ECU Boot-Up Code Verification for Fast Secure Startup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic control units (ECUs) with fast boot-up requirements cannot execute secure boot processes, compromising security due to insufficient time for code verification.
Innovation Solution
An electronic control device with a controller and security verifier ensures security by verifying boot-up code during shutdown, enabling execution during next boot-up, using a secure module to validate code before execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure boot is executed during boot-up using a secure module, then security is improved, but boot-up time increases
Solution Approach 1:
The patent performs code verification during the shutdown period before the system is fully powered off. The security verifier validates the boot-up code while the system is transitioning to shutdown state, so that when fast boot-up is triggered, the verification has already been completed or can be quickly completed, eliminating the need for time-consuming verification during the critical boot-up phase.
2Reliability
If code verification is performed before code execution, then security is improved, but boot-up speed deteriorates
Solution Approach 1:
The system performs the code verification action in advance during the shutdown transition period. The security verifier validates the boot-up code before the system enters the shutdown state, so that when fast boot-up is initiated, the verification result is already available or can be quickly confirmed, allowing the system to skip the verification step during boot-up and achieve fast startup while maintaining security.
Data Source
AI summary
The present invention provides a technology to ensure security during fast boot-up. Provided according to the present invention is an electronic control device installed on a mobile body, the electronic control device including a controller which controls a microcomputer using code, a security verifier which makes security verification of the code, and boot-up code which is part of the code and is executed when the microcomputer is booted. The controller enables, when the code or the boot-up code has been verified by the security verifier at the time of a transition of the microcomputer to a shutdown state, the boot-up code to be executed during next boot-up.


