CPU Boot Security via Fused Public Key Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods to prevent unauthorized operation of custom integrated circuits, such as CPUs, are either impractical for large-scale production or can be bypassed, as they rely on manual tracking, physical locking, or unique identifiers that can be modified.
Innovation Solution
Implementing public-key cryptography by fusing the public key into the CPU's non-volatile memory during manufacturing, creating a digital signature (product key hash) that must be verified during the boot process to ensure authorized operation, making it computationally infeasible to use the CPU without the corresponding private key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual tracking of each integrated circuit is used to prevent unauthorized use, then security is improved, but logistic effort and complexity increase significantly
Solution Approach 1:
The patent replaces manual tracking mechanisms with an automated authentication system. The CPU incorporates a cryptographic authentication module that automatically verifies authorization codes during the boot process, eliminating the need for manual tracking of each CPU from manufacturing to deployment. This substitution of mechanical/manual processes with automated cryptographic verification resolves the contradiction by maintaining security while dramatically reducing logistic complexity.
2Reliability
If physical locking of the CPU and server platform is used during transit, then security is improved, but the method cannot prevent unauthorized use after unlocking
Solution Approach 1:
The patent implements preliminary action by embedding an unclonable identification element in the CPU during manufacturing and pre-configuring the authentication module. This allows the CPU to perform self-authentication at the boot process stage, providing continuous security protection beyond physical transit. The authentication mechanism is activated in advance and operates automatically, extending protection from temporary physical locking to ongoing operational security.
3Reliability
If a unique identifier is stored in the CPU to prevent unauthorized use, then security is improved, but the firmware can be modified to bypass the check
Solution Approach 1:
The patent introduces an intermediary authentication module that acts as a mediator between the unique identifier and the boot process. This module implements cryptographic verification by comparing the identifier against authorized codes using secure authentication algorithms. The intermediary layer prevents direct access to the identifier and protects against firmware modification attacks, as any tampering would be detected by the cryptographic verification process.
4Reliability
If public-key cryptography is implemented by fusing the public key into the CPU, then security is improved, but device complexity increases
Solution Approach 1:
The patent merges the cryptographic authentication functionality directly into the CPU's existing boot process and control logic. The authentication module is integrated with the system's existing firmware and hardware architecture, combining security functions with operational functions. This merging approach implements public-key cryptography without requiring separate standalone security hardware, thus improving security while minimizing the increase in overall device complexity.
Data Source
AI summary
A system includes a processor coupled to an integrated circuit. The processor includes a non-volatile memory to store instructions to perform a boot process. The boot process is discontinued to prevent unauthorized use of the processor if a value received from the integrated circuit in response to a first value sent to the integrated is not valid.


