Secure Boot Processing System Inbound Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing systems face security vulnerabilities during boot-up operations due to the potential for unauthorized access and modification of boot program code, which can compromise the integrity of the system and make it susceptible to further attacks.

Innovation Solution

A secure boot processing system with an immutable secure boot controller that disallows inbound access during initial boot-up tasks, ensuring only immutable and critical security operations are performed before allowing external access to load a bootloader program, thereby preventing unauthorized changes and enhancing security through the principle of least privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the boot processing system allows inbound access during boot-up operations, then external devices can load and update boot program code, but the system becomes vulnerable to unauthorized access and security attacks

Engineering Contradiction:
Improveability to load and update boot program codeVSAvoidunauthorized access and security attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The boot processing system dynamically changes its access control state during the boot-up process. The inbound access to the boot processing system is disabled during critical boot-up operations and enabled after boot-up completes, allowing the system to adapt its security posture based on operational phase

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary security configuration by disabling inbound access before critical boot-up operations begin. This preliminary action ensures that the system is in a secure state before executing immutable boot tasks, preventing unauthorized interference

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If the boot processing system disallows inbound access during immutable boot-up tasks, then security is enhanced, but the system cannot load bootloader program code from external memory

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidability to load bootloader program
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The access control mechanism is made dynamic, transitioning from a permanently restricted state to a temporarily restricted state. The system disables inbound access only for the duration of critical boot-up tasks, then re-enables it to allow bootloader loading, balancing security with operational functionality

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The boot-up process is segmented into distinct phases with different access control policies. Critical immutable tasks are isolated in a secure phase with inbound access disabled, while subsequent phases enable access for bootloader loading, allowing security and functionality to coexist in different temporal segments

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230078058A1Computing systems employing a secure boot processing system that disallows inbound access when performing immutable boot-up tasks for enhanced security, and related methods
Publication Date: 2023.03.16 AMPERE COMPUTING LLC
  • US20230078058A1 patent drawing
  • US20230078058A1 patent drawing
  • US20230078058A1 patent drawing

AI summary

Computing systems employing a secure boot processing system that disallows in-bound access when performing immutable boot-up tasks for enhanced security, and related methods and computer-readable media. The computing system includes a secure boot processing system that performs boot-up operations. The secure boot processing system includes an immutable secure boot subsystem that performs lower-level, immutable boot-up tasks that are critical to the security of the computing system. To prevent or mitigate external unauthorized access to the immutable secure boot subsystem that could compromise the security of the computing system, the immutable secure boot controller is configured to disallow external, inbound access to boot system interface of the secure boot processing system to perform immutable boot-up tasks. In this manner, there is not an access path for an external agent to change early immutable boot-up tasks performed by the immutable secure boot subsystem that could otherwise corrupt the computing system.