Intel® Boot Guard
Hardware-based boot integrity protection that prevents unauthorized software and malware takeover of boot blocks critical to a system’s function, thus providing added level of platform security based on hardware. Configurable boot types include:
Measured Boot—Measures the initial boot block into the platform storage device such as trusted platform module (TPM) or Intel® Platform Trust Technology (PTT).
Verified Boot—Cryptographically verifies the platform initial boot block using the boot policy key.