Security Hardware

kFBL

Ensuring Device Integrity from the Very First Instruction

kFBL secure boot chain: ROM, bootloader, application, update

Core Features

Secure Boot Chain

Establishes a hardware-anchored Root of Trust (RoT) and verifies the integrity and authenticity of each boot stage, preventing unauthorized software execution.

Code Authentication

Performs cryptographic signature verification (e.g., RSA, ECDSA) of all firmware images before execution, ensuring only trusted code runs on the device.

Anti-Rollback Protection

Prevents attackers from downgrading to older, potentially vulnerable firmware versions through secure version control mechanisms.

Encrypted Firmware

Supports decryption of encrypted firmware images during the update process to protect intellectual property and prevent reverse engineering.

Hardware Integration

Seamlessly integrates with on-chip security features, Hardware Security Modules (HSMs), or Secure Elements (SE) for enhanced key protection and cryptographic operations.

Minimal Overhead

Highly optimized for resource-constrained embedded systems, offering a minimal flash footprint (typically 8-32KB) and negligible impact on boot time.

kFBL: Ensuring Trust from Boot-Up to Update

The Kayten Flash Bootloader employs a multi-stage process to establish a chain of trust from the hardware up to the application, and ensures that firmware updates are applied securely and reliably.

Secure Boot Process

1

Hardware Root of Trust

Boot process initiates from immutable code (e.g., ROM, OTP memory) or a hardware-verified first-stage bootloader, establishing the initial trust anchor.

2

Bootloader Verification

kFBL's integrity and authenticity are verified using cryptographic signatures, often anchored in hardware (e.g., secure fuses, PUF, or an HSM).

3

Firmware Authentication

The application firmware and any subsequent boot stages are authenticated via digital signatures before execution, ensuring they originate from a trusted source.

4

Secure Execution

Once verified, the application firmware is launched in a secure execution environment, with memory protection and other hardware security features configured by kFBL.

Secure Update Process

Update Reception

  • New firmware image is received via a designated update channel (e.g., CAN, Ethernet, USB).
  • The image is temporarily stored in a dedicated, isolated memory area (e.g., secondary flash bank).
  • Basic integrity checks (e.g., checksums, size verification) are performed on the received image.

Update Installation

  • Full cryptographic authentication (signature verification) of the update package.
  • Version control and anti-rollback checks to prevent downgrades to vulnerable versions.
  • Atomic update process: if installation fails, the system safely reverts to the previous valid image (A/B partitioning or similar).
  • Post-update verification and secure handover to the newly updated application.

kFBL Technical Specifications

The Kayten Flash Bootloader is designed for broad compatibility, robust security, and minimal resource consumption on embedded devices.

Supported MCU Families

  • Infineon: TRAVEO™ T2G
  • NXP: S32Kx, i.MX RT Series, LPC Series, Kinetis
  • STMicroelectronics: STM32 Family (F, G, H, L, U Series)
  • Renesas: RH850 Family, RL78 Family, RX Family
  • Texas Instruments: C2000™ Real-time MCUs, MSP430™ MCUs
  • Microchip: PIC32, SAM D/E/L/C Series

Security Features

  • Cryptographic Algorithms: RSA (2048/3072/4096), ECDSA (P-256/P-384/P-521), AES-GCM (128/256), SHA-2 (256/384/512)
  • Firmware Image Authentication: Digital Signatures (PKCS#1 v1.5, PSS)
  • Firmware Image Encryption: AES-GCM or AES-CBC with secure key derivation
  • Secure Key Storage Integration: Support for HSMs, Secure Elements (SEs), or on-chip secure memory
  • Hardware Security Module (HSM) Support: e.g., Kayten kHSM, SHE, TPM

Update Channels

  • Automotive: CAN/CAN-FD (UDS - ISO 14229), Ethernet (DoIP - ISO 13400), FlexRay, LIN
  • Industrial/IoT: Ethernet (TCP/IP, UDP), Serial (UART, RS-485), Wireless (BLE, Wi-Fi, LoRaWAN - via host application)
  • Local: USB, SPI, I2C (for development/manufacturing)

Performance & Footprint

  • Typical Boot Time: < 100ms (MCU dependent)
  • Flash Footprint: 8KB - 32KB (configuration dependent)
  • RAM Requirement: 2KB - 8KB (configuration dependent)
  • Firmware Update Speed: > 100 KB/s (bus and flash technology dependent)
  • Memory Layouts: Dual-bank flash for A/B updates, single-bank with recovery partition

kFBL Applications: Securing Diverse Embedded Systems

The Kayten Flash Bootloader is a versatile solution, adaptable to a wide range of industries and embedded systems requiring robust boot security and secure firmware updates.

Automotive ECUs

Ensures integrity and authenticity for all types of Electronic Control Units (ECUs) in vehicles, from gateways and domain controllers to ADAS and infotainment systems.

  • • Gateway Modules & Domain Controllers
  • • ADAS & Autonomous Driving ECUs
  • • Infotainment & Telematics Systems
  • • Powertrain & Chassis Control Units

Industrial Controls

Provides robust boot security and secure update capabilities for critical industrial control systems (ICS), PLCs, and other automation components.

  • • Programmable Logic Controllers (PLCs)
  • • Industrial PCs (IPCs) & HMIs
  • • Robotic Controllers & Motion Systems
  • • Smart Sensors & Actuators

Medical Technology

Delivers the highest level of security and integrity for life-critical medical devices, ensuring trustworthy operation and secure software maintenance.

  • • Patient Monitoring Systems
  • • Infusion Pumps & Drug Delivery Systems
  • • Diagnostic Imaging Equipment
  • • Implantable Medical Devices (IMDs)

Defense & Aerospace

Meets stringent security standards for critical defense and aerospace systems, ensuring operational integrity and resilience against tampering.

  • • Secure Communication Systems
  • • Unmanned Aerial Vehicles (UAVs)
  • • Radar & Sensor Systems
  • • Flight Control & Avionics Systems

Energy Systems

Protects critical infrastructure components in the energy sector, from smart grid devices to renewable energy controllers.

  • • Smart Meters & Grid Edge Devices
  • • Substation Automation Systems
  • • Renewable Energy Controllers (Solar, Wind)
  • • Electric Vehicle Charging Infrastructure

General IoT Devices

Provides a foundational security layer for a wide range of connected IoT devices.

  • • Smart Home Devices
  • • Wearable Technology
  • • Connected Appliances
  • • Asset Tracking Systems

Use Cases

Automotive

  • ECU firmware updates
  • Secure boot implementation
  • Rollback protection
  • Anti-theft protection

Defense

  • Secure system initialization
  • Tamper detection
  • Classified boot sequences
  • Hardware attestation

Ensure Device Integrity with Kayten Secure Flash Bootloader

Protect your embedded systems from boot-time attacks and ensure trustworthy firmware updates. Contact us to learn more about kFBL and start your evaluation.