connected objects

  • Connected objects
  • Cloud & Infrastructure