Processor State Integrity via Secure Boot Measurement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In data processing apparatuses, it is challenging to determine the current state of integrity as they become vulnerable to tampering once they start operating and processing data, with existing solutions being susceptible to external attacks.
Innovation Solution
A data processing apparatus with power control circuitry that powers up secure boot up software to perform measurements, using secure keys accessible only during boot up to sign and verify the state, ensuring the integrity of the system by combining measurements with random values for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the data processing apparatus starts to execute code and process data, then productivity is improved, but the security and integrity of the system deteriorates due to increased vulnerability to tampering
Solution Approach 1:
The patent applies preliminary action by performing integrity measurements during the boot-up process before the system executes user code. The boot-up software measures characteristics of critical components (processors, memory, peripherals) and stores these measurements in non-volatile storage before the vulnerable operational phase begins. This allows the system to establish a baseline of integrity before productivity activities start.
Solution Approach 2:
The patent uses an intermediary approach by introducing a dedicated measurement software component that acts as a mediator between the boot-up software and the operational system. This measurement software performs integrity checks on various system components and generates measurement values that can be verified later, serving as an intermediary that bridges the secure boot-up phase with the potentially vulnerable operational phase.
2Use of energy by moving object
If power control circuitry powers down processors to save energy, then energy consumption is reduced, but the ability to perform integrity measurements deteriorates
Solution Approach 1:
The patent applies preliminary action by performing all necessary integrity measurements during the boot-up process before the processors are powered down. The measurement software executes while processors are still active during boot-up, captures integrity data, and stores it in non-volatile storage. When processors are later powered down for energy savings, the integrity measurements have already been completed and stored, so no measurement capability is lost.
3Reliability
If boot up software is stored in ROM to ensure security, then system integrity is improved, but the flexibility to perform various measurements deteriorates
Solution Approach 1:
The patent applies segmentation by dividing the software functionality into separate components: the secure boot-up software stored in ROM handles security and initialization, while a separate measurement software component performs integrity measurements. This segmentation allows the ROM-based boot-up software to maintain security while the flexible measurement software can adapt to measure different system components (processors, memory, peripherals) without compromising the security guarantees.
Data Source
AI summary
A data processing apparatus formed on an integrated circuit comprising: a plurality of processors; power control circuitry configured to control power up and power down of the processors; a read only memory for storing boot up software for booting up each of the processors. The power control circuitry is configured to respond to receipt of a check state request, to control one of the processors that is currently powered down to power up and to access the boot up software. The boot up software accessed in response to the check state request controls the processor to perform a measurement indicative of a current state of the data processing apparatus and to output a value indicative of the measurement.


