Chain of Trust
EZ BSP establishes an unbroken chain of trust from the hardware root of trust through bootloader, kernel, and application layers — ensuring only cryptographically authenticated software can execute on your device.
EZ BSP establishes an unbroken chain of trust from the hardware root of trust through bootloader, kernel, and application layers — ensuring only cryptographically authenticated software can execute on your device.
A hardware root of trust architecture in our long-term support EZ BSPs. Built so only your software runs on your devices. Each layer verifies the next before handing over execution.
From eval-kit prototype to signed production images — and the maintenance loop that keeps the fleet current.
Early evaluation on unsecured eval-kit hardware; design your carrier hardware.
Carrier hardware and initial software running on unsecured SOM modules.

Enable the secure device framework using dummy secrets on your prototype hardware.

Stand up the secure signing service and generate your production secrets.
Steps 5–8 repeat whenever a new software image is needed.
Generate your production image, ready for signing.

Sign the production image using your secure signing service.

Ezurio or your manufacturing partner programs the secure image onto SOMs at the factory.
Upload your signed image to your device-management service for OTA deployment.
Assess security advisories and bug fixes that require a new software image.
From steps 4 and 6 above
Private keys never touch a build machine. Every image is signed via AWS KMS — the key stays in the managed vault, and every signature is logged in AWS CloudTrail.
AWS KMS
Managed vault · Your private key
From step 7a above
Your secure boot secrets, tied to your part number and programmed at the factory at production volume. Ezurio handles every step of the provisioning line — so you can ship secure devices without building your own programming infrastructure.
Get in touch with our sales and engineering team to find the SOM that best meets your needs, powered by our comprehensive EZ BSP.