Embedded Controller Secure Boot Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure boot methods for electronic devices are vulnerable to malicious software and Trojan programs that can load before antivirus software, compromising secure information, and the use of a Trust Platform Module (TPM) increases device costs.
Innovation Solution
A secure boot method utilizing an embedded controller to verify a secure loader and BIOS through Hash verification, locking and unlocking hardware to ensure secure booting, preventing unauthorized access and ensuring the integrity of the operating system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a TPM chip is used to verify software and ensure secure booting, then the security reliability is improved, but the device cost increases
Solution Approach 1:
The patent extracts the secure boot verification function from the dedicated TPM chip and implements it within the existing embedded controller. The embedded controller performs hash verification of the secure loader and BIOS, thereby removing the need for a separate TPM chip while maintaining security functionality.
Solution Approach 2:
The embedded controller is designed to perform multiple functions: it serves as both the system controller and the secure boot verification module. By integrating the hash verification capability into the embedded controller, the system achieves multi-functionality without requiring additional dedicated security hardware.
2Reliability
If antivirus software is loaded after malicious software, then the antivirus software can work, but the secure information may be compromised before antivirus protection activates
Solution Approach 1:
The patent implements preliminary action by verifying the secure loader and BIOS before the operating system loads any software, including antivirus programs. The embedded controller performs hash verification at this early stage to ensure that only authorized, unmodified code executes, preventing malicious software from loading before antivirus protection can activate.
Data Source
AI summary
An embodiment of the invention provides a secure boot method for an electronic device including an embedded controller and a processor. The method includes the steps of verifying a secure loader by the embedded controller, unlocking a peripheral hardware of the electronic device by the embedded controller, and executing the secure loader by the processor.


