SoC Secure Boot Authentication Writing via an Overlay Data Register
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hardware-combined secure boot schemes risk damaging chips if incorrect authentication information is written to the one-time programmable (OTP) memory, leading to increased production costs.
Innovation Solution
A method and system that utilize an overlay data register (ODR) to simulate authentication information verification during development, allowing secure verification before writing to the OTP memory, reducing the risk of errors and costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication information is written directly to OTP memory during development, then the secure boot process can be implemented, but the risk of chip damage increases due to potential writing errors
Solution Approach 1:
The patent introduces a preparation phase where authentication information is first written to a configurable register before being transferred to OTP memory. This preliminary action allows verification of the information's correctness before permanent storage, preventing chip damage from erroneous writes while still enabling secure boot functionality.
Solution Approach 2:
The patent uses a configurable register as an intermediary between the authentication information source and the OTP memory. This intermediary allows the system to hold and verify authentication information temporarily, providing a safety buffer that prevents direct permanent writes until verification is complete, thus reducing chip damage risk.
2Manufacturing precision
If authentication information is verified before writing to OTP memory, then the risk of erroneous data is reduced, but the development process becomes more complex
Solution Approach 1:
The patent designs the configurable register to serve multiple functions: it acts as a temporary storage location for authentication information, a verification buffer, and a transfer intermediary. This multi-functionality reduces the need for separate dedicated verification hardware, thereby limiting the increase in overall system complexity while still enabling accuracy verification.
Solution Approach 2:
The system uses its existing processor and memory structures to perform verification functions without requiring external verification equipment. The configurable register leverages the system's own resources to validate authentication information before permanent storage, achieving high manufacturing precision while minimizing additional complexity.
Data Source
AI summary
A method and a system for writing authentication information are provided. The method is applicable to a system-on-chip (SoC) and includes configuring a processor to perform: writing predetermined authentication information into an overlay data register (ODR); executing a boot process, reading the ODR according to a secure attribute table stored in a read-only memory to obtain to-be-verified authentication information corresponding to the predetermined authentication information used to replace authentication information predetermined to be read from a one-time programmable (OTP) memory; executing a security verification process of the boot process on the to-be-verified authentication information to determine whether or not the to-be-verified authentication information passes a security verification; and in response to determining that the to-be-verified authentication information passes the security verification, writing the to-be-verified authentication information into the OTP memory to serve as the authentication information.


