Processor State Integrity via Secure Boot Measurement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data processing apparatuses, it is challenging to determine the current state of integrity as they become vulnerable to tampering once they start operating and processing data, with existing solutions being susceptible to external attacks.

Innovation Solution

A data processing apparatus with power control circuitry that powers up secure boot up software to perform measurements, using secure keys accessible only during boot up to sign and verify the state, ensuring the integrity of the system by combining measurements with random values for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the data processing apparatus starts to execute code and process data, then productivity is improved, but the security and integrity of the system deteriorates due to increased vulnerability to tampering

Engineering Contradiction:
Improvedata processing capabilityVSAvoidsystem integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing integrity measurements during the boot-up process before the system executes user code. The boot-up software measures characteristics of critical components (processors, memory, peripherals) and stores these measurements in non-volatile storage before the vulnerable operational phase begins. This allows the system to establish a baseline of integrity before productivity activities start.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a dedicated measurement software component that acts as a mediator between the boot-up software and the operational system. This measurement software performs integrity checks on various system components and generates measurement values that can be verified later, serving as an intermediary that bridges the secure boot-up phase with the potentially vulnerable operational phase.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Use of energy by moving object

If power control circuitry powers down processors to save energy, then energy consumption is reduced, but the ability to perform integrity measurements deteriorates

Engineering Contradiction:
Improvepower consumptionVSAvoidintegrity measurement capability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent applies preliminary action by performing all necessary integrity measurements during the boot-up process before the processors are powered down. The measurement software executes while processors are still active during boot-up, captures integrity data, and stores it in non-volatile storage. When processors are later powered down for energy savings, the integrity measurements have already been completed and stored, so no measurement capability is lost.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If boot up software is stored in ROM to ensure security, then system integrity is improved, but the flexibility to perform various measurements deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidmeasurement flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies segmentation by dividing the software functionality into separate components: the secure boot-up software stored in ROM handles security and initialization, while a separate measurement software component performs integrity measurements. This segmentation allows the ROM-based boot-up software to maintain security while the flexible measurement software can adapt to measure different system components (processors, memory, peripherals) without compromising the security guarantees.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11068275B2Providing a trustworthy indication of the current state of a multi-processor data processing apparatus
Publication Date: 2021.07.20 ARM LTD
  • US11068275B2 patent drawing
  • US11068275B2 patent drawing
  • US11068275B2 patent drawing

AI summary

A data processing apparatus formed on an integrated circuit comprising: a plurality of processors; power control circuitry configured to control power up and power down of the processors; a read only memory for storing boot up software for booting up each of the processors. The power control circuitry is configured to respond to receipt of a check state request, to control one of the processors that is currently powered down to power up and to access the boot up software. The boot up software accessed in response to the check state request controls the processor to perform a measurement indicative of a current state of the data processing apparatus and to output a value indicative of the measurement.