Measured boot on QEMU
Protected UEFI variables with U-Boot
https://www.linaro.org/blog/securing-a-device-with-trusted-substrate/
Firmware device updates with brick/rollback protection