Secure Boot Device and Its Operating Method
By using a combination of memory and processor in the boot device, using a symmetric key and public key algorithm to generate decrypted data and verification values, the problem of slow boot speed caused by the complexity of the encryption algorithm is solved, and the balance of security and speed is achieved.
Patent Information
- Application Number
- CN202080071074.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-10-08
- Filing Date
- 2020-08-31
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2040-08-31
AI Technical Summary
As the complexity of the encryption algorithm increases, the security of the boot device increases, but the boot speed becomes slower, and a method of increasing the boot speed while ensuring security is needed.
Using a combination of memory and processor, decrypted data and verification values are generated through symmetric key algorithms and public key algorithms, and compared during the boot process. Some steps of Montgomery algorithm are used for verification, including generation and comparison of symmetric keys, encryption headers, decryption headers, hash messages and final verification values.
It realizes that the boot speed is improved while ensuring safety. By executing some Montgomery algorithm steps in the preparation operation, the boot process is simplified and the overall efficiency is improved.
Smart Images

Figure CN114514725B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a secure booting device with improved speed and a method of operating the same. Background Art
[0002] As the demand for data security increases, secure booting of a booting device has become mandatory. However, in order to further enhance security, as the complexity of the encryption algorithm increases according to secure booting, the time taken to complete booting gradually increases.
[0003] Therefore, a method is needed to increase the booting speed while the booting device operates according to an encryption algorithm for security. Summary of the Invention
[0004] Technical Problem
[0005] The present invention provides a secure booting device with enhanced security and speed and a method of operating the same.
[0006] Technical Solution
[0007] A secure booting device for solving the problems to be solved by the present invention according to an embodiment includes: a memory configured to store encrypted data, an encrypted header, and a symmetric key; and a processor configured to generate decrypted data and a decrypted header by applying a symmetric key algorithm using the symmetric key to the encrypted data and the encrypted header, the decrypted header including a public key and a pre-key generated from the public key, generate a comparison hash message by applying a hash algorithm to the decrypted data, generate a final verification value by applying a public key algorithm using the public key and the pre-key to the decrypted header, compare the comparison hash message with the final verification value, and determine that booting fails if the comparison hash message and the final verification value are different from each other.
[0008] In this embodiment, the pre-key is a result obtained by calculating P = (C^2) mod n, where P may indicate the pre-key, C may indicate a constant, and n may indicate a part of the public key.
[0009] In this embodiment, the decrypted header may further include a signature, and the processor may generate the final verification value by applying a public key algorithm using the public key and the pre-key to the signature.
[0010] In this embodiment, the decryption header further includes a signature, and the processor applies the public key algorithm by sequentially executing A = (S * P) mod n, B = (A^k) mod n, and R = B mod n, where S may indicate the signature, P may indicate the pre-key, k and n may indicate the public key, and R may indicate the final verification value.
[0011] In this embodiment, the signature is generated by applying a public key algorithm using a private key to a reference hash message generated by applying a hash algorithm to unencrypted data, the reference hash message is generated by applying a hash algorithm to unencrypted data, and the private key may be paired with the public key.
[0012] In this embodiment, the memory may further store a reference hash public key, and the processor may generate a comparison hash public key by applying a hash algorithm to the public key, compare the reference hash public key with the comparison hash public key, and if the reference hash public key and the comparison hash public key are different from each other, may determine that the boot fails.
[0013] In this embodiment, the memory may further store a comparison magic number inherent in the software, the decryption header may further include a reference magic number, and the processor may compare the comparison magic number with the reference magic number, and if the comparison magic number and the reference magic number are different from each other, may determine that the boot fails.
[0014] In this embodiment, the encrypted data and the encryption header are stored in a NAND memory, and the symmetric key may be stored in a one-time programmable (OTP) memory different from the NAND memory.
[0015] An operation method of a security boot device for solving the problems to be solved by the present invention according to an embodiment includes the following steps: generating decrypted data and a decryption header by the processor applying a symmetric key algorithm using a symmetric key stored in a memory to encrypted data and an encryption header stored in the memory; generating a comparison hash message by the processor applying a hash algorithm to the decrypted data; generating a final verification value by the processor applying a public key algorithm using a public key and a pre-key included in the decryption header to the decryption header; and comparing the comparison hash message with the final verification value, and if the comparison hash message and the final verification value are different from each other, determining that the boot fails.
[0016] In this embodiment, the pre-key is a result obtained by calculating P = (C^2) mod n, where P may indicate the pre-key, C may indicate a constant, and n may indicate a part of the public key.
[0017] In this embodiment, the decryption header may further include a signature, and the step of generating the final verification value may include the following steps: generating the final verification value by applying a public key algorithm using the public key and the pre-key to the signature.
[0018] In this embodiment, the decryption header may further include a signature, and the step of generating the final verification value sequentially executes the steps of A = (S * P) mod n, B = (A^k) mod n, and R = B mod n, where S may indicate the signature, P may indicate the pre-key, k and n may indicate the public key, and R may indicate the final verification value.
[0019] In this embodiment, the method may further include the following steps: the processor compares a software-inherent comparison magic number stored in the memory with a reference magic number included in the decryption header, and if the comparison magic number and the reference magic number are different from each other, determines that the boot fails.
[0020] In this embodiment, the method may further include the following steps: the processor generates a comparison hash public key by applying a hash algorithm to the public key, compares a reference hash public key stored in the memory with the comparison hash public key, and if the reference hash public key and the comparison hash public key are different from each other, determines that the boot fails.
[0021] An operating method of a secure boot device for solving the problems to be solved by the present invention according to an embodiment includes a preparation step and a boot step, where the preparation step includes the following steps: the processor generates a symmetric key, a public key, and a private key paired with the public key; the processor generates a reference hash message by applying a hash algorithm to data, and generates a signature by applying a public key algorithm using the private key to the reference hash message; the processor generates a pre-key from the public key by executing at least a part of the public key algorithm; the processor adds the signature, the public key, and the pre-key to the header; the processor generates encrypted data and an encrypted header by applying a symmetric key algorithm using the symmetric key to the data and the header, and stores the encrypted data and the encrypted header in a memory; and the processor generates a reference hash public key by applying a hash algorithm to the public key, and stores the reference hash public key and the symmetric key in the memory.
[0022] In this embodiment, the step of generating the pre-key from the public key may apply P = (C^2) mod n, where P may indicate the pre-key, C may indicate a constant, and n may indicate a part of the public key.
[0023] In this embodiment, the booting step includes the following steps: the processor generates decryption data and a decryption header by applying a symmetric key algorithm using the symmetric key to the encrypted data and the encrypted header; the processor generates a comparison hash message by applying a hash algorithm to the decryption data; the processor generates a final verification value by applying a public key algorithm using the public key included in the decryption header and the pre-key to the decryption header; and the comparison hash message is compared with the final verification value, and if the comparison hash message and the final verification value are different from each other, it is determined that the booting fails.
[0024] In this embodiment, the step of generating the final verification value may be sequentially performing the steps of A = (S * P) mod n, B = (A^k) mod n, and R = B mod n, where S may indicate the signature, P may indicate the pre-key, k and n may indicate the public key, and R may indicate the final verification value.
[0025] In this embodiment, the preparation step and the booting step may be performed as separate steps, respectively.
[0026] In this embodiment, the step of generating the pre-key and the step of generating the final verification value may be performed as separate steps, respectively.
[0027] Technical effects
[0028] According to an embodiment of the present invention, since some steps of the Montgomery algorithm are performed in the preparation operation, the verification is completed by performing the remaining steps of the Montgomery algorithm in the booting operation, thereby providing a secure booting device with enhanced security and speed and its operation method. Description of the drawings
[0029] Figure 1 is a block diagram showing the configuration of a secure booting device according to an embodiment.
[0030] Figure 2 and Figure 3 is a flowchart for explaining a method of preparing operation of a secure booting device according to an embodiment.
[0031] Figure 4 is a diagram for explaining in detail a booting method of a secure booting device according to an embodiment. Detailed description of the invention
[0032] Since the present invention can have various modified embodiments, preferred embodiments are shown in the drawings and described in the detailed description. However, this does not limit the present invention to specific embodiments, and it should be understood that the present invention encompasses all modifications, equivalents, and substitutions within the spirit and technical scope of the present invention. In the description of the present invention, when it is considered that certain detailed explanations of related technologies may unnecessarily obscure the essence of the present invention, their detailed explanations are omitted.
[0033] The terms used herein are only for describing certain embodiments and are not intended to limit the present invention. As used herein, the singular forms are also intended to include the plural forms unless the context clearly indicates otherwise. It will be further understood that when used in this specification, the terms "comprises" and / or "comprising" specify the presence of the stated features, numbers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, numbers, steps, operations, elements, components, and / or groups thereof.
[0034] Embodiments of the present invention can be represented by functional block configurations and various processing steps. Such functional blocks can be implemented by multiple hardware configurations and / or software configurations that perform specific functions. For example, embodiments of the present invention can employ ICs such as memories, processors, logic units, and lookup tables that can perform various functions by controlling more than one microprocessor or by other control systems. Similar to components that can be implemented by software programming or software factors, embodiments of the present invention can be implemented by programming or scripting languages such as C, C++, Java, and assembler, which include various algorithms implemented by combinations of data structures, procedures, routines, or other programming constructs. The functional aspects can be implemented by algorithms executed in more than one processor. In addition, embodiments of the present invention can employ related technologies for electronic environment setting, signal processing, and / or data processing, etc. Terms such as "mechanism", "element", "means", and "formation" can be used widely and are not limited to mechanical and physical configurations. The above terms can include the meaning of a series of routines of software related to a processor, etc.
[0035] Reference will now be made in detail to embodiments of the present invention, which are illustrated in the accompanying drawings.
[0036] Figure 1 is a block diagram showing the configuration of a secure boot device 100 according to an embodiment.
[0037] Refer to Figure 1 , a secure boot device 100 according to an embodiment may include a memory 110, a processor 120, a communication interface 130, and a user interface 140.
[0038] The memory 110 may include a first memory 111, a second memory 113, and a third memory 115. The first memory 111, the second memory 113, and the third memory 115 may be non-volatile memories. The first memory 111, the second memory 113, and the third memory 115 may store different data respectively.
[0039] The first memory 111 stores encrypted data and an encrypted header. The first memory 111 may be a NAND memory.
[0040] The second memory 113 stores a reference hash public key and an Advanced Encryption Standard (AES) key. The second memory 113 may be a One Time Programmable (OTP) memory.
[0041] The third memory 115 stores a software-specific comparison magic number. The software may include, but is not limited to, a boot loader, a kernel, an operating system, an application, etc. The third memory 115 may be a boot read only memory (ROM).
[0042] The processor 120 generates decrypted data and a decrypted header by applying the AES algorithm using the AES key stored in the second memory 113 to the encrypted data and the encrypted header stored in the first memory 111. The decrypted header includes an RSA (Rivest, Schamir, Adelman) public key, a signature, and a pre key. And the processor 120 generates a comparison hash message by applying a secure hash algorithm (SHA) to the decrypted data, generates a final verification value by applying the RSA algorithm using the RSA public key and the pre key to the signature, compares the comparison hash message with the final verification value, and determines that the boot fails if the comparison hash message and the final verification value are different from each other.
[0043] The processor 120 may apply the RSA algorithm for sequentially executing Equation 1 to Equation 3 to the signature. Equation 1 to Equation 3 may be at least a part of a Montgomery algorithm, which is a type of RSA algorithm.
[0044]
Equation 1
[0045] A = (S * P) mod n
[0046] S may indicate the signature, P may indicate the pre key, and n may indicate a part of the RSA public key (k, n).
[0047]
Equation 2
[0048] B = (A^k) mod n
[0049] A may indicate A in the left term of Equation 1. k may indicate a part of the RSA public key (k, n).
[0050]
Equation 3
[0051] R = B mod n
[0052] B may indicate B in the left term of Equation 2. n may indicate a part of the RSA public key (k, n), and R may indicate the final verification value.
[0053] A signature may be generated by applying the RSA algorithm using the RSA private key to a reference hash message, where the reference hash message is generated by applying the SHA algorithm of Equation 4 to unencrypted data.
[0054]
Equation 4
[0055] S = (sha(M)^d) mod n
[0056] M may indicate the reference hash message. The RSA private key (d, n) may be paired with the RSA public key (k, n).
[0057] Meanwhile, the pre - key may be the result obtained by calculating Equation 5.
[0058]
Equation 5
[0059] P = (C^2) mod n
[0060] P may be the pre - key, C may be a constant, and n may be a part of the RSA public key (k, n). C may be, for example, 2^4608, but is not limited thereto. Equation 5 may be at least a part of a type of Montgomery algorithm of the RSA algorithm.
[0061] The processor 120 may apply the SHA algorithm to the RSA public key to generate a comparison hash public key, may compare the reference hash public key stored in the second memory 113 with the comparison hash public key, and may determine a boot failure when the reference hash public key and the comparison hash public key are different from each other.
[0062] The processor 120 may compare the comparison magic number included in the third memory 115 with the reference magic number included in the decrypted header, and may determine a boot failure if the comparison magic number and the reference magic number are different from each other.
[0063] When the comparison hash message is the same as the final verification value, the reference hash public key is the same as the comparison hash public key, and the comparison magic number is the same as the reference magic number, the processor 120 may determine that the boot is successful. For example, when the comparison magic number is the same as the reference magic number, the reference hash public key is the same as the comparison hash public key, and the comparison hash message is the same as the final verification value, the processor 120 may determine that the boot is successful.
[0064] Figure 2 and Figure 3 is a flowchart for explaining a method of preparing the secure boot device 100 according to an embodiment.
[0065] The preparation operation of the secure boot device 100 is performed during the process of the secure boot device 100 and corresponds to the operation of storing data on the boot loader, kernel, operating system, and application in the memory 110. The preparation operation of the secure boot device 100 may be performed by the secure boot device 100 or a different process processor (not shown) from the secure boot device 100, but is not limited thereto.
[0066] Hereinafter, the process of the preparation operation performed by the process processor (not shown) will be described in detail, and this process may be applied to the preparation operation performed by the secure boot device 100 or other devices.
[0067] Referring to Figure 2 , in operation S210, the process processor (not shown) generates an AES key, an RSA public key, and an RSA private key.
[0068] The RSA public key (k, n) and the RSA private key (d, n) may be paired.
[0069] Next, in operation S220, the process processor (not shown) generates a reference hash message by applying the SHA algorithm to the data.
[0070] The data may be an image of a boot loader, kernel, operating system, application, etc., but is not limited thereto.
[0071] Next, in operation S230, the process processor (not shown) generates a signature by applying the RSA algorithm using the RSA private key to the reference hash message.
[0072] In this case, the process processor (not) may use Equation 4 to generate the signature.
[0073] Next, in operation S240, the process processor (not shown) generates a pre-key by applying a part of the RSA algorithm using the RSA public key.
[0074] In this case, the process processor (not shown) may use Equation 5 to generate the pre-key.
[0075] Next, in operation S250, a process processor (not shown) adds a reference magic number, a signature, an RSA public key, and a pre-key to the header of the data.
[0076] Next, in operation S260, the process processor (not shown) generates encrypted data and an encrypted header by applying the AES algorithm using the AES key to the data and the header, and in operation S270, stores the encrypted data and the encrypted header in the first memory 111.
[0077] Refer to Figure 3 , in operation S310, the process processor (not shown) generates a reference hash public key by applying the SHA algorithm to the RSA public key.
[0078] Next, in operation S320, the process processor (not shown) stores the reference hash public key and the AES key in the second memory 113.
[0079] Although not shown in Figure 2 and Figure 3 , other operations that do not affect security can also be performed in the preparation operation of the secure boot device 100 of the present invention in addition to Equation 5. Therefore, a secure boot with enhanced security and speed can be performed because the verification is completed by only performing operations that affect security in the boot operation.
[0080] Figure 4 is a diagram for explaining in detail a boot method of a secure boot device according to an embodiment.
[0081] The boot operation of the secure boot device 100 corresponds to an operation of verifying data on a boot loader, a kernel, an operating system, and an application stored in the memory 110 by referring to the preparation operation of the secure boot device 100 described in Figure 2 and Figure 3 . The boot operation of the secure boot device 100 can be performed by the secure boot device 100, but is not limited thereto.
[0082] Refer to Figure 4 , in operation S410, the processor 120 generates decrypted data and a decrypted header by applying the AES algorithm using the AES key to the encrypted data and the encrypted header stored in the first memory 111.
[0083] Next, in operation S420, the processor 120 compares the software-inherent comparison magic number stored in the third memory 115 with the reference magic number included in the decrypted header.
[0084] Due to this comparison, in operation S490, if the comparison magic number and the reference magic number are different from each other, the processor 120 determines that the boot fails.
[0085] According to an embodiment of the present invention, since the secure boot device 100 is only booted when verifying the software inherent comparison information stored in the third memory 115 using the decryption result of the software inherent information encrypted and stored in the first memory 111 during the process, the boot security can be further enhanced.
[0086] On the other hand, if the comparison magic number and the reference magic number are the same, in operation S430, the processor 120 generates a comparison hash public key by applying the SHA algorithm to the RSA public key included in the decrypted header.
[0087] Next, in operation S440, the processor 120 compares the reference hash public key stored in the second memory 113 with the comparison hash public key.
[0088] Due to this comparison, if the reference hash public key and the comparison hash public key are different from each other, in operation S490, the processor 120 determines that the boot fails.
[0089] According to an embodiment of the present invention, since the secure boot device 100 is only booted when verifying the encrypted key information stored in the second memory 113 during the process using the decryption result of the encrypted key information encrypted and stored in the first memory 111 during the process, the boot security can be further enhanced.
[0090] On the other hand, if the reference hash public key and the comparison hash public key are the same, in operation S450, the processor 120 generates a comparison hash message by applying the SHA algorithm to the decrypted data.
[0091] Next, in operation S460, the processor 120 generates a final verification value by applying the RSA algorithm using the RSA public key and the pre-key included in the decrypted header to the signature included in the decrypted header.
[0092] In this case, the processor 120 may apply the RSA algorithm for sequentially executing Equation 1 to Equation 3 to the signature included in the decrypted header.
[0093] Meanwhile, the Montgomery algorithm is an algorithm for verifying encrypted information by sequentially applying Equation 5, Equation 1, Equation 2, and Equation 3. According to an embodiment of the present invention, since some steps of the Montgomery algorithm applying Equation 5 have been executed in the preparation operation, the verification is only completed by executing the remaining steps of the Montgomery algorithm applying Equation 1 to Equation 3 in the boot operation, so the speed of secure boot can be greatly improved.
[0094] Next, in operation S470, the processor 120 compares the hash message and the final verification value.
[0095] Due to this comparison, if the comparison hash message and the final verification value are different from each other, then in operation S490, the processor 120 determines that the boot fails.
[0096] According to an embodiment of the present invention, since the secure boot device 100 is booted only when the decryption result of the header stored in the first memory 111 after being encrypted in the process is verified using the decryption result of the data encrypted and stored in the first memory 111 in the process, the boot security can be further enhanced.
[0097] On the other hand, if the comparison hash message and the final verification value are the same, then in operation S480, the processor 120 determines that the boot is successful.
[0098] According to an embodiment of the present invention, since the secure boot device 100 is booted only when the verification of various information is completed in various ways, the boot security can be further enhanced.
[0099] The present invention has been described above with reference to the preferred embodiments of the present invention. Those of ordinary skill in the art to which the present invention pertains will understand that the present invention can be implemented in a modified form without departing from the essential features of the present invention.
[0100] It should be understood that the embodiments described herein should be considered only in an illustrative sense and not for the purpose of limitation. The scope of the present invention is indicated in the claims rather than in the above description, and the inventions claimed in the claims and the inventions equivalent to the claimed inventions should be construed as being included in the present invention.
Claims
1. A secure boot device, comprising: A first memory configured to store encrypted data and an encrypted header generated by applying a symmetric key algorithm using a symmetric key, the encrypted header including a public key, a pre - key generated from the public key, and a reference magic number; A second memory configured to store the symmetric key; A third memory configured to store a comparison magic number inherent to the software; And A processor configured to generate decrypted data and a decrypted header by applying the symmetric key algorithm using the symmetric key to the encrypted data and the encrypted header, generate a comparison hash message by applying a hash algorithm to the decrypted data, generate a final verification value by applying a public key algorithm to the decrypted header, and determine whether the boot is successful according to the result of comparing the comparison hash message with the final verification value, wherein the decrypted header includes the public key, the pre - key, and the reference magic number, the public key algorithm uses the public key and the pre - key, the pre - key is a result obtained by calculating P=(C^2) mod n, P indicates the pre - key, C indicates a constant, and n indicates a part of the public key, wherein the processor determines whether the boot is successful according to the result of comparing the comparison magic number with the reference magic number.
2. The secure boot device according to claim 1, wherein, the decrypted header further includes a signature, and the public key algorithm is applied to the signature.
3. The secure boot device according to claim 2, wherein, the public key algorithm is applied by sequentially performing A=(S * P) mod n, B=(A^k) mod n, and R = B mod n, wherein S indicates the signature, P indicates the pre - key, k and n indicate the public key, and R indicates the final verification value.
4. The secure boot device according to claim 2, wherein, the signature is generated by applying a public key algorithm using a private key to a reference hash message, the reference hash message being generated by applying a hash algorithm to unencrypted data, and the private key is paired with the public key.
5. The secure boot device according to claim 1, wherein, the memory further stores a reference hash public key, the processor generates a comparison hash public key by applying a hash algorithm to the public key, and determines whether the boot is successful according to the result of comparing the reference hash public key with the comparison hash public key.
6. An operating method of a secure boot device, including a preparation step and a boot step, wherein, the preparation step includes the following steps: The processor generates a pre - key from a public key by executing at least a part of a public key algorithm, and adds the public key, the pre - key, and a reference magic number to the header of the data; The processor generates encrypted data and an encrypted header by applying a symmetric key algorithm using a symmetric key to the data and the header; The first memory stores the encrypted data and the encrypted header; The second memory stores the symmetric key; And The third memory stores a comparison magic number inherent to the software, Wherein, the header includes the public key, the pre-key, and the comparison magic number. The step of generating the pre-key from the public key is the step of applying P = (C ^ 2) mod n, where P indicates the pre-key, C indicates a constant, and n indicates a part of the public key. The booting step includes the following steps: The processor generates decrypted data and a decrypted header by applying the symmetric key algorithm using the symmetric key to the encrypted data and the encrypted header; The processor determines whether the booting is successful based on the result of comparing the comparison magic number with the reference magic number.
7. The method for operating a secure booting device according to claim 6, wherein, The processor generates a reference hash message by applying a hash algorithm to the data, and generates a signature by applying a public key algorithm to the reference hash message; wherein, the header further includes the signature.
8. The method for operating a secure booting device according to claim 7, wherein, The booting step further includes the following steps: The processor generates a comparison hash message by applying a hash algorithm to the decrypted data; The processor generates a final verification value by applying a public key algorithm to the decrypted header; and The processor determines whether the booting is successful based on the result of comparing the comparison hash message with the final verification value.
9. The method for operating a secure booting device according to claim 8, wherein, The step of generating the final verification value includes the following steps: Applying a public key algorithm to the signature included in the encrypted header.
10. The method for operating a secure booting device according to claim 8, wherein, The step of generating the final verification value is to sequentially execute the steps of A = (S * P) mod n, B = (A ^ k) mod n, and R = B mod n, where S indicates the signature, P indicates the pre-key, k and n indicate the public key, and R indicates the final verification value.
11. The method for operating a secure booting device according to claim 8, the booting step further includes the following steps: The memory stores a reference hash public key; The processor generates a comparison hash public key by applying a hash algorithm to the public key; and The processor determines whether the booting is successful based on the comparison result between the reference hash public key and the comparison hash public key.
12. The method for operating a secure booting device according to claim 6, wherein, The preparation step and the booting step are executed as separate steps respectively.
13. The method for operating a secure booting device according to claim 8, wherein, The step of generating the pre-key and the step of generating the final verification value are executed as separate steps respectively.
14. The method for operating a secure booting device according to claim 6, wherein, The first memory is a NAND memory.
15. The method for operating a secure booting device according to claim 14, wherein, The second memory is a one-time programmable memory different from the NAND memory.
Citation Information
Patent Citations
RSA decoding method and device
CN104104504A
Secure boot sequencer and secure boot device
CN108280035A
Method and apparatus for device security verification utilizing a virtual trusted computing base
US20190163910A1