SoC Secure Boot Authentication Writing via an Overlay Data Register

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware-combined secure boot schemes risk damaging chips if incorrect authentication information is written to the one-time programmable (OTP) memory, leading to increased production costs.

Innovation Solution

A method and system that utilize an overlay data register (ODR) to simulate authentication information verification during development, allowing secure verification before writing to the OTP memory, reducing the risk of errors and costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication information is written directly to OTP memory during development, then the secure boot process can be implemented, but the risk of chip damage increases due to potential writing errors

Engineering Contradiction:
Improvesecure boot implementationVSAvoidchip damage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a preparation phase where authentication information is first written to a configurable register before being transferred to OTP memory. This preliminary action allows verification of the information's correctness before permanent storage, preventing chip damage from erroneous writes while still enabling secure boot functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses a configurable register as an intermediary between the authentication information source and the OTP memory. This intermediary allows the system to hold and verify authentication information temporarily, providing a safety buffer that prevents direct permanent writes until verification is complete, thus reducing chip damage risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If authentication information is verified before writing to OTP memory, then the risk of erroneous data is reduced, but the development process becomes more complex

Engineering Contradiction:
Improveauthentication information accuracyVSAvoidwriting process complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent designs the configurable register to serve multiple functions: it acts as a temporary storage location for authentication information, a verification buffer, and a transfer intermediary. This multi-functionality reduces the need for separate dedicated verification hardware, thereby limiting the increase in overall system complexity while still enabling accuracy verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses its existing processor and memory structures to perform verification functions without requiring external verification equipment. The configurable register leverages the system's own resources to validate authentication information before permanent storage, achieving high manufacturing precision while minimizing additional complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12430419B2Method and system for writing authentication information
Publication Date: 2025.09.30 REALTEK SEMICON CORP
  • US12430419B2 patent drawing
  • US12430419B2 patent drawing
  • US12430419B2 patent drawing

AI summary

A method and a system for writing authentication information are provided. The method is applicable to a system-on-chip (SoC) and includes configuring a processor to perform: writing predetermined authentication information into an overlay data register (ODR); executing a boot process, reading the ODR according to a secure attribute table stored in a read-only memory to obtain to-be-verified authentication information corresponding to the predetermined authentication information used to replace authentication information predetermined to be read from a one-time programmable (OTP) memory; executing a security verification process of the boot process on the to-be-verified authentication information to determine whether or not the to-be-verified authentication information passes a security verification; and in response to determining that the to-be-verified authentication information passes the security verification, writing the to-be-verified authentication information into the OTP memory to serve as the authentication information.