Firmware Authentication Element for Multi-Processor Secure Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected devices face security vulnerabilities due to over-the-air firmware updates, which can be exploited by attackers to download compromised firmware or malware, especially in systems with multiple processors requiring multistage upgrades, making secure boot and authenticated firmware updates costly and challenging.

Innovation Solution

An apparatus with a firmware authentication element that uses cryptographic authentication to verify the authenticity of firmware updates for multiple processors, eliminating the need for individual authentication mechanisms in each processor by controlling the execution and updating process through signaling and secure storage of cryptographic information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each processor includes individual firmware authentication means, then each processor can independently verify firmware authenticity, but the device complexity and cost increase significantly

Engineering Contradiction:
Improvefirmware authentication reliabilityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A dedicated firmware authentication element is introduced as an intermediary component that performs cryptographic verification of firmware updates. This single authentication element serves multiple processors, eliminating the need for each processor to include its own authentication hardware while maintaining security reliability through centralized cryptographic verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If centralized firmware authentication is implemented, then the authentication process is simplified and cost reduced, but the complexity of controlling firmware execution across multiple processors increases

Engineering Contradiction:
Improveauthentication mechanism complexityVSAvoidfirmware execution control
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The authentication element provides feedback signals to processors indicating whether firmware updates are authentic and ready for execution. This feedback mechanism simplifies the processor's role to merely receiving and executing authenticated firmware while the authentication element manages the complex cryptographic verification and coordination across multiple processors

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If remote firmware updates are enabled, then system adaptability and update capability improve, but security vulnerabilities and attack surfaces increase

Engineering Contradiction:
Improvefirmware update capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Cryptographic verification of firmware authenticity is performed in advance by the authentication element before the firmware is executed by processors. This preliminary authentication action ensures that only verified, unmodified firmware can be installed through remote updates, preventing malware injection and security vulnerabilities while maintaining update adaptability

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10565380B2Apparatus and associated method for authenticating firmware
Publication Date: 2020.02.18 NXP BV
  • US10565380B2 patent drawing
  • US10565380B2 patent drawing

AI summary

An apparatus comprising an authentication processor configured to, based on received firmware and predetermined cryptographic authentication information, provide for cryptographic based authentication of the received firmware to control execution of the received firmware by any one of a plurality of processors. Each processor of the plurality of processors is uniquely addressable by a boot sequencer.