Secure Boot Algorithm Selection for Evolving Cryptographic Standards

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic devices face challenges in meeting evolving security requirements due to the rapid development of cryptographic algorithms, as they are typically limited to using a single cryptographic algorithm for secure boot, making it difficult to adapt to new, higher-security algorithms like post-quantum cryptographic algorithms.

Innovation Solution

Implementing an algorithm selection identifier in the electronic device that allows it to select from multiple supported cryptographic algorithms during the boot process, ensuring flexibility and compatibility with future security enhancements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single cryptographic algorithm is used for secure boot, then the device structure is simple and easy to implement, but the device cannot adapt to evolving security requirements and new cryptographic algorithms

Engineering Contradiction:
Improveadaptability to cryptographic algorithmsVSAvoidboot verification system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic algorithm selection by introducing an algorithm selection identifier that allows the boot verification system to dynamically choose between multiple cryptographic algorithms (e.g., RSA, ECC, post-quantum algorithms) based on security requirements. The system transitions from a static single-algorithm approach to a dynamic multi-algorithm framework where the verification algorithm can be changed without hardware modification.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal boot verification system that can perform verification using multiple different cryptographic algorithms through a unified framework. The algorithm selection identifier and corresponding verification modules enable the system to function with different cryptographic standards (RSA, ECC, post-quantum algorithms) without requiring separate dedicated systems for each algorithm.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple cryptographic algorithms are supported, then the device can meet evolving security requirements, but the device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidboot verification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the boot verification system into distinct algorithm-specific verification modules (first algorithm verification module, second algorithm verification module, etc.), each responsible for a specific cryptographic algorithm. This segmentation allows the system to support multiple algorithms while maintaining clear separation of functions, making the complexity manageable and the system more reliable through specialized verification paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an algorithm selection identifier as an intermediary element that mediates between the boot verification system and multiple cryptographic algorithms. This identifier acts as a selector that directs the verification process to the appropriate algorithm module, managing the complexity of supporting multiple algorithms through a centralized selection mechanism rather than direct integration of all algorithms simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cryptographic algorithms are updated to higher security standards, then security requirements are met, but existing devices cannot perform secure boot with new algorithms

Engineering Contradiction:
Improvecryptographic securityVSAvoidalgorithm compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by pre-configuring multiple algorithm verification modules and an algorithm selection identifier in the boot verification system during device manufacturing or initialization. This preliminary setup enables the device to immediately support both current and future cryptographic algorithms (including post-quantum algorithms) without requiring updates when security standards evolve, as the capability is already in place but not yet activated.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12572662B2Boot verification method and related apparatus
Publication Date: 2026.03.10 HUAWEI TECH CO LTD
  • US12572662B2 patent drawing
  • US12572662B2 patent drawing
  • US12572662B2 patent drawing

AI summary

A boot verification method is applied to an electronic device having a secure boot function. An algorithm selection identifier is set in the electronic device to indicate an algorithm used by the electronic device in a boot process, so that on the basis of supporting a plurality of algorithms, the electronic device can select, based on the algorithm selection identifier, a corresponding algorithm to perform boot.