Securing the Device Below the Kernel, Hardware-Rooted Security for Mobile and Payment Fleets

Kernel exploits, zero-click spyware, and AI-accelerated vulnerability discovery are outpacing software-only defences on smartphones and Android payment terminals. This whitepaper makes the case for containment by design, built on five hardware-rooted controls engineered at manufacture: locked bootloaders, verified boot, TEE trustlets, attestation, and signed OTA updates. It also shows how these controls support compliance with the EU Cyber Resilience Act, PCI standards, sovereignty requirements, and post-quantum deadlines.

By Shreyas Sarangan
Senior Principal Staff Engineer, Borqs (a Sasken company).
Securing the Device Below the Kernel, Hardware-Rooted Security for Mobile and Payment Fleets