OTP Memory Read Validation for Secure Boot Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Non-volatile memory (NVM) contents read return issues in one-time-programmable (OTP) memory lead to potential unsecure boot scenarios due to incorrect reading of zero values, which can be exploited by hackers, resulting from weaknesses in the surrounding circuit or processor unit components.
Innovation Solution
Incorporating a spare area in the NVM/OTP memory for production testing and using a proprietary bit pattern for validation, where a local read finite state machine (FSM) hardware compares this pattern with a pre-defined value to set an OTP_READ_OK bit, ensuring secure boot operations by differentiating between correct and incorrect read values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If OTP memory is used to store secure boot indication bits, then secure boot functionality is enabled, but the system becomes vulnerable to attacks where unexpected power-up sequences cause incorrect read values (all zeros) that cannot be differentiated from true zero values
Solution Approach 1:
The patent applies preliminary action by performing a validation read of the OTP memory contents before using the secure boot indication bit. A validation bit is read and checked to confirm the OTP memory is functioning correctly before proceeding with secure boot operations. This preliminary validation prevents the system from proceeding with incorrect assumptions about OTP values.
Solution Approach 2:
The patent introduces an intermediary validation mechanism between the OTP memory and the secure boot decision logic. A validation bit or validation routine acts as a mediator that verifies the integrity of OTP reads, separating the raw OTP data from the secure boot determination process and preventing direct exploitation of read errors.
2Productivity
If the bootrom code directly uses OTP read values to determine secure boot, then the boot process is simple and fast, but the system cannot differentiate between true zero values and false returned zeros caused by circuit weaknesses
Solution Approach 1:
The validation read is performed as a preliminary action before the main secure boot decision. This allows the system to quickly verify OTP integrity with a single additional read operation, maintaining overall boot speed while adding essential security validation.
Solution Approach 2:
The system performs self-validation by reading and verifying its own OTP memory contents before proceeding with secure boot operations. The bootrom code includes built-in validation logic that autonomously checks the integrity of OTP reads without requiring external intervention.
Data Source
AI summary
A boot read only memory (ROM) chip unit can perform a secure boot routine based on various operations. A processor device comprises a boot ROM chip with processing circuitry on a system board configured to perform a system board power up according to a read operation in a one-time-programmable OTP memory/non-volatile memory (NVM). The OTP memory/NVM includes a spare area in a portion of the OTP/NVM that can receive a first sequence pattern. The processor determines whether a secure boot indication indicates a secure boot routine, and differentiates one or more read return content of the OTP memory/NVM between a wrongly read return content and a trusted read return content, in response to, or concurrent with, the secure boot indication indicating the secure boot routine.


