Secure boot-up techniques using modification of preloaded expected tag images
By using the authentication mechanism of the expected label image and hardware memory authenticator, the problem of excessive startup time and power consumption in the secure startup process in the prior art is solved, and a more efficient secure startup process is achieved.
Patent Information
- Application Number
- CN202380083881.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-12
- Filing Date
- 2023-11-21
- Publication Date
- 2025-07-04
AI Technical Summary
During the existing secure boot process, the use of encryption software to individually authenticate software images result in excessive startup time and power consumption, which cannot meet the needs of fast startup and low power consumption.
Use expected tag images for authentication, generate authentication tags before loading software images through hardware memory authenticator, and compare them with expected tags, reducing signature verification and hash calculations, and improving startup performance.
Reduces startup time and power consumption, improves the efficiency of the safe startup process, and meets the needs of fast startup and low power consumption.
Smart Images

Figure CN120266117A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to techniques for modifying a secure boot process. Aspects of the present disclosure relate to using an expected tag image in combination with a hardware memory authenticator to authenticate a software image for secure use on a computing device. Background Art
[0002] Devices including embedded systems (e.g., system-on-chip (SoC)) typically implement some form of secure boot process. The secure boot process can provide authentication (e.g., signature verification, integrity check, etc.) of one or more software images at different stages such as initial boot of the device, reboot of the device, returning the device from hibernation, restarting a device subsystem, etc. However, authenticating any number of software images using encrypted software alone during the secure boot process may adversely affect the boot performance in terms of time (e.g., boot time) and / or power consumption. Summary of the Invention
[0003] Systems and techniques for a modified secure boot process are described herein that include using an expected tag image to authenticate a software image being used on a computing device. According to some aspects of the present disclosure, the systems and techniques can use a previously generated and / or authenticated expected tag image to authenticate additional software images loaded during the secure boot process.
[0004] According to at least one example, a process for impersonation of identity in an access control system is provided. The process includes: obtaining an expected tag image that includes an expected tag corresponding to an image to be loaded into a memory; loading, by a memory controller, the expected tag into a first memory region corresponding to a hardware memory authenticator; loading, by the memory controller, the image into a second memory region; providing an authentication indication to the hardware memory authenticator, wherein the authentication indication triggers the hardware memory authenticator to authenticate the image; reading a portion of the image from the second memory region; generating, at the hardware memory authenticator, an authentication tag corresponding to the portion of the image; and performing a comparison of the authentication tag with the expected tag to obtain an authentication result, wherein the authentication result is a successful match and the portion of the image is authenticated.
[0005] In another illustrative example, an apparatus for image authentication for secure boot is provided. The apparatus may include: at least one memory; and at least one processor coupled to the at least one memory and configured to: obtain an expected tag image that includes an expected tag corresponding to an image to be loaded into the memory; load the expected tag into a first memory region corresponding to a hardware memory authenticator by a memory controller; load the image into a second memory region by the memory controller; provide an authentication indication to the hardware memory authenticator, where the authentication indication triggers the hardware memory authenticator to authenticate the image; read a portion of the image from the second memory region; generate an authentication tag corresponding to the portion of the image at the hardware memory authenticator; and perform a comparison of the authentication tag with the expected tag to obtain an authentication result, where the authentication result is a successful match and the portion of the image is authenticated.
[0006] In another illustrative example, a non-transitory computer-readable medium storing instructions is provided, the instructions when executed by one or more processors cause the one or more processors to: obtain an expected tag image that includes an expected tag corresponding to an image to be loaded into the memory; load the expected tag into a first memory region corresponding to a hardware memory authenticator by a memory controller; load the image into a second memory region by the memory controller; provide an authentication indication to the hardware memory authenticator, where the authentication indication triggers the hardware memory authenticator to authenticate the image; read a portion of the image from the second memory region; generate an authentication tag corresponding to the portion of the image at the hardware memory authenticator; and perform a comparison of the authentication tag with the expected tag to obtain an authentication result, where the authentication result is a successful match and the portion of the image is authenticated.
[0007] In another illustrative example, an apparatus for image authentication for secure boot is provided. The apparatus may include: means for obtaining an expected tag image that includes an expected tag corresponding to an image to be loaded into the memory; means for loading the expected tag into a first memory region corresponding to a hardware memory authenticator by a memory controller; means for loading the image into a second memory region by the memory controller; means for providing an authentication indication to the hardware memory authenticator, where the authentication indication triggers the hardware memory authenticator to authenticate the image; means for reading a portion of the image from the second memory region; means for generating an authentication tag corresponding to the portion of the image at the hardware memory authenticator; and means for performing a comparison of the authentication tag with the expected tag to obtain an authentication result, where the authentication result is a successful match and the portion of the image is authenticated.
[0008] In some aspects, one or more of the devices described herein are the following, part of the following, and / or include the following: a mobile or wireless communication device (e.g., a mobile phone or other mobile device), an extended reality (XR) device or system (e.g., a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a wearable device (e.g., a network-connected watch or other wearable device), a vehicle or a computing device or component of a vehicle, a camera, a personal computer, a laptop computer, a server computer or server device (e.g., an edge or cloud-based server, a personal computer acting as a server device, a mobile device such as a mobile phone acting as a server device, an XR device acting as a server device, a vehicle acting as a server device, a network router, or other device acting as a server device), a system on a chip (SoC), any combination thereof, and / or other types of devices. In some aspects, the device includes one camera or multiple cameras for capturing one or more images. In some aspects, the device includes a display for displaying one or more images, notifications, and / or other displayable data. In some aspects, the device includes one or more sensors (e.g., one or more RF sensors), such as one or more gyroscopes, one or more gyroscopic testers, one or more accelerometers, any combination thereof, and / or other sensors.
[0009] This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood by reference to the appropriate portions of the entire specification of this patent, any or all of the drawings, and each claim.
[0010] The foregoing and other features and examples will become more apparent after reference to the following specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Exemplary examples of the present application are described in detail below with reference to the following drawings:
[0012] Figure 1 is a block diagram illustrating certain components of a computing device according to some examples;
[0013] Figure 2 is a block diagram illustrating a hardware identity imitator according to some examples;
[0014] Figure 3 is a block diagram illustrating an environment in which techniques for modifying a secure boot process are implemented according to some examples;
[0015] Figure 4is a block diagram of an environment implementing techniques for a modified secure boot process according to some examples;
[0016] Figure 5 is a block diagram of an environment implementing techniques for a modified secure boot process according to some examples;
[0017] Figure 6 is a flowchart of an example process for modified secure boot techniques according to some examples;
[0018] Figure 7 is a diagram illustrating an example of a computing system for implementing certain aspects described herein. DETAILED DESCRIPTION
[0019] Certain aspects and examples of the present disclosure are provided below. As will be apparent to those skilled in the art, some of these aspects and examples may be applied independently, and some of them may be applied in combination. In the following description, specific details are set forth for purposes of explanation to provide a thorough understanding of the examples of the present application. However, it will be apparent that the various examples may be practiced without these specific details. The accompanying drawings and description are not intended to be restrictive. Additionally, certain details known to those of ordinary skill in the art may be omitted to avoid obscuring the description.
[0020] In the following description of the drawings, in the various examples described herein, any component described with reference to a drawing may be equivalent to one or more similarly named (or numbered) components described with reference to any other drawing. For the sake of brevity, the description of these components may not be repeated in full with reference to each drawing. Accordingly, each example of a component of each drawing is incorporated by reference and is assumed to optionally exist within each other drawing having one or more similarly named components. Additionally, according to the various examples described herein, any description of a component of a drawing is to be interpreted as an optional example, which may be implemented in addition to, in combination with, or in place of an example described with reference to a corresponding similarly named component in any other drawing.
[0021] The following description provides only illustrative examples and is not intended to limit the scope, applicability, or configuration of the present disclosure. Instead, the following description of the illustrative examples will provide those skilled in the art with an enabling description for implementing the exemplary examples. It should be understood that various changes may be made to the functions and arrangements of the elements without departing from the spirit and scope of the present application as set forth in the appended claims.
[0022] As used herein, the phrase operatively coupled or operatively connecting (or any variation thereof) means that there is a direct or indirect connection between components / devices / equipment, etc. that permits the components to interact with each other in some manner. For example, the phrase "operatively connected" can refer to any direct connection (e.g., a wired connection directly between two devices or components) or an indirect connection (e.g., a wired and / or wireless connection between any number of devices or components that operatively connect the connected devices). Thus, any path through which information can travel can be considered an operative connection. Additionally, operatively connected devices and / or components can exchange things other than information, such as, for example, electrical current, radio frequency signals, etc.
[0023] This document describes systems, apparatuses, processes (also referred to as methods), and computer-readable media (collectively referred to as "systems and techniques") for providing an improved secure boot process, which can reduce boot time, lower power consumption, and provide other advantages. When implementing a secure boot process, a device can load a software image (which may be referred to herein as an image) into the device memory. The software image can correspond to any part and / or subsystem of the device, such as, for example, an operating system, a modem subsystem, a hypervisor, a digital signal processor (DSP) subsystem, etc.
[0024] The secure boot process can include: obtaining metadata corresponding to the image on a per-software-image basis; verifying the signature corresponding to the image; loading the image from a storage device into the memory; obtaining segments of the image from the memory; hashing the segments; comparing the hash with an expected hash (e.g., obtained from the hashed segment metadata of the image); and authenticating the image only when all hashes in the hash match successfully. When authentication is successful, the image can be considered loaded and ready to use. The hashing of segments and the hash comparison are typically performed by an encryption software block. Thus, in order to successfully complete the secure boot of a device (or any aspect thereof), each image to be loaded (e.g., ten images) can undergo a process where encryption software is used to verify the signature of each image and further perform a hashing algorithm on each segment of each image in order to perform an authenticated hash comparison. Hashing of image segments can be an expensive operation in terms of time and power consumption proportional to the image size. Thus, the above-described secure boot process may not meet the boot time requirements in some scenarios, such as when faster boot time and / or lower boot power consumption are needed (e.g., automotive computing devices, Internet of Things (IoT) devices, etc.).
[0025] Additionally, the memory controller may include a hardware memory authenticator for implementing runtime memory integrity checks. Such a hardware memory authenticator may be configured to compute an authentication tag for an image or a portion thereof before the image is loaded into memory or while the image is being loaded into memory (e.g., during a secure boot process, during a subsystem restart, when returning the device from a sleep state, etc.). When an image or a portion thereof is to be read during runtime, the hardware memory authenticator may be configured to obtain the data to be read, compute a tag for the data, and compare it with a previously computed tag for the data. If the comparison results in a successful match, the integrity of the data is verified. If not, the integrity check for the runtime data fails (e.g., detection of corrupted data has occurred), and the corrupted data may not be made available for processing (e.g., by one or more processors of the computing device), for example.
[0026] To improve the secure boot process (e.g., improve boot time and power consumption), the systems and techniques provided herein may modify the secure boot process by using an expected tag image. As used herein, a tag refers to an authentication tag. An authentication tag (e.g., a message authentication code (MAC)) may be any item of information that permits authentication of data of any size or type. As an example, a software image (e.g., data) to be loaded during a secure boot process or a segment thereof may be input into a hashing algorithm to obtain an output or hash of the segment, where each hash serves as a tag for the segment. The expected tag may be a tag computed prior to the secure boot process. For example, the expected tag may be obtained separately (e.g., "offline") from the device on which the secure boot is to be performed. In some examples, a collection of expected tags for all or any portion of an image (e.g., a software image) to be loaded during a secure boot process may be collected and included in a separate image (referred to herein as an expected tag image). Like other images, the expected tag image itself may be signed and authenticated prior to top use, as further discussed below. Additionally, in some examples, the expected tag image may be authenticated and protected from being modified to serve as a root of trust, where the authentication is performed using techniques related to hashing and signing.
[0027] Then, a secure boot process such as the above-described secure boot process (e.g., using hash and signature verification techniques to authenticate an expected label image) can be used to load the expected label image. For example, at or near the start of the secure boot process, before loading at least a portion of other images to be loaded, the expected label image can be obtained (e.g., by a storage controller from a flash storage device) and provided to a memory controller. Then, the memory controller can obtain metadata from the expected label image and use the metadata and encryption software to perform a signature verification for the image, and (e.g., also use the metadata for the expected label image to) hash the expected label image and / or portions thereof to perform a hash comparison. Once the signature verification and hash comparison have been successfully performed, the expected label image can be considered authenticated. Thus, the expected label of the expected label image can be loaded into a memory region (e.g., an expected label region) for later use by a hardware memory authenticator of the memory controller, where the memory region corresponds to the hardware memory authenticator and is at least temporarily accessible by the hardware memory authenticator. In some examples, the memory region storing the expected label can be locked and accessible only by the hardware memory authenticator for at least the secure boot process, and the hardware memory authenticator can be configured to access the memory region to obtain the expected label when authenticating software images. The hardware memory authenticator can remain inactive during the loading of the expected label image (e.g., an active bit for the hardware memory authenticator can be set to zero).
[0028] Then, the modified secure boot process can continue to be executed. As the modified secure boot process continues, the hardware memory authenticator can remain off (e.g., deactivated). For example, an indicator bit for the hardware memory authenticator can remain set to zero. Then, images to be loaded during the secure boot process can be loaded into the memory without undergoing the signature verification, hash comparison, and / or authentication processes used in the previous secure boot process. The hardware memory authenticator can be configured to be deactivated at the start of the secure boot process (e.g., during startup, restart, subsystem restart, etc.). In some examples, deactivating the hardware memory authenticator causes the hardware memory authenticator not to perform authentication operations, which can improve the performance of the initial portion of the secure boot process.
[0029] Next, an indication to begin performing authentication of an image already in memory (e.g., a memory region in which an image has been loaded, which can be analogous to a dummy read of a requested hardware execution region) can be provided to the hardware memory authenticator in parallel with other operations being performed (e.g., loading additional images, performing operations using the loaded and previously authenticated images, etc.). For example, an active indicator bit can be set to a value such as zero or one. In response to this indication, the hardware memory authenticator can obtain the image or a portion thereof from memory, compute a tag, and compare the tag to a previously loaded expected tag to authenticate the image. In some examples, signature verification can be performed on the tag. In some examples, once the software image has been authenticated using the above process, the software image can be executed on the computing device.
[0030] Using the modified secure boot process described above, boot time and power consumption can be improved (e.g., the boot time can be reduced and / or the power consumption can be reduced). As an example, signature verification for each image to be loaded may no longer be performed using cryptographic software, and hashing may also not be performed using cryptographic software (since they can instead be performed using the hardware memory authenticator). Additionally, as another example, boot time can be further improved by performing authentication by checking the tag computed by the hardware memory authenticator against the previously loaded and trusted expected tag in parallel with other operations being performed.
[0031] Additionally or alternatively, in some examples, memory can be saved and made available for use after the modified secure boot process is complete by deleting (e.g., discarding) all or any portion of the expected tag from memory. As an example, in some scenarios, one or more images loaded as part of the modified secure boot process may not need to be reused unless the device is rebooted (which would anyway delete the expected tag), such as the operating system, hypervisor, etc. If there are no images that may be reused during runtime, the expected tag can be deleted from memory, making the memory available for the device to be used for other purposes. However, if there are images that can be restarted (e.g., restart of a modem, other peripherals, etc.) without a full reboot, the expected tag can instead be kept in memory, and sequential processing of such tags can be maintained.
[0032] In an alternative or additional example, the modified boot process may not use the expected label images as described above. Instead, during a first secure boot process (e.g., during a first power supply or power cycle of the device), the memory controller and / or the hardware memory authenticator may compute labels for one or more images and build an expected label repository in a region of the memory for later use, as in the modified secure boot process described above. As an example, the expected labels generated in this alternative manner may be used to restart a subsystem (e.g., a modem subsystem) and authenticate the images for the restarted subsystem. This alternative technique for generating and using expected labels may be a less intrusive change to existing secure boot processes while still providing an improvement in performance (e.g., the time to restart a subsystem).
[0033] The examples described herein can address the need to improve device performance by reducing or eliminating time-consuming software operations to be performed during the secure boot process of a computing device.
[0034] Various aspects of the systems and techniques described herein will be discussed below with reference to the drawings. Figure 1 FIG. 1 is a block diagram illustrating an example of a computing device 100. As shown, the computing device 100 includes a processor 102, a memory controller 104, a memory device 106, a storage controller 108, and a storage device 110. Each of these components is described below.
[0035] A computing device 100 is any device, part of a device, or any collection of devices capable of electronically processing instructions and may include, but is not limited to, any of the following: one or more processors (e.g., components including integrated circuits), memory, input and output devices (not shown), non-volatile storage hardware (not shown), one or more physical interfaces (not shown), any number of other hardware components (not shown), and / or any combination thereof. Examples of computing devices include, but are not limited to, mobile devices (e.g., laptop computers, smart phones, personal digital assistants, tablet computers, automotive computing systems, and / or any other mobile computing device), Internet of Things (IoT) devices, servers (e.g., blade servers in a blade server chassis, rack-mounted servers in a rack, etc.), desktop computers, storage devices (e.g., disk drive arrays, Fibre Channel storage devices, Internet Small Computer System Interface (iSCSI) storage devices, tape storage devices, flash arrays, network-attached storage devices, etc.), network devices (e.g., switches, routers, multilayer switches, etc.), wearable devices (e.g., networked watches or smart watches or other wearable devices), robotic devices, smart TVs, smart appliances, extended reality (XR) devices (e.g., augmented reality, virtual reality, etc.), any device including one or more system-on-chips (SoCs), and / or any other type of computing device having the foregoing requirements. In one or more examples, any or all of the foregoing examples may be combined to create a system of such devices, which may be collectively referred to as a computing device. Other types of computing devices may be used without departing from the scope of the examples described herein.
[0036] In some examples, computing device 100 includes a processor 102. In some examples, processor 102 is any component that includes circuitry for executing instructions (e.g., of a computer program). As an example, such circuitry can be an integrated circuit implemented at least in part using transistors that implement such component as an arithmetic logic unit, a control unit, logic gates, registers, and the like. In some examples, the processor can include additional components, such as, for example, cache memory. In some examples, the processor retrieves and decodes instructions, which are then executed. Execution of the instructions can include operating on data, which can include reading and / or writing data. In some examples, the instructions and data used by the processor are stored in a memory (e.g., memory device 106) of computing device 100. The processor can perform various operations for executing software, such as an operating system, applications, and the like. Processor 102 can cause data to be written from a memory of computing device 100 to a storage device of the computing device and / or cause data to be read from the storage device via the memory. Examples of processors include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), a neural processing unit, a tensor processing unit, a data processing unit (DPU), a digital signal processor (DSP), and the like.
[0037] In some examples, computing device 100 includes a memory controller 104. In some examples, memory controller 104 is operatively connected to processor 102. In some examples, memory controller 104 is any hardware, software, firmware, or any combination thereof that is configured to at least partially manage data being sent to and / or being sent from a memory (e.g., memory device 106) of computing device 100. Although Figure 1 memory controller 104 is shown as separate from processor 102, one of ordinary skill in the relevant art will understand that all or any part of the functionality of the memory controller can be incorporated into processor 102 and / or implemented separately from processor 102. Additional aspects of memory controller 104 are discussed further in the Figure 2 description below. Although Figure 1 computing device 100 is shown as having a single memory controller 104, computing device 100 can have any number of memory controllers without departing from the scope of the examples described herein.
[0038] In some examples, computing device 100 includes memory device 106. In some examples, memory device 106 is operatively connected to memory controller 104. Memory device 106 can be any type of computer memory. In some examples, memory device 106 is a volatile storage device. As an example, memory device 106 can be random access memory (RAM). In one or more examples, the data stored in memory device 106 is located at a memory address and can thus be accessed by processor 102 using the memory address. Similarly, processor 102 can use the memory address to write data to memory device 106. In some examples, memory controller 104 can be used at least in part to facilitate the interaction between processor 102 and memory device 106. Memory device 106 can be used to store any type of data, such as, for example, software images, computer programs, calculation results, etc. In some examples, memory device 106 (e.g., via memory controller 104) is operatively connected to processor 102. Although Figure 1 computing device 100 is shown as having a single memory device 106, computing device 100 can have any number of memory devices without departing from the scope of the examples described herein.
[0039] In some examples, computing device 100 includes storage controller 108. In some examples, storage controller 108 is operatively connected to processor 102. In some examples, storage controller 108 is any hardware, software, firmware, or any combination thereof configured to at least partially manage access to data stored on any number of storage devices (e.g., storage device 110). Storage controller (e.g., storage controller 108) can include and / or be operatively connected to any number of other devices, components, etc. (not shown) for managing access to data stored on storage devices (e.g., storage device 110). Storage controller 108 can control access to data stored on any number of storage devices (e.g., storage device 110) by, for example, providing access (which can be controlled access) to other components of computing device 100 when reading data from and / or writing data to the storage device. Although Figure 1 computing device 100 is shown as including a single storage controller 108, computing device 100 can include any number of storage controllers without departing from the scope of the examples described herein. Storage controller 108 can be configured to implement any number of storage device-related specifications, best practices, protocols, etc. to manage access to the storage devices of a given computing device.
[0040] In some examples, computing device 100 includes storage device 110. In some examples, storage device 110 is operatively connected to storage controller 108. In some examples, storage device 110 (e.g., via storage controller 108) is operatively connected to processor 102. Storage device 110 can be used to store any type of data. Data can be written to and / or read from storage device 110. As an example, storage device 110 can store an operating system image, software images, application data, etc. Without departing from the scope of the examples described herein, storage device 110 can store any other type of data. In some examples, storage device 110 is a flash storage device. In some examples, storage device 110 includes a NAND flash memory device. Without departing from the scope of the examples described herein, storage device 110 can use any other type of storage technology. Although Figure 1 computing device 100 is shown with a single storage device 110, computing device 100 can include any number of storage devices without departing from the scope of the examples described herein.
[0041] In some examples, computing device 100 includes storage device 110, which is a non-volatile storage device. Storage device 110 can be, for example, a persistent memory device. In some examples, storage device 110 can be any type of computer storage device. Examples of types of computer storage devices include but are not limited to hard disk drives, solid state drives, flash memory storage devices, tape drives, removable disk drives, universal serial bus (USB) storage devices, secure digital (SD) cards, optical storage devices, read-only memory devices, etc. Although Figure 1 storage device 110 is shown as part of computing device 100, storage device 110 can be separate from and operatively connected to computing device 100 (e.g., an external drive array, cloud storage device, etc.).
[0042] While Figure 1 a certain number of components are shown in a particular configuration, those of ordinary skill in the art should understand that computing device 100 can include more components or fewer components and / or components arranged in any number of alternative configurations without departing from the scope of the examples described herein. Additionally, although Figure 1 not shown herein, those of ordinary skill in the art should understand that computing device 100 can execute any amount or type of software or firmware (e.g., a boot loader, an operating system, a hypervisor, virtual machines, computer applications, mobile device applications, etc.) when powered on. Thus, the examples disclosed herein should not be limited to Figure 1 the configuration of the components shown herein.
[0043] Figure 2 is an example portion block diagram of a computing device (e.g., Figure 1 computing device 100) that includes a memory controller 200 and a memory device 206. The memory controller 200 may include a hardware memory authenticator 204, and the memory device 206 may include an image area 208 and an expected tag area 210. Each of these components is described below.
[0044] In some examples, the memory controller 200 is the same as or substantially similar to Figure 1 the memory controller 104 shown and described above. Thus, the memory controller is configured to control access to one or more memory devices (e.g., memory device 206). In some examples, the memory controller 200 includes a hardware memory authenticator 204. In some examples, the hardware memory authenticator 204 is any hardware, software, firmware, or any combination thereof configured to perform various tasks related to access of a memory device (e.g., memory device 206).
[0045] In some examples, the hardware memory authenticator 204 is configured to perform a runtime integrity check on software being used from a memory device (e.g., memory device 206). To this end, in some examples, the hardware memory authenticator 204 may be configured to compute an authentication tag for an image (e.g., a software image) or a portion thereof before the image is loaded into memory or while the image is being loaded into memory (e.g., during a secure boot process, during a subsystem restart, when returning the device from hibernation, etc.). When an image or a portion thereof is to be read during runtime, the hardware memory authenticator may be configured to obtain the data to be read, compute a tag for the data, and compare it with a previously computed tag for the data. If the comparison results in a successful match, the integrity of the data is verified. If not, the integrity check for the runtime data fails (e.g., detection of corrupted data has occurred), and for example, the corrupted data cannot be made available for processing.
[0046] In some examples, the hardware memory authenticator 204 is configured to perform certain operations in response to an authentication indication. As an example, the authentication indication may be a certain configuration bit (e.g., one or zero) that determines whether the hardware memory authenticator 204 is to perform authentication of certain data. In some examples, the hardware memory authenticator 204 may have a configuration bit set to a certain state (e.g., zero) so that the hardware memory authenticator 204 does not perform an operation when data passes through the memory controller 200, and is set to a different state (e.g., one) so that the hardware memory authenticator 204 performs certain operations to authenticate data that has passed through the memory controller 200. The operations performed by the hardware memory authenticator 204 are described below inFigures 3 to 5 is further discussed in the description.
[0047] In one or more embodiments, the memory device 206 is the same as or substantially similar to the memory device 106 shown and described above. Thus, the memory device 206 can include any number of memory regions. In some examples, a memory region can be any portion of the memory, which may or may not include contiguous segments of the memory. In some examples, one such region is the image region 208. In some examples, the image region 208 is any region of the memory device that is configured to store one or more software images, which can be used to control any portion of a computing device (e.g., Figure 1 the computing device 100) or otherwise loaded onto the computing system (e.g., during a secure boot process) such that the software included in the image can be executed on the computing device. Thus, in some examples, the software image can include application code, one or more executable files, any data files associated with the software of the image, etc. The software image (which may be referred to as an image) can correspond to any portion and / or subsystem of the device, such as, for example, an operating system, a modem subsystem, a hypervisor, a digital signal processor (DSP) subsystem, etc. Figure 1 In some examples, the memory device 206 includes an expected tag region 210. In some examples, the expected tag region 210 is the portion of the memory device 206 that is associated with and / or corresponds to the hardware memory authenticator 204. In some examples, the expected tag region 210 is configured to store an expected tag image. As used herein, a tag refers to an authentication tag. An authentication tag (e.g., a message authentication code (MAC)) can be any item of information that permits the authentication of any size or type of data. As an example, a software image (e.g., data) or a segment thereof to be loaded during a secure boot process can be input into a hashing algorithm to obtain an output or hash of the segment, where each hash serves as a tag for the segment. The expected tag can be a tag calculated prior to the secure boot process. For example, the expected tag can be obtained separately (e.g., "offline") from the device on which the secure boot is to be performed. A set of expected tags for all or any portion of the image to be loaded during the secure boot process can be included in a separate image (referred to herein as the expected tag image). Like other images, the expected tag image itself can be signed. In some examples, the memory region corresponding to the hardware memory authenticator 204 (e.g., the expected tag region 210) can be locked during at least the secure boot process such that only the hardware memory authenticator can access the memory region.
[0048] In some examples, the memory device 206 includes an expected tag region 210. In some examples, the expected tag region 210 is the portion of the memory device 206 that is associated with and / or corresponds to the hardware memory authenticator 204. In some examples, the expected tag region 210 is configured to store an expected tag image. As used herein, a tag refers to an authentication tag. An authentication tag (e.g., a message authentication code (MAC)) can be any item of information that permits the authentication of any size or type of data. As an example, a software image (e.g., data) or a segment thereof to be loaded during a secure boot process can be input into a hashing algorithm to obtain an output or hash of the segment, where each hash serves as a tag for the segment. The expected tag can be a tag calculated prior to the secure boot process. For example, the expected tag can be obtained separately (e.g., "offline") from the device on which the secure boot is to be performed. A set of expected tags for all or any portion of the image to be loaded during the secure boot process can be included in a separate image (referred to herein as the expected tag image). Like other images, the expected tag image itself can be signed. In some examples, the memory region corresponding to the hardware memory authenticator 204 (e.g., the expected tag region 210) can be locked during at least the secure boot process such that only the hardware memory authenticator can access the memory region.
[0049] Although Figure 2illustrates a certain number of components in a particular configuration, but one of ordinary skill in the art should understand that, without departing from the scope of the examples described herein, a computing device (e.g., computing device 100) may include more components or fewer components, and / or components arranged in any number of alternative configurations. Accordingly, the examples disclosed herein should not be limited to Figure 1 the configuration of the components shown in
[0050] Figure 3 , Figure 4 and Figure 5 illustrates an example environment 312 in accordance with one or more examples described herein. The following examples are for explanatory purposes only and are not intended to limit the scope of the examples described herein. Additionally, while the examples illustrate certain aspects of the examples described herein, all possible aspects of such examples may not be illustrated in this particular example.
[0051] Figure 3 The environment 312 illustrated in depicts an example scenario in which a computing device implements a modified secure boot process. In such a scenario, the configuration bits for the hardware memory authenticator 304 may be set to a value (e.g., zero) that indicates that the hardware memory authenticator 304 is not performing an operation to authenticate data written to the positive memory device 306 (e.g., it is deactivated). The hardware memory authenticator 304 may be configured to be initially deactivated during startup and / or restart of the computing device. In some examples, the hardware memory authenticator 304 may be actively deactivated during startup and / or restart. As discussed above in the description of Figure 1 and Figure 2 , whether the hardware memory authenticator 304 is activated or deactivated can be controlled at least in part by a configuration setting (e.g., a configuration bit) that can be set to various values (e.g., zero or one) to control the state of the hardware memory authenticator 304. Accordingly, the state (e.g., activation or deactivation) can be changed by providing an indication to change the configuration setting. As an example, as described above and below, an authentication indication can be provided to the hardware memory authenticator to transition a relevant configuration bit from one value (e.g., zero) to another value (e.g., one) in order to transition the hardware memory authenticator from a deactivated state to an activated state. In some examples, the configuration bit may be referred to as an authentication indicator and may be controlled by the processor 300, for example.
[0052] In some examples, such as Figure 3As shown, an expected label image is obtained for loading and authentication. The expected label image can be a software image including an authentication label for any number of software images to be loaded to perform various functions of the computing device. The authentication label can be calculated offline (e.g., on a separate computing device (not shown)) using one or more hashing algorithms and aggregated into the expected label image. Before the scenario depicted in Figure 3 , the expected label image can be stored in a storage device (not shown) of a computing device in the environment 312. The expected label image can be obtained from the storage device and stored in the expected label area 310 of the memory device 306 by the memory controller 302 upon request from the processor 300. The expected label image can be authenticated before being loaded into the expected label area 310 of the memory device 306. For example, at or near the start of the secure boot process, before at least a portion of other images to be loaded are loaded, the expected label image can be obtained (e.g., by the storage controller from a flash storage device) and provided to the memory controller 302. The memory controller can then obtain metadata from the expected label image and use the metadata and encryption software to perform a signature check on the image and (e.g., also use the metadata for the expected label image to) hash the expected label image and / or portions thereof to perform a hash comparison. Once the signature verification and hash comparison have been successfully performed, the expected label image can be considered authenticated. Thus, the expected label of the expected label image can be loaded into a memory area for later use by the hardware memory authenticator of the memory controller. The hardware memory authenticator 304 can remain disabled during the loading of the expected label image (e.g., the configuration bit for the hardware memory authenticator can be set to zero). In some examples, the expected label area 310 of the memory device 306 can be locked after successful authentication of the expected label image and loading of the expected label image.
[0053] Moving on to Figure 4 , a configuration bit used as an authentication indicator for the hardware memory authenticator 304 remains set to a value (e.g., zero), meaning that the hardware memory authenticator 304 remains disabled. Continuing with the scenario, the processor 300 continues to load the expected label for at least one software image present in the expected label area 310 into the image area 308 of the memory device 306. The software image can be loaded into the image area 308 of the memory device 306 via the memory controller 302 without any signature verification or authentication having been performed yet.
[0054] Moving on to Figure 5, the processor 300 transitions a configuration bit that serves as an authentication indicator for the hardware memory authenticator 304 to a value (e.g., one) that indicates the hardware memory authenticator 304 should authenticate a software image previously loaded into the image region 308. The configuration bit is transitioned by providing an authentication indication to the hardware memory authenticator 304. In response to the change in the state of the configuration bit, the hardware memory authenticator 304 obtains at least a portion of the software image from the image region 308 and performs a hashing algorithm to obtain an authentication tag corresponding to the portion of the software image. Next, the hardware memory authenticator 304 obtains the expected authentication tag for the portion of the software image from the expected tag region 310. Next, the hardware memory authenticator 304 performs a comparison of the two authentication tags. If the computed authentication tag matches the expected authentication tag for the portion of the software image, the authentication of the portion of the software image is successful. Any number of portions of the software image can undergo the foregoing process to authenticate the software image as a whole. Once all relevant portions of the software image have been so authenticated, execution of the software image can proceed. In some examples, if any portion of the software image fails the authentication check, the software image can be considered unauthenticated, and execution of the software image on the computing device can be prevented.
[0055] In some examples, the process depicted in Figures 3 to 5 can be repeated for any software image to be used during operation of the computing device. During any such image authentication, other operations can be performed by the computing device (e.g., loading additional images, performing operations using the loaded and authenticated images, etc.). In some examples, after successful authentication of one or more software images, all or any portion of the expected tag region can be deleted (e.g., discarded), thereby freeing the expected tag region 310 or a portion thereof for use by the computing device for other operations. Additionally or alternatively, all or any portion of the expected tags stored in the expected tag region 310 can be retained for use during operation of the computing device. As an example, certain subsystems of the computing device (e.g., a modem subsystem) may need to be restarted while the remainder of the computing device continues to operate. In such scenarios, the expected tags from the expected tag region 310 can be used to repeat the above process for the software images corresponding to the subsystems.
[0056] Figure 6 is a flowchart illustrating an example of a process 600 for image authentication for secure boot in accordance with examples described herein. The process 600 can be performed at least in part, for example, by Figure 1 the computing device 100 shown in Figure 2 or any of the components shown therein (e.g., the processor 102, the memory controller 104, the storage controller 108, and the memory device 106 and / or the storage device 110), Figure 2 the memory controller 200 shown and described above,Figure 2 the hardware memory authenticator 204 shown and described above and / or Figure 2 the memory device 206 shown and described above.
[0057] At block 602, process 600 includes: obtaining an expected label image that includes an expected label corresponding to an image to be loaded into a memory (e.g., Figure 2 image region 208 of memory device 206). The expected label image can be obtained by a processor (e.g., Figure 1 processor 102). The expected label image can include any number of expected labels corresponding to any number of software images (e.g., images) and / or portions thereof. The expected label image can be generated offline prior to authentication of the image (e.g., at a separate computing device). The expected label image can be a signed image. The expected label image can be obtained from a storage device (e.g., Figure 1 storage device 110). The expected label image can be obtained at any time during operation of the computing device, including but not limited to during initial boot, during startup, during restart, during subsystem restart, during return from device hibernation, etc. In some examples, the expected label image undergoes a secure boot process to verify the signature for the expected label image and authenticate the expected label image, which occurs prior to (e.g., at block 604) loading one or more expected labels of the expected label image into a memory region.
[0058] At block 604, process 600 includes: loading, by a memory controller (e.g., Figure 1 memory controller 104), the expected label into a first memory region corresponding to the hardware memory authenticator. Any number of expected labels can be loaded into the memory region without departing from the scope of the examples described herein. As discussed above, the signature for the expected label image and / or authentication of the expected label image can occur prior to the expected label being loaded into the memory region. In some examples, the first memory region is an expected label region corresponding to the hardware memory authenticator at least during the secure boot process. Thus, in some examples, the first memory region can be a memory region to which the hardware memory authenticator has exclusive access and is configured to be accessed during the secure boot process when authenticating an image.
[0059] At block 606, process 600 includes: by a memory controller (e.g., Figure 1The memory controller 104) loads the image into the second memory area. Without departing from the scope of the examples described herein, any number of images can be loaded into the second memory area. One or more images loaded into the second memory area may not undergo an authentication process when they are loaded into the second memory area, while the expected tag images undergo an authentication process. The second memory area can be an area of the memory device configured to store any number of software images during a secure boot process (e.g., Figure 2 the image area 208).
[0060] At block 608, process 600 includes: providing an authentication indication to a hardware memory authenticator (e.g., Figure 2 the hardware memory authenticator 204), where the authentication indication triggers the hardware memory authenticator to authenticate the image. In some examples, the authentication indication is any information that causes the state of the hardware memory authenticator to transition from a deactivated state to an activated state when provided to the hardware memory authenticator. In some examples, the deactivated state is a state in which the hardware memory authenticator does not perform authentication operations on software images during a secure boot process. In some examples, the activated state is a state in which the hardware memory authenticator performs authentication operations on one or more images (e.g., software images). As an example, the hardware memory authenticator can include and / or be operatively connected to a component for storing bits, and the state of the bits can control whether the hardware memory authenticator is deactivated or activated. The hardware memory authenticator can be configured to be deactivated at the start of a secure boot process (e.g., during startup, restart, subsystem restart, return from system hibernation, etc.). The hardware memory authenticator can be deactivated at any time by changing the state of a configuration bit. As an example, the hardware memory authenticator can be deactivated whenever a relevant configuration bit is set to a specific value (e.g., zero). In some examples, as discussed above, providing the authentication indication to the hardware memory authenticator includes changing a configuration bit such that the state of the hardware memory authenticator (e.g., by changing the configuration bit from zero to one) transitions from deactivated to activated, which can trigger the hardware memory authenticator to start authenticating the image and / or portions thereof as part of a secure boot process.
[0061] At block 610, process 600 includes: reading a portion of the image from the second memory area (e.g., Figure 2 the image area 208). In some examples, the portion of the image is read by a hardware memory authenticator (e.g., Figure 2 the hardware memory authenticator 204). A portion of the image can refer to the entire software image or any sub - portion thereof.
[0062] At block 612, process 600 includes: at the hardware memory authenticator (e.g., Figure 2At the hardware memory authenticator 204), an authentication tag corresponding to a portion of the image is generated. In some examples, as discussed above in Figures 1 to 5 the description of, the authentication tag is any data item that can be used to authenticate all or any portion of the image, such as, for example, a MAC. Any suitable technique can be used to generate the authentication tag. As an example, the authentication tag can be generated by the hardware memory authenticator by performing a hash function using the portion of the image as input, where the output is the authentication tag.
[0063] At block 614, process 600 includes: performing a comparison of the authentication tag with an expected tag to obtain an authentication result, where the authentication result is a successful match and the portion of the image is authenticated. In some examples, to perform the comparison, the comparison is performed by the hardware memory authenticator (e.g., Figure 2 the hardware memory authenticator 204). In some examples, to perform the comparison, the hardware memory authenticator obtains the expected tag corresponding to the portion of the image from a second memory region (e.g., Figure 2 the image region 208). In some examples, the comparison results in a successful match of the authentication tag generated by the hardware memory authenticator with the expected tag, indicating that at least a portion of the image is authenticated. When each portion in the image is successfully authenticated, the image as a whole can be authenticated. However, in some examples, if a second portion of the image is not successfully authenticated using the above techniques, the authentication of the image can be considered to have failed. In some examples, if the image is successfully authenticated by the hardware memory authenticator, the image can be executed on the computing device. In some examples, if the image is not successfully authenticated, the execution of the image may not be permitted on the computing device.
[0064] In some examples, process 600 or any other process described herein can be performed by a computing device or apparatus and / or one or more components thereof and / or one or more components operatively connected to the computing device. As an example, process 600 can be performed in whole or in part by Figure 2 the hardware memory authenticator 204 shown and described above.
[0065] The hardware memory authenticator can be any suitable device, can include any suitable device, or be a component of any suitable device, such as a vehicle or a computing device of a vehicle (e.g., a driver monitoring system (DMS) of a vehicle), a mobile device (e.g., a mobile phone), a desktop computing device, a tablet computing device, a wearable device (e.g., a VR headset, an AR headset, AR glasses, an internet-connected watch or a smartwatch, or other wearable devices), a server computer, a robotic device, a television, a smart speaker, a voice assistant device, a SoC, and / or any other device having the resource capabilities to perform the processes described herein (including process 600 and / or other processes described herein). In some cases, a computing device or apparatus (e.g., including a hardware identity imitator) can include various components, such as one or more input devices, one or more output devices, one or more processors, one or more microprocessors, one or more microcomputers, one or more cameras, one or more sensors, and / or other components configured to perform the operations of the processes described herein. In some examples, the computing device can include a display, a network interface configured to communicate and / or receive data, an RF sensing component, any combination thereof, and / or other components. The network interface can be configured to communicate and / or receive data based on Internet Protocol (IP) or other types of data.
[0066] The components of the hardware memory authenticator can be implemented at least in part in circuitry. For example, the components can include electronic circuitry or other electronic hardware, and / or can be implemented using electronic circuitry or other electronic hardware, which can include one or more programmable electronic circuits (e.g., a microprocessor, a graphics processing unit (GPU), a digital signal processor (DSP), a central processing unit (CPU), and / or other suitable electronic circuitry), and / or can include computer software, firmware, or any combination thereof for performing the various operations described herein, and / or can be implemented at least in part using computer software, firmware, or any combination thereof for performing the various operations described herein.
[0067] Figure 6The process 600 shown is illustrated as a logical flow diagram, and the operations represent a sequence of operations that can be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations. In general, computer-executable instructions include routines, programs, objects, components, data structures, etc. that perform particular functions or implement particular data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of the described operations can be combined in any order and / or in parallel to implement the process.
[0068] Additionally, process 600 and / or other processes described herein can be executed under the control of one or more computer systems configured with executable instructions and can be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) executed jointly on one or more processors, implemented in hardware, or implemented by a combination thereof. As noted above, the code can be stored on a computer-readable or machine-readable storage medium, e.g., in the form of a computer program comprising a plurality of instructions executable by one or more processors. The computer-readable or machine-readable storage medium can be non-transitory.
[0069] Figure 7 is a diagram illustrating an example of a system for implementing certain aspects of the present technology. Specifically, Figure 7 illustrates an example of a computing system 700, which can be any computing device, such as a computing device that constitutes an internal computing system, a remote computing system, a camera, or any component thereof, where the components of the system communicate with each other using connection 705. Connection 705 can be a physical connection using a bus or a direct connection into a processor 710, such as in a chipset architecture. Connection 705 can also be a virtual connection, a networked connection, or a logical connection.
[0070] In some examples, computing system 700 is a distributed system, where the functions described in this disclosure can be distributed within one data center, multiple data centers, a peer-to-peer network, etc. In some examples, one or more of the described system components represent many such components, each of which performs a part or all of the functions that the component is described for. In some examples, the components can be physical or virtual devices.
[0071] Example system 700 includes at least one processing unit (CPU or processor) 710 and a connection 705 that couples various system components including system memory 715 (such as read-only memory (ROM) 720 and random access memory (RAM) 725) to the processor 710. Computing system 700 may include a cache 712 of high-speed memory that is directly connected to, in close proximity to, or integrated as part of the processor 710.
[0072] Processor 710 may include any general-purpose processor and hardware services or software services, such as services 732, 734, and 736 stored in storage device 730, which are configured to control processor 710 and special-purpose processors in which software instructions are incorporated into the actual processor design. Processor 710 may be substantially a stand-alone computing system that contains multiple cores or processors, buses, memory controllers, caches, etc. A multi-core processor may be symmetric or asymmetric.
[0073] To enable user interaction, computing system 700 includes an input device 745 that may represent any number of input mechanisms, such as a microphone for voice, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, voice, etc. Computing system 700 may also include an output device 735 that may be one or more of a number of output mechanisms. In some instances, a multimodal system may enable a user to provide multiple types of input / output to communicate with computing system 700. Computing system 700 may include a communication interface 740 that generally may govern and manage user input and system output. The communication interface may execute or facilitate receiving and / or transmitting wired or wireless communications using a wired and / or wireless transceiver, including using an audio jack / plug, a microphone jack / plug, a universal serial bus (USB) port / plug, Apple ® Lightning ® port / plug, an Ethernet port / plug, a fiber optic port / plug, a proprietary wired port / plug, Bluetooth ® wireless signaling, Bluetooth ® low energy (BLE) wireless signaling, iBeacon ®Those communications of wireless signal transmission, radio frequency identification (RFID) wireless signal transmission, near field communication (NFC) wireless signal transmission, dedicated short range communication (DSRC) wireless signal transmission, 802.11 Wi-Fi wireless signal transmission, wireless local area network (WLAN) signal transmission, visible light communication (VLC), worldwide interoperability for microwave access (WiMAX), infrared (IR) communication wireless signal transmission, public switched telephone network (PSTN) signal transmission, integrated services digital network (ISDN) signal transmission, 3G / 4G / 5G / LTE cellular data network wireless signal transmission, ad hoc network signal transmission, radio wave signal transmission, microwave signal transmission, infrared signal transmission, visible light signal transmission, ultraviolet light signal transmission, wireless signal transmission along the electromagnetic spectrum, or some combination thereof. The communication interface 840 may also include one or more global navigation satellite system (GNSS) receivers or transceivers for determining the location of the computing system 800 based on one or more signals received from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the United States' Global Positioning System (GPS), Russia's Global Navigation Satellite System (GLONASS), China's BeiDou Navigation Satellite System (BDS), and Europe's Galileo GNSS. There are no restrictions on operating on any particular hardware arrangement, and thus the underlying features here can be easily replaced to obtain improved hardware or firmware arrangements as they are developed.
[0074] The storage device 730 can be a non-volatile and / or non-transitory and / or computer-readable memory device and can be a hard disk or other types of computer-readable media that can store computer-accessible data, such as magnetic tape cartridges, flash memory cards, solid state memory devices, digital versatile disks, cassette tapes, floppy disks, flexible disks, hard disks, magnetic tapes, magnetic stripe / tape, any other magnetic storage media, flash storage devices, memristor memories, any other solid state memory, compact disc read-only memory (CD-ROM) optical discs, rewritable compact discs (CD), digital video discs (DVD), Blu-ray discs (BDD), holographic optical discs, another optical medium, secure digital (SD) cards, micro secure digital (microSD) cards, MemoryStick ®Cards, smart card chips, EMV chips, subscriber identity module (SIM) cards, mini / micro / nano / pico SIM cards, other integrated circuit (IC) chips / cards, random access memory (RAM), static RAM (SRAM), dynamic RAM (DRAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash EPROM (FLASHEPROM), cache memory (L1 / L2 / L3 / L4 / L5 / L#), resistive random access memory (RRAM / ReRAM), phase change memory (PCM), spin transfer torque RAM (STT-RAM), other memory chips or cartridges and / or combinations thereof.
[0075] The storage device 730 may include software services, servers, services, etc. When the code defining such software is executed by the processor 710, the code causes the system to perform functions. In some examples, the hardware services that perform specific functions may include software components for performing functions stored in a computer-readable medium connected to the necessary hardware components (such as the processor 710, connection 705, output device 735, etc.).
[0076] As used herein, the term "computer-readable medium" includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other media capable of storing, containing, or carrying instructions and / or data. The computer-readable medium may include non-transitory media in which data can be stored and which do not include carrier waves and / or transient electronic signals propagated wirelessly or over a wired connection. Examples of non-transitory media may include, but are not limited to, magnetic disks or tapes, optical storage media (such as compact discs (CDs) or digital versatile discs (DVDs)), flash memory, memory or memory devices. The computer-readable medium may have code and / or machine-executable instructions stored thereon, which may represent procedures, functions, subroutines, programs, routines, subroutines, modules, software packages, classes, or any combination of instructions, data structures, or program statements. By passing and / or receiving information, data, arguments, parameters, or memory contents, a code segment can be coupled to another code segment or hardware circuit. Information, arguments, parameters, data, etc. can be passed, forwarded, or sent using any suitable means, including memory sharing, message passing, token passing, network sending, etc.
[0077] In some examples, computer-readable storage devices, media, and memories may include cables or wireless signals containing bitstreams, etc. However, when mentioned, non-transitory computer-readable storage media specifically exclude media such as power consumption, carrier signals, electromagnetic waves, and signals themselves.
[0078] Specific details were provided in the above description to provide a thorough understanding of the examples and illustrations provided herein. However, those of ordinary skill in the art will understand that the examples may be implemented without these specific details. For clarity, in some instances, the present technology may be presented as including separate functional blocks, including functional blocks that include devices, device components, operations, steps, or routines in a method embodied in software, hardware, or a combination of hardware and software. Additional components other than those shown in the figures and / or described herein may be used. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form so as not to obscure the examples with unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail so as to avoid obscuring the examples.
[0079] The above may describe various examples as processes or methods, which are depicted as flowcharts, process schematics, data flow diagrams, structure diagrams, or block diagrams. Although a flowchart may describe operations as a sequential process, many of the operations in the operations may be performed in parallel or concurrently. In addition, the order of the operations may be rearranged. A process is terminated when the operations of the process are completed, but the process may have additional operations not included in the figures. A process may correspond to a method, function, procedure, subroutine, subprogram, etc. When a process corresponds to a function, the termination of the process may correspond to the function returning to the calling function or the main function.
[0080] The processes and methods according to the above examples may be implemented using computer-executable instructions stored or otherwise obtained from a computer-readable medium. Such instructions may include, for example, instructions and data that cause or otherwise configure a general-purpose computer, a special-purpose computer, or a processing device to perform a certain function or a group of functions. Portions of the computer resources used may be accessed through a network. The computer-executable instructions may be, for example, binary, intermediate format instructions such as assembly language, firmware, source code, etc. Examples of computer-readable media that may be used to store instructions, the information used, and / or the information created during the methods according to the described examples include magnetic or optical disks, flash memory, USB devices with non-volatile memory, networked storage devices, etc.
[0081] Devices implementing the processes and methods according to these disclosures can include hardware, software, firmware, middleware, microcode, hardware description language, or any combination thereof, and can take any form factor among a variety of form factors. When implemented in software, firmware, middleware, or microcode, the program code or code segments (e.g., computer program product) for performing the necessary tasks can be stored in a computer-readable or machine-readable medium. The processor can execute the necessary tasks. Typical examples of form factors include laptop computers, smart phones, mobile phones, tablet devices, or other small form factor personal computers, personal digital assistants, rack-mounted devices, stand-alone devices, etc. The functionality described herein can also be embodied in peripheral devices or plug-in cards. By additional example, such functionality can also be implemented on a circuit board among different chips or different processes executed on a single device.
[0082] Instructions, the media for conveying such instructions, the computing resources for executing them, and other structures for supporting such computing resources are example components for providing the functions described in this disclosure.
[0083] In the foregoing description, aspects of this application have been described with reference to specific examples of this application, but those skilled in the art will recognize that this application is not limited thereto. Thus, although the illustrative examples of this application have been described in detail herein, it should be understood that the inventive concept can be implemented and adopted in other various ways, and the appended claims are intended to be construed to include these variations, unless limited by the prior art. The various features and aspects of the above applications can be used individually or jointly. In addition, the examples described herein can be utilized in any number of environments and applications beyond those described herein without departing from the broader substance and scope of this specification. Therefore, the specification and drawings should be considered illustrative rather than restrictive. For purposes of illustration, the methods are described in a specific order. It should be understood that in alternative examples, the methods can be performed in an order different from that described.
[0084] Those of ordinary skill in the art should understand that, without departing from the scope of this specification, the less than (“<”) and greater than (“>”) symbols or terms used herein can be replaced with less than or equal to (“ ”) and greater than or equal to (“ ”) symbols, respectively.
[0085] In cases where a component is described as “configured to” perform certain operations, such a configuration can be achieved, for example, by designing an electronic circuit or other hardware to perform the operations, by programming a programmable electronic circuit (e.g., a microprocessor or other suitable electronic circuit) to perform the operations, or any combination thereof.
[0086] The phrase "coupled to" means that any component is physically connected to another component directly or indirectly, and / or any component communicates with another component directly or indirectly (e.g., connected to another component through a wired or wireless connection and / or other suitable communication interfaces).
[0087] Claim language or other language that recites "at least one of" a set and / or "one or more" of a set indicates that one member of the set or multiple members of the set (in any combination) satisfy the claim. For example, claim language that recites "at least one of A and B" or "at least one of A or B" means A, B, or A and B. In another example, claim language that recites "at least one of A, B, and C" or "at least one of A, B, or C" means A, B, C, or A and B, or A and C, or B and C, or A and B and C. The language "at least one of" a set and / or "one or more" of a set does not limit the set to the items listed in the set. For example, claim language that recites "at least one of A and B" or "at least one of A or B" may mean A, B, or A and B, and may additionally include items not listed in the set of A and B.
[0088] The various illustrative logical blocks, modules, circuits, and algorithmic operations described in connection with the examples disclosed herein can be implemented as electronic hardware, computer software, firmware, or combinations thereof. To clearly illustrate this interchangeability of hardware and software, the various illustrative components, blocks, modules, circuits, and operations have been described generally above in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present application.
[0089] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices, such as a general-purpose computer, a wireless communication device such as a cellular phone, or an integrated circuit device having multiple uses, including applications in wireless communication devices such as cellular phones and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be at least partially realized by a computer-readable data storage medium comprising program code, the program code including instructions that, when executed, perform one or more of the methods described above. The computer-readable data storage medium may form part of a computer program product, which may include packaging materials. The computer-readable medium may include a memory or data storage medium, such as random access memory (RAM) (such as synchronous dynamic random access memory (SDRAM)), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), flash memory, magnetic or optical data storage media, and the like. Additionally or alternatively, the techniques may be at least partially realized by a computer-readable communication medium that carries or conveys program code in the form of instructions or data structures that can be accessed, read, and / or executed by a computer, such as a propagated signal or wave.
[0090] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other equivalent integrated or discrete logic circuits. Such a processor may be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor; but in an alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Thus, as used herein, the term "processor" may refer to any of the foregoing structures, any combination of the foregoing structures, or any other structure or apparatus suitable for implementing the techniques described herein.
[0091] Exemplary aspects of the present disclosure include:
[0092] Aspect 1: A method for image authentication for secure boot, the method comprising: obtaining an expected tag image, the expected tag image including an expected tag corresponding to an image to be loaded into a memory; loading, by a memory controller, the expected tag into a first memory region corresponding to a hardware memory authenticator; loading, by the memory controller, the image into a second memory region; providing an authentication indication to the hardware memory authenticator, wherein the authentication indication triggers the hardware memory authenticator to authenticate the image; reading a portion of the image from the second memory region; generating, at the hardware memory authenticator, an authentication tag corresponding to the portion of the image; and performing a comparison of the authentication tag with the expected tag to obtain an authentication result, wherein the authentication result is a successful match and the portion of the image is authenticated.
[0093] Aspect 2: The method according to aspect 1, wherein the expected tag image is authenticated before loading the expected tag.
[0094] Aspect 3: The method according to aspect 1 or 2, wherein the expected tag image further comprises: a plurality of additional expected tags, and wherein each additional expected tag of the plurality of additional expected tags corresponds to a separate one of a plurality of images.
[0095] Aspect 4: The method according to any one of aspects 1 to 3, wherein the hardware memory authenticator is deactivated before providing the authentication indication to the hardware memory authenticator.
[0096] Aspect 5: The method according to any one of aspects 1 to 4, the method further comprising: after performing the comparison, discarding the expected tag from the first memory region.
[0097] Aspect 6: The method according to any one of aspects 1 to 5, the method further comprising: performing a second comparison of a second authentication tag of a second portion of the image with a second expected tag to obtain a second authentication result, wherein the second authentication result is a failed match and the second portion of the image is not authenticated.
[0098] Aspect 7: The method according to any one of aspects 1 to 6, the method further comprising: restarting a subsystem of a computing device; and after the restart, authenticating an image corresponding to the subsystem using a second expected tag from the expected tag image.
[0099] Aspect 8: The method according to any one of aspects 1 to 7, wherein the expected tag image is a signed image.
[0100] Aspect 9: The method according to any one of aspects 1 to 8, wherein providing the authentication indication to the hardware memory authenticator includes: setting a bit associated with the hardware memory authenticator to a value that indicates that the hardware memory authenticator is to authenticate the image.
[0101] Aspect 10: The method according to any one of aspects 1 to 9, wherein after the image is authenticated, the image can be used for execution on a computing device.
[0102] Aspect 11: An apparatus for image authentication for secure boot, the apparatus comprising: at least one memory; and at least one processor, the at least one processor coupled to the at least one memory and configured to: obtain an expected tag image that includes an expected tag corresponding to an image to be loaded into the memory; load the expected tag into a first memory region corresponding to a hardware memory authenticator by a memory controller; load the image into a second memory region by the memory controller; provide an authentication indication to the hardware memory authenticator, wherein the authentication indication triggers the hardware memory authenticator to authenticate the image; read a portion of the image from the second memory region; generate an authentication tag corresponding to the portion of the image at the hardware memory authenticator; and perform a comparison of the authentication tag with the expected tag to obtain an authentication result, wherein the authentication result is a successful match and the portion of the image is authenticated.
[0103] Aspect 12: The apparatus according to aspect 11, wherein the expected tag image is authenticated before the expected tag is loaded.
[0104] Aspect 13: The apparatus according to aspect 11 or 12, wherein the expected tag image further includes: a plurality of additional expected tags, and wherein each additional expected tag of the plurality of additional expected tags corresponds to a separate one of a plurality of images.
[0105] Aspect 14: The apparatus according to any one of aspects 11 to 13, wherein the hardware memory authenticator is deactivated before the authentication indication is provided to the hardware memory authenticator.
[0106] Aspect 15: The apparatus according to any one of aspects 11 to 14, the apparatus further comprising: discarding the expected tag from the first memory region after the comparison is performed.
[0107] Aspect 16: The apparatus according to aspects 11 to 15, wherein the at least one processor is further configured to: perform a second comparison of a second authentication tag of the second portion of the image with a second expected tag to obtain a second authentication result, wherein the second authentication result is a failed match and the second portion of the image is not authenticated.
[0108] Aspect 17: The apparatus according to aspects 11 to 16, wherein the at least one processor is further configured to: restart a subsystem of the computing device; and after the restart, authenticate an image corresponding to the subsystem using a second expected tag from the expected tag image.
[0109] Aspect 18: The apparatus according to aspects 11 to 17, wherein the expected tag image is a signed image.
[0110] Aspect 19: The apparatus according to aspects 11 to 18, wherein providing the authentication instruction to the hardware memory authenticator includes: setting a bit associated with the hardware memory authenticator to a value that indicates the hardware memory authenticator is to authenticate the image.
[0111] Aspect 20: The apparatus according to aspects 11 to 19, wherein after the image is authenticated, the image can be used to execute on the computing device.
[0112] Aspect 21: A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to: obtain an expected tag image that includes an expected tag corresponding to an image to be loaded into a memory; load the expected tag into a first memory region corresponding to a hardware memory authenticator by a memory controller; load the image into a second memory region by the memory controller; provide an authentication instruction to the hardware memory authenticator, wherein the authentication instruction triggers the hardware memory authenticator to authenticate the image; read a portion of the image from the second memory region; generate an authentication tag corresponding to the portion of the image at the hardware memory authenticator; and perform a comparison of the authentication tag with the expected tag to obtain an authentication result, wherein the authentication result is a successful match and the portion of the image is authenticated.
[0113] Aspect 22: The non-transitory computer-readable medium according to aspect 21, wherein the expected tag image is authenticated before the expected tag is loaded.
[0114] Aspect 23: The non-transitory computer-readable medium according to aspect 21 or 22, wherein the expected tag image further includes: a plurality of additional expected tags, and wherein each additional expected tag of the plurality of additional expected tags corresponds to a separate one of the plurality of images.
[0115] Aspect 24: The non-transitory computer-readable medium according to aspects 21 to 23, wherein the hardware memory authenticator is deactivated before providing the authentication indication to the hardware memory authenticator.
[0116] Aspect 25: The non-transitory computer-readable medium according to aspects 21 to 24, the non-transitory computer-readable medium according to claim 21, wherein the instructions further cause the one or more processors to: after performing the comparison, discard the expected tag from the first memory area.
[0117] Aspect 26: The non-transitory computer-readable medium according to aspects 21 to 25, wherein the instructions further cause the one or more processors to: perform a second comparison of a second authentication tag and a second expected tag for a second portion of the image to obtain a second authentication result, wherein the second authentication result is a failed match and the second portion of the image is not authenticated.
[0118] Aspect 27: The non-transitory computer-readable medium according to aspects 21 to 26, wherein the instructions further cause the one or more processors to: restart a subsystem of the computing device; and after the restart, authenticate an image corresponding to the subsystem using a second expected tag from the expected tag image.
[0119] Aspect 28: The non-transitory computer-readable medium according to aspects 21 to 27, wherein the expected tag image is a signed image.
[0120] Aspect 29: The non-transitory computer-readable medium according to aspects 21 to 28, wherein providing the authentication indication to the hardware memory authenticator includes: setting a bit associated with the hardware memory authenticator to a value that indicates the hardware memory authenticator is to authenticate the image.
[0121] Aspect 30: The non-transitory computer-readable medium according to aspects 21 to 29, wherein after the image is authenticated, the image can be used to execute on a computing device.
Claims
1. A method for image authentication for secure boot, the method comprising: Obtaining an expected tag image, the expected tag image including an expected tag corresponding to an image to be loaded into a memory; Loading, by a memory controller, the expected tag into a first memory area corresponding to a hardware memory authenticator; Loading, by the memory controller, the image into a second memory area; Providing an authentication instruction to the hardware memory authenticator, wherein the authentication instruction triggers the hardware memory authenticator to authenticate the image; Reading a portion of the image from the second memory area; Generating, at the hardware memory authenticator, an authentication tag corresponding to the portion of the image; And Performing a comparison of the authentication tag with the expected tag to obtain an authentication result, wherein the authentication result is a successful match and the portion of the image is authenticated.
2. The method according to claim 1, wherein the expected tag image is authenticated before loading the expected tag.
3. The method according to claim 1, wherein the expected label image further comprises: A plurality of additional expected tags, and wherein each additional expected tag of the plurality of additional expected tags corresponds to a separate one of a plurality of images.
4. The method according to claim 1, wherein the hardware memory authenticator is deactivated before providing the authentication instruction to the hardware memory authenticator.
5. The method according to claim 1, wherein the method further comprises: After performing the comparison, discarding the expected tag from the first memory area.
6. The method according to claim 1, the method further comprising: Performing a second comparison of a second authentication tag of a second portion of the image with a second expected tag to obtain a second authentication result, wherein the second authentication result is a failed match and the second portion of the image is not authenticated.
7. The method according to claim 1, the method further comprising: Restarting a subsystem of a computing device; And After the restart, authenticating an image corresponding to the subsystem using a second expected tag from the expected tag image.
8. The method according to claim 1, wherein the expected tag image is a signed image.
9. The method according to claim 1, wherein providing the authentication indication to the hardware memory authenticator comprises: Setting a bit associated with the hardware memory authenticator to a value that indicates the hardware memory authenticator is to authenticate the image.
10. The method according to claim 1, wherein after the image is authenticated, the image can be used to execute on a computing device.
11. An apparatus for image authentication for secure boot, the apparatus comprising: At least one memory; And At least one processor, the at least one processor coupled to the at least one memory and configured to: Obtain an expected tag image, the expected tag image including an expected tag corresponding to an image to be loaded into a memory; Load, by a memory controller, the expected tag into a first memory area corresponding to a hardware memory authenticator; Load, by the memory controller, the image into a second memory area; Provide an authentication instruction to the hardware memory authenticator, wherein the authentication instruction triggers the hardware memory authenticator to authenticate the image; Read a portion of the image from the second memory area; Generate an authentication tag corresponding to the portion of the image at the hardware memory authenticator; And Perform a comparison of the authentication tag with the expected tag to obtain an authentication result, where the authentication result is a successful match and the portion of the image is authenticated.
12. The apparatus according to claim 11, wherein the expected tag image is authenticated before the expected tag is loaded.
13. The apparatus according to claim 11, wherein the expected tag image further comprises: A plurality of additional expected tags, and wherein each additional expected tag of the plurality of additional expected tags corresponds to a separate one of the plurality of images.
14. The apparatus according to claim 11, wherein the hardware memory authenticator is deactivated before the authentication indication is provided to the hardware memory authenticator.
15. The apparatus according to claim 11, wherein the apparatus further comprises: After performing the comparison, discard the expected tag from the first memory area.
16. The method according to claim 1, wherein the at least one processor is further configured to: perform a second comparison of a second authentication tag of a second portion of the image with a second expected tag to obtain a second authentication result, where the second authentication result is a failed match and the second portion of the image is not authenticated.
17. The apparatus according to claim 11, wherein the at least one processor is further configured to: Restart a subsystem of the computing device; and After the restart, use a second expected tag from the expected tag image to authenticate an image corresponding to the subsystem.
18. The apparatus according to claim 11, wherein the expected tag image is a signed image.
19. The apparatus according to claim 11, wherein providing the authentication indication to the hardware memory authenticator comprises: Set a bit associated with the hardware memory authenticator to a value that indicates that the hardware memory authenticator is to authenticate the image.
20. The apparatus according to claim 11, wherein after the image is authenticated, the image can be used to execute on a computing device.
21. A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to: Obtain an expected tag image that includes an expected tag corresponding to an image to be loaded into memory; Load the expected tag into a first memory area corresponding to a hardware memory authenticator by a memory controller; Load the image into a second memory area by the memory controller; Provide an authentication indication to the hardware memory authenticator, where the authentication indication triggers the hardware memory authenticator to authenticate the image; Read a portion of the image from the second memory area; Generate an authentication tag corresponding to the portion of the image at the hardware memory authenticator; And Perform a comparison of the authentication tag with the expected tag to obtain an authentication result, where the authentication result is a successful match and the portion of the image is authenticated.
22. The non-transitory computer-readable medium according to claim 21, wherein the expected tag image is authenticated before the expected tag is loaded.
23. The non-transitory computer-readable medium according to claim 21, wherein the expected label image further comprises: a plurality of additional expected tags, and each of the plurality of additional expected tags corresponds to a separate one of the plurality of images.
24. The non-transitory computer-readable medium of claim 21, wherein the hardware memory authenticator is deactivated before providing the authentication indication to the hardware memory authenticator.
25. The non-transitory computer-readable medium of claim 21, wherein the instructions further cause the one or more processors to: after performing the comparison, discard the expected tag from the first memory region.
26. The non-transitory computer-readable medium of claim 21, wherein the instructions further cause the one or more processors to: perform a second comparison of a second authentication tag and a second expected tag for a second portion of the image to obtain a second authentication result, wherein the second authentication result is a failed match and the second portion of the image is not authenticated.
27. The non-transitory computer-readable medium of claim 21, wherein the instructions further cause the one or more processors to: restart a subsystem of the computing device; and after the restart, authenticate an image corresponding to the subsystem using a second expected tag from the expected tag image.
28. The method of claim 1, wherein the expected tag image is a signed image.
29. The non-transitory computer-readable medium according to claim 21, wherein providing the authentication indication to the hardware memory authenticator includes: Set a bit associated with the hardware memory authenticator to a value that indicates the hardware memory authenticator is to authenticate the image.
30. The non-transitory computer-readable medium of claim 21, wherein after the image is authenticated, the image is available for execution on a computing device.