Dual CPU Boot Verification for Secure Startup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information processing systems face challenges in detecting alterations of programs stored in external memory, particularly when settings are configured to avoid detection, leading to security vulnerabilities and increased manufacturing costs due to the need for re-writable storage for public key and encryption method settings.

Innovation Solution

An information processing apparatus and method that includes a first CPU, a second CPU, a first nonvolatile memory for storing a boot program, and a second nonvolatile memory for storing boot programs, where the first CPU determines if a verification method is set for program alteration, executing the appropriate boot program to write settings and verify program integrity, ensuring secure startup.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security settings (public key, encryption method) are stored in a re-writable storage apparatus to allow flexible configuration according to shipment destination and application, then adaptability is improved, but the risk of undetected alteration increases and manufacturing cost increases due to writing time

Engineering Contradiction:
Improveflexibility of security settingsVSAvoidsecurity of program integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the boot program into two distinct programs: a first boot program for initial setup and a second boot program for normal operation with verification. This segmentation allows the system to separate the configuration phase from the operational phase, enabling flexible security settings to be written during manufacturing while ensuring integrity verification during normal operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by requiring that security settings (public key, encryption method) be written into the storage apparatus during the manufacturing process before the product is shipped. This preliminary configuration allows the system to be customized for different shipment destinations and applications while maintaining security through subsequent verification.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security settings are stored in a non-re-writable storage apparatus like ROM to ensure security, then program integrity is improved, but adaptability deteriorates as settings cannot be changed according to shipment destination and application

Engineering Contradiction:
Improvesecurity of program integrityVSAvoidflexibility of security settings
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by making the storage apparatus re-writable during the manufacturing process but enabling integrity verification during normal operation. The system dynamically transitions from a writable state during configuration to a verified-read-only state during operation, combining the benefits of both flexibility and security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback through the verification mechanism where the second boot program reads the security settings from the storage apparatus and verifies their integrity using encryption. This feedback loop ensures that any unauthorized alterations are detected, maintaining security while allowing flexible configuration during manufacturing.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If a program is written to an OTP-ROM for boot operation, then adaptability is improved, but manufacturing time increases leading to higher manufacturing cost

Engineering Contradiction:
Improvecustomization of security settingsVSAvoidwriting time to OTP-ROM
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies partial action by writing only the necessary security settings (public key, encryption method) to the storage apparatus during manufacturing, rather than writing entire programs. This reduces the writing time and manufacturing cost while still achieving the required adaptability for different shipment destinations and applications.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11914714B2Information processing apparatus and start-up method of the same
Publication Date: 2024.02.27 CANON KK
  • US11914714B2 patent drawing
  • US11914714B2 patent drawing
  • US11914714B2 patent drawing

AI summary

An information processing apparatus includes a first CPU, a second CPU, a first nonvolatile memory that stores a boot program to be executed by the first CPU at a time of start-up, and a second nonvolatile memory that stores a first boot program and a second boot program for verifying a program. The first CPU determines whether or not a verification method is set in the first nonvolatile memory, and if not, the first CPU executes the first boot program, and writes the setting of the verification method to the second nonvolatile memory. If the verification method is set, the first CPU executes the second boot program in accordance with the setting, and when the processing of the second boot program is normally ended, the second CPU starts up the information processing apparatus.