HSM Loader Signature Segmentation for Secure Startup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing the startup sequence of control units in time-critical applications, such as engine control units, face delays due to the initialization of the data memory by the hardware security module (HSM), which occurs at a reduced clock frequency, compromising the speed and security of the startup process.

Innovation Solution

The loader program signature is stored in the protected program memory of the HSM, allowing for immediate access and authentication during startup, even at a reduced clock frequency, ensuring a fast and secured startup sequence by preventing unauthorized manipulation of the control unit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the data memory of the HSM is initialized at reduced clock frequency to ensure security, then the security of the startup sequence is improved, but the startup time increases

Engineering Contradiction:
ImprovesecurityVSAvoidstartup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the signature storage into two distinct memory areas within the HSM: a first memory area (program memory) that is immediately accessible at startup and a second memory area (data memory) that requires initialization. By placing the loader program signature in the first memory area, the system can perform authentication without waiting for the second memory area to be initialized, thus resolving the contradiction between security and startup time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by pre-storing the loader program signature in the first memory area of the HSM before startup. This allows the authentication process to begin immediately without waiting for the data memory initialization, effectively preparing the critical authentication data in advance to eliminate startup delays while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the HSM operates at reduced clock frequency during initialization to ensure secure authentication, then the security of program authentication is improved, but the authentication speed decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent extracts the critical authentication function from the initialization sequence by storing the loader program signature in the first memory area that is accessible immediately upon HSM startup. This separation allows the authentication process to proceed independently of the slower initialization of the second memory area, thus extracting the speed-critical authentication step from the security-critical but slow initialization process.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The signature is preliminarily stored in the first memory area before the HSM needs to perform authentication. This preliminary placement of the signature data allows the authentication process to use higher clock frequencies without compromising security, as the critical authentication data is already in place and does not require the slow initialization process.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the loader program signature is stored in the data memory requiring initialization, then the security protection is improved, but the startup sequence speed decreases

Engineering Contradiction:
Improvesignature protectionVSAvoidstartup sequence speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the HSM memory into two functional areas: a first memory area for storing the loader program signature that is immediately accessible, and a second memory area (data memory) that requires initialization for other security functions. This segmentation allows the signature to be protected within the secure HSM boundary while being accessible without waiting for the full initialization sequence, thus resolving the contradiction between protection and speed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The loader program signature is preliminarily stored in the first memory area during HSM manufacturing or initial configuration, before the control unit startup. This preliminary placement ensures the signature is securely stored and immediately accessible during startup, eliminating the need to wait for data memory initialization while maintaining the security benefits of HSM storage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11822661B2Method for carrying out a secured startup sequence of a control unit
Publication Date: 2023.11.21 ROBERT BOSCH GMBH
  • US11822661B2 patent drawing
  • US11822661B2 patent drawing

AI summary

A method for carrying out a secured startup sequence of a control unit, which includes a host that is configured to execute a loader program and one or multiple application programs, and a hardware security module (HSM) which includes a program memory and a data memory. The method includes a starting of the host and of the HSM; an authentication of the loader program by the HSM with the aid of a loader program signature stored in the program memory of the HSM; and, an execution of the loader program by the host if the authentication of the loader program is successful.