Very little thought has been given to this so far. I suppose it would
not be too difficult to decrypt pages as they are being written. Do you
have a specific application in mind? Also, xboot does support an API
mode so a user application can update itself online or when the
interface to obtain a new firmware image is more complicated than can
fit in a 4k boot section. Using the API, xboot can be used to install a
firmware image downloaded over the internet or read off of a filesystem
on a flash drive of some sort.
Alex Forencich