Boot System Memory Segmentation for Illegal Operation Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices face issues with protecting their boot programs from illegal operations, as current methods are ineffective in reducing attacks on the boot program during the boot process.

Innovation Solution

An electronic device with a controller that controls a first memory to be inaccessible and a second memory to be accessible after a power-on self-test, allowing only authorized updates to be stored in the second memory, thereby preventing illegal operations on the boot system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the boot program is made accessible for normal operations, then ease of operation is improved, but security against illegal operations deteriorates

Engineering Contradiction:
Improveaccessibility of boot programVSAvoidillegal operations on boot program
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides the memory into two separate regions: a first memory for storing the boot program and a second memory for storing updated boot programs. The controller is configured to block access to the first memory while allowing access to the second memory, effectively segmenting the functionality to prevent illegal operations on the original boot program while maintaining operational capability through the updated version.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The controller acts as an intermediary between the memory systems and the processing units. It mediates access rights by blocking direct access to the first memory containing the original boot program, while allowing access to the second memory containing updated versions, thus preventing illegal operations without completely disabling boot program functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the boot program is isolated to prevent illegal operations, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveprotection from illegal operationsVSAvoidaccessibility of boot program
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent segments the boot program storage into two distinct memory regions with different access characteristics. The first memory stores the protected original boot program with blocked access, while the second memory stores updated versions with enabled access, allowing the system to maintain security while preserving operational capability through proper segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a copying mechanism where updated boot programs are stored in the second memory as copies of the original boot program from the first memory. This allows the system to maintain the protected original version while having accessible copies available for operation, thus preserving both security and ease of operation.

Inventive Principle:
Principle #26Copying

3Device complexity

If a single memory is used for boot program storage, then device complexity is reduced, but reliability of boot program protection deteriorates

Engineering Contradiction:
Improvememory structureVSAvoidboot program protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces segmentation of the memory system into two distinct regions: a first memory for storing the protected boot program and a second memory for storing updated versions. This segmentation, while increasing structural complexity, significantly enhances the reliability of boot program protection by enabling selective access control and preventing illegal operations on the original boot program.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11921599B2Control method and electronic device
Publication Date: 2024.03.05 LENOVO (BEIJING) LTD
  • US11921599B2 patent drawing
  • US11921599B2 patent drawing
  • US11921599B2 patent drawing

AI summary

Control method and electronic device are provided. The electronic device includes: a controller; a first memory, connected to the controller and storing at least a boot system; and a second memory, connected to the controller, for storing update data of the boot system. After the electronic device completes a power-on self-test, the controller controls the first memory to be in an inaccessible state and controls the second memory to be in an accessible state.