Raymond Mao

Firmware Developer @Linaro

Ottawa, CA
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Jan 2023 — Present

Firmware Developer @Linaro

View department →

Working on open-source firmware projects (TF-A, OP-TEE, U-Boot) to implement Arm SystemReady required features and drive upstream adoption across the Arm ecosystem.Firmware Handoff• Co-developed the Firmware Handoff specification with Arm ecosystem members, defining a unified parameter-passing model across boot stages.• Implemented end-to-end drivers and libraries across TF-A, OP-TEE, and U-Boot, enabling standardized handoff for device tree, OP-TEE pageable part, SPMC manifest, TPM event log, and device tree overlays.• Impact: Adopted across Arm platforms and incorporated into AMD’s next-generation firmware designs.Cryptography• Integrated MbedTLS v3.6 LTS into U-Boot, replacing legacy crypto modules and enabling EFI loader and Secure Boot features (hash, X509, PKCS7, RSA, MSCode) on top of MbedTLS.• Optimized binary footprint and performance trade-offs for constrained environments; refactored Kconfig to allow selectable crypto backends (MbedTLS or legacy crypto) across SPL / TPL / U-Boot proper.• Contributed upstream patches to MbedTLS for PKCS#9 authenticate attributes, multiple-signer certificate decoding in PKCS#7 messages, and MSCode support.• Result: U-Boot now includes a GPLv2-compliant, fully maintained crypto library with HTTPS capability (via LWIP integration).Measured Boot & TPM• Implemented TPM 2.0 PCR allocation/shutdown logic and U-Boot test console; TCG2 run-time detection and reconfiguration for active PCR banks, plus recovery routine to prevent potential cross-stage (TF-A/U-Boot) hash algorithm mismatches in the measured events.Ecosystem Collaboration & Upstream Stewardship• Serve as U-Boot custodian, maintaining and reviewing upstream patches for crypto, bloblist, TCG/TPM, and EFI loader subsystems.• Collaborate with Arm, AMD, and other Linaro member companies on cross-project feature alignment and integration debugging.• Contribute fixes, feature improvements, and design reviews across TF-A, OP-TEE, and U-Boot.

EDUCATION

1996 — 2000

South China University of Technology

Bachelor, Electronic Information Technology

SKILLS

Rich Experience in Debugging Complex Problems on RtosStrong C ,C++, Objective-C and Linux, Ucos KnowledgeGood Knowledge in Dvb, Mpeg and Middleware, Loader IntegrationRich Experience in Ca, Stb Security, Descrambling, Crypto Algorithms, OpensslDigital TvSet Top BoxDvbDebuggingRtosMpegEmbedded SystemsEmbedded LinuxLinux KernelSocDevice DriversMipsLinuxSemiconductorsArmFirmwareSystem on a Chip (Soc)Real-Time Operating Systems (Rtos)

ABOUT RAYMOND MAO

15+ years of experience in embedded firmware development across Arm ecosystem, semiconductor vendors, and consumer device platforms- Working in Linaro LEDGE team, implementing Arm SystemReady-related specifications (UEFI/TCG/TPM) across TF-A, OP-TEE, and U-Boot, turning architecture-level standards into production-quality firmware- Collaborating with RISE (RISC-V Software Ecosystem) to enable RISC-V core SW infrastructure to OpenSBI- Co-developed the Firmware Handoff specification and led its end-to-end implementation across BL2 (TF-A), BL31 (SPMD), BL32 (OP-TEE), and BL33 (U-Boot), establishing a unified mechanism for runtime parameter handoff across multiple boot stages on arm64 platforms- U-Boot custodian/maintainer for MbedTLS-port, with broader contributions across security and boot infrastructure, including crypto, bloblist, EFI loader, and TCG/TPM subsystems, covering feature development, integration, and upstream code review- Collaborated with engineers from Linaro member companies (Arm, AMD, Qualcomm, Socionext) on cross-company design alignment, upstream review, and resolution of complex cross-stage firmware integration issues- Early member of the Arm China joint venture secure firmware team; core developer of PSA-compliant (Platform Security Architecture) IoT security reference design and lead coordinator for PSA certification- Broadcom core firmware developer for DTV/set-top box platforms; co-author of the DCAS (Downloadable Conditional Access System) specification and lead contributor to both endpoint certification standards and product-level implementations- Strong domain experience across IoT/IoV, DTV, secure firmware, and security certification ecosystems; effective in working with silicon vendors, OEMs, and certification bodies- Multilingual: English, Mandarin, Japanese.EXPERTISEsemiconductor, embedded system, C, SoC, secure firmware, IoT, IoV, Arm, Cortex, TrustZone, PSA, U-Boot, TF-M, TF-A, Trusted Firmware, OP-TEE, TCG, TPM, UEFI, Secure Boot, Measured Boot, Capsule Update, Root-of-Trust, cryptography, cipher algorithm, key derivation, FOTA, Device Management, MbedTLS, OpenSSL, mcuboot, FreeRTOS, Zephyr, GlobalPlatform, Broadcom, set-top box, STB, DVB, Conditional Access, JCAS, DCAS, bootloader, OTA, descrambling, smartcard, PKI, X.509, TLS, DTLS, LwM2M, Coap, MQTT, RTOS, Linux, kernel, Linux Hardening, debugging, GDB, perf, O-profile, GNU toolchain, uCOS, middleware, loader, integration, CI/CD, Git, Repo, Gerrit, GitHub, Bitbucket, Jenkins, JIRA

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.