This guide outlines the steps to enable Thistle Verified Boot (TVB) on a BeagleY-AI using an Infineon OPTIGA™ Trust M as the hardware root of trust. By the end, your BeagleY-AI will only boot kernels signed by your Thistle Control Center project’s key, verified against the public key stored in the Trust M.
You’ve successfully enabled Thistle Verified Boot on a BeagleY-AI with the Trust M secure element. Your device will now only boot kernels signed with your project’s private key, enhancing the security of your deployment.