Secure Boot Cryptographic Algorithm Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices typically store only one cryptographic algorithm for secure boot, which limits their ability to adapt to varying security requirements, potentially compromising security if the pre-installed algorithm does not meet higher security standards or user needs.

Innovation Solution

A method for managing cryptographic resources that allows for the flexible use of multiple cryptographic algorithms by updating and enabling/disabling them based on different security requirements, using a secure storage entity to store baseline information for each algorithm, including status and public key information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If only one cryptographic algorithm is stored in the secure storage entity, then the device complexity is reduced and ease of operation is improved, but the adaptability to different security requirements deteriorates

Engineering Contradiction:
Improveadaptability to different security requirementsVSAvoidcryptographic resource management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The cryptographic resources are segmented into multiple independent algorithm modules (RSA, ECC, SM2, SHA, SM3), each with its own baseline information stored in the secure storage entity. This segmentation allows the device to selectively enable different algorithms based on security requirements without increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic cryptographic resource management where the enabled cryptographic algorithm can be changed online through updating baseline information in the secure storage entity. The status information field allows runtime switching between different algorithms without requiring hardware redesign or device recall.

Inventive Principle:
Principle #15Dynamics

2Reliability

If the cryptographic algorithm is stored in a secure storage entity and cannot be modified, then the reliability and security are improved, but the adaptability to updated security standards deteriorates

Engineering Contradiction:
Improvesecure boot reliabilityVSAvoidadaptability to updated security standards
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Multiple cryptographic algorithm baseline information is pre-stored in the secure storage entity during device manufacturing, including status information for each algorithm. This preliminary preparation enables later online switching between algorithms without compromising the security of the storage entity or requiring physical modification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the status parameter of cryptographic algorithms stored in the secure storage entity to enable or disable specific algorithms. By modifying the status information field rather than the algorithm itself, the system maintains storage security while achieving adaptability to updated security standards.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If multiple cryptographic algorithms are supported with online updating capability, then the adaptability to different security requirements is improved, but the device complexity increases

Engineering Contradiction:
Improveflexibility in cryptographic algorithm selectionVSAvoidcryptographic resource baseline information management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The secure storage entity is designed with universal structure that can store baseline information for multiple cryptographic algorithms (RSA, ECC, SM2, SHA, SM3) using the same data format and management mechanism. This multi-functionality approach avoids increasing device complexity while supporting diverse cryptographic resources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses baseline information copies of cryptographic algorithms rather than storing the full algorithm implementations in the secure storage entity. Each algorithm has a compact baseline information representation including status flags, allowing efficient management of multiple algorithms without proportionally increasing storage complexity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12021982B2Method for performing secure boot based on redundant cryptographic algorithm and device
Publication Date: 2024.06.25 HUAWEI TECH CO LTD
  • US12021982B2 patent drawing
  • US12021982B2 patent drawing
  • US12021982B2 patent drawing

AI summary

This application discloses a method for performing secure boot based on a redundant cryptographic algorithm and a device. The method includes: obtaining first indication information and second indication information, and updating first baseline information based on the first indication information and the second indication information. The first indication information uniquely identifies a first cryptographic algorithm, the second indication information is used to instruct a network device to update the first cryptographic resource baseline information stored in a secure storage entity, and the first cryptographic resource baseline information is used to perform integrity verification on a first cryptographic resource used by the network device in a secure boot process.