Firmware Source Verification Using OTP Identity and Root of Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firmware loaded by unauthorized entities during device manufacturing can lead to unauthorized access and system malfunction, compromising device security and integrity.

Innovation Solution

Implementing a Root of Trust (ROT) firmware that verifies the identity of the manufacturing firmware by comparing it with an identity stored in One Time Programmable (OTP) memory, ensuring only authorized firmware is executed and generating device secret keys only if the identity matches, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If firmware is loaded during device manufacturing without identity verification, then device manufacturing and firmware updates are simplified and faster, but device security and firmware integrity are compromised due to unauthorized access

Engineering Contradiction:
Improvefirmware loading speedVSAvoiddevice security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by storing the firmware provider identity in OTP memory during device manufacturing before the firmware is actually loaded and executed. This pre-established identity record enables later verification without slowing down the firmware loading process, as the verification can be performed quickly by comparing against the pre-stored identity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism using OTP memory to store and compare firmware provider identities. This intermediary layer acts as a trusted mediator between the firmware loading process and security verification, allowing automated identity checking without requiring complex manual verification procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If identity verification is implemented for firmware providers, then device security and firmware integrity are improved, but device complexity and manufacturing process complexity increase

Engineering Contradiction:
Improvefirmware integrityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security verification function into a separate, dedicated component using OTP memory to store firmware provider identities. This segmentation isolates the verification logic from the main firmware loading process, reducing overall system complexity by creating a modular, independent verification subsystem that can be implemented as a simple compare operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses OTP (One Time Programmable) memory to store firmware provider identities, which is a simple, non-reconfigurable storage medium. This disposable-like approach to identity storage simplifies the verification system, as OTP memory provides secure, write-once storage without requiring complex update or management mechanisms.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of operation

If secret keys are generated for unauthorized firmware, then firmware functionality is maintained, but unauthorized access to device data and system malfunction occur

Engineering Contradiction:
Improvefirmware executionVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing identity verification before secret key generation. The system proactively prevents unauthorized firmware from obtaining secret keys by checking the firmware provider identity against the OTP-stored identity in advance, thereby blocking unauthorized access before it can occur rather than reacting to it later.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements a feedback mechanism where the secret key generation process is conditioned on the result of identity verification. If the firmware provider identity matches the stored identity, secret keys are generated; otherwise, generation is blocked. This feedback loop ensures that only authorized firmware can obtain the keys needed for execution, creating a security gate without preventing legitimate operation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250356020A1Technologies to track firmware sources
Publication Date: 2025.11.20 INTEL CORP
  • US20250356020A1 patent drawing
  • US20250356020A1 patent drawing
  • US20250356020A1 patent drawing

AI summary

Examples described herein relate to tracking identification of firmware providers to identify unauthorized firmware providers. For example, prior to sharing device secret data with a firmware provider, circuitry can store an identification of the firmware provider in one time programmable (OTP) memory to record the identifier of the firmware provider.