Bus Intermediary Security Device for Boot Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic systems lack effective security measures to ensure the integrity of the boot process and prevent unauthorized access to peripheral devices over bus interfaces, such as SPI and I2C buses, which can lead to security threats and compromised system integrity.

Innovation Solution

A security device connected to the bus, equipped with a processor and interface, monitors transactions and disrupts unauthorized access by forcing dummy values on bus lines, overriding dedicated signals, and responding to bus-master devices to ensure only authorized transactions occur, using existing bus signals without additional pins or interconnections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security device monitors and disrupts unauthorized bus transactions by forcing dummy values, then system security and boot process integrity are improved, but device complexity and bus signal interference increase

Engineering Contradiction:
Improveboot process integrityVSAvoidsecurity device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security device acts as an intermediary component inserted into the existing bus architecture between the host device and peripheral devices. It monitors bus transactions and selectively disrupts unauthorized access by forcing dummy values on bus lines, while allowing legitimate transactions to pass through unchanged. This intermediary approach provides security without requiring fundamental changes to the host or peripheral devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security functionality is extracted as a separate, dedicated device rather than being integrated into the host device or peripheral devices. This extraction allows the security device to independently monitor and control bus transactions, providing specialized security functions that would complicate the main system components if integrated within them.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the security device disrupts unauthorized transactions by forcing dummy values on bus lines, then unauthorized access is prevented, but bus signal integrity and normal communication may be affected

Engineering Contradiction:
Improveaccess securityVSAvoidbus signal interference
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security device applies preliminary anti-action by preparing to force dummy values on bus lines in response to detected unauthorized transactions. The device continuously monitors bus transactions and is ready to immediately counteract unauthorized access attempts by injecting dummy values, thereby preventing harmful actions before they can compromise system security.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The security device employs feedback mechanisms by continuously monitoring bus transactions and adjusting its behavior based on the detected transaction type. When an unauthorized transaction is detected, the device responds by forcing dummy values; when a legitimate transaction is detected, the device allows normal communication to proceed. This feedback-based approach ensures that security measures are applied selectively rather than continuously, minimizing interference with normal bus operations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10691807B2Secure system boot monitor
Publication Date: 2020.06.23 NUVOTON
  • US10691807B2 patent drawing
  • US10691807B2 patent drawing
  • US10691807B2 patent drawing

AI summary

A security device includes an interface and a processor. The interface is configured for connecting to a bus that serves a host device and a non-volatile memory (NVM) device. The processor is connected to the bus in addition to the host device and the NVM device. The processor is configured to detect on the bus a boot process, in which the host device retrieves boot code from the NVM device, and to ascertain a security of the boot process, based on an authentic copy of at least part of the boot code of the host device.