
The Cryptographic Foundation of Modern PC Booting
To prevent malicious hypervisors and kernel rootkits from loading before the operating system, UEFI Secure Boot enforces a strict cryptographic hierarchy from the moment your computer power button is pressed. Anti-cheats like Riot Vanguard require Secure Boot on Windows 11 to guarantee OS kernel integrity.
The 4 Cryptographic Databases in UEFI BIOS
| Key / Database | Full Name | Cryptographic Role |
|---|---|---|
| PK | Platform Key | Establishes root ownership between motherboard OEM and firmware |
| KEK | Key Exchange Key | Authorizes updates to the signature databases (Microsoft / OEM) |
| db | Signature Database | Whitelist of trusted EFI bootloaders and kernel driver hashes |
| dbx | Forbidden Signature DB | Blacklist of revoked bootloaders vulnerable to bootkits |
Why Custom Key Enrollment Triggers Vanguard Errors
Some custom BIOS spoofers enroll self-signed certificates into the db database to boot unsigned cheat drivers. Vanguard kernel attestation detects non-standard OEM root certs and blocks game launch with VAN 9003 error codes. Learn how to restore standard keys in our guide on fixing Vanguard VAN 9003 Secure Boot errors.
Audit your system network security and check your outward IP telemetry on our free online IP scanner.