Flash encryption
This measure encrypts the contents of the Device’s external flash memory.
Benefit: Encrypted contents on the flash memory cannot be physically read out.
Procedure
- Once this feature is enabled, firmware is flashed as plaintext
- Data is encrypted in place on the first boot.
More Details
With flash encryption enabled, the following types of data are encrypted by default:
- Firmware bootloader
- Partition Table
- All “app” type partitions
- Other types of data can be encrypted conditionally:
- Any partition marked with the encrypted flag in the partition table.
- Secure Boot bootloader digest if Secure Boot is enabled.
For proof of implementation, contact us