Secure OTP Memory Programming via Boot ROM Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for programming one-time programmable (OTP) memory in semiconductor chips lack security, as they do not ensure data integrity and authenticity, making it vulnerable to unauthorized access and data exposure.
Innovation Solution
A system and method for securely programming OTP memory by using an OTP programming vector that includes an electronic signature, authenticated using a public key, and encrypted data, which is decrypted and programmed into the OTP memory using a symmetric key, with optional software error correction code for reliability, ensuring secure and random data storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional programming methods are used for OTP memory, then the programming process is simple and fast, but security is compromised and data integrity cannot be ensured
Solution Approach 1:
The patent applies preliminary action by pre-storing authentication data (public keys, encryption keys) in the boot ROM before the OTP programming process begins. The programming vector is pre-encrypted and signed before being transferred to the chip. This ensures that security checks are performed using pre-established credentials, preventing unauthorized programming while maintaining a structured process.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the boot ROM acts as a mediator between the programming device and the OTP memory. The boot ROM verifies the programming vector's authenticity using public key cryptography and decrypts sensitive data using stored encryption keys. This intermediary layer ensures data integrity without requiring the programming device to directly access OTP memory, resolving the contradiction between security and process simplicity.
2Reliability
If authentication and encryption mechanisms are added to OTP programming, then security is improved, but programming time and processing complexity increase
Solution Approach 1:
The patent performs authentication and decryption operations during the normal boot sequence before OTP programming begins. The public key and encryption key are already loaded in the boot ROM, so authentication of the programming vector and decryption of programming data occur as part of the initialization process rather than adding separate time-consuming steps during actual programming.
Solution Approach 2:
The system performs self-authentication where the chip's boot ROM automatically verifies the programming vector's digital signature and decrypts the programming data using stored keys. This self-service mechanism eliminates the need for external authentication hardware or manual security checks, ensuring security without proportionally increasing programming time.
3Loss of information
If the OTP memory is programmed with customer-specific secrets, then data protection is improved, but vulnerability to unauthorized access increases if security measures are inadequate
Solution Approach 1:
The boot ROM serves as an intermediary that protects customer-specific secrets in OTP memory. It holds encryption keys and public keys that authenticate programming vectors, preventing unauthorized writing to OTP memory. Even if physical access is obtained, the intermediary authentication layer ensures that only verified programming operations can modify OTP contents, protecting against unauthorized access while enabling secure data storage.
Solution Approach 2:
The patent applies preliminary anti-action by pre-configuring the system with authentication credentials in the boot ROM before any OTP programming occurs. The digital signature verification and encryption/decryption mechanisms are established in advance, creating preemptive barriers against unauthorized access. This preliminary security setup ensures that customer-specific secrets remain protected from the outset rather than requiring reactive security measures.
Data Source
AI summary
A semiconductor chip may be operable to receive and copy an OTP programming vector presented by the semiconductor chip programming device into its memory after it boots up from the boot read-only memory (ROM). The OTP programming vector which is a computer program may comprise an encrypted data to be programmed into the one-time programmable (OTP) memory in the semiconductor chip and may be signed with an electronic signature. The semiconductor chip may be operable to authenticate the OTP programming vector in the memory. The authenticated OTP programming vector in the memory may be executed to decrypt the data and program the data in a random data format into the OTP memory and then report the status via one or more general purpose input/output (GPIO) pins on the semiconductor chip.


