Processor Boot Security Device for Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data processing devices face challenges in securing network authentication information from unauthorized access during the boot sequence, as authentication information can be misappropriated if not properly verified and authenticated.
Innovation Solution
The method involves determining the boot source and verifying boot code authentication information to ensure that access to network authentication information is only allowed if the device is booted from an expected source and the boot code is authenticated, using a processor and flash memory configuration where the network communication authentication information is restricted unless an authorized boot sequence is initiated.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication information is stored at each node for secure communication, then communication security is improved, but the authentication information becomes subject to unauthorized access and misappropriation
Solution Approach 1:
The authentication information is segmented into two distinct types: boot code authentication information (stored in first addressable portion of flash memory) and network communication authentication information (stored in second addressable portion of flash memory). This segmentation allows differential access control where only authenticated boot code can access the network authentication information, preventing misappropriation while maintaining security.
Solution Approach 2:
The system performs preliminary authentication of the boot code before allowing access to network authentication information. The processor verifies boot code authentication information during the boot sequence before enabling access to the second addressable portion containing network authentication information. This preliminary action ensures that only authorized, authenticated code can subsequently access sensitive authentication data.
2Ease of operation
If network authentication information is made accessible for communication, then communication functionality is improved, but the information becomes vulnerable to misappropriation
Solution Approach 1:
The boot code authentication process acts as an intermediary mechanism between the processor and the network authentication information. The system requires successful authentication of boot code as an intermediate step before granting access to network authentication information. This intermediary layer ensures that communication functionality is enabled only through authenticated, authorized code paths.
Solution Approach 2:
The system dynamically controls access to network authentication information based on the authentication status of the boot code. During unauthorized boot sequences, access to the second addressable portion is inhibited. After successful authentication of authorized boot code, access is dynamically enabled. This dynamic access control balances communication functionality with security protection.
Data Source
AI summary
A method of securing network authentication information at a data processing device includes determining a boot source from which to boot the device and comparing the boot source to an expected source. If the boot source is not the expected source, access to the network authentication information is inhibited, such as by disabling access to the portion of memory that stores the authentication information. Further, if the boot source is the expected source, boot code authentication information is retrieved from memory and verified during the boot sequence. If the device authentication information is not authenticated, access to the network authentication information is inhibited. Accordingly, access to the network authentication information is allowed only if the data processing device is booted from an expected source, and only if the boot code is authenticated, thereby reducing the likelihood of unauthorized access to the network authentication information.


