Boot Manager Mode Selection for IC Testing Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems with high security features, such as measured boot, reduce flexibility for testing and debugging along the supply chain, making it difficult to perform operations at intermediate stages due to stringent security protocols.

Innovation Solution

Implementing a boot manager that selects an operation mode based on input signals, allowing for different modes such as full operational and debug/testing modes, which can disable or block security features like measured boot and cryptographic access, enabling testing without compromising security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If high security features such as measured boot are enabled, then security level is improved, but flexibility for testing and debugging is reduced

Engineering Contradiction:
Improvesecurity levelVSAvoidflexibility for testing and debugging
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically switches between secure boot mode and test/debug mode based on operational requirements. A mode selection mechanism allows the boot manager to adapt its behavior - enabling measured boot and security protocols when in secure mode, while disabling these restrictions when in test mode, thus resolving the contradiction between maintaining high security and enabling testing flexibility

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different quality attributes are applied to different operational contexts. In secure operational contexts, full security measures including measured boot are enforced. In testing contexts, security restrictions are relaxed to allow debugging operations. This localized application of security qualities allows the system to optimize for either security or testability depending on the current operational phase

Inventive Principle:
Principle #3Local quality

2Reliability

If security features are enabled during testing, then security level is improved, but testing and debugging operations become difficult

Engineering Contradiction:
Improvesecurity levelVSAvoidtesting and debugging operations
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The boot manager implements dynamic mode switching that adjusts security feature activation based on the current operational phase. During testing operations, the system can transition to a test mode where security features are temporarily suspended or modified, making debugging operations feasible while maintaining the ability to revert to full security mode when testing is complete

Inventive Principle:
Principle #15Dynamics

3Reliability

If measured boot is enforced, then security verification is improved, but supply chain testing flexibility is reduced

Engineering Contradiction:
Improvesecurity verificationVSAvoidsupply chain testing flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The measured boot enforcement is made dynamic through mode selection. In production deployment scenarios, measured boot is fully enforced to ensure security verification. In supply chain testing scenarios, the system can switch to a test mode that relaxes or disables measured boot requirements, allowing intermediate testing and validation operations along the supply chain without compromising the security verification capability when deployed

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12164641B1Designating an operational mode for an integrated circuit
Publication Date: 2024.12.10 AMAZON TECH INC
  • US12164641B1 patent drawing
  • US12164641B1 patent drawing
  • US12164641B1 patent drawing

AI summary

An operational mode can be designated for a computing device, such as an integrated circuit. In particular, an input signal may be used to determine an operational mode, which may lead to bypassing or otherwise restricting one or more boot operations to permit use of the computing device. Such an approach provides improved flexibility to permit use of the computing device for testing or debugging while maintaining security features used during other operational modes.