Boot System Memory Segmentation for Illegal Operation Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic devices face issues with protecting their boot programs from illegal operations, as current methods are ineffective in reducing attacks on the boot program during the boot process.
Innovation Solution
An electronic device with a controller that controls a first memory to be inaccessible and a second memory to be accessible after a power-on self-test, allowing only authorized updates to be stored in the second memory, thereby preventing illegal operations on the boot system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the boot program is made accessible for normal operations, then ease of operation is improved, but security against illegal operations deteriorates
Solution Approach 1:
The patent divides the memory into two separate regions: a first memory for storing the boot program and a second memory for storing updated boot programs. The controller is configured to block access to the first memory while allowing access to the second memory, effectively segmenting the functionality to prevent illegal operations on the original boot program while maintaining operational capability through the updated version.
Solution Approach 2:
The controller acts as an intermediary between the memory systems and the processing units. It mediates access rights by blocking direct access to the first memory containing the original boot program, while allowing access to the second memory containing updated versions, thus preventing illegal operations without completely disabling boot program functionality.
2Object-affected harmful factors
If the boot program is isolated to prevent illegal operations, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent segments the boot program storage into two distinct memory regions with different access characteristics. The first memory stores the protected original boot program with blocked access, while the second memory stores updated versions with enabled access, allowing the system to maintain security while preserving operational capability through proper segmentation.
Solution Approach 2:
The patent implements a copying mechanism where updated boot programs are stored in the second memory as copies of the original boot program from the first memory. This allows the system to maintain the protected original version while having accessible copies available for operation, thus preserving both security and ease of operation.
3Device complexity
If a single memory is used for boot program storage, then device complexity is reduced, but reliability of boot program protection deteriorates
Solution Approach 1:
The patent introduces segmentation of the memory system into two distinct regions: a first memory for storing the protected boot program and a second memory for storing updated versions. This segmentation, while increasing structural complexity, significantly enhances the reliability of boot program protection by enabling selective access control and preventing illegal operations on the original boot program.
Data Source
AI summary
Control method and electronic device are provided. The electronic device includes: a controller; a first memory, connected to the controller and storing at least a boot system; and a second memory, connected to the controller, for storing update data of the boot system. After the electronic device completes a power-on self-test, the controller controls the first memory to be in an inaccessible state and controls the second memory to be in an accessible state.


