Objectives
|
|||
- C Language knowledge (see for example our L2 training course)
- Embedded Linux Build knowledge (see for example our D1 training course)
- You may be interested also by the SEC9 Advanced Embedded Linux Security course
- You may be interested also by the SEC1 Secure Development for Embedded System course
- You may be interested also by the SEC2 Advanced Embedded Systems Security course
- Training manuals and software exercises
- One Linux PC for two trainees
- One target platform for two trainees
- Total: 2 days
- From 40% to 50% of training time is devoted to practical activities
- Cours théorique
- Support imprimé et PDF (en anglais).
- Assistance du formateur tout au long de la formation.
- Activités pratiques (40-50% de la durée)
- Exemples de code, exercices et solutions.
- Un PC (un par binôme au-delà de 6 stagiaires) avec carte cible si nécessaire.
- Machine virtuelle préconfigurée téléchargeable pour refaire les TP après le cours.
- Chaque session débute par un point avec les stagiaires.
- Tout ingénieur ou technicien en systèmes embarqués possédant les prérequis ci-dessus.
- Les prérequis sont évalués avant la formation.
- Les progrès sont évalués par le formateur via les exercices pratiques, et par des quizz pour les sections sans exercices.
- Chaque stagiaire reçoit une attestation de réussite.
- En cas de prérequis manquant, une formation différente ou complémentaire est proposée.
Plan du cours
- Linux history
- Linux architecture and modularity
- Linux system components
- The various licenses used by Linux (GPL, LGPL, etc)
- Low-level boot
- Boot on NOR
- Boot on NAND
- Boot on SD/MMC/eMMC
- Multistage Boot
- Why do we need a trusted boot chain
- Security Concerns
- Confidentiality and Integrity
- Tampering Prevention
- Compliance and Certification
| Exercise : | Boot the platform with the prebuilt image | |
- Secure Boot concept
- The chain of trust
- Complete secure boot process
- Key Management
- Introduction to key management
- Cryptographic algorithms and key types
- Key storage options: Hardware-based and software-based
- Key management processes: Generation and revocation of keys
- ARM-based platforms hardware features overview
- Secure Monitor
- Secure World
- Trusted Execution Environment
- Secure Boot on RISCV and X86_64
- Cryptographic Accelerators
- Software Solutions
- Open source
- Proprietary
| Exercise : | Generate keys that are going to be used for platform encryption | |
- U-Boot
- Capabilities and features
- Configuration, customization, and compilation
- U-Boot SPL as First-Stage Boot Loader (SSBL)
- Role of u-boot in the trusted boot chain
- How U-Boot verifies the authenticity of the images it loads
- Configuration options for securing the boot process
- Interaction with the secure world and Trusted Execution Environment
- Signing U-boot
- Arm Trusted Firmware (ATF)
- Overview and features
- ATF Boot flow
- Services
- Build and deploy
- Other platform specific components
| Exercise : | Build and boot the platform with U-boot as FSBL and SSBL | |
| Exercise : | Build and Boot the platform with ATF as FSBL and U-boot as SSBL | |
- Introduction to Linux kernel
- Source code
- Configuration
- Compilation
- FIT (Flattened Image Tree) Image
- What is FIT and why is it used
- Advantages of using FIT image
- Configuration
- Building a Secure FIT Image
- Kernel Configuration for a Secure Linux Platform
- Configuration options for secure boot in the Linux kernel
- Access Control Configuration overview
| Exercise : | Create a secured FIT Linux image | |
- Tips for hardening and securing a rootfs
- Minimizing the rootfs
- Strong authentication
- Keep software updated
- Using initramfs
- Read-only root filesystem
- Introduction to read-only root filesystem
- Purpose and benefits
- Overview of the different solutions available
- SquashFS
- CramFS: Small memory footprint
- OverlayFS-based read-only root filesystem
- UnionFS-based read-only root filesystem
- Considerations when choosing a read-only root filesystem solution
- Evaluation based on use case, security, performance, and compatibility
- Encrypting Update Images
- Securely update Linux platform using Mender
| Exercise : | Create a read-only file system using SquashFS | |
- Introduction to OP-TEE
- Key Features
- Hardware, software, and firmware requirements
- Architecture of OP-TEE
- Components, modules, and communication channels
- Use Cases
- Secure storage
- Secure communication
- Secure execution of applications
- OP-TEE build and deployment
- Setting up the environment
- Configuration of OP-TEE
- Compilation of OP-TEE
- Comparison to other TEE solutions
- Trusted Applications (TA) on OP-TEE
- The role of a TA in a secure system
- Writing a Trusted Application
- Loading and executing a Trusted Application within the OP-TEE runtime
- Debugging and testing Trusted Applications
- Communication between Trusted Applications and normal world applications
- Best practices for creating secure Trusted Applications
| Exercise : | Build and install OP-TEE | |
| Exercise : | Write a TA application that communicates with a normal world application | |
Plus d'information
Pour vous enregistrer ou pour toute information supplémentaire, contactez nous par email à l'adresse info@ac6-formation.com.
Les inscriptions aux sessions de formation sont acceptées jusqu'à une semaine avant le début de la formation. Pour une inscription plus tardive nous consulter
Vous pouvez aussi remplir et nous envoyer le bulletin d'inscription
Ce cours peut être dispensé dans notre centre de formation près de Paris ou dans vos locaux, en France ou dans le monde entier.
Les sessions inter-entreprises programmées sont ouvertes dès deux inscrits. Sous condition d'un dossier complet, les inscriptions sont acceptées jusqu'à une semaine avant le début de la formation.
Dernière mise à jour du plan de cours : 20 mai 2026
L'inscription à nos formations est soumise à nos Conditions Générales de Vente