Integrated Circuit Secure Boot with Signature Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrated circuits face security threats when firmware is falsified, leading to abnormal operation and potential data leakage due to the failure of encryption engines to function properly, especially when the CPU operates abnormally.
Innovation Solution
Incorporating a security management part with a set value holding part, start control part, and state control part that performs secure boot with signature verification on the boot program, resetting the data processing part if falsification is detected, and interrupting connections to protect against security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the integrated circuit uses a traditional boot process without secure verification, then the ease of operation is improved, but the reliability deteriorates due to firmware falsification risks
Solution Approach 1:
The patent implements preliminary action by performing signature verification on the boot program before the system operates. The security management part verifies the authenticity of the boot program stored in the integrated circuit during the boot process, preventing execution of falsified firmware. This advance verification ensures reliability without requiring complex runtime security mechanisms.
2Reliability
If the integrated circuit implements secure boot with signature verification, then the reliability is improved, but the device complexity increases due to additional security management components
Solution Approach 1:
The patent applies segmentation by dividing the integrated circuit into distinct functional parts: a data processing part and a security management part. The security management part is further segmented into a set value holding part (for storing security parameters), a start control part (for controlling boot process), and a state control part ( for managing operational state). This segmentation isolates security functions from data processing, improving reliability while keeping each segment's complexity manageable.
3Reliability
If the integrated circuit resets the data processing part upon detecting falsification, then the reliability is improved, but the loss of time increases due to system reset operations
Solution Approach 1:
The patent implements preliminary anti-action by detecting and responding to firmware falsification at the boot stage before the data processing part begins normal operation. The state control part monitors the boot process and immediately resets the data processing part if falsification is detected, preventing any potential data leakage or malicious execution. This early detection and response minimizes the time window for security threats while protecting data integrity.
Data Source
AI summary
An integrated circuit includes a data processing part, a data management part. The data processing part processes data. The data management part manages security of the data processing part. The security management part includes a set value holding part, a start control part and a state control part. The set value holding part holds a set value of security strength. The start control part starts the integrated circuit by secure boot which performs signature verification on a boot program in a case where the security strength shown by the set value is over a predetermined level. The state control part resets the data processing part when falsification of the boot program is detected by the signature verification in the secure boot.


