Delegated Security Attestation for Multi-Host Image Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secured SoCs face resource insufficiency and prolonged boot performance due to increased data volume of executable images, necessitating redesigns for various requirements and inefficient integrity checks.

Innovation Solution

An electronic system with multiple security devices connected to host devices, where a master security device performs attestation on slave devices to enable or disable their functionality for verifying executable images, reducing verification time and resource demands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number of SPI hosts or I2C hosts on the motherboard increases, then the required number of SPI channel monitors or I2C channel filter controllers in the security SoC increases, but redesigning or manufacturing a completely new secured SoC becomes impractical

Engineering Contradiction:
Improvenumber of host devices supportedVSAvoidsecurity SoC design complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the security verification function into multiple independent security devices. Each security device can independently verify executable images for one or more host devices. This segmentation allows the system to support multiple hosts without requiring a complete redesign of a single complex security SoC, as each security device operates independently with its own verification capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security device architecture where each security device can serve multiple host devices (SPI hosts or I2C hosts). The security devices use standardized interfaces and protocols to communicate with different types of hosts, allowing a single security device design to fulfill multiple verification roles without requiring custom designs for each host configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If the data volume of executable images is huge, then the secured SoC needs to expend more time to complete the integrity check or image verification, but boot performance becomes an issue

Engineering Contradiction:
Improveintegrity check completenessVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the verification process by distributing the integrity check workload across multiple independent security devices. Each security device handles verification for specific host devices or specific executable images in parallel. This parallelization significantly reduces the total verification time compared to a single security device processing all images sequentially, while maintaining complete integrity checking through coordinated verification across all security devices.

Inventive Principle:
Principle #1Segmentation

3Productivity

If a single secured SoC is used for all verification tasks, then resource insufficiency occurs when multiple hosts need verification, but adding more security devices increases system complexity

Engineering Contradiction:
Improveverification throughputVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the verification workload across multiple independent security devices, where each device handles a subset of verification tasks. This segmentation increases verification throughput by enabling parallel processing of executable images from multiple hosts simultaneously. The modular architecture of independent security devices actually reduces overall system complexity compared to a single monolithic security SoC that would need to handle all verification tasks, as each device can be designed and validated independently.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12536273B2Electronic system and security authority delegation method thereof
Publication Date: 2026.01.27 ASPEED TECH
  • US12536273B2 patent drawing
  • US12536273B2 patent drawing
  • US12536273B2 patent drawing

AI summary

An electronic system and a security authority delegation method thereof are provided. The electronic system includes a first host device, a second host device, a first security device, and a second security device. The first security device is connected to the first host device. The second security device is connected to the second host device and the first security device. The first security device performs an attestation process on the second security device. If the second security device passes the attestation process, the first security device enables the second security device to verify executable images of the second host device. If the second security device does not pass the attestation process, the first security device disables a function of the second security device, and the function includes verifying the executable image of the second host device.