The Raspberry Pi (a low-cost ARM-based system on a board) has attracted the attention of hackers and people experimenting with embedded systems.
Raspberry Pi boards are becoming an increasingly popular part of network-integrated industrial prototyping systems. And now, it's attracting the attention of the software digital rights management (DRM) industry.
At the Hannover Messe industrial technology trade show in Germany today, WIBU Systems introduced a Raspberry Pi “starter kit” based on CodeMeter technology that provides embedded system developers with secure booting capabilities for Pi-based hardware. The package includes a software development kit and the CmStick—a USB “dongle” that can be used to ensure that only software with appropriate certificates can run on the Raspberry Pi. This could potentially prevent an attacker from exploiting embedded code.
However, this is not exactly UEFI for Raspberry Pi. The CmStick contains a SmartCard chip with about 384 kilobytes of memory and can store information for “thousands” of software products, according to WIBU, allowing the system it is connected to to check for a pre-approved set of certificates, as well as perform signature checks. CodeMeter technology is already integrated into the Wind River VxWorks real-time operating system. The SDK in the starter kit aims to allow developers to integrate the CmStick’s license and digital signature checking into the operating system of their choice to prevent the execution of unsigned or malicious code.
This kind of security is great for embedded systems, but it also requires that every piece of software developed be digitally signed, which rules out using Raspberry Pi Linux distributions (or any open source RTOS) without prior work. But many embedded developers who have focused their efforts on the Windows may not have to worry much longer, given that Windows 10 will support the Raspberry Pi 2 and will be digitally signed when it is released.

