Embedded Controller Secure Boot Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure boot methods for electronic devices are vulnerable to malicious software and Trojan programs that can load before antivirus software, compromising secure information, and the use of a Trust Platform Module (TPM) increases device costs.

Innovation Solution

A secure boot method utilizing an embedded controller to verify a secure loader and BIOS through Hash verification, locking and unlocking hardware to ensure secure booting, preventing unauthorized access and ensuring the integrity of the operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a TPM chip is used to verify software and ensure secure booting, then the security reliability is improved, but the device cost increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the secure boot verification function from the dedicated TPM chip and implements it within the existing embedded controller. The embedded controller performs hash verification of the secure loader and BIOS, thereby removing the need for a separate TPM chip while maintaining security functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The embedded controller is designed to perform multiple functions: it serves as both the system controller and the secure boot verification module. By integrating the hash verification capability into the embedded controller, the system achieves multi-functionality without requiring additional dedicated security hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If antivirus software is loaded after malicious software, then the antivirus software can work, but the secure information may be compromised before antivirus protection activates

Engineering Contradiction:
Improveantivirus effectivenessVSAvoidmalicious software interference
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by verifying the secure loader and BIOS before the operating system loads any software, including antivirus programs. The embedded controller performs hash verification at this early stage to ensure that only authorized, unmodified code executes, preventing malicious software from loading before antivirus protection can activate.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9292300B2Electronic device and secure boot method
Publication Date: 2016.03.22 VIA TECH INC
  • US9292300B2 patent drawing
  • US9292300B2 patent drawing
  • US9292300B2 patent drawing

AI summary

An embodiment of the invention provides a secure boot method for an electronic device including an embedded controller and a processor. The method includes the steps of verifying a secure loader by the embedded controller, unlocking a peripheral hardware of the electronic device by the embedded controller, and executing the secure loader by the processor.