Evolving Root of Trust via Block Protection Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for evolving the root of trust in computer systems are costly and time-consuming, as they require redesigning the read-only memory to replace the root of trust, which increases manufacturing costs and time.
Innovation Solution
A method for evolving the root of trust using a block protection storage device with fuse bits and protection bits, where verification firmware is written in an unprotected block and then set to protected, allowing for secure and reliable upgrades without altering the original firmware, and enabling encryption of user firmware information for enhanced security verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the root of trust is replaced by remanufacturing the read-only memory, then the root of trust can be updated, but the mask must be redesigned which increases the manufacturing cost and time cost
Solution Approach 1:
The storage device is divided into multiple blocks (first block, second block, etc.), allowing the root of trust to be segmented across different blocks. This enables selective updating of specific blocks without requiring complete remanufacturing of the entire read-only memory, thus reducing manufacturing cost and time while maintaining update capability.
Solution Approach 2:
The method performs preliminary actions by first writing verification firmware to a block, then setting the corresponding protection fuse bit and protection bit to true to protect the block before finalizing the root of trust evolution. This preliminary protection mechanism ensures secure updates without requiring costly remanufacturing processes.
2Reliability
If the root of trust is burned in read-only memory to ensure security, then the integrity is protected, but the root of trust cannot be replaced or evolved
Solution Approach 1:
The system transitions from a static read-only memory model to a dynamic block-based model where protection status can change. Blocks can be dynamically protected by setting protection fuse bits and protection bits, allowing the root of trust to evolve while maintaining integrity protection through the dual-bit protection mechanism.
Solution Approach 2:
Before allowing root of trust evolution, the method performs preliminary actions by writing verification firmware to a block and then setting both the protection fuse bit and protection bit to true. This preliminary protection ensures that once a block is used for root of trust, it becomes securely protected, enabling reliable evolution without compromising integrity.
3Reliability
If multiple blocks are used for root of trust evolution, then the security verification capability is enhanced, but the device complexity increases
Solution Approach 1:
The storage device is segmented into multiple blocks with corresponding protection fuse bits and protection bits. This segmentation allows enhanced security verification capability by distributing root of trust across multiple blocks, while the systematic organization of blocks with paired protection mechanisms keeps management complexity manageable through clear correspondence between blocks and their protection bits.
Data Source
AI summary
The embodiment of the present disclosure provides a method for evolving a root of trust and an electronic device using the method. Through the present disclosure, the root of trust can be evolved several times to strengthen the security verification capability for secure boot. Different from the conventional method of burning the root of trust in the read-only memory, the present disclosure uses a block protection storage device to write a verification firmware to be added to the root of trust into an unprotected block of the block protection storage device. Further, after the writing is completed, the unprotected block in which the verification firmware is written becomes a protected block, so as to make the evolvable root of trust secure and reliable, and can achieve credibility for evolving the root of trust.


