# 配置安全服务

Qualcomm Linux Security 提供广泛的安全配置，旨在增强设备安全性，确保软件的真实性和完整性，并为开发者和用户保护关键和敏感信息。

本节将指导您完成以下配置工作流程。

![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [启用安全启动](https://docs.qualcomm.com/doc/80-70022-11SC/topic/enable-secure-boot.html#enable-secure-boot)

![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [启用 UEFI 安全启动](https://docs.qualcomm.com/doc/80-70022-11SC/topic/enable-uefi-secure-boot.html#enable-uefi-secure-boot)

![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [从 Qualcomm TEE 启用设备配置](https://docs.qualcomm.com/doc/80-70022-11SC/topic/enable-device-devcfg-from-qtee.html#enable-device-devcfg-from-qtee)

![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [启用 SELinux](https://docs.qualcomm.com/doc/80-70022-11SC/topic/enable-selinux.html#enable-selinux)

![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [安装或升级 SoftSKU 功能包](https://docs.qualcomm.com/doc/80-70022-11SC/topic/upgrade-qualcomm-wes-feature-pack.html#upgrade-qualcomm-wes-feature-pack)

## 后续步骤

- 要调整 Qualcomm TEE 配置，请参阅[从 Qualcomm TEE 启用设备配置 (Devcfg)](https://docs.qualcomm.com/doc/80-70022-11SC/topic/enable-device-devcfg-from-qtee.html#enable-device-devcfg-from-qtee)。
- 要启用安全启动并确保只有受信任的应用程序在设备上运行，请参阅[启用安全启动](https://docs.qualcomm.com/doc/80-70022-11SC/topic/enable-secure-boot.html#enable-secure-boot)。
- 要执行严格的访问控制，请参阅[启用 SELinux](https://docs.qualcomm.com/doc/80-70022-11SC/topic/enable-selinux.html#enable-selinux)。
- 要确保在启动过程中只加载经过验证和受信任的应用程序，请参阅[启用 UEFI 安全启动](https://docs.qualcomm.com/doc/80-70022-11SC/topic/enable-uefi-secure-boot.html#enable-uefi-secure-boot)。
- 要安装或升级 QCS5430 SoftSKU 功能包，请参阅[安装或升级 SoftSKU 功能包](https://docs.qualcomm.com/doc/80-70022-11SC/topic/upgrade-qualcomm-wes-feature-pack.html#upgrade-qualcomm-wes-feature-pack)。

Last Published: Apr 14, 2026

[Previous Topic
验证 Qualcomm Linux 的安全配置](https://docs.qualcomm.com/bundle/publicresource/80-70022-11SC/topics/bring-up.md) [Next Topic
从 Qualcomm TEE 启用设备配置 (Devcfg)](https://docs.qualcomm.com/bundle/publicresource/80-70022-11SC/topics/enable-device-devcfg-from-qtee.md)