CPU Boot Security via Fused Public Key Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods to prevent unauthorized operation of custom integrated circuits, such as CPUs, are either impractical for large-scale production or can be bypassed, as they rely on manual tracking, physical locking, or unique identifiers that can be modified.

Innovation Solution

Implementing public-key cryptography by fusing the public key into the CPU's non-volatile memory during manufacturing, creating a digital signature (product key hash) that must be verified during the boot process to ensure authorized operation, making it computationally infeasible to use the CPU without the corresponding private key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual tracking of each integrated circuit is used to prevent unauthorized use, then security is improved, but logistic effort and complexity increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidlogistic effort
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual tracking mechanisms with an automated authentication system. The CPU incorporates a cryptographic authentication module that automatically verifies authorization codes during the boot process, eliminating the need for manual tracking of each CPU from manufacturing to deployment. This substitution of mechanical/manual processes with automated cryptographic verification resolves the contradiction by maintaining security while dramatically reducing logistic complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical locking of the CPU and server platform is used during transit, then security is improved, but the method cannot prevent unauthorized use after unlocking

Engineering Contradiction:
ImprovesecurityVSAvoidprotection duration
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by embedding an unclonable identification element in the CPU during manufacturing and pre-configuring the authentication module. This allows the CPU to perform self-authentication at the boot process stage, providing continuous security protection beyond physical transit. The authentication mechanism is activated in advance and operates automatically, extending protection from temporary physical locking to ongoing operational security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a unique identifier is stored in the CPU to prevent unauthorized use, then security is improved, but the firmware can be modified to bypass the check

Engineering Contradiction:
ImprovesecurityVSAvoidfirmware integrity
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent introduces an intermediary authentication module that acts as a mediator between the unique identifier and the boot process. This module implements cryptographic verification by comparing the identifier against authorized codes using secure authentication algorithms. The intermediary layer prevents direct access to the identifier and protects against firmware modification attacks, as any tampering would be detected by the cryptographic verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If public-key cryptography is implemented by fusing the public key into the CPU, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the cryptographic authentication functionality directly into the CPU's existing boot process and control logic. The authentication module is integrated with the system's existing firmware and hardware architecture, combining security functions with operational functions. This merging approach implements public-key cryptography without requiring separate standalone security hardware, thus improving security while minimizing the increase in overall device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11341248B2Method and apparatus to prevent unauthorized operation of an integrated circuit in a computer system
Publication Date: 2022.05.24 INTEL CORP
  • US11341248B2 patent drawing
  • US11341248B2 patent drawing
  • US11341248B2 patent drawing

AI summary

A system includes a processor coupled to an integrated circuit. The processor includes a non-volatile memory to store instructions to perform a boot process. The boot process is discontinued to prevent unauthorized use of the processor if a value received from the integrated circuit in response to a first value sent to the integrated is not valid.