Electronic Device Secure Boot Provisioning via eFuse Key Recording
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for applying secure booting to electronic devices, such as IoT devices, are inefficient and costly, requiring individual programming by processor manufacturers, which is time-consuming and inconvenient for mass production.
Innovation Solution
A method for applying secure booting using a multi-booting mode that records an encryption key to an eFuse through a special system stored on an external memory card, allowing for efficient secure booting without additional manufacturer-provided programs, and updating the boot loader to a secure system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure booting is applied by directly recording a private key to an eFuse using an additional program provided by a processor manufacturer, then data security is improved, but production time and cost increase significantly
Solution Approach 1:
The patent applies preliminary action by pre-storing the private key in the eFuse during the manufacturing process before the device is deployed. The key is recorded in advance using a special system that can be loaded from an external memory card, eliminating the need for time-consuming individual programming during mass production while ensuring security is established before the device enters service.
Solution Approach 2:
The patent introduces an intermediary approach by using a special system that acts as a mediator between the external memory card and the eFuse. This special system loads the private key from the external memory card and records it to the eFuse, serving as an intermediate step that simplifies the manufacturing process while maintaining security requirements.
2Reliability
If secure booting is applied by using additional programs provided by processor manufacturers, then data security is improved, but manufacturing complexity and cost increase
Solution Approach 1:
The patent applies self-service by enabling the device to load and record the private key using its own boot loader and processing capabilities. The existing boot loader is utilized to load the special system from an external memory card, which then records the private key to the eFuse using the device's internal resources, eliminating the need for external manufacturer-provided programs and simplifying the manufacturing process.
3Reliability
If individual programming is performed for each electronic device by processor manufacturers, then secure booting is achieved, but production time and cost increase
Solution Approach 1:
The patent applies universality by creating a standardized special system that can be universally applied to multiple devices simultaneously. The special system is stored on an external memory card and can be loaded by any device's boot loader to record the private key to its eFuse, allowing mass production without individual programming while maintaining secure booting functionality across all devices.
Data Source
AI summary
An electronic device and a method of applying secure booting to the electronic device are provided. The electronic device executes a boot loader, identifies whether a private key is stored in an eFuse, identifies whether the boot loader is a secure system that executes secure booting by using the private key, determines a booting mode based on a result of the identification, and records an encryption key in the eFuse by using a special system loaded from an external memory card, according to the determined booting mode.


