Firmware Authentication Element for Multi-Processor Secure Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Connected devices face security vulnerabilities due to over-the-air firmware updates, which can be exploited by attackers to download compromised firmware or malware, especially in systems with multiple processors requiring multistage upgrades, making secure boot and authenticated firmware updates costly and challenging.
Innovation Solution
An apparatus with a firmware authentication element that uses cryptographic authentication to verify the authenticity of firmware updates for multiple processors, eliminating the need for individual authentication mechanisms in each processor by controlling the execution and updating process through signaling and secure storage of cryptographic information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If each processor includes individual firmware authentication means, then each processor can independently verify firmware authenticity, but the device complexity and cost increase significantly
Solution Approach 1:
A dedicated firmware authentication element is introduced as an intermediary component that performs cryptographic verification of firmware updates. This single authentication element serves multiple processors, eliminating the need for each processor to include its own authentication hardware while maintaining security reliability through centralized cryptographic verification
2Device complexity
If centralized firmware authentication is implemented, then the authentication process is simplified and cost reduced, but the complexity of controlling firmware execution across multiple processors increases
Solution Approach 1:
The authentication element provides feedback signals to processors indicating whether firmware updates are authentic and ready for execution. This feedback mechanism simplifies the processor's role to merely receiving and executing authenticated firmware while the authentication element manages the complex cryptographic verification and coordination across multiple processors
3Adaptability or versatility
If remote firmware updates are enabled, then system adaptability and update capability improve, but security vulnerabilities and attack surfaces increase
Solution Approach 1:
Cryptographic verification of firmware authenticity is performed in advance by the authentication element before the firmware is executed by processors. This preliminary authentication action ensures that only verified, unmodified firmware can be installed through remote updates, preventing malware injection and security vulnerabilities while maintaining update adaptability
Data Source
AI summary
An apparatus comprising an authentication processor configured to, based on received firmware and predetermined cryptographic authentication information, provide for cryptographic based authentication of the received firmware to control execution of the received firmware by any one of a plurality of processors. Each processor of the plurality of processors is uniquely addressable by a boot sequencer.

