Dell Secure Boot and Secure Operation for VDI Environments with PowerEdge R6415, R7415, R7425 Servers Owner's Manual - User Guide
Summary
Dell EMC technical note on Secure Boot and Secure Operation for VDI environments using PowerEdge R6415, R7415, and R7425 servers. Describes how Secure Boot verifies cryptographic signatures of drivers and OS loaders before execution to prevent rootkits/bootkits from executing before the OS loads. Emphasizes that VDI security must extend beyond endpoint protection to include pre-hypervisor BIOS and boot-loader integrity. Authored by Sonja Hickey.
Page 1 Text Content
Direct from Power Edge Product Group Development
Secure Boot and Secure Operation for VDI Environments with Power Edge R6415, R7415, R7425 Servers
Securing VDI environments goes beyond implementing end-point security. Other security-related issues need to be considered, especially risks associated with infrastructure supporting those environments. One such example regards
Tech Note by:
security controls for the virtualized OS, which need to provide the same level of Sonja Hickey security as those used for operating systems running directly on hardware. IT professionals should also determine whether other pre-hypervisor (BIOS, boot loader, etc.) steps and configurations are invoked according to the enterprise’s SUMMARY security standards. Physical security may not be the newest of risk mitigation techniques, but the IT professional’s assessment of the VDI environment should include assurance that all related hardware is appropriately restricted relative to
While there are many aspects of physical access, thereby reducing the chance that CPU boot processes could VDI deployments to consider, be altered. That being said, Secure Boot and Secure Operation are two critical security risks should be security measures that should be considered for implementation in VDI considered and addressed. environments.
Adequately securing a VDI Secure Boot environment goes beyond The main objective of malware writers is to make malicious code start as early implementing just end-point and as possible, enabling it to make modifications to the operating system’s code software-based security and system drivers. Rootkits/bootkits are one of the most advanced tools solutions. available to cybercriminals since it enables malicious code to start before the
operating system loads. ‘Secure Boot’ mitigates these threats by checking the
Implementing Secure Boot and cryptographic signatures for drivers and other code loaded prior to the OS Secure Operation in running and preventing unsigned (untrusted) device drivers from being loaded. infrastructure supporting VDI environments is critical. Secure Operation
As many people know, systems provide encryption solutions for Data at Rest (on a HDD or SSD) and for Data in Motion (on a network), but data running in main system memory is not encrypted, leaving it vulnerable to attacks such as memory scrapes and cold boot attacks. ‘Secure Memory Encryption’ or SME mitigates this challenge by providing a solution that encrypts system memory and protects data at rest.
Implementing Secure Boot and Secure Operation The combination of both hardware- and software-based security measures provide a far superior solution than implementing one or the other. Dell Power Edge R6415, R7415 and R7425 servers, which are based on AMD EPYC processors, complete the second half of the equation by providing provide hardware-based security measures. These measures are implemented through what is called ‘System-on-a-Chip’ or SOC. This feature provides a dedicated 32-bit microcontroller located on the physical die of the chip.
SOC addresses the Secure Boot concern by prohibiting modifications to an operating system’s code and system drivers. It does this by providing a hardware root of trust that is designed to ensure only known and trusted software is loaded and run from the initial boot load through the BIOS load. It does this through 4 steps, as follows (see Figure 1):
© 2018 Dell Inc. or its subsidiaries. All Rights Reserved. Dell, EMC and other trademarks are trademarks of Dell Inc. or its subsidiaries
Page Summary Contents For Dell Secure Boot and Secure Operation for VDI Environments with PowerEdge R6415, R7415, R7425 Servers Owner's Manual - User Guide
Manual Details
| Brand | Dell |
|---|---|
| Pages | 2 |
| File Size | 200.68 KB |
| Published | July 03, 2026 |
Enter the captcha to get the download link:
Frequently Asked Questions
What is 'Secure Boot' designed to prevent?
It mitigates rootkits/bootkits by checking cryptographic signatures for drivers loaded prior to the OS, preventing unsigned devices from loading.
How does SME protect data in a VDI environment?
Secure Memory Encryption (SME) encrypts system memory, protecting 'data at work' from attacks like memory scrapes and cold boot attacks.
Which PowerEdge servers support these security features?
The Dell PowerEdge R6415, R7415, and R7425 servers are based on AMD EPYC processors and provide Secure Boot and Secure Operation capabilities.
What is the function of the 'System-on-a-Chip' (SOC)?
The SOC provides a dedicated 32-bit microcontroller serving as a hardware root of trust to ensure only known and trusted software loads from the initial boot through BIOS load.