Processor Secure Boot Configuration for Counterfeit Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In complex electronic device manufacturing, securing components before assembly is challenging due to the involvement of multiple, potentially insecure manufacturing facilities, leading to risks of counterfeit devices being created by reverse-engineering components.

Innovation Solution

A method is implemented where the first manufacturing facility configures the processor with a secure boot feature and cryptographic keys, locking it from further alteration, and ensures only signed software is executed, while a Manufacturing Authentication Server verifies the processor's identity and security settings, preventing unauthorized access or tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If components are manufactured at multiple external facilities, then cost savings and manufacturing efficiency are improved, but security and risk of counterfeit devices worsen

Engineering Contradiction:
Improvemanufacturing efficiencyVSAvoiddevice security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by configuring the processor with secure boot features and cryptographic keys at the component manufacturing stage, before the component is delivered to the final assembly facility. This pre-configuration ensures security measures are established prior to distribution across multiple manufacturing facilities, preventing counterfeit device creation while maintaining the benefits of external component manufacturing

Inventive Principle:
Principle #10Preliminary action

2Reliability

If components are manufactured under single roof, then security control is improved, but manufacturing cost and complexity worsen

Engineering Contradiction:
Improvesecurity controlVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the manufacturing process into distinct stages: component manufacturing at specialized external facilities and final assembly at the main facility. Security is maintained through cryptographic binding of components to specific devices, allowing distributed manufacturing while preserving security control without requiring centralized production

Inventive Principle:
Principle #1Segmentation

3Reliability

If cryptographic keys are stored in secure storage, then device security is improved, but access control and verification complexity worsen

Engineering Contradiction:
Improvedevice securityVSAvoidverification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by implementing a secure boot mechanism where the processor automatically verifies cryptographic signatures during startup without requiring external intervention. The processor uses its embedded secure storage to self-validate software authenticity, reducing verification complexity while maintaining strong security controls

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2405377B1Securing a component prior to manufacture of a device
Publication Date: 2017.12.27 BLACKBERRY LTD
  • EP2405377B1 patent drawingFigure 1
  • EP2405377B1 patent drawingFigure 2
  • EP2405377B1 patent drawingFigure 3

AI summary

By securing a component within a product, before the component is delivered to the final device manufacturing facility, the device manufacturing process can be made provably secure. Additionally, the component may be tested for security and authenticity during manufacture and even later, as the device enters use by a consumer.