Hardware Attestation via PUF Fingerprinting for Secure Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing measured and trusted boot solutions fail to provide comprehensive assurance regarding the integrity and authenticity of hardware components, particularly in detecting malicious hardware module replacements.

Innovation Solution

The integration of unique Physically Unclonable Function (PUF) responses for each hardware module, combined with software and firmware measurements, is used to create a secure measured boot process. This ensures that each hardware module has a distinct, unclonable fingerprint, making it difficult for attackers to replace components without detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional measured boot solutions are used to verify software integrity, then software authentication is achieved, but hardware component authenticity cannot be detected

Engineering Contradiction:
Improvehardware authenticationVSAvoidhardware integrity assurance
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments the boot verification process into separate hardware and software components. Hardware modules are individually measured and authenticated through unique PUF responses, while software components are verified through traditional measured boot techniques. This segmentation allows independent verification of hardware authenticity without compromising software verification capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

PUF (Physically Unclonable Function) responses serve as an intermediary mechanism between hardware components and the attestation system. The PUF responses provide a unique, unclonable fingerprint for each hardware module, enabling the system to detect hardware replacements while maintaining compatibility with existing software verification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If hardware modules are replaced to improve system performance or availability, then system flexibility increases, but security against malicious replacement is compromised

Engineering Contradiction:
Improvehardware replaceabilityVSAvoidmalicious hardware replacement
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary measurement and recording of PUF responses from hardware modules during the boot process, before any potential malicious replacement can occur. These measurements are stored and used as reference values for future attestation, enabling the system to detect any unauthorized hardware changes while still allowing legitimate hardware replacements through proper re-registration procedures.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive hardware and software measurement is implemented, then system integrity is enhanced, but boot process complexity increases

Engineering Contradiction:
Improvesystem integrityVSAvoidboot process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges hardware PUF-based attestation with traditional software measured boot processes into a unified verification framework. Both hardware and software measurements are collected, combined, and stored together in the attestation database, allowing comprehensive integrity verification without requiring separate independent processes.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250168020A1Secure attestation of hardware device
Publication Date: 2025.05.22 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250168020A1 patent drawing
  • US20250168020A1 patent drawing
  • US20250168020A1 patent drawing

AI summary

A device comprises a plurality of hardware, HW, modules including a first HW module comprising a Physically Un-clonable Function, PUF, the first HW module or the plurality of HW modules being communicated with a requester. The device receives (1006), from the requester, a request to transmit an output to the requester. It activates (1008) the PUF, reads a response from the PUF, and adds the response to an output. The device transmits (1012) the output to the requester, and it receives (1002) one or more of a firmware, FW, component, a software, SW, component, or a bitstream, BS, component before receiving (1006) the request from the requester.