Secure Boot Controller for Avionics Cold Start Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure boot mechanisms for embedded systems, particularly in avionics, require modifications to other system components to integrate a secure boot mechanism, leading to costly and complex recertification processes, especially for high-criticality components like those with a DAL A level.

Innovation Solution

A secure boot controller that determines the type of system startup (cold or hot) and executes verification functions only during cold starts, allowing secure boot integration without modifying other components, thus avoiding recertification needs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure boot mechanisms are integrated into embedded systems by modifying existing architectures, then security is improved, but device complexity and recertification requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidarchitecture modification
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the secure boot functionality into a separate, independent verification module that operates parallel to the main system components. This verification module contains the signature verification logic and operates independently without requiring modifications to the operational modules, thus improving security while avoiding architecture complexity and recertification issues.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a verification module as an intermediary component between the boot process and the operational modules. This intermediary performs signature verification on startup code without requiring the operational modules to be modified, thereby achieving security enhancement while maintaining the integrity and certification status of existing components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure boot mechanisms are integrated into high-criticality components (DAL level A), then security is improved, but recertification cost and complexity increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidrecertification cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

By segmenting secure boot functionality into a standalone verification module, the patent ensures that high-criticality operational modules remain unchanged. This allows the verification module to be certified independently while operational modules retain their existing certifications, dramatically reducing recertification costs for DAL level A systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The verification module acts as an intermediary that performs security verification without becoming part of the certified operational modules. This separation means that adding secure boot capabilities does not trigger recertification requirements for existing high-criticality components, reducing manufacturing and certification costs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If signature verification is performed at system startup, then security is improved, but startup time and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidstartup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The verification module performs signature verification in advance during the boot process before transferring control to operational modules. By completing security verification preliminarily and independently, the system ensures security without causing time loss during the execution of certified operational modules, as the verification occurs in a separate, pre-configured phase.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3907638B1Secure controller for starting an on-board system, associated on-board system and secure starting method
Publication Date: 2024.08.21 THALES SA
  • EP3907638B1 patent drawingFigure 1

AI summary

The present invention relates to a secure startup controller (18) for an embedded system (10), the embedded system (10) further comprising an operational module (12) integrating an operational function of the system (10), and a verification module (14) integrating a function for verifying various components of the system (10); The controller (18) is configured to: - on a cold start of the system (10), make the verification function executable at startup to perform a functional check including a check of the authenticity and integrity of the operational function; - when the functional check is successful, on each hot start following said cold start of the system (10), make the operational function executable at startup.