HSM Loader Signature Segmentation for Secure Startup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for securing the startup sequence of control units in time-critical applications, such as engine control units, face delays due to the initialization of the data memory by the hardware security module (HSM), which occurs at a reduced clock frequency, compromising the speed and security of the startup process.
Innovation Solution
The loader program signature is stored in the protected program memory of the HSM, allowing for immediate access and authentication during startup, even at a reduced clock frequency, ensuring a fast and secured startup sequence by preventing unauthorized manipulation of the control unit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the data memory of the HSM is initialized at reduced clock frequency to ensure security, then the security of the startup sequence is improved, but the startup time increases
Solution Approach 1:
The patent segments the signature storage into two distinct memory areas within the HSM: a first memory area (program memory) that is immediately accessible at startup and a second memory area (data memory) that requires initialization. By placing the loader program signature in the first memory area, the system can perform authentication without waiting for the second memory area to be initialized, thus resolving the contradiction between security and startup time.
Solution Approach 2:
The patent applies preliminary action by pre-storing the loader program signature in the first memory area of the HSM before startup. This allows the authentication process to begin immediately without waiting for the data memory initialization, effectively preparing the critical authentication data in advance to eliminate startup delays while maintaining security.
2Reliability
If the HSM operates at reduced clock frequency during initialization to ensure secure authentication, then the security of program authentication is improved, but the authentication speed decreases
Solution Approach 1:
The patent extracts the critical authentication function from the initialization sequence by storing the loader program signature in the first memory area that is accessible immediately upon HSM startup. This separation allows the authentication process to proceed independently of the slower initialization of the second memory area, thus extracting the speed-critical authentication step from the security-critical but slow initialization process.
Solution Approach 2:
The signature is preliminarily stored in the first memory area before the HSM needs to perform authentication. This preliminary placement of the signature data allows the authentication process to use higher clock frequencies without compromising security, as the critical authentication data is already in place and does not require the slow initialization process.
3Reliability
If the loader program signature is stored in the data memory requiring initialization, then the security protection is improved, but the startup sequence speed decreases
Solution Approach 1:
The patent segments the HSM memory into two functional areas: a first memory area for storing the loader program signature that is immediately accessible, and a second memory area (data memory) that requires initialization for other security functions. This segmentation allows the signature to be protected within the secure HSM boundary while being accessible without waiting for the full initialization sequence, thus resolving the contradiction between protection and speed.
Solution Approach 2:
The loader program signature is preliminarily stored in the first memory area during HSM manufacturing or initial configuration, before the control unit startup. This preliminary placement ensures the signature is securely stored and immediately accessible during startup, eliminating the need to wait for data memory initialization while maintaining the security benefits of HSM storage.
Data Source
AI summary
A method for carrying out a secured startup sequence of a control unit, which includes a host that is configured to execute a loader program and one or multiple application programs, and a hardware security module (HSM) which includes a program memory and a data memory. The method includes a starting of the host and of the HSM; an authentication of the loader program by the HSM with the aid of a loader program signature stored in the program memory of the HSM; and, an execution of the loader program by the host if the authentication of the loader program is successful.

