Meaning
Ownership over the initial sequence of instructions executed by a microcontroller or processor upon reset resides with the entity holding the signing keys. Verification of the firmware image occurs before execution to ensure only authorized code runs on the hardware. Bootloader custody defines the chain of trust from the hardware root to the operating system.
Signature Verification
Public keys stored in read-only memory or one-time programmable fuses validate the incoming code. The signature verification of the bootloader custody prevents the execution of unauthorized or tampered binaries. If the signature check fails, the device remains in a secure state or enters a recovery mode.
Ownership Transfer
Provisioning involves the secure injection of customer keys into a module during manufacturing. The ownership transfer of the bootloader custody allows a buyer to replace vendor-provided default keys with their own secret credentials. This process usually happens once.
It marks the transition from a generic part to a secured asset. Irreversible fuse blowing permanently locks the device to the new owner.
Security Lifecycle
Transitions between development, testing, production, and end-of-life stages are managed via internal registers. The security lifecycle of the bootloader custody determines whether debug ports like jtag are open or closed. Production units generally disable all external debugging to maintain the integrity of the stored secrets.