Device Unit Operating State Configuration for Secure Boot Flexibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial embedded systems face challenges in maintaining security and integrity while allowing users to run modified software or firmware without compromising the security of industrial automation and control systems, as existing secure boot mechanisms restrict user flexibility and may jeopardize system integrity.

Innovation Solution

A device unit with multiple operating states, including a protected 'closed mode' for authorized software execution and an 'open mode' for user-configurable software, using cryptographic means to manage and switch between these states, ensuring integrity protection and user flexibility through device authentication and certificate management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure boot mechanisms are implemented to protect system integrity, then system security is improved, but user flexibility to run modified software deteriorates

Engineering Contradiction:
Improvesystem securityVSAvoiduser flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system is segmented into two distinct operating modes: a first operating mode with full secure boot protection for system security, and a second operating mode with relaxed restrictions for user flexibility. The secure boot mechanism selectively activates or deactivates based on the current operating mode, allowing both security and flexibility to coexist in different operational contexts.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cryptographic means are used to protect software execution, then system integrity is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesystem integrityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The secure boot configuration is made dynamic rather than static. The system can switch between a first operating mode where secure boot is active and a second operating mode where it is deactivated. This dynamic configuration allows the system to adapt its security level and operational ease based on current needs, resolving the contradiction between system integrity and ease of operation.

Inventive Principle:
Principle #15Dynamics

3Reliability

If BIOS password security is strengthened to protect secure boot, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesecure boot securityVSAvoidexpenditure to keep BIOS password secure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure boot configuration capability is extracted from the BIOS password protection mechanism. Instead of relying solely on BIOS password security, the system provides a dedicated module that can configure secure boot activation/deactivation independently. This separates the configuration function from the password protection mechanism, reducing the complexity and expenditure associated with maintaining high-level BIOS password security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11914715B2Device unit suitable for operation in a protected and/or open operating state and associated method
Publication Date: 2024.02.27 SIEMENS AG
  • US11914715B2 patent drawing
  • US11914715B2 patent drawing

AI summary

Provided is a device unit, including a module, which can configure the device unit with an operating state from among different operating states during the start-up process and/or during ongoing operation of the device unit, wherein a first protected operating state of the different operating states is designed to allow the execution of at least one operating process which can be predefined and to optionally protect the operating process by means of defined cryptographic means, wherein at least one second operating state of the different operating states is designed to deactivate the first protected operating state and to allow at least one other changeable operating process and to optionally protect the operating process by means of specifiable cryptographic means.