Glossary · OT cybersecurity
Secure boot
Also known as: Verified boot, Trusted boot
German: Sicherer Systemstart
In embedded and computer security, secure boot is a mechanism that verifies the digital signature of each piece of boot software, such as bootloader, firmware and operating system, before executing it, starting from a hardware root of trust, so that a device only runs software from an authorized publisher.
- OT security
In one sentence
Secure boot verifies the signature of each boot stage from a hardware root of trust, so a device only runs software from an authorized publisher.
Example
A PLC with secure boot refuses to start a manipulated firmware image and instead remains in a safe diagnostic state with an error LED.
How it applies
- Product development: Secure boot builds a chain of trust: immutable boot code verifies the bootloader, which verifies the firmware or operating system. It protects against persistent manipulation of device software. IEC 62443-4-2 includes requirements for verifying software integrity at boot for embedded devices at higher security levels.
- Operation: Secure boot only protects if it is enabled and keys are managed. On industrial PCs, it is often a BIOS or UEFI setting that must be configured at commissioning.
- Maintenance: Updates must be signed with keys the device trusts. Replacing a key or revoking a compromised one needs a planned process.
- Documentation: Manuals should state whether secure boot is supported and enabled by default, how the device behaves when verification fails, and how service staff distinguish a boot failure caused by manipulation from a hardware fault.
Secure boot vs. signed update
A Signed update is checked when it is installed. Secure boot checks the software every time the device starts, so it also detects manipulation after installation.