Back to / Embedded Systems

AUTOSAR Bootloader

KopherBoot

Released Version 0.1.0

Build a production ECU boot and update architecture with KopherBit's AUTOSAR BSW stack and APP Boot, including PBL, an updatable SBL, HSM / SHE integration, secure boot, and secure programming.

Actual KITE Reflasher product screen
Actual KITE Reflasher UDS Sequencer product screen with Diagnostic Session Control, Security Access, File Download, CRC verification, and ECU Reset steps

Overview

A complete boot chain across KopherBit BSW, APP Boot, PBL, and SBL

KopherBoot uses KopherBit's own AUTOSAR BSW stack for DCM, PduR, CanTp, and security services, while APP Boot connects application-side update entry, state handover, and boot coordination. PBL acts as the stable first-stage boot and root of trust that can authenticate and update the SBL; the SBL performs flash operations, image verification, and application launch. Project-specific security algorithms can connect to the MCU's HSM or SHE for secure boot and secure programming. KITE Reflasher turns OEM-specific update steps into a repeatable, traceable engineering and production workflow.

KopherBoot production boot and secure-update architecture

KopherBoot
KopherBoot architecture with APP Boot, KopherBit AUTOSAR BSW, PBL, an updatable SBL, flash driver, HSM or SHE, and KITE Reflasher

KopherBit AUTOSAR BSW

KopherBit supplies DCM, PduR, CanTp, and security services so one team owns the bootloader communication and platform baseline.

APP Boot integration

Coordinate application-side update entry, state handover, image validity, and the transition to the bootloader.

PBL / updatable SBL

Use a stable PBL to authenticate and update the SBL, combining a trusted foundation with maintainable functionality.

Secure boot and programming

Connect project security algorithms to HSM / SHE to protect the boot chain, keys, and firmware download.

Actual Product Interface

These are current KITE Reflasher product screens showing CAN / ISO-TP setup and the configurable UDS flashing workflow.

Actual KITE Reflasher CAN Hardware screen with device, baud rate, ISO-TP addressing, and target-chip settings

Actual CAN and ISO-TP project setup

This is the current KITE Reflasher Hardware workspace: select the CAN device and baud rate, configure functional and physical request / response IDs, then set up the flashing environment for the target chip and project.

Actual KITE Reflasher UDS Sequencer screen showing Diagnostic Session Control, Security Access, File Download, CRC verification, and ECU Reset

Actual configurable UDS flashing sequence

The screen shows the editable steps and parameters directly: Programming Session, DTC / Communication Control, Security Access, firmware download, CRC verification, and ECU Reset can be saved as an OEM- or ECU-variant-specific project flow.

Product Highlights

KopherBoot runs on KopherBit's own AUTOSAR BSW stack, allowing diagnostic communication, security services, and boot logic to be configured and verified together.

The stable PBL establishes the root of trust and authenticates SBL updates; the SBL handles flash drivers, firmware verification, and application launch.

Security algorithms can use HSM / SHE key storage and acceleration, while KITE Reflasher validates secure boot, secure programming, and recovery behavior.

Core Capabilities

KopherBit AUTOSAR BSW

Use KopherBit DCM, PduR, CanTp, and security services as the complete UDS communication baseline, configured for the MCU, flash, and OEM specification.

APP Boot program

Manage application-side update conditions, state flags, image validity, restart, and handover to the bootloader.

PBL and updatable SBL

The PBL provides stable startup plus SBL authentication and update; the SBL runs flash drivers, memory operations, and application launch.

Security algorithms and HSM / SHE

Integrate project-specific hash, MAC, signature, and key checks while using the MCU's HSM / SHE for protected keys and critical operations.

Secure boot and secure programming

Build a verification chain from the hardware root through PBL and SBL to the application, blocking unauthorized or modified software.

Custom KITE Reflasher workflow

Configure session, security, erase, download, transfer, verify, reset, retry, and trace for engineering and production programming.

From MCU and security requirements to a production update workflow

Create one boot and update specification across KopherBit AUTOSAR BSW, APP Boot, PBL / SBL, and the MCU security module, then validate and lock it with KITE Reflasher.

1

Confirm platform and security requirements

Identify the MCU, flash, HSM / SHE, memory map, OEM diagnostic specification, keys, and algorithm policy.

2

Integrate BSW and APP Boot

Configure KopherBit DCM / PduR / CanTp and security services, then define application update entry, state handover, and boot conditions.

3

Configure PBL / SBL

Establish the PBL root of trust, SBL authentication and update, flash drivers, recovery behavior, and optional A/B-bank strategy.

4

Validate and release with Reflasher

Verify SBL updates, secure boot, secure programming, interruption recovery, and traces, then lock the engineering or production workflow.

Where It Fits

For AUTOSAR ECU programs that need a complete bootloader baseline, a maintainable SBL, a secure boot chain, and a validated programming workflow.

New ECU bootloader

Build an OEM-compliant production baseline with KopherBit AUTOSAR BSW, APP Boot, PBL / SBL, and the required diagnostic and memory specification.

Secure SBL maintenance

Let the stable PBL authenticate and update the SBL so communication, flash, or security functionality can evolve through a controlled process.

Secure-update / OTA foundation

Integrate HSM / SHE, trust chain, signature verification, A/B banks, and failure recovery as the secure-update baseline.

Supported Formats & Standards

KopherBit AUTOSAR BSW DCM / PduR / CanTp APP Boot PBL / Updatable SBL Flash Driver HSM / SHE Secure Boot Secure Programming ISO 14229 UDS KITE Reflasher