I’m trying to work out whether the Jetson Nano supports encryption of the boot loader (U-Boot), and if so how one would go about it. The Jetson Nano Fuse Specification Application Note hints at the possibility with the SBK + DK, but then also goes on to state that this is obsolete and not used any more. With using PKC it only appears possible to verify the boot loader, not encrypt it.
The reason for my asking is that we’d like to be able to encrypt the root filesystem in order to prevent read-out of proprietary code. This obviously necessitates having a decryption key which must also be protected, and could be provided by the boot loader as long as the loader itself is encrypted.
Thankful for any insight that can be provided.