DefenderBox is a compact, security-hardened mini PC built for edge and field deployments where data protection and tamper resistance are non-negotiable. It combines commodity AMD Ryzen hardware with a fully measured, TPM-backed secure boot chain and full-disk encryption, delivered as a locked-down customer device rather than a general-purpose desktop.

  • Verified boot from UEFI Firmware through shim, systemd-boot/GRUB, a signed Unified Kernel Image (UKI), the Linux kernel, and initramfs — each stage measured before System Start.
  • TPM 2.0 PCR measurements gate a TPM policy that authorizes unsealing the LUKS key, which unlocks the encrypted root filesystem before Mount Root FS — data at rest stays encrypted end to end.
  • EFI System Partition, a read-only Boot/UKI partition, active/inactive A and B root filesystem partitions for atomic updates, a Data partition, and a dedicated Recovery Partition.
  • A resident Device Agent (Provisioning, Update, TPM, Key, Health, Attestation, Policy, Rollback, and Remote Recovery managers) that maintains device integrity in the field.
  • The Customer Device communicates with backend services over mutual TLS (mTLS), authenticating both endpoints for every session.

LINDUXTRY’S ROLE

  • Rebranded and packaged the base hardware platform as the finished DefenderBox product for the client.
  • Designed and implemented the secure boot chain and TPM 2.0 + LUKS2 full-disk encryption flow shown above.
  • Defined the A/B partition layout and recovery scheme for safe, atomic field updates.
  • Built the on-device Device Agent suite (provisioning, update, TPM, key, health, attestation, policy, rollback, remote recovery).
  • Set up mTLS-based device-to-backend communication for authenticated, encrypted connectivity.
  • Produced the product photography, feature images, and this portfolio datasheet.