Secure Boot Cryptographic Algorithm Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network devices typically store only one cryptographic algorithm for secure boot, which limits their ability to adapt to varying security requirements, potentially compromising security if the pre-installed algorithm does not meet higher security standards or user needs.
Innovation Solution
A method for managing cryptographic resources that allows for the flexible use of multiple cryptographic algorithms by updating and enabling/disabling them based on different security requirements, using a secure storage entity to store baseline information for each algorithm, including status and public key information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If only one cryptographic algorithm is stored in the secure storage entity, then the device complexity is reduced and ease of operation is improved, but the adaptability to different security requirements deteriorates
Solution Approach 1:
The cryptographic resources are segmented into multiple independent algorithm modules (RSA, ECC, SM2, SHA, SM3), each with its own baseline information stored in the secure storage entity. This segmentation allows the device to selectively enable different algorithms based on security requirements without increasing overall system complexity.
Solution Approach 2:
The system implements dynamic cryptographic resource management where the enabled cryptographic algorithm can be changed online through updating baseline information in the secure storage entity. The status information field allows runtime switching between different algorithms without requiring hardware redesign or device recall.
2Reliability
If the cryptographic algorithm is stored in a secure storage entity and cannot be modified, then the reliability and security are improved, but the adaptability to updated security standards deteriorates
Solution Approach 1:
Multiple cryptographic algorithm baseline information is pre-stored in the secure storage entity during device manufacturing, including status information for each algorithm. This preliminary preparation enables later online switching between algorithms without compromising the security of the storage entity or requiring physical modification.
Solution Approach 2:
The system changes the status parameter of cryptographic algorithms stored in the secure storage entity to enable or disable specific algorithms. By modifying the status information field rather than the algorithm itself, the system maintains storage security while achieving adaptability to updated security standards.
3Adaptability or versatility
If multiple cryptographic algorithms are supported with online updating capability, then the adaptability to different security requirements is improved, but the device complexity increases
Solution Approach 1:
The secure storage entity is designed with universal structure that can store baseline information for multiple cryptographic algorithms (RSA, ECC, SM2, SHA, SM3) using the same data format and management mechanism. This multi-functionality approach avoids increasing device complexity while supporting diverse cryptographic resources.
Solution Approach 2:
The system uses baseline information copies of cryptographic algorithms rather than storing the full algorithm implementations in the secure storage entity. Each algorithm has a compact baseline information representation including status flags, allowing efficient management of multiple algorithms without proportionally increasing storage complexity.
Data Source
AI summary
This application discloses a method for performing secure boot based on a redundant cryptographic algorithm and a device. The method includes: obtaining first indication information and second indication information, and updating first baseline information based on the first indication information and the second indication information. The first indication information uniquely identifies a first cryptographic algorithm, the second indication information is used to instruct a network device to update the first cryptographic resource baseline information stored in a secure storage entity, and the first cryptographic resource baseline information is used to perform integrity verification on a first cryptographic resource used by the network device in a secure boot process.


