Processor Boot Security Device for Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing devices face challenges in securing network authentication information from unauthorized access during the boot sequence, as authentication information can be misappropriated if not properly verified and authenticated.

Innovation Solution

The method involves determining the boot source and verifying boot code authentication information to ensure that access to network authentication information is only allowed if the device is booted from an expected source and the boot code is authenticated, using a processor and flash memory configuration where the network communication authentication information is restricted unless an authorized boot sequence is initiated.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication information is stored at each node for secure communication, then communication security is improved, but the authentication information becomes subject to unauthorized access and misappropriation

Engineering Contradiction:
Improvecommunication securityVSAvoidunauthorized access to authentication information
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication information is segmented into two distinct types: boot code authentication information (stored in first addressable portion of flash memory) and network communication authentication information (stored in second addressable portion of flash memory). This segmentation allows differential access control where only authenticated boot code can access the network authentication information, preventing misappropriation while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication of the boot code before allowing access to network authentication information. The processor verifies boot code authentication information during the boot sequence before enabling access to the second addressable portion containing network authentication information. This preliminary action ensures that only authorized, authenticated code can subsequently access sensitive authentication data.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If network authentication information is made accessible for communication, then communication functionality is improved, but the information becomes vulnerable to misappropriation

Engineering Contradiction:
Improvecommunication functionalityVSAvoidauthentication information misappropriation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The boot code authentication process acts as an intermediary mechanism between the processor and the network authentication information. The system requires successful authentication of boot code as an intermediate step before granting access to network authentication information. This intermediary layer ensures that communication functionality is enabled only through authenticated, authorized code paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically controls access to network authentication information based on the authentication status of the boot code. During unauthorized boot sequences, access to the second addressable portion is inhibited. After successful authentication of authorized boot code, access is dynamically enabled. This dynamic access control balances communication functionality with security protection.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9141804B2Processor boot security device and methods thereof
Publication Date: 2015.09.22 QUALCOMM INC
  • US9141804B2 patent drawing
  • US9141804B2 patent drawing
  • US9141804B2 patent drawing

AI summary

A method of securing network authentication information at a data processing device includes determining a boot source from which to boot the device and comparing the boot source to an expected source. If the boot source is not the expected source, access to the network authentication information is inhibited, such as by disabling access to the portion of memory that stores the authentication information. Further, if the boot source is the expected source, boot code authentication information is retrieved from memory and verified during the boot sequence. If the device authentication information is not authenticated, access to the network authentication information is inhibited. Accordingly, access to the network authentication information is allowed only if the data processing device is booted from an expected source, and only if the boot code is authenticated, thereby reducing the likelihood of unauthorized access to the network authentication information.