Boot Code Alteration Detection With Specific-Area Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies fail to identify and address alterations in specific areas of boot code, such as layout information, within a nonvolatile memory, and cannot effectively recover altered boot code without disrupting early-stage activation functions.
Innovation Solution
An information processing apparatus is equipped with a first storage medium storing boot code and specific area signature values, enabling detection and recovery of alterations by using boot code and specific area signature values, with a built-in controller performing verification and recovery processes independently of the CPU.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If signature verification is performed on the entire boot code, then alteration detection is achieved, but the altered area cannot be identified
Solution Approach 1:
The boot code is divided into multiple specific areas, each with its own signature value stored in the nonvolatile memory. The alteration detection unit verifies each specific area independently using its corresponding signature value, enabling both detection of alterations and identification of the altered area location.
2Reliability
If recovery processing is performed without network functions, then early-stage activation is maintained, but the scope of recovery is limited
Solution Approach 1:
Multiple specific area signature values are prepared and stored in the nonvolatile memory beforehand. When alteration is detected, the alteration detection unit immediately identifies the altered area using these pre-stored signatures, enabling recovery processing to be performed within the existing activation framework without requiring network functions or expanding the recovery scope beyond what is already supported.
Data Source
AI summary
An information processing apparatus includes a first storage medium configured to store a first boot code, a boot code signature value for the entire first boot code, and a specific area signature value for a specific area in the first storage medium, and an alteration detection unit configured to perform detection of an alteration of the first boot code by using the boot code signature value stored in the first storage medium, and perform detection of an alteration in the specific area by using the specific area signature value stored in the first storage medium.


