Electronic Device Secure Boot Provisioning via eFuse Key Recording

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for applying secure booting to electronic devices, such as IoT devices, are inefficient and costly, requiring individual programming by processor manufacturers, which is time-consuming and inconvenient for mass production.

Innovation Solution

A method for applying secure booting using a multi-booting mode that records an encryption key to an eFuse through a special system stored on an external memory card, allowing for efficient secure booting without additional manufacturer-provided programs, and updating the boot loader to a secure system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure booting is applied by directly recording a private key to an eFuse using an additional program provided by a processor manufacturer, then data security is improved, but production time and cost increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidproduction efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-storing the private key in the eFuse during the manufacturing process before the device is deployed. The key is recorded in advance using a special system that can be loaded from an external memory card, eliminating the need for time-consuming individual programming during mass production while ensuring security is established before the device enters service.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary approach by using a special system that acts as a mediator between the external memory card and the eFuse. This special system loads the private key from the external memory card and records it to the eFuse, serving as an intermediate step that simplifies the manufacturing process while maintaining security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure booting is applied by using additional programs provided by processor manufacturers, then data security is improved, but manufacturing complexity and cost increase

Engineering Contradiction:
Improvedata securityVSAvoidmanufacturing ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies self-service by enabling the device to load and record the private key using its own boot loader and processing capabilities. The existing boot loader is utilized to load the special system from an external memory card, which then records the private key to the eFuse using the device's internal resources, eliminating the need for external manufacturer-provided programs and simplifying the manufacturing process.

Inventive Principle:
Principle #25Self-service

3Reliability

If individual programming is performed for each electronic device by processor manufacturers, then secure booting is achieved, but production time and cost increase

Engineering Contradiction:
Improvesecure bootingVSAvoidproduction time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies universality by creating a standardized special system that can be universally applied to multiple devices simultaneously. The special system is stored on an external memory card and can be loaded by any device's boot loader to record the private key to its eFuse, allowing mass production without individual programming while maintaining secure booting functionality across all devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12423436B2Electronic device and method for applying secure booting to electronic device
Publication Date: 2025.09.23 SAMSUNG ELECTRONICS CO LTD
  • US12423436B2 patent drawing
  • US12423436B2 patent drawing
  • US12423436B2 patent drawing

AI summary

An electronic device and a method of applying secure booting to the electronic device are provided. The electronic device executes a boot loader, identifies whether a private key is stored in an eFuse, identifies whether the boot loader is a secure system that executes secure booting by using the private key, determines a booting mode based on a result of the identification, and records an encryption key in the eFuse by using a special system loaded from an external memory card, according to the determined booting mode.