Bootstrap Controller Secure Boot RMA State Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional secure boot processes in computer hardware are vulnerable to malware attacks through test and debug ports, which are often disabled to prevent attacks, but this makes it difficult to assess hardware failures and perform returned merchandise authorization (RMA) processes.

Innovation Solution

An apparatus with one-time programmable (OTP) indicators and a bootstrap controller that controls boot-time switches and access to debug and test ports, enabling secure boot while allowing later analysis for RMA processes by switching between secure and RMA states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If test and debug ports are permanently disabled to prevent malware attacks, then security is improved, but the ability to assess hardware failures for RMA processes is lost

Engineering Contradiction:
ImprovesecurityVSAvoidhardware failure assessment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic control of test and debug port accessibility through a bootstrap controller that responds to different operational conditions. The system transitions between a secure state (ports disabled) and an RMA state (ports enabled), allowing the accessibility of test ports to change based on the operational context rather than being permanently fixed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational parameter of test port accessibility based on the state of one-time programmable indicators. When the bootstrap controller detects specific OTP patterns, it modifies the parameter controlling port accessibility, switching between enabled and disabled states to balance security requirements with RMA assessment needs.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication certificates are used to control access to test ports during boot, then security is improved, but the system remains vulnerable to attacks

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to attack
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security measures by using one-time programmable indicators that are programmed before the chip enters production. These OTP indicators establish a trusted foundation before the authentication certificate verification process begins, creating a hierarchical security model where hardware-based OTP protection precedes software-based certificate validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The bootstrap controller acts as an intermediary between the authentication certificate verification process and the test port access control. It mediates the interaction by using OTP indicators as a trusted reference to validate certificate-based authentication, adding an intermediate layer of security that prevents direct attacks on the certificate verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of repair

If full debug capability is available for RMA processing, then ease of repair is improved, but security during normal operation is compromised

Engineering Contradiction:
ImproveRMA processingVSAvoidsecurity
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The patent segments the operational states into distinct modes: a secure state for normal operation where test ports are disabled, and an RMA state for repair operations where test ports are enabled. The bootstrap controller divides the control logic into separate pathways that respond to different OTP indicator patterns, ensuring that full debug capability is isolated to the RMA state and cannot be accessed during secure operation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230083979A1Method and system for secure boot and RMA intervention
Publication Date: 2023.03.16 AMPERE COMPUTING LLC
  • US20230083979A1 patent drawing
  • US20230083979A1 patent drawing
  • US20230083979A1 patent drawing

AI summary

A system and method is provided that enables a processor to undergo RMA after being in a secured operating state, where the secure state includes hardware disabling of test access ports and debug ports during a boot process. The apparatus providing this computer security at power-on or boot-up may have at least two one-time programmable indicators, a bootstrap controller that controls at least two boot-time switches and reads the one-time programmable indicators, and a read only memory storing at least one instruction. The bootstrap controller calculates an operating state such as a secure state or RMA state based on the at least two one-time programmable indicators. The bootstrap controller then enables or disables an execution of the at least one instruction or enables or disables a hardware port based on the operating state. The bootstrap controller may provide switching between RMA and secure states via sequential one-time programming of indicators.