Secure Boot Semiconductor Memory OTP Capacity Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing semiconductor memory systems using one-time programmable (OTP) memory for secure boot methods face challenges with increased manufacturing costs and longer production times due to larger cell size and slower recording times compared to conventional memory.

Innovation Solution

A semiconductor memory system comprising external, internal, and OTP memory, where the first boot loader verifies the integrity of the second boot loader and generates a test secret key using boot information from both external and OTP memory, controlling the boot process based on message authentication codes or hash values to ensure secure operation without the need for additional OTP memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If OTP memory is used to store secret key for secure boot, then security is improved, but manufacturing cost increases due to larger cell size

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a test secret key as a copy/derivation of the actual secret key stored in OTP memory. The test secret key is generated by combining boot information from external memory with the secret key from OTP memory, allowing verification without directly accessing or storing the actual secret key in multiple locations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces boot information as an intermediary element that mediates between the secret key and the verification process. The boot information (message authentication code or hash value) serves as a intermediate representation that can be verified without exposing the actual secret key, reducing the need for additional OTP memory.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If OTP memory is used to store secret key for secure boot, then security is improved, but production time increases due to slower recording time

Engineering Contradiction:
ImprovesecurityVSAvoidproduction time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary generation of boot information (message authentication code or hash value) during the manufacturing process. By pre-computing and storing the boot information in external memory alongside the secret key in OTP memory, the system avoids time-consuming operations during production and enables faster verification during boot.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a test secret key as a copy/derivation of the actual secret key stored in OTP memory. The test secret key is generated by combining boot information from external memory with the secret key from OTP memory, allowing verification without directly accessing or storing the actual secret key in multiple locations.

Inventive Principle:
Principle #26Copying

3Reliability

If additional OTP memory is used to enhance security, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidmemory structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the boot information serve multiple functions: it acts as both an authentication mechanism and a key derivation element. The same boot information (message authentication code or hash value) is used to verify the integrity of the boot process and to generate the test secret key, eliminating the need for separate security structures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the secret key storage (in OTP memory) with boot information storage (in external memory) into a unified security verification system. The test secret key generation process combines both elements, creating an integrated approach that reduces overall system complexity compared to separate security modules.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8443203B2Secure boot method and semiconductor memory system using the method
Publication Date: 2013.05.14 SAMSUNG ELECTRONICS CO LTD
  • US8443203B2 patent drawing
  • US8443203B2 patent drawing
  • US8443203B2 patent drawing

AI summary

A semiconductor memory system includes an external memory, an internal memory, and a one-time programmable (OTP) memory. The external memory includes a kernel, a public key, first boot information used to authenticate the public key and generate a test secret key, and a second boot loader verifying integrity of the kernel. The internal memory includes a first boot loader that verifies integrity of the second boot loader and generates the test secret key. The OTP memory includes second boot information generated using the public key and a secret key. Since the secure boot method and the semiconductor memory system using the method do not need an additional OTP memory to store a secret key unlike conventional technology, the capacity and recording time of the OTP memory can be reduced to about half compared to the conventional technology.