Trusted boot tool (TBT)
TBT is a software or software-hardware system that prevents unauthorized access and the execution of malicious code at the stage of operating system loading.
Contents
What is a trusted boot tool
Trusted boot tool (TBT) is a software or software-hardware system aimed at preventing unauthorized access and the execution of malicious code (bootkits) at the stage of operating system loading. TBT provides user authentication, integrity checking of boot files and protection from substitution of the operating system loader.
TBTs are critically important for protecting critical information infrastructure (CII) facilities and government information systems, where guaranteed protection from attacks at the earliest stages of system startup is required. Attacks at the boot stage are especially dangerous, since they occur before the launch of antiviruses and other protection tools, which makes the system completely vulnerable.
TBT is also a mandatory requirement for systems processing state secrets and personal data, according to the orders of FSTEC of Russia. Without TBT, it is impossible to obtain a conformity certificate for such systems.
How TBT works
A trusted boot tool performs the following functions:
- User authentication — requesting a password, token or biometric data before the OS loads.
- Integrity checking — control of system files, the registry and boot sectors.
- Protection from bootkits — preventing the launch of malicious code before the OS starts.
- Event registration — logging of access attempts and violations for SIEM systems.
TBT integrates with access control systems (ACS) and identification tools, providing comprehensive protection at all stages of the information system's operation.
The operating principle of TBT is based on creating a "root of trust" — a hardware-software module that guarantees that all subsequent system components are loaded in a trusted order. TBT checks the digital signatures of boot files, compares their checksums with reference values, and only after that transfers control to the operating system. If at least one file has been changed, loading is blocked and the system notifies the administrator.
Main types of TBT
Trusted boot tools are classified by architecture:
- Software-hardware modules — independent physical devices (expansion cards, USB tokens, TPM modules) operating before the OS loads.
- Software tools — integrated into BIOS/UEFI (for example, Secure Boot) or the boot record of the disk.
- Hardware trusted boot modules (HTBM) — specialized devices providing step-by-step integrity control of technical and software tools.
Certified solutions are popular in Russia: Dallas Lock, Sobol, ViPNet SafeBoot, Accord-HTBAM. The choice of TBT is discussed at the stage of security system design.
Hardware trusted boot modules are considered the most reliable, since they are physically separated from the main system and cannot be compromised by software attacks.
TBT and regulatory requirements
The use of TBT is regulated by the orders of FSTEC of Russia and the requirements for the protection of government information systems. For CII facilities, TBT is a mandatory protection element according to the requirements of 187-FZ. Systems using TBT pass special certification that confirms their ability to withstand attacks at the boot stage.
The choice of TBT should be made taking into account the security class of the system and regulatory requirements. For example, for systems processing state secrets, the use of TBTs certified by the FSB of Russia is required. For commercial systems, FSTEC certification is sufficient.
Frequently asked questions
Why is a trusted boot tool needed?
A trusted boot tool (TBT) protects the system from attacks at the early boot stage, when the OS has not yet been launched and antiviruses are not working. This makes it possible to prevent the injection of bootkits and rootkits that can intercept system control before the start of protection.
What Russian TBT solutions are available on the market?
The Russian market offers certified solutions: Dallas Lock, Sobol, ViPNet SafeBoot, Accord-HTBM. Most of them meet the requirements of 187-FZ and can be used at CII facilities.
How is TBT different from Secure Boot?
Secure Boot is a built-in UEFI mechanism that checks the digital signatures of loaders. TBT is a more comprehensive solution that can include hardware tokens, biometric authentication and extended integrity checking mechanisms not available in standard Secure Boot.
Is TBT a hardware or software solution?
TBT can be both software (integrated into UEFI or the boot record) and hardware (physical expansion cards, USB tokens). For CII facilities, hardware modules that provide the maximum level of protection from physical intervention are often used.
How does TBT integrate with other security systems?
What is a hardware trusted boot module (HTBM)?
HTBM is a specialized hardware device installed on the motherboard that performs system integrity checking before the BIOS/UEFI starts. HTBM is considered the most reliable type of TBT, since it is physically separated from the main system and cannot be compromised by software attacks.
Is the use of TBT mandatory for commercial organizations?
For commercial organizations, the use of TBT is not mandatory, unless they work with personal data or are CII facilities. However, for banks, insurance companies and other organizations working with confidential information, the use of TBT is recommended as a security best practice.
Other terms in «Information Security»
Was this information helpful?
Protect your network today
Leave a request — our information security specialists will help you select, configure and integrate trusted boot tool (tbt) into your infrastructure. We will protect your data from threats.