Split first level bootloader for secure ASIC initialization

WO2026201455A1PCT designated stage Publication Date: 2026-10-01SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2026/054948
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-27
Filing Date
2026-02-24
Publication Date
2026-10-01

Smart Images

  • Figure EP2026054948_01102026_PF_FP_ABST
    Figure EP2026054948_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a secure boot system comprising an Application-Specific Integrated Circuit with a first level bootloader (BL1.1) and a secure storage area (SSA), an external memory (EXM), and a target memory (TMR). The secure storage area (SSA) stores a hash of a second level bootloader (BL1.2), while the external memory (EXM) stores the second level bootloader (BL1.2). The first level bootloader (BL1.1) is configured to calculate a first hash of the second level bootloader (BL1.2) in the external memory (EXM), compare it with the stored hash, load the second level bootloader (BL1.2) to the target memory (TMR) if the first hash matches, calculate a second hash of the loaded second level bootloader (BL1.2), and execute the second level bootloader (BL1.2) if the second hash matches the stored hash. This two-stage verification process ensures the integrity and security of the boot sequence in resource- constrained Application-Specific Integrated Circuit environments.
Need to check novelty before this filing date? Find Prior Art

Description

202502664 Auslandsfassung1DescriptionSPLIT FIRST LEVEL BOOTLOADER FOR SECURE ASIC INITIALIZATIONFIELD OF INVENTION

[0001] The present disclosure relates to secure boot systems for integrated circuits, and more particularly to a split first level bootloader architecture for Application-Specific Integrated Circuits [ASIC] with limited memory and high security requirements.BACKGROUND

[0002] The increasing complexity and security demands of modern integrated circuits necessitate innovative solutions to ensure secure and reliable device initialization. Application-Specific Integrated Circuits are widely used in various industries due to their optimized performance for specific tasks. However, these specialized chips often face constraints in terms of available memory and require robust security measures to protect against unauthorized access and tampering.

[0003] Boot processes for ASICs are particularly vulnerable to security threats, as they represent the initial point of execution for the entire system. Malicious actors may attempt to exploit weaknesses in the boot sequence to gain control over the device or extract sensitive information. Consequently, implementing a secure boot mechanism is paramount for maintaining the integrity and confidentiality of ASIC-based systems.

[0004] Traditional boot processes often rely on a single, monolithic bootloader to initialize the system and load subsequent software components. While this approach can be effective for simpler systems, it may not provide the flexibility and security required for more complex ASIC implementations. As ASICs continue to evolve and incorporate more sophisticated features, there is a growing need for boot architectures that can adapt to changing security requirements and hardware configurations.

[0005] Memory constraints pose a significant challenge in designing secure boot systems for ASICs. The limited on-chip memory available for storing bootloader code and security- related data necessitates efficient use of resources without compromising security. Additionally, the202502664 Auslandsfassung2ability to update and patch boot software is becoming increasingly important to address newly discovered vulnerabilities and improve system functionality over time.

[0006] Verification of boot components is a critical aspect of secure ASIC initialization. Ensuring that only authenticated and unaltered code is executed during the boot process is essential for maintaining a trusted computing environment. However, implementing robust verification mechanisms within the constraints of ASIC hardware can be challenging, particularly when balancing security requirements with performance and power consumption considerations.

[0007] As the threat landscape continues to evolve, there is an ongoing need for innovative approaches to secure boot processes in ASICs. These solutions must address the challenges of limited memory, efficient verification, and adaptability to changing security requirements while maintaining the performance and reliability expected of ASIC-based systems.

[0008] WO-2021163537-A1 discloses a secure boot method for an electronic device that involves verifying the integrity of boot components using cryptographic signatures. The method includes loading a first-stage bootloader from a read-only memory, verifying its integrity, and then using it to load and verify subsequent bootloader stages. While this approach provides a foundation for secure booting, it may not fully address the specific memory constraints and flexibility requirements of ASICs. The present invention builds upon this concept by introducing a split first level bootloader architecture that may offer improved adaptability and resource efficiency for ASIC implementations.

[0009] IIS-11250167-B2 describes a secure boot process for integrated circuits that utilizes a hardware root of trust and multiple stages of verification. The invention includes a method for securely booting a system-on-chip (SoC) by verifying the integrity of boot code stored in external memory before execution. This prior art highlights the importance of secure boot processes in integrated circuits, which is also a key focus of the present invention. However, the current invention may provide a more specialized approach tailored to the unique requirements of ASICs, potentially offering enhanced security and efficiency in resource-constrained environments.

[0010] US11280829-B1 presents a secure boot system for programmable devices that employs a multi-stage boot process with integrity verification at each stage. The system includes a first-stage bootloader stored in on-chip memory and subsequent bootloader stages stored in202502664 Auslandsfassung3external memory. While this prior art shares some similarities with the present invention in terms of using multiple bootloader stages, the current invention may offer a novel split first level bootloader architecture specifically designed for ASICs. This approach may provide additional benefits in terms of security, flexibility, and resource utilization for ASIC-based systems.CN 116775150 A discloses a chip secure boot method where a public key and signature are obtained from loaded next-stage software, a hash operation is performed on the obtained public key to obtain a first hash value, and when the first hash value is consistent with the hash reference value of the public key, the next stage software is verified based on the obtained public key and signature.US 2025 / 015981 A1 discloses a computing device configured to implement secure boot using post-quantum cryptography, wherein a CC authentication unit may implement a secure hash algorithm (SHA), including SHA-256 and SHA-512.CN 119646829 A discloses a firmware secure boot method where a hardware measurement root controls the boot sequence and, if verification fails, prevents the system from continuing to start and resets the CPU to restart the system's startup process.SUMMARY

[0011] This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter.

[0012] According to an aspect of the present disclosure, a secure boot system is provided. The secure boot system includes an Application-Specific Integrated Circuit comprising a first level bootloader and a secure storage area. The secure boot system also includes an external memory and a target memory. The secure storage area stores a hash of a second level bootloader. The external memory stores the second level bootloader. The first level bootloader is configured to calculate a first hash of the second level bootloader stored in the external memory. The first level bootloader is further configured to compare the first hash with the hash stored in the secure storage area. If the first hash matches the hash stored in the secure storage area, the first level bootloader loads the second level bootloader from the external memory to the target memory. The first level bootloader then calculates a second hash of the second level bootloader loaded in the target memory. If the second hash matches the hash202502664 Auslandsfassung4stored in the secure storage area, the first level bootloader executes the second level bootloader.

[0013] According to other aspects of the present disclosure, the secure boot system may include one or more of the following features. The first level bootloader may be stored in a readonly memory of the Application-Specific Integrated Circuit. The hash stored in the secure storage area may be a cryptographic hash generated using a secure hash algorithm. The secure hash algorithm may be selected from the group consisting of SHA-256, SHA-3, and BLAKE2. The first level bootloader may be further configured to initiate a system reset if either the first hash or the second hash does not match the hash stored in the secure storage area. The second level bootloader may be configured to perform additional hardware initialization and memory management tasks. The second level bootloader may be further configured to load and execute a main operating system or application code after completing the additional hardware initialization and memory management tasks.

[0014] According to another aspect of the present disclosure, a method for secure booting of an integrated circuit is provided. The method includes initiating a boot process with a first level bootloader stored in an Application-Specific Integrated Circuit. The method further includes calculating, by the first level bootloader, a first hash of a second level bootloader stored in an external memory. The first hash is compared with a reference hash stored in a secure storage area of the Application-Specific Integrated Circuit. If the first hash matches the reference hash, the second level bootloader is loaded from the external memory to a target memory. A second hash of the second level bootloader loaded in the target memory is calculated. If the second hash matches the reference hash, the second level bootloader is executed.

[0015] According to other aspects of the present disclosure, the method may include one or more of the following features. The method may further include initiating a system reset if either the first hash or the second hash does not match the reference hash stored in the secure storage area. The reference hash stored in the secure storage area may be a cryptographic hash generated using a secure hash algorithm. The secure hash algorithm may be selected from the group consisting of SHA-256, SHA-3, and BLAKE2. The second level bootloader may be configured to perform additional hardware initialization and memory management tasks. The second level bootloader may be further configured to load and execute a main operating system or application code after completing the additional hardware initialization and memory management tasks. The first level bootloader may be stored in a read-only memory of the Application-Specific Integrated Circuit.202502664 Auslandsfassung5

[0016] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing instructions is provided. When executed by a processor of an Application-Specific Integrated Circuit, the instructions cause the processor to perform a secure boot process. The secure boot process includes initiating a first level bootloader stored in the Application-Specific Integrated Circuit. The process further includes calculating a first hash of a second level bootloader stored in an external memory. The first hash is compared with a reference hash stored in a secure storage area of the Application-Specific Integrated Circuit. If the first hash matches the reference hash, the second level bootloader is loaded from the external memory to a target memory. A second hash of the second level bootloader loaded in the target memory is calculated. If the second hash matches the reference hash, the second level bootloader is executed.

[0017] According to other aspects of the present disclosure, the non-transitory computer-readable storage medium may include one or more of the following features. The instructions may further cause the processor to initiate a system reset if either the first hash or the second hash does not match the reference hash stored in the secure storage area. The reference hash stored in the secure storage area may be a cryptographic hash generated using a secure hash algorithm. The secure hash algorithm may be selected from the group consisting of SHA-256, SHA-3, and BLAKE2. The second level bootloader may be configured to perform additional hardware initialization and memory management tasks. The second level bootloader may be further configured to load and execute a main operating system or application code after completing the additional hardware initialization and memory management tasks.

[0018] First level bootloaderThe first level bootloader is the initial bootloader stage that executes on an integrated circuit after power-on or reset. It is typically implemented in read-only memory [ROM] and contains the core security features of the boot process. The first level bootloader is responsible for initializing critical hardware components and verifying the authenticity of subsequent boot stages. In secure debugging systems, the first level bootloader serves as the root of trust for the entire boot process. It receives and verifies unlock software, comparing it against the unique identification stored in the integrated circuit's memory. Based on this verification, the first level bootloader decides whether to activate debug or diagnosis interfaces. An implementation of a first level bootloader includes a hardcoded program in the integrated circuit's ROM that contains cryptographic keys and algorithms for verifying digital signatures. It performs basic hardware initialization, loads the second level bootloader from flash memory, and verifies its integrity before passing control.202502664 Auslandsfassung6

[0019] Second level bootloaderThe second level bootloader is a more flexible and updateable stage of the boot process that follows the first level bootloader. It is typically stored in non-volatile memory and can be updated or modified as needed. The second level bootloader provides additional functionality and configurability beyond the fixed first level bootloader. In the context of secure debugging, the second level bootloader unlock is a specialized version created specifically for enabling debug or diagnosis interfaces. It contains the necessary code and authentication mechanisms to safely unlock these interfaces while maintaining overall system security. The second level bootloader unlock is verified by the first level bootloader before execution. An implementation of a second level bootloader includes a program stored in flash memory that is loaded and verified by the first level bootloader. It performs more extensive hardware initialization, sets up memory management, and prepares the system for loading the main operating system or application code. In the case of a second level bootloader unlock, it includes additional code to enable and configure debug interfaces securely.

[0020] Application-Specific Integrated CircuitAn Application-Specific Integrated Circuit is a custom-designed integrated circuit tailored for a specific application or purpose. In the context of secure boot systems, an ASIC incorporates dedicated hardware components and security features to ensure the integrity and authenticity of the boot process. The ASIC serves as the foundation for implementing secure boot mechanisms, housing critical components such as the first level bootloader and cryptographic elements. The role of an ASIC in secure boot systems is to provide a hardware-based root of trust that is resistant to tampering and unauthorized modifications. It executes the initial stages of the boot process, verifies the integrity of subsequent boot components, and manages secure debug access. The ASIC's design allows for optimized performance and security in executing these specialized tasks. An implementation of an ASIC for secure boot systems includes a ROM containing the first level bootloader, dedicated cryptographic hardware for accelerating hash calculations and signature verifications, secure storage for cryptographic keys and deviceunique identifiers, and controlled interfaces for external memory and debug access. The ASIC also incorporates physical security measures such as anti-tamper circuitry and protected memory regions to prevent unauthorized access to sensitive information.

[0021] HashA hash is a fixed-size numerical value generated from input data of arbitrary size using a mathematical algorithm. In the context of secure boot systems, a hash function is used to create202502664 Auslandsfassung7a unique digital fingerprint of boot components, firmware, or other critical data. Calculating a hash involves processing the input data through the hash algorithm to produce the resulting hash value. The role of hashes in secure boot systems is to verify the integrity and authenticity of boot components and software. By comparing calculated hashes with pre-computed reference values, the system can detect any unauthorized modifications or corruptions in the boot process. Hashes are essential for ensuring that only trusted and unaltered code is executed during the boot sequence. An implementation of hash calculation in a secure boot system involves using a cryptographic hash function such as SHA-256 or SHA-3. The first level bootloader calculates the hash of the second level bootloader stored in external memory. This calculated hash is then compared with a reference hash value stored securely within the ASIC. If the calculated hash matches the reference hash, the system proceeds with loading and executing the second level bootloader. If the hashes do not match, the system halts the boot process or initiates a recovery procedure to prevent the execution of potentially compromised code.

[0022] The foregoing general description of the illustrative embodiments and the following detailed description thereof are merely exemplary aspects of the teachings of this disclosure and are not restrictive.BRIEF DESCRIPTION OF FIGURES

[0023] Non-limiting and non-exhaustive examples are described with reference to the following figures.FIG. 1 illustrates a block diagram of a Secure Boot System, according to aspects of the present disclosure.FIG. 2 illustrates another block diagram of a Secure Boot System, according to an embodiment. FIG. 3 illustrates a flowchart for a secure boot process method, according to aspects of the present disclosure.FIG. 4 illustrates another flowchart for a secure boot process method, according to an embodiment.DETAILED DESCRIPTION

[0024] The following description sets forth exemplary aspects of the present disclosure. It should be recognized, however, that such description is not intended as a limitation on the202502664 Auslandsfassung8scope of the present disclosure. Rather, the description also encompasses combinations and modifications to those exemplary aspects described herein.

[0025] A secure boot system SBS provides a secure and reliable method for initializing and verifying the integrity of software components in an Application-Specific Integrated Circuit ASIC. The secure boot system SBS comprises several key components that work together to ensure a trusted boot process.

[0026] The secure boot system SBS includes an Application-Specific Integrated Circuit ASIC. The Application-Specific Integrated Circuit ASIC contains a first level bootloader BL1.1 and a secure storage area SSA. A first level bootloader BL1.1 serves as the initial code executed during the boot process, while the secure storage area SSA stores critical security information.

[0027] In addition to the Application-Specific Integrated Circuit ASIC, the secure boot system SBS incorporates an external memory EXM. The external memory EXM stores a second level bootloader BL1.2, which contains more complex initialization routines and security features.

[0028] The secure boot system SBS also includes a target memory TMR. The target memory TMR serves as the destination for loading and executing verified software components during the boot process.

[0029] A crucial aspect of the secure boot system SBS is the storage of a hash of the second level bootloader BL1.2 within the secure storage area SSA of the Application-Specific Integrated Circuit ASIC. This hash acts as a reference for verifying the integrity of the second level bootloader BL1.2 stored in the external memory EXM.

[0030] The secure boot system SBS implements a multi-stage verification process to ensure the authenticity and integrity of the boot components. The first level bootloader BL1.1 initiates this process by verifying the second level bootloader BL1.2 before allowing its execution. This approach enhances the overall security of the system by preventing the execution of unauthorized or tampered code.

[0031] FIG. 1 illustrates a block diagram of the Secure Boot System SBS. The Secure Boot System SBS includes an Application-Specific Integrated Circuit ASIC and an External Memory EXM.202502664 Auslandsfassung9

[0032] The Application-Specific Integrated Circuit ASIC comprises several components. A Read-Only Memory ROM stores the first level bootloader BL1.1. A Secure Storage Area SSA includes a hash storage HS2 for storing a hash of the second level bootloader BL1.2. The Application-Specific Integrated Circuit ASIC also includes a Processor CPU.

[0033] The External Memory EXM stores the second level bootloader BL1.2. This arrangement allows for potential updates or modifications to the second level bootloader BL1.2 without altering the Application-Specific Integrated Circuit ASIC itself.

[0034] The first level bootloader BL1.1 connects to the Secure Storage Area SSA and the External Memory EXM. This connection enables the first level bootloader BL1.1 to access the stored hash in the hash storage HS2 and verify the integrity of the second level bootloader BL1.2 stored in the External Memory EXM.

[0035] The Processor CPU connects to the Read-Only Memory ROM, Secure Storage Area SSA, and External Memory EXM, allowing it to coordinate the boot process and execute the bootloaders.

[0036] During the boot process, the first level bootloader BL1.1 initiates the sequence. The first level bootloader BL1.1 calculates a first hash of the second level bootloader BL1.2 stored in the External Memory EXM. The first level bootloader BL1.1 then compares this first hash with the hash stored in the Secure Storage Area SSA.

[0037] If the first hash matches the stored hash, the first level bootloader BL1.1 loads the second level bootloader BL1.2 from the External Memory EXM to a Target Memory TMR. After loading, the first level bootloader BL1.1 calculates a second hash of the second level bootloader BL1.2 now loaded in the Target Memory TMR.

[0038] The first level bootloader BL1.1 then compares this second hash with the hash stored in the Secure Storage Area SSA. If the second hash matches the stored hash, the first level bootloader BL1.1 executes the second level bootloader BL1.2.

[0039] This architecture allows for a secure boot process with verification steps, enhancing the overall security of the system while maintaining flexibility for potential updates to the second level bootloader BL1.2 in the External Memory EXM.202502664 Auslandsfassung10

[0040] FIG. 2 illustrates a block diagram of an enhanced secure boot system SBS. The secure boot system SBS includes an Application-Specific Integrated Circuit ASIC and an External Memory EXM.

[0041] The Application-Specific Integrated Circuit ASIC comprises several components, including a first level bootloader BL1.1, a Hash Calculation Module HCM, a Verification Module VFM, a Loading Module LDM, and a System Reset Controller SRC. The Application-Specific Integrated Circuit ASIC also includes a Processor CPU, a Read-Only Memory ROM, and a Secure Storage Area SSA.

[0042] The External Memory EXM stores the second level bootloader BL1.2. This arrangement allows for potential updates or modifications to the second level bootloader BL1.2 without altering the Application-Specific Integrated Circuit ASIC itself.

[0043] The Hash Calculation Module HCM calculates hashes of the second level bootloader BL1.2 stored in the External Memory EXM and after it is loaded into the Target Memory TMR. The Verification Module VFM compares these calculated hashes with a reference hash stored in the Secure Storage Area SSA.

[0044] The Loading Module LDM loads the second level bootloader BL1.2 from the External Memory EXM to the Target Memory TMR if the first hash verification is successful. The System Reset Controller SRC connects to both the Verification Module VFM and Loading Module LDM, and initiates a system reset if any hash verification fails.

[0045] The secure boot process begins with the first level bootloader BL1.1 initiating the boot sequence. The Hash Calculation Module HCM calculates the first hash of the second level bootloader BL1.2 stored in the External Memory EXM. The Verification Module VFM then compares this hash with the reference hash stored in the Secure Storage Area SSA.

[0046] If the first hash matches the reference hash, the Loading Module LDM loads the second level bootloader BL1.2 into the Target Memory TMR. The Hash Calculation Module HCM then calculates a second hash of the loaded second level bootloader BL1.2. The Verification Module VFM verifies this second hash against the reference hash in the Secure Storage Area SSA.202502664 Auslandsfassung11

[0047] If both verifications are successful, the second level bootloader BL1.2 executes. If any verification fails, the System Reset Controller SRC initiates a system reset.

[0048] The hash stored in the Secure Storage Area SSA is a cryptographic hash generated using a secure hash algorithm. The secure hash algorithm is selected from the group consisting of SHA-256, SHA-3, and BLAKE2.

[0049] The first level bootloader BL1.1 is configured to initiate a system reset if either the first hash or the second hash does not match the hash stored in the Secure Storage Area SSA. This functionality is implemented through the System Reset Controller SRC.

[0050] The second level bootloader BL1.2 is configured to perform additional hardware initialization and memory management tasks. After completing these tasks, the second level bootloader BL1.2 loads and executes a main operating system or application code.

[0051] This architecture allows for a secure boot process with multiple verification steps, enhancing the overall security of the system while maintaining flexibility for potential updates to the second level bootloader BL1.2 in the External Memory EXM.

[0052] FIG. 3 illustrates a flowchart for a secure boot process method 500 for an Application-Specific Integrated Circuit ASIC. The method 500 begins with a step 502, where the boot process initiates with the first level bootloader BL1.1. The first level bootloader BL1.1 is stored in a Read-Only Memory ROM of the Application-Specific Integrated Circuit ASIC.

[0053] The process then moves to a step 504, where the first level bootloader BL1.1 calculates a first hash of the second level bootloader BL1.2 stored in the External Memory EXM. Following this calculation, the method 500 proceeds to a step 506, where the first hash is compared with a reference hash stored in the Secure Storage Area SSA.

[0054] After the comparison, the method 500 reaches a decision point at a step 508, where it checks if the first hash matches the reference hash. If the first hash matches, the process continues to a step 510, where the second level bootloader BL1.2 is loaded from the External Memory EXM to the Target Memory TMR.

[0055] The method 500 then progresses to a step 512, where a second hash of the loaded second level bootloader BL1.2 is calculated. After the second hash calculation, the process202502664 Auslandsfassung12reaches another decision point at a step 514, where it checks if the second hash matches the reference hash.

[0056] If the second hash matches, the method 500 moves to a step 516, where the second level bootloader BL1.2 is executed. The second level bootloader BL1.2 performs additional hardware initialization and memory management tasks. After completing these tasks, the second level bootloader BL1.2 loads and executes a main operating system or application code.

[0057] If either the first hash (at step 508) or the second hash (at step 514) does not match the reference hash, the process proceeds to a step 518, where a system reset is initiated.

[0058] The reference hash stored in the Secure Storage Area SSA is a cryptographic hash generated using a secure hash algorithm. The secure hash algorithm is selected from the group consisting of SHA-256, SHA-3, and BLAKE2.

[0059] This two-stage verification process ensures the integrity of the second level bootloader BL1.2 both in the External Memory EXM and after loading it into the Target Memory TMR. The method 500 incorporates decision points that determine whether to proceed with the boot process or initiate a system reset based on the hash verification results.

[0060] FIG. 4 illustrates a flowchart for an alternative secure boot process method 600 for an Application-Specific Integrated Circuit ASIC. The method 600 begins with a step 602, where power is applied to the Application-Specific Integrated Circuit ASIC containing the first level bootloader BL1.1 and the Secure Storage Area SSA.

[0061] The process then moves to a step 604, where the first level bootloader BL1.1 calculates a first hash of the second level bootloader BL1.2 stored in the External Memory EXM. Following this calculation, the method 600 proceeds to a step 606, where the first level bootloader BL1.1 compares the first hash with a reference hash stored in the Secure Storage Area SSA.

[0062] If the first hash matches the reference hash, the process continues to a step 608, where the first level bootloader BL1.1 loads the second level bootloader BL1.2 from the External Memory EXM to the Target Memory TMR. The method 600 then progresses to a step 610, where the first level bootloader BL1.1 calculates a second hash of the second level bootloader BL1.2 now loaded in the Target Memory TMR.

[0063] After the second hash calculation, the process reaches a decision point at a step 612, where the first level bootloader BL1.1 checks if the second hash matches the reference hash202502664 Auslandsfassung13stored in the Secure Storage Area SSA. If the second hash matches the reference hash, the method 600 moves to a step 614, where the second level bootloader BL1.2 is executed.

[0064] If either the first hash (at step 606) or the second hash (at step 612) does not match the reference hash stored in the Secure Storage Area SSA, the process proceeds to a step 616, where the boot process is halted or recovery is initiated.

[0065] The method 600 differs from the process shown in FIG. 3 in its handling of verification failures. Instead of initiating a system reset, this alternative method 600 halts the boot process or initiates a recovery procedure. This approach provides more flexibility in responding to potential security breaches or corruption of the second level bootloader BL1.2.

[0066] In some cases, the Processor CPU of the Application-Specific Integrated Circuit ASIC executes instructions stored in a non-transitory computer-readable storage medium to perform the secure boot process method 600. These instructions implement the steps of the method 600, including the initiation of the first level bootloader BL1.1, hash calculations, comparisons, and decision-making processes.

[0067] The first level bootloader BL1.1 is stored in the Read-Only Memory ROM of the Application-Specific Integrated Circuit ASIC, ensuring its integrity and availability at the start of the boot process. The Hash Calculation Module HCM performs the hash calculations in steps 604 and 610, while the Verification Module VFM handles the hash comparisons in steps 606 and 612.

[0068] The Loading Module LDM is responsible for loading the second level bootloader BL1.2 from the External Memory EXM to the Target Memory TMR in step 608. If a hash mismatch occurs, instead of using the System Reset Controller SRC to initiate a system reset, the method 600 implements a more nuanced approach by halting the boot process or initiating a recovery procedure in step 616.

[0069] This alternative secure boot process provides enhanced flexibility in handling potential security issues while maintaining the core principles of verifying the integrity of the second level bootloader BL1.2 through multiple hash checks.

[0070] The secure boot system SBS supports various implementations and modifications to enhance security, flexibility, and performance. These variations allow the system to adapt to different hardware configurations and security requirements.202502664 Auslandsfassung14

[0071] The hash algorithm used for verifying the second level bootloader BL1.2 supports implementation using different cryptographic hash functions. In some cases, SHA-256 serves as the hash algorithm. Alternatively, SHA-3 or BLAKE2 function as the hash algorithm. The choice of hash algorithm depends on factors such as computational efficiency, security strength, and hardware support.

[0072] The storage location for the second level bootloader BL1.2 varies across implementations. In some cases, the second level bootloader BL1.2 resides in on-chip flash memory. Alternatively, EEPROM stores the second level bootloader BL1.2. In other implementations, a secure element houses the second level bootloader BL1.2. The selection of storage location balances factors including security, cost, and read / write performance.

[0073] The boot process incorporates additional verification stages in some implementations. For example, an intermediate verification occurs after loading a portion of the second level bootloader BL1.2. This approach allows for earlier detection of potential tampering or corruption.

[0074] Error handling approaches differ across implementations. In some cases, the system enters a secure recovery mode upon failed verification. Alternatively, the system logs detailed error information for later analysis. Some implementations use a retry mechanism with a limited number of attempts before forcing a system reset.

[0075] The functionality of the first level bootloader BL1.1 expands in certain implementations. For instance, the first level bootloader BL1.1 performs basic hardware initialization tasks beyond verifying and loading the second level bootloader BL1.2. These tasks include initializing critical system clocks, setting up basic memory controllers, or performing essential power management tasks. The specific additional functions depend on the particular hardware architecture and requirements.

[0076] These variations and alternative implementations provide flexibility in adapting the secure boot system SBS to diverse hardware platforms and security needs. The modular nature of the system allows for customization without compromising the core security principles.

[0077] A number of implementations have been described. Nevertheless, it will be understood that various modifications may be made without departing from the spirit and scope of the disclosure. Accordingly, other implementations are within the scope of the following claims.

Claims

202502664 Auslandsfassung15CLAIMS1. A secure boot system, comprising:an Application-Specific Integrated Circuit (ASIC) comprising a first level bootloader (BL1.1) and a secure storage area (SSA);an external memory (EXM); anda target memory (TMR);characterised in that:the secure storage area (SSA) stores a hash of a second level bootloader (BL1.2);the external memory (EXM) stores the second level bootloader (BL1.2); andthe first level bootloader (BL1.1) is configured to:calculate a first hash of the second level bootloader (BL1.2) stored in the external memory (EXM);compare the first hash with the hash stored in the secure storage area (SSA);load the second level bootloader (BL1.2) from the external memory (EXM) to the target memory (TMR) if the first hash matches the hash stored in the secure storage area (SSA); calculate a second hash of the second level bootloader (BL1.2) loaded in the target memory (TMR); andexecute the second level bootloader (BL1.2) if the second hash matches the hash stored in the secure storage area (SSA).

2. The secure boot system of claim 1, wherein the first level bootloader (BL1.1) is stored in a read-only memory (ROM) of the Application-Specific Integrated Circuit (ASIC).

3. The secure boot system of claim 1, wherein the hash stored in the secure storage area (SSA) is a cryptographic hash generated using a secure hash algorithm.

4. The secure boot system of claim 3, wherein the secure hash algorithm is selected from the group consisting of SHA-256, SHA-3, and BLAKE2.

5. The secure boot system of claim 1, wherein the first level bootloader (BL1.1) is further configured to initiate a system reset if either the first hash or the second hash does not match the hash stored in the secure storage area (SSA).202502664 Auslandsfassung166. The secure boot system of claim 1, wherein the second level bootloader (BL1.2) is configured to perform additional hardware initialization and memory management tasks.

7. The secure boot system of claim 6, wherein the second level bootloader (BL1.2) is further configured to load and execute a main operating system or application code after completing the additional hardware initialization and memory management tasks.

8. A method for secure booting of an integrated circuit, comprising:initiating a boot process with a first level bootloader (BL1.1) stored in an Application-Specific Integrated Circuit (ASIC);characterised by:calculating, by the first level bootloader (BL1.1), a first hash of a second level bootloader (BL1.2) stored in an external memory (EXM);comparing the first hash with a reference hash stored in a secure storage area (SSA) of the Application-Specific Integrated Circuit (ASIC);loading the second level bootloader (BL1.2) from the external memory (EXM) to a target memory (TMR) if the first hash matches the reference hash;calculating a second hash of the second level bootloader (BL1.2) loaded in the target memory (TMR); andexecuting the second level bootloader (BL1.2) if the second hash matches the reference hash.

9. The method of claim 8, further comprising initiating a system reset if either the first hash or the second hash does not match the reference hash stored in the secure storage area (SSA).

10. The method of claim 8, wherein the reference hash stored in the secure storage area (SSA) is a cryptographic hash generated using a secure hash algorithm.

11. The method of claim 10, wherein the secure hash algorithm is selected from the group consisting of SHA-256, SHA-3, and BLAKE2.

12. The method of claim 8, wherein the second level bootloader (BL1.2) is configured to perform additional hardware initialization and memory management tasks.

13. The method of claim 12, wherein the second level bootloader (BL1.2) is further configured to load and execute a main operating system or application code after completing the additional hardware initialization and memory management tasks.202502664 Auslandsfassung1714. The method of claim 8, wherein the first level bootloader (BL1.1) is stored in a read-only memory (ROM) of the Application-Specific Integrated Circuit (ASIC).

15. A non-transitory computer-readable storage medium storing instructions that, when executed by a processor of an Application-Specific Integrated Circuit (ASIC), cause the processor to perform a secure boot process comprising:initiating a first level bootloader (BL1.1) stored in the Application-Specific Integrated Circuit (ASIC);characterised by:calculating a first hash of a second level bootloader (BL1.2) stored in an external memory (EXM);comparing the first hash with a reference hash stored in a secure storage area (SSA) of the Application-Specific Integrated Circuit (ASIC);loading the second level bootloader (BL1.2) from the external memory (EXM) to a target memory (TMR) if the first hash matches the reference hash;calculating a second hash of the second level bootloader (BL1.2) loaded in the target memory (TMR); andexecuting the second level bootloader (BL1.2) if the second hash matches the reference hash.

16. The non-transitory computer-readable storage medium of claim 15, wherein the instructions further cause the processor to initiate a system reset if either the first hash or the second hash does not match the reference hash stored in the secure storage area (SSA).

17. The non-transitory computer-readable storage medium of claim 15, wherein the reference hash stored in the secure storage area (SSA) is a cryptographic hash generated using a secure hash algorithm.

18. The non-transitory computer-readable storage medium of claim 17, wherein the secure hash algorithm is selected from the group consisting of SHA-256, SHA-3, and BLAKE2.

19. The non-transitory computer-readable storage medium of claim 15, wherein the second level bootloader (BL1.2) is configured to perform additional hardware initialization and memory management tasks.202502664 Auslandsfassung1820. The non-transitory computer-readable storage medium of claim 19, wherein the second level bootloader (BL1.2) is further configured to load and execute a main operating system or application code after completing the additional hardware initialization and memory management tasks.