Secure Boot Semiconductor Memory OTP Capacity Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing semiconductor memory systems using one-time programmable (OTP) memory for secure boot methods face challenges with increased manufacturing costs and longer production times due to larger cell size and slower recording times compared to conventional memory.
Innovation Solution
A semiconductor memory system comprising external, internal, and OTP memory, where the first boot loader verifies the integrity of the second boot loader and generates a test secret key using boot information from both external and OTP memory, controlling the boot process based on message authentication codes or hash values to ensure secure operation without the need for additional OTP memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If OTP memory is used to store secret key for secure boot, then security is improved, but manufacturing cost increases due to larger cell size
Solution Approach 1:
The patent creates a test secret key as a copy/derivation of the actual secret key stored in OTP memory. The test secret key is generated by combining boot information from external memory with the secret key from OTP memory, allowing verification without directly accessing or storing the actual secret key in multiple locations.
Solution Approach 2:
The patent introduces boot information as an intermediary element that mediates between the secret key and the verification process. The boot information (message authentication code or hash value) serves as a intermediate representation that can be verified without exposing the actual secret key, reducing the need for additional OTP memory.
2Reliability
If OTP memory is used to store secret key for secure boot, then security is improved, but production time increases due to slower recording time
Solution Approach 1:
The patent performs preliminary generation of boot information (message authentication code or hash value) during the manufacturing process. By pre-computing and storing the boot information in external memory alongside the secret key in OTP memory, the system avoids time-consuming operations during production and enables faster verification during boot.
Solution Approach 2:
The patent creates a test secret key as a copy/derivation of the actual secret key stored in OTP memory. The test secret key is generated by combining boot information from external memory with the secret key from OTP memory, allowing verification without directly accessing or storing the actual secret key in multiple locations.
3Reliability
If additional OTP memory is used to enhance security, then security is improved, but device complexity increases
Solution Approach 1:
The patent makes the boot information serve multiple functions: it acts as both an authentication mechanism and a key derivation element. The same boot information (message authentication code or hash value) is used to verify the integrity of the boot process and to generate the test secret key, eliminating the need for separate security structures.
Solution Approach 2:
The patent merges the secret key storage (in OTP memory) with boot information storage (in external memory) into a unified security verification system. The test secret key generation process combines both elements, creating an integrated approach that reduces overall system complexity compared to separate security modules.
Data Source
AI summary
A semiconductor memory system includes an external memory, an internal memory, and a one-time programmable (OTP) memory. The external memory includes a kernel, a public key, first boot information used to authenticate the public key and generate a test secret key, and a second boot loader verifying integrity of the kernel. The internal memory includes a first boot loader that verifies integrity of the second boot loader and generates the test secret key. The OTP memory includes second boot information generated using the public key and a secret key. Since the secure boot method and the semiconductor memory system using the method do not need an additional OTP memory to store a secret key unlike conventional technology, the capacity and recording time of the OTP memory can be reduced to about half compared to the conventional technology.


