Chain of Trust
EZ BSP establishes an chain of trust from the hardware root of trust from the processor hardware root of trust through bootloader, kernel, and application layers — ensuring only your software can run on your device.
EZ BSP establishes an chain of trust from the hardware root of trust from the processor hardware root of trust through bootloader, kernel, and application layers — ensuring only your software can run on your device.
A hardware root of trust architecture in our long-term support EZ BSPs. Built so only your software runs on your devices. Each layer verifies the next before handing over execution.
From eval-kit prototype to signed production images — and the maintenance loop that keeps the fleet current.
Early evaluation on unsecured eval-kit hardware; design your carrier hardware.
Carrier hardware and initial software running on unsecured SOM modules.

Enable the secure device framework using dummy secrets on your prototype hardware.

Stand up the secure signing service and generate your production secrets.
Steps 5–8 repeat whenever a new software image is needed.
Generate your production image, ready for signing.

Sign the production image using your secure signing service.

Ezurio or your manufacturing partner programs the secure image onto SOMs at the factory.
Upload your signed image to your device-management service for OTA deployment.
Assess security advisories and bug fixes that require a new software image.
From steps 4 and 6 above
You don’t have to design a signing service - EZ BSP helps set up cost effective embedded centric image signing.
AWS KMS
Managed vault · Your private key
From step 7a above
You can ship secure devices in volume — without standing up your own factory provisioning infrastructure.
Get in touch with our sales and engineering team to find the SOM that best meets your needs, powered by our comprehensive EZ BSP.