Meaning
Security architecture requires that a system refuses to execute older, authenticated but potentially vulnerable firmware. Implementing anti-rollback protection ensures that once a system has been updated to a newer revision, any attempt to install an earlier version containing known security flaws is blocked. This mechanism relies on comparing the version identifier of the incoming payload against a non-volatile value stored securely in the hardware.
Hardware Anchor
Secure storage of the current version minimum is necessary to prevent physical bypass of the check. Emulated storage in standard flash sectors is often insufficient because it can be cleared or overwritten during a full chip erase. Modern designs utilize dedicated registers or write-once memory cells to hold the version index.
Execution Flow
During the boot sequence, the primary bootloader reads the version field from the signed header of the application image. It then retrieves the minimum allowed version from the secure memory of the device. If the image version is lower than the stored value, the bootloader halts the boot sequence or switches to a recovery image.
Version Update
The update of the rollback threshold occurs only after the new image has been verified and successfully executed. This prevents locking the device into an unbootable state if the new firmware fails during the initial boot phase. Once the system completes its first successful power-on self-test, the persistent counter is incremented to match the version of the active firmware.