This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

Trusted boot tool (TBT)

Information Security

TBT is a software or software-hardware system that prevents unauthorized access and the execution of malicious code at the stage of operating system loading.

What is a trusted boot tool

Trusted boot tool (TBT) is a software or software-hardware system aimed at preventing unauthorized access and the execution of malicious code (bootkits) at the stage of operating system loading. TBT provides user authentication, integrity checking of boot files and protection from substitution of the operating system loader.

ISP — Information Security Means: NCD, AVS, TLS, MCS Key security means: NCD (protection against unauthorized access, access control), AVS (antivirus protection, FSTEC certification), TLS (trusted loading tool), MCS (removable media control, USB encryption). Requirements for GIS and PDPIS under 152-FZ and 187-FZ. Information security means NCD, AVS, TLS, AVT — system security measures NCD Unauthorized access UNA protection Access control AVS Antivirus protection tool Antivirus + antispam FSTEC certification TLS Trusted loading tool OS loading control Hardware verification AVT Media control tool USB, CD/DVD, SD Media encryption Requirements for info-security means in GIS and PDPIS FSTEC Level-4 NDV FSB CIPF (GOST) Registry Of domestic software Laws 152-FZ / 187-FZ Security means are a mandatory element of information system attestation
Trusted boot tool (TBT) — term diagram

TBTs are critically important for protecting critical information infrastructure (CII) facilities and government information systems, where guaranteed protection from attacks at the earliest stages of system startup is required. Attacks at the boot stage are especially dangerous, since they occur before the launch of antiviruses and other protection tools, which makes the system completely vulnerable.

TBT is also a mandatory requirement for systems processing state secrets and personal data, according to the orders of FSTEC of Russia. Without TBT, it is impossible to obtain a conformity certificate for such systems.

How TBT works

A trusted boot tool performs the following functions:

  1. User authentication — requesting a password, token or biometric data before the OS loads.
  2. Integrity checking — control of system files, the registry and boot sectors.
  3. Protection from bootkits — preventing the launch of malicious code before the OS starts.
  4. Event registration — logging of access attempts and violations for SIEM systems.

TBT integrates with access control systems (ACS) and identification tools, providing comprehensive protection at all stages of the information system's operation.

The operating principle of TBT is based on creating a "root of trust" — a hardware-software module that guarantees that all subsequent system components are loaded in a trusted order. TBT checks the digital signatures of boot files, compares their checksums with reference values, and only after that transfers control to the operating system. If at least one file has been changed, loading is blocked and the system notifies the administrator.

Main types of TBT

Trusted boot tools are classified by architecture:

  • Software-hardware modules — independent physical devices (expansion cards, USB tokens, TPM modules) operating before the OS loads.
  • Software tools — integrated into BIOS/UEFI (for example, Secure Boot) or the boot record of the disk.
  • Hardware trusted boot modules (HTBM) — specialized devices providing step-by-step integrity control of technical and software tools.

Certified solutions are popular in Russia: Dallas Lock, Sobol, ViPNet SafeBoot, Accord-HTBAM. The choice of TBT is discussed at the stage of security system design.

Hardware trusted boot modules are considered the most reliable, since they are physically separated from the main system and cannot be compromised by software attacks.

TBT and regulatory requirements

The use of TBT is regulated by the orders of FSTEC of Russia and the requirements for the protection of government information systems. For CII facilities, TBT is a mandatory protection element according to the requirements of 187-FZ. Systems using TBT pass special certification that confirms their ability to withstand attacks at the boot stage.

The choice of TBT should be made taking into account the security class of the system and regulatory requirements. For example, for systems processing state secrets, the use of TBTs certified by the FSB of Russia is required. For commercial systems, FSTEC certification is sufficient.

Frequently asked questions

Why is a trusted boot tool needed?

A trusted boot tool (TBT) protects the system from attacks at the early boot stage, when the OS has not yet been launched and antiviruses are not working. This makes it possible to prevent the injection of bootkits and rootkits that can intercept system control before the start of protection.

What Russian TBT solutions are available on the market?

The Russian market offers certified solutions: Dallas Lock, Sobol, ViPNet SafeBoot, Accord-HTBM. Most of them meet the requirements of 187-FZ and can be used at CII facilities.

How is TBT different from Secure Boot?

Secure Boot is a built-in UEFI mechanism that checks the digital signatures of loaders. TBT is a more comprehensive solution that can include hardware tokens, biometric authentication and extended integrity checking mechanisms not available in standard Secure Boot.

Is TBT a hardware or software solution?

TBT can be both software (integrated into UEFI or the boot record) and hardware (physical expansion cards, USB tokens). For CII facilities, hardware modules that provide the maximum level of protection from physical intervention are often used.

How does TBT integrate with other security systems?

TBT integrates with ACS for centralized access management, with CIPF for ensuring the integrity of cryptographic keys and with SIEM for transferring trusted boot event logs.

What is a hardware trusted boot module (HTBM)?

HTBM is a specialized hardware device installed on the motherboard that performs system integrity checking before the BIOS/UEFI starts. HTBM is considered the most reliable type of TBT, since it is physically separated from the main system and cannot be compromised by software attacks.

Is the use of TBT mandatory for commercial organizations?

For commercial organizations, the use of TBT is not mandatory, unless they work with personal data or are CII facilities. However, for banks, insurance companies and other organizations working with confidential information, the use of TBT is recommended as a security best practice.

Was this information helpful?

Protect your network today

Leave a request — our information security specialists will help you select, configure and integrate trusted boot tool (tbt) into your infrastructure. We will protect your data from threats.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm