Secure Bootloader for iMX RT-1170 Based Medical Device with TLS 1.3 and IDPS

CASE STUDY SNAPSHOT

Customer :  A medical device technology company developing connected patient monitoring equipment
Size :  51–200
Project vertical :  Medical Devices, Embedded Security
Challenge :  Develop a production secure bootloader for an NXP iMX RT-1170 based connected medical monitoring device, implementing dual bootloader architecture, cryptographic firmware validation, TLS 1.3 secured HTTPS firmware update, network intrusion detection, and tamper-evident log storage to meet medical device cybersecurity requirements
Solution :  Production dual-stage secure bootloader on NXP iMX RT-1170 with FreeRTOS, WolfSSL TLS 1.3 stack, WolfCrypt RSA/SHA256 firmware validation, WolfSentry IDPS network firewall, LittleFS secure log storage, and HTTPS-based secure firmware update over network
Services & Products Availed :  Embedded Firmware Development, Embedded Security, Secure Boot Development, Medical Device Software
Tools and Technologies:
  • Target MCU:  NXP iMX RT-1170 (ARM Cortex-M7 + Cortex-M4)
  • OS:  FreeRTOS
  • Security Stack:  WolfSSL (TLS 1.3), WolfCrypt (RSA, SHA256), WolfSentry IDPS
  • Filesystem:  LittleFS (LFS)
  • Update:  HTTPS over TLS 1.3
  • Interfaces:  SPI, USB, GPIO
  • Languages:  C
  • Tools:  MCUXpresso IDE

Introduction

Connected medical devices, patient monitoring equipment, diagnostic instruments, and therapeutic devices that communicate with hospital networks and cloud backends, present a unique cybersecurity challenge. These devices must be reliably protected against firmware tampering, unauthorised access, and network-based attacks, while operating within the real-time and resource constraints of embedded microcontroller platforms. Regulatory bodies including the FDA increasingly require medical device manufacturers to demonstrate systematic cybersecurity controls, including secure boot, encrypted communications, and intrusion detection, as part of the market authorisation process.

A medical device technology company developing a connected patient monitoring device on the NXP iMX RT-1170 crossover MCU approached Embien to develop a production secure bootloader for their platform. The iMX RT-1170, combining a 1GHz Cortex-M7 with a 400MHz Cortex-M4, provided the processing capability required for a security-rich bootloader implementation, but exploiting this effectively within the real-time constraints of a medical device required careful architecture across the dual-bootloader design, cryptographic validation pipeline, network security stack, and filesystem management.

Challenge

The dual bootloader requirement, with a primary bootloader and a secondary bootloader each serving distinct roles in the secure boot chain, introduced architectural complexity. The boundary of responsibility between the two bootloaders had to be clearly defined, with the handoff between them executed securely and reliably. The primary bootloader's role in establishing the initial root of trust had to be kept minimal and immutable, any vulnerability in the primary bootloader would compromise the entire security chain. The secondary bootloader carried the richer functionality, firmware validation, network connectivity, HTTPS update, and IDPS, but had to itself be validated by the primary bootloader before execution.

Integrating a full TLS 1.3 stack and an IDPS firewall within a FreeRTOS embedded environment on the iMX RT-1170 required careful management of the memory and task scheduling resources available to the bootloader. The WolfSSL and WolfSentry stacks both have configurable footprints, but finding the right configuration that provided the required security functionality within the MCU's RAM and flash budget, while leaving adequate headroom for the medical device application, required systematic profiling and optimisation.

The HTTPS firmware update mechanism, downloading firmware from a remote server over TLS 1.3, validating it cryptographically, and programming it to flash, had to be robust against all failure modes encountered in a clinical network environment: intermittent connectivity, server timeouts, partial downloads, and power loss during programming. A failed update that left the device unable to boot would be a serious patient safety concern in a medical device context.

LittleFS filesystem management for secure log storage required careful integration with the iMX RT-1170's external flash interface, with the filesystem configuration optimised for the wear levelling and power-loss resilience characteristics essential for reliable log retention on flash media in a medical device that may experience sudden power interruption.

Solution

secure bootloader iMX RT-1170

Dual Bootloader Architecture

The secure boot chain is implemented as a two-stage bootloader architecture on the NXP iMX RT-1170. The primary bootloader occupies a small, immutable protected region of the internal flash. Its sole responsibility is to validate the cryptographic signature of the secondary bootloader image before transferring execution, keeping the primary bootloader's attack surface minimal and its logic simple enough to be thoroughly reviewed and trusted. The primary bootloader's code and the embedded root public key are protected against modification through the iMX RT-1170's flash access control mechanisms.

The secondary bootloader runs under FreeRTOS and carries the full security functionality of the boot chain, performing its own validation of the application firmware image, managing the HTTPS firmware update process, enforcing network security through WolfSentry, maintaining the secure log, and handling the controlled handoff to the medical device application on successful validation. Running the secondary bootloader under FreeRTOS enables proper task scheduling and timeout management for the network-dependent update and validation functions, capabilities that would be impractical in a bare-metal secondary bootloader.

WolfCrypt Firmware Validation

Firmware integrity and authenticity are enforced through WolfCrypt's RSA and SHA256 implementations. Firmware images, both the secondary bootloader and the medical device application, are signed using RSA asymmetric cryptography during the manufacturing signing process. The SHA256 hash of each firmware image is computed and verified against the RSA-decrypted signature using the embedded public key before the image is accepted for execution or programming. Images that fail validation are rejected, with the rejection event logged to the secure log and the device held in a defined safe state. The WolfCrypt implementation was configured and validated for the iMX RT-1170's Cortex-M7 core, with hardware acceleration leveraged where available to minimise signature verification time within the bootloader's timing budget.

WolfSSL TLS 1.3 Stack

All network communication from the bootloader, both the HTTPS firmware update channel and any server-side reporting, is secured using the WolfSSL TLS 1.3 stack. TLS 1.3 was specifically chosen for its improved security properties over earlier TLS versions, eliminating legacy cipher suites, requiring forward secrecy for all sessions, and reducing the handshake round trips that introduce latency in embedded network contexts. The WolfSSL stack was configured for the iMX RT-1170's memory constraints, with unnecessary cipher suites and protocol versions disabled to minimise the flash and RAM footprint without compromising the security strength of the TLS implementation. Server certificate validation is enforced, ensuring that the bootloader will only communicate with servers presenting certificates from the authorised certificate authority, preventing man-in-the-middle attacks on the firmware update channel.

WolfSentry IDPS Network Firewall

WolfSentry, an embedded intrusion detection and prevention system, was integrated into the secondary bootloader's network stack as a real-time firewall governing all inbound and outbound network traffic during the bootloader's network-active phase. WolfSentry enforces a strict allowlist policy, permitting only the specific network interactions required for firmware update and status reporting, and blocking all other traffic. Anomalous connection attempts, unexpected traffic patterns, and protocol violations are detected by WolfSentry and blocked before they can interact with the bootloader's network services. Detection events are logged to the secure log with full connection metadata, providing a tamper-evident record of any network-based attack attempts observed during the bootloader phase for regulatory and incident investigation purposes.

HTTPS Firmware Update

Firmware updates are delivered over HTTPS, secured by the WolfSSL TLS 1.3 stack, from the customer's firmware distribution server. The update process is initiated either automatically on boot when a new firmware version is detected, or on command from the server. The secondary bootloader downloads the firmware image in chunks, storing received data progressively to the staging area in external flash managed by the LittleFS filesystem. Download progress is checkpointed, enabling a partially completed download to be resumed after an interruption rather than restarted from the beginning, important for reliable update delivery over clinical network connections that may be intermittent.

Once the complete image is received, WolfCrypt RSA/SHA256 validation is performed on the staged image before it is committed to the application flash partition. An image that fails validation is discarded from the staging area, the existing application firmware remains intact and the device continues to operate on the last validated version. Only after successful validation is the new firmware programmed to the application partition and the device restarted to execute it.

LittleFS Secure Log Storage

Operational and security event logs are stored in a LittleFS filesystem on the iMX RT-1170's external flash. LittleFS was selected for its power-loss resilience, the filesystem's copy-on-write design ensures that a sudden power interruption during a log write cannot corrupt the filesystem structure or previously stored log entries. Log entries cover boot validation outcomes, firmware update events, WolfSentry detection events, and device operational events relevant to the medical device's audit trail requirements. Log integrity is protected through per-entry checksums that detect any post-write modification of stored log content, preserving the trustworthiness of the audit record for regulatory and incident investigation purposes.

Benefits

  • Dual-stage root of trust Immutable primary bootloader validates the secondary bootloader before execution, establishing a hardware-anchored chain of trust that protects the complete boot sequence from tampering on the iMX RT-1170 platform
  • WolfSSL TLS 1.3 secured update HTTPS firmware update channel secured with TLS 1.3 and server certificate validation eliminates man-in-the-middle attack risk on the firmware distribution path, a critical protection for medical device update integrity
  • WolfSentry IDPS firewall Real-time embedded intrusion detection and prevention enforces strict network allowlist policy during bootloader operation, blocking unsanctioned network interactions and logging detection events for regulatory audit purposes
  • Fault-tolerant resumable update Checkpointed download with LittleFS staging and cryptographic pre-commit validation ensures update reliability across intermittent clinical network connections without risk of bricking the medical device on update failure
  • Power-loss resilient audit logging LittleFS-backed tamper-evident secure log retains a complete, integrity-verified audit trail of boot, update, and security events across power interruptions, supporting medical device regulatory submission and incident investigation requirements

Conclusion

This secure bootloader project demonstrates Embien's capability to deliver production-grade embedded security implementations for connected medical devices on the NXP iMX RT-1170 platform. By architecting a dual-stage bootloader with WolfCrypt firmware validation, WolfSSL TLS 1.3 network security, WolfSentry IDPS intrusion prevention, and LittleFS-backed secure logging, all running under FreeRTOS within the iMX RT-1170's resource constraints, Embien provided its medical device customer with a comprehensive, regulatory-aligned security foundation that protects the device against firmware tampering, network attacks, and unauthorised access throughout its operational lifetime. This project reflects Embien's depth at the intersection of embedded real-time systems, cryptographic security implementation, and medical device regulatory requirements, a combination that is increasingly essential as connected medical devices face growing cybersecurity scrutiny from regulators and healthcare institutions alike.

Looking to implement production-grade secure boot and network security for your connected medical device or IoT product?

Partner with Embien for secure bootloader development with TLS 1.3, IDPS integration, and fault-tolerant OTA on NXP iMX RT and other embedded platforms.

For further information on how your personal data is processed, please refer to the Embien Privacy Policy.