LinuxLink Login   |   1.866.392.4897 |    |  Contact Us          

TRST Secure by Design: Timesys Security Services

Commercial or open source, no code is threat-proof. By addressing device security early in the design of your open source embedded Linux-based product, you can minimize threats throughout its lifecycle and reduce the overall time and cost associated with managing vulnerabilities.

To help you secure by design, Timesys offers Security Services in a variety of areas.

secure boot and chain of trust

Secure Boot / Chain of Trust

Ensure your device is not running tampered software by verifying its authenticity before execution. Establish software authenticity all the way from the bootloader to user applications. Our secure boot services help implement:

  • Verified bootloader (NXP i.MX / QorIQ, Qualcomm Snapdragon, TI Sitara, Atmel SAMA5, Xilinx Zynq and more)
  • Kernel verification (FIT image, SoC specific mechanisms)
  • Root filesystem verification (dm-verity, IMA/EVM, FIT image)

embedded Linux software authentication

Device Encryption and Secure Key Storage

You can protect IP and sensitive user information by encrypting data/software. It is also critical to protect the key used for encryption using a secure storage mechanism. Additionally, software that handles confidential data should run from within a hardware/software-isolated environment.

We provide solutions and services that span:

  • Anti-cloning (IP and Data Protection)
  • Key Management and secure key storage
  • Data protection using encryption — In use, in motion, and at rest
  • Trusted Platform Module (TPM)
  • Trusted Execution Environment (TEE) using Arm TrustZone and OP-TEE
  • Device identity and authentication

security vulnerability patching

OTA Software Updates

We can help you determine how to update/deploy software securely and deny unauthorized software installs. Leverage our expertise to help you with:

  • Over-the-air (OTA) updates of the software on your embedded system
  • Package updates
  • Full OS updates
  • Signing of packages and images
  • Server authentication

timesys security audit

Security Audit

By performing a risk analysis, our audit services can help you determine what potential threats your system might encounter and what should be secured. Timesys’ security audits:

  • Provide a detailed review of packages and default system configuration
  • Run & analyze reports from audit and scanning tools
  • Provide you with an end-to end-review of system security
  • Provide you with a risk management and recovery plan

embedded device system hardening


You need to choose system security configurations wisely to reduce the attack surface. Typically, development focus is on the application with little consideration for system security. Our hardening service focuses on:

  • Access & authorization
  • Vulnerability
  • Logging of all user access
  • Logging of access level changes by any program
  • Disable unused services and ports
  • Security-oriented configurations for packages and kernel

Need help with designing security into your open source embedded device?

We’d be happy to talk to you about how we can help you address the unique security needs of your embedded software and implement security during the product design phase. To get started, schedule your no-obligation 30-minute security consultation now. Simply fill out our online form, email us at or call us at 1.866.392.4897 (toll-free) or +1.412.232.3250.

Schedule Consultation


Eighty percent of all external attacks take advantage of known vulnerabilities in unpatched software and misconfigured systems.*

*The National Institute of Standards and Technology (NIST)
National Vulnerability Database /

After you secure by design, be sure to stay secure.

Continuously monitoring for CVEs and updating your customized software is key to minimizing security threats throughout its lifecycle. Timesys TRST Device Security Solutions includes our Security Vulnerability and Patch Notification — to help you maintain your device’s security posture.

Learn How

Related Resources

documentation icon

Timesys Datasheet

Timesys TRST Security Services

Timesys University Webinar Series | Sponsored by:

Reduce Risk with RISC:
Designing and Maintaining Secure Embedded Linux Devices with Advantech RISC Platforms

View Details

Timesys Security Video

Secure Boot on i.MX 6Quad Powered Advantech DMS-BA16 Qseven Module

Timesys Security Video

Secure Firmware Update Using SWUpdate

Timesys Security Blog

Secure boot on Snapdragon 410

Additional Security Resources

documentation icon

Timesys CVE Notification

View a Sample Timesys CVE Report

try meta-timesys security notification for Yocto

meta-timesys Yocto Layer

Try Timesys Security ‘Pull’ Notification for Yocto

Timesys Security Video

Timesys Security Vulnerability and
Patch Notification Service for Yocto

Timesys Security Video

Timesys Security Vulnerability and
Patch Notification Service for Factory

Timesys Security Video

Timesys Patch Notification Service