Valuable Medium Processing Security With Secure Boot Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing valuable medium processing systems face challenges in ensuring the security of multiple software components that execute various processes, particularly in preventing unauthorized execution and verifying software vulnerabilities.
Innovation Solution
Implementing a secure boot function with a processor that executes prohibition and authentication processes to ensure secure communication and verification among apparatuses, using a verification apparatus to authenticate and verify the validity of execution apparatuses, and employing a tamper-resistant storage unit to manage boot data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple software components are used to execute various processes in a valuable medium processing system, then the functionality and versatility of the system are improved, but the security risk and complexity of verifying software validity increase
Solution Approach 1:
The patent implements a secure boot mechanism that performs preliminary authentication of software components before they are executed. The validity determination unit authenticates each software component's signature and verifies its integrity before allowing execution, preventing unauthorized or malicious software from running in the system.
Solution Approach 2:
The patent introduces a verification apparatus as an intermediary between the software components and the execution environment. This verification apparatus includes a validity determination unit that acts as a mediator to authenticate software signatures and determine validity, isolating the security verification process from the main execution flow.
2Reliability
If a secure boot function with authentication processes is implemented, then the security of software execution is improved, but the system complexity and processing time increase
Solution Approach 1:
The verification apparatus is designed as a universal security mechanism that can authenticate multiple types of software components (boot programs, operating systems, application programs) using a unified authentication framework. The validity determination unit handles different authentication scenarios through a single multi-functional system.
Solution Approach 2:
The system implements self-service authentication where software components carry their own digital signatures that automatically verify their validity. The validity determination unit checks these embedded signatures without requiring external verification for each component, enabling the system to authenticate itself.
3Reliability
If authentication and verification processes are performed for all software components, then the security against unauthorized execution is improved, but the processing speed and system efficiency decrease
Solution Approach 1:
The secure boot mechanism performs authentication of critical system software (boot programs, operating systems) before the system fully boots up. This preliminary authentication ensures that the core execution environment is secure before any application software runs, establishing a trusted base for subsequent operations.
Solution Approach 2:
The system implements selective authentication where critical security-related software components undergo rigorous verification, while less critical components may use simplified verification or inherit trust from already-verified parent components. The validity determination unit skips redundant verification steps for software that has already been authenticated through the software hierarchy.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A valuable medium processing apparatus according to the present disclosure that includes a secure boot function and executes a first medium process related to a valuable medium, the valuable medium processing apparatus including: a safe in which a container that stores the valuable medium is disposed inside; and a circuit board arranged inside the safe and equipped with a processor, the processor being configured to: execute an execution prohibition process of transmitting a prohibition command of prohibiting execution of a second medium process related to the valuable medium to an execution apparatus that executes the second medium process, and execute a prohibition release process of releasing the prohibition command when a validity of the execution apparatus is confirmed.