The invention relates to the technical field of
system security, and discloses a
firmware package generation method, a secure starting method, a
verification method, a device and a medium, the starting method is suitable for a vehicle-mounted SoC
system without OTP / eFuse and with a BootROM unmodifiable, and complementary building of a trusted root is achieved in a
software mode. In response to the starting instruction, the BootROM loads a security bootstrap program; during first deployment, a secure
storage area is created in a nonvolatile memory, and an initial root public key and an abstract thereof are written in to complete initialization of a trust chain. In the subsequent starting process, after the security bootstrap program verifies the integrity of the root public key, the
mirror image public key, the abstract and the signature of the
mirror image to be started are verified, and it is ensured that the source is legal and the data is complete. On-line updating of a root public key through a chain signature mechanism is supported, that is, a current effective root private key is used for carrying out abstract signature on a new public key, and the new public key can be replaced after the signature
verification of an old public key is passed, so that key rotation and trust anchor migration without hardware modification are realized.