Multicore SoC Secure Boot via Hardware Security Subsystem

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data processing systems face challenges in providing a flexible, secure, and cost-effective method for activating functionality due to inefficiencies in security solutions that rely on hierarchical trust models and static security policies, which are not well-suited for dynamic and versatile security needs.

Innovation Solution

A data processing system with a hardware security subsystem that uses public-key cryptography for authentication and dynamically configurable system reactions, including secure memory region verification and sanctions, to ensure the integrity and authenticity of boot codes and application software during runtime, without requiring dedicated cryptographic accelerators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional hierarchical trust model with sequential initialization is used, then security integrity is maintained, but system startup time and initialization duration increase

Engineering Contradiction:
Improvesecurity integrityVSAvoidsystem startup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing a root of trust in hardware during manufacturing, and pre-configuring security policies that can be dynamically loaded. The secure boot process uses pre-stored cryptographic keys and signatures in hardware security modules, allowing verification to occur rapidly without sequential initialization delays. The system prepares security credentials and policies in advance, enabling fast authentication during boot.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the security verification functions from the main processing sequence and implements them in dedicated hardware security subsystems. By separating security-critical operations (cryptographic verification, key management) into independent hardware modules, the system can perform security checks in parallel with other initialization processes, reducing overall startup time while maintaining integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Device complexity

If static security policies are used, then implementation simplicity is maintained, but system adaptability and versatility decrease

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsystem flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security policies that can be modified at runtime without requiring system reconfiguration or reboot. The security subsystem allows authorized components to update security rules, access controls, and verification parameters during operation. This enables the system to adapt to changing security requirements while maintaining a relatively simple underlying hardware architecture.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal security framework that can handle multiple security scenarios and policy types through a single configurable subsystem. The hardware security module supports various cryptographic algorithms, authentication methods, and policy enforcement mechanisms, allowing the same physical infrastructure to serve diverse security needs across different applications and workloads.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If dedicated cryptographic accelerators are used, then authentication speed improves, but device complexity and cost increase

Engineering Contradiction:
Improveauthentication speedVSAvoidhardware overhead
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges cryptographic acceleration functions directly into the existing security subsystem hardware, eliminating the need for separate dedicated cryptographic accelerators. The security module integrates key generation, storage, and verification functions in a unified architecture, reducing overall device complexity while maintaining fast authentication performance through hardware-accelerated cryptographic operations.

Inventive Principle:
Principle #5Merging (Combining)

4Device complexity

If security assets are used only during system initialization, then security circuitry cost is reduced, but productivity and security coverage decrease

Engineering Contradiction:
Improvesecurity circuitry overheadVSAvoidsecurity operation coverage
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent implements continuous security verification and asset utilization throughout system operation, not just during initialization. The security subsystem remains active during runtime, performing ongoing authentication, authorization, and integrity verification of executing code and data. This continuous operation maximizes the utilization of security hardware resources while providing comprehensive security coverage across the entire system lifecycle.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11797681B2Fast and versatile multicore SoC secure boot method
Publication Date: 2023.10.24 NXP USA INC
  • US11797681B2 patent drawing
  • US11797681B2 patent drawing
  • US11797681B2 patent drawing

AI summary

A system, method, and apparatus are provided for securely controlling operations of a data processing system by activating a security subsystem to control startup behavior of application subsystems, installing SMR parameters which include an initial authenticity proof for use with an initial verification process for the SMR and calculating an alternate authenticity proof for use with a subsequent verification process for the SMR, and then by subsequently verifying the SMR using the alternate authenticity proof for the subsequent verification process applied to the SMR so that the security subsystem can apply a comprehensive system reaction for the application subsystem based on the SMR verification results.