DefenderBox is a compact, security-hardened mini PC built for edge and field deployments where data protection and tamper resistance are non-negotiable. It combines commodity AMD Ryzen hardware with a fully measured, TPM-backed secure boot chain and full-disk encryption, delivered as a locked-down customer device rather than a general-purpose desktop.
- Verified boot from UEFI Firmware through shim, systemd-boot/GRUB, a signed Unified Kernel Image (UKI), the Linux kernel, and initramfs — each stage measured before System Start.
- TPM 2.0 PCR measurements gate a TPM policy that authorizes unsealing the LUKS key, which unlocks the encrypted root filesystem before Mount Root FS — data at rest stays encrypted end to end.
- EFI System Partition, a read-only Boot/UKI partition, active/inactive A and B root filesystem partitions for atomic updates, a Data partition, and a dedicated Recovery Partition.
- A resident Device Agent (Provisioning, Update, TPM, Key, Health, Attestation, Policy, Rollback, and Remote Recovery managers) that maintains device integrity in the field.
- The Customer Device communicates with backend services over mutual TLS (mTLS), authenticating both endpoints for every session.
LINDUXTRY’S ROLE
- Rebranded and packaged the base hardware platform as the finished DefenderBox product for the client.
- Designed and implemented the secure boot chain and TPM 2.0 + LUKS2 full-disk encryption flow shown above.
- Defined the A/B partition layout and recovery scheme for safe, atomic field updates.
- Built the on-device Device Agent suite (provisioning, update, TPM, key, health, attestation, policy, rollback, remote recovery).
- Set up mTLS-based device-to-backend communication for authenticated, encrypted connectivity.
- Produced the product photography, feature images, and this portfolio datasheet.