Memory Boot Attestation Using Dual Measurement Registers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing memory devices fail to directly report to the host whether the bootloader or firmware is falsified, leading to uncertainty in diagnosing booting failures.
Innovation Solution
A memory device system that includes an interface to receive measurement values, attester firmware to generate and record values, and a host to determine falsification based on recorded measurement values and reference values, enabling direct verification of bootloader and firmware integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the memory device verifies bootloader and firmware integrity internally, then safe boot capability is improved, but the ability to directly report verification results to the host deteriorates
Solution Approach 1:
The patent introduces measurement value registers (first register for bootloader, second register for attester firmware) as intermediaries to store and transmit verification results. These registers act as mediators between the internal verification process and the host, enabling direct reporting of authentication results without compromising the verification capability.
2Loss of information
If measurement values are recorded in registers, then direct reporting to host is improved, but device complexity increases
Solution Approach 1:
The patent segments the verification result storage into separate registers: a first register for bootloader measurement values and a second register for attester firmware measurement values. This segmentation organizes the complexity by dedicating specific storage locations to specific verification targets, making the system manageable and reportable.
3Measurement precision
If multiple measurement values are transmitted to the host, then diagnostic accuracy is improved, but communication overhead increases
Solution Approach 1:
The patent extracts only the essential measurement values (bootloader measurement value and attester firmware measurement value) that are necessary for diagnostic purposes and transmits them to the host. This extraction approach provides sufficient diagnostic accuracy while minimizing unnecessary data transmission.
Data Source
AI summary
Provided is a system including a memory device including an interface configured to receive a measurement value generation request signal from a host and transmit a first measurement value and a second measurement value to the host, attester firmware configured to receive measurement values for a plurality of pieces of firmware, a bootloader configured to perform booting, a first register configured to record a first measurement value of the bootloader, and a second register configured to record a second measurement value for the attester firmware in response to the first measurement value being recorded, and the host including processing circuitry configured to receive the first measurement value and the second measurement value, and determine whether to falsify the bootloader or the attester firmware based on at least one of (1) the first measurement value and first reference values or (2) the second measurement value and second reference values.


