Fuse-Based Secure Boot for BIOS Authentication Hardening

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems are vulnerable to unauthorized modifications and attacks due to insecure boot processes and memory devices, which can compromise the integrity and confidentiality of data, especially in contexts like secure cloud and 5G applications.

Innovation Solution

Implementing a secure boot process using static and/or dynamic fuses to encode a secret key, authenticate the BIOS, and utilize a hardware encryption engine with integrity and anti-replay properties to secure communication and storage, minimizing the trusted computing base by making the processing device the root of trust and reducing dependency on other components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional boot process is used, then the system is easier to manufacture and operate, but the system becomes vulnerable to unauthorized modifications and attacks

Engineering Contradiction:
Improvesystem securityVSAvoidboot process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication actions during the boot process by encoding secret keys in fuses and using hardware encryption engines to verify BIOS authenticity before system operation. This preliminary security verification prevents unauthorized modifications early in the boot sequence, addressing the vulnerability to attacks while maintaining a structured boot process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary security components including fuse-based secret key storage and hardware encryption engines that act as mediators between the boot process and the system operations. These intermediaries provide security verification without completely redesigning the entire boot process, thus improving reliability while limiting the increase in complexity to specific security modules.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security hardening measures are implemented, then protection against attacks is improved, but dependency on other components is reduced

Engineering Contradiction:
Improveprotection against attacksVSAvoidtrusted computing base
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the root of trust functionality from external components and embeds it directly in the processing device through fuse-based secret key storage and integrated hardware encryption engines. This extraction minimizes the trusted computing base by eliminating dependencies on external security components while maintaining strong protection against attacks through self-contained security mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If fuses are used to encode secret keys, then authentication security is improved, but manufacturing complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidmanufacturing process
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements self-service manufacturing by encoding secret keys in fuses during the semiconductor fabrication process itself, rather than requiring separate post-manufacturing security provisioning steps. The fuse-based key encoding is integrated into the chip manufacturing flow, allowing security features to be established automatically during production without adding significant manufacturing complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260017376A1Security hardened processing device
Publication Date: 2026.01.15 SDG LOGIC INC
  • US20260017376A1 patent drawing
  • US20260017376A1 patent drawing
  • US20260017376A1 patent drawing

AI summary

Techniques are described herein for security hardened processing devices. For example, a method can include performing a secure boot of a processing device of a computer system. The processing device is configured as a root of trust for a secure boot process. The computer system can include the processing device and a non-volatile memory storing a basic input/output system (BIOS) for the secure boot process. The method can include identifying a set of programmable fuses of the processing device, deriving an encryption key using a value encoded by the set of programmable fuses in the processing device, and authenticating the BIOS to perform the secure boot process using a key derivation algorithm based on the encryption key.