Secure Boot Authentication with Chain Information Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information processing apparatuses lack effective protection against third-party attacks during secure boot, as the general-purpose interface can be rewritten and programs signed with a secure boot key may have vulnerabilities.

Innovation Solution

An information processing apparatus with an authentication processing unit to validate startup programs, a trust list storage unit to identify trustworthy providers, a chain information storage unit to track unauthorized program execution, a startup processing unit to update chain information, and a restriction processing unit to limit security-related protocols when unauthorized programs are detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a general-purpose interface is used for information exchange in secure boot, then ease of operation is improved, but reliability deteriorates because the interface can be rewritten by third-party programs

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The interface is segmented into two distinct parts: a trusted interface stored in flash memory that cannot be rewritten, and a general-purpose interface stored in memory that can be rewritten. This segmentation allows the system to maintain both ease of operation (through the general-purpose interface) and reliability (through the trusted interface), resolving the technical contradiction.

Inventive Principle:
Principle #1Segmentation

2Reliability

If secure boot key signing is implemented, then reliability is improved, but object-generated harmful factors worsen because vulnerabilities in signed programs can still be exploited

Engineering Contradiction:
ImprovereliabilityVSAvoidobject-generated harmful factors
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

A trusted interface acts as an intermediary between the secure boot process and the general-purpose interface. Even if vulnerabilities exist in signed programs, the trusted interface mediates information exchange and prevents exploitation, thereby maintaining reliability while addressing the harmful factors generated by vulnerable programs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If chain information tracking is implemented, then reliability is improved, but device complexity increases due to additional storage and processing requirements

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Chain information is tracked in advance by recording the execution status of startup programs in a trust list before potential security breaches occur. This preliminary action establishes a baseline of trusted programs, enabling the system to detect and respond to unauthorized changes without requiring complex real-time analysis, thus improving reliability while minimizing device complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4557135A1Information processing apparatus, control method, and program
Publication Date: 2025.05.21 LENOVO (SINGAPORE) PTE LTD
  • EP4557135A1 patent drawingFigure 1
  • EP4557135A1 patent drawingFigure 2
  • EP4557135A1 patent drawingFigure 3~4

AI summary

Provided is an information processing apparatus to improve the protection against third party attacks in secure boot. The information processing apparatus includes: an authentication processing unit that confirms the validity of a startup program for booting an OS based on a security key in BIOS processing; a trust list storage unit that stores a trust list, a list of trustable providers of the startup program; a chain information storage unit that stores chain information indicating whether the startup program has been executed when the startup program is unauthorized; a startup processing unit that changes the chain information when the startup program acquired from a provider not included in the trust list has been executed in secure boot processing for executing the startup program whose validity has been confirmed by the authentication processing unit; and a restriction processing unit that restricts the use of security-related protocols when the chain information has been changed to information indicating that the unauthorized startup program has been executed.