Secure Boot

Secure Boot ensures that the software executed by the system is trusted and originated from Nokia IP Routing.

At every boot of the CSM, each step in the boot process verifies the digital signature of the next software element to boot for integrity and authenticity up to the 7705 SAR operating system images. This boot sequence forms the chain of trust for Secure Boot.

Software image signatures use RSA-4096 keys and SHA-384 hashes.

The Secure Boot chain is rooted in the platform CSM firmware based on UEFI specifications. The Nokia Platform Key, Key Exchange Key, and the allowed and disallowed databases are provisioned when Secure Boot is activated to perform the required signature verification.

Firmware updates are also digitally signed and verified using the same principle. The signature verification of a firmware update is performed at boot time by the existing firmware before the firmware update can proceed.

Note: Secure Boot is supported on all 7705 SAR platforms except the 7705 SAR-M and the 7705 SAR-18.