A Survey of Trust Chain in Secure Embedded Systems: From Secure Boot to TEE Applications
Hyunmin Kim · IEEE Access · 2026
The proliferation of connected embedded systems across critical infrastructure, automotive, medical, and industrial domains has made trust chain architecture a fundamental design requirement. A trust chain establishes cryptographically verifiable integrity from an immutable hardware root of trust through boot stages to runtime execution, ensuring only authenticated software operates on the platform. This survey presents a comprehensive analysis of trust chain architectures for secure embedded systems, synthesizing nearly 100 publications spanning 2004–2025. We propose a hierarchical taxonomy across five dimensions: Hardware Root of Trust mechanisms (TPM 2.0, ARM TrustZone, Intel SGX/TDX, AMD SEV-SNP, ARM CCA, RISC-V PMP); Secure Boot Chain implementations (verified, measured, and authenticated boot); Trusted Execution Environment architectures (OP-TEE, commercial TEEs, confidential computing, RISC-V solutions); TEE applications (secure storage, cryptographic services, confidential AI, biometrics, payments); and Remote Attestation protocols (TPM-based, lightweight IoT, zero-knowledge, post-quantum variants). Through comparative evaluation of 45+ implementations across 15 platforms, we assess solutions based on security guarantees, performance overhead, memory footprint, and certification status. Published benchmarks indicate TEE context switching overhead ranges from approximately $0.4~\mu $ s (seL4 IPC) to $85~\mu $ s (full TA invocation), secure boot adds approximately 57 ms–600 ms to boot time depending on platform, and trust chain components require 32–512 KB additional flash memory. We provide critical analysis of 2024–2025 vulnerabilities affecting UEFI Secure Boot (CVE-2024-7344, CVE-2025-3052), AMD SEV-SNP (RMPocalypse), and Intel TDX, demonstrating ongoing security challenges in production systems. We identify critical research gaps: absence of end-to-end formal verification; persistent TEE interface vulnerabilities; attestation scalability limitations; insufficient side-channel protections in VM-level confidential computing; and urgent post-quantum migration needs following NIST’s 2024–2025 standardization. Seven priority research directions are proposed, including compositional verification frameworks, side-channel resistant TEE design, scalable swarm attestation, zero-knowledge attestation verification, and quantum-resistant trust establishment with emerging PQC hardware support.