Firmware Certificate Hash Binding for Boot Time Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for updating firmware in electronic devices often require lengthy verification processes during booting, which can increase boot time and compromise security.
Innovation Solution
A method that involves verifying a firmware certificate using a public key upon power supply or reset, and then verifying a firmware code based on a hash value within the certificate, allowing for efficient and secure firmware updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firmware verification is performed during booting, then security is improved, but boot time increases
Solution Approach 1:
The patent applies preliminary action by verifying the firmware certificate and binding the hash value to the certificate before the booting process begins. The firmware image includes a certificate with a bound hash value that is verified in advance, allowing the booting process to proceed without performing full firmware verification during startup, thus reducing boot time while maintaining security
Solution Approach 2:
The patent introduces an intermediary element - the bound hash value embedded in the firmware certificate. This hash value acts as a mediator between the firmware code and the verification process, allowing quick verification by comparing the calculated hash of the running firmware against the pre-bound hash in the certificate, rather than verifying the entire firmware during boot
Data Source
AI summary
A method for updating firmware of an electronic device includes verifying a first firmware certificate using a first public key, based on at least one of the electronic device being supplied power or the electronic device being reset, verifying a first firmware code included in the first firmware image based on a first hash value included in the first firmware certificate, and operating the electronic device using the first firmware code, based on the verifying of the first firmware certificate and the verifying of the first firmware code being successful. The first firmware certificate being included in a first firmware image stored in a memory of the electronic device.


