Secure Boot Algorithm Switching for Post-Quantum Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic algorithms used in secure boot processes, such as RSA and ECC, are vulnerable to post-quantum attacks and may not meet the higher security requirements needed for communication devices, particularly in the post-quantum era, posing a risk to network device security.

Innovation Solution

A secure boot method that allows communication devices to switch to a first cryptographic algorithm capable of resisting post-quantum attacks by obtaining external secure boot code (ESBC) and performing integrity checks before verifying the signature of next-level software using the first cryptographic algorithm, which may be stored in a secure storage entity like a one-time programmable memory or security chip.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptographic algorithms (RSA, ECC) are used for secure boot, then the device can perform secure boot verification, but the security protection cannot meet higher security requirements or post-quantum security standards

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidresistance to post-quantum attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic cryptographic algorithm selection mechanism that allows the secure boot process to adaptively choose between traditional algorithms (RSA, ECC) and post-quantum resistant algorithms based on security requirements. The system can switch algorithms dynamically, enabling it to meet both current and future security standards without requiring hardware redesign.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the cryptographic algorithm parameter from fixed to variable, allowing the system to select different algorithms based on security threats. By introducing algorithm selection capability, the system can adjust its cryptographic parameters to resist both classical and quantum computing attacks, thereby improving adaptability while maintaining reliability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a new cryptographic algorithm is introduced to resist post-quantum attacks, then post-quantum security is achieved, but the device complexity increases due to multiple algorithm support

Engineering Contradiction:
Improvepost-quantum security resistanceVSAvoidcryptographic algorithm implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal secure boot framework that can handle multiple cryptographic algorithms through a unified interface. The verification module is designed to work with different algorithms (RSA, ECC, and post-quantum algorithms) without requiring separate verification paths, thereby reducing overall system complexity while maintaining multi-algorithm support.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary algorithm selection mechanism that mediates between the secure boot verification process and multiple cryptographic algorithms. This intermediary layer abstracts the complexity of multiple algorithms, allowing the core verification process to remain simple while supporting diverse cryptographic implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If external secure boot code is obtained and integrity check is performed, then the communication device can flexibly switch cryptographic algorithms, but the boot process time increases

Engineering Contradiction:
Improvealgorithm switching capabilityVSAvoidboot process duration
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs preliminary integrity checks on external secure boot code during the boot process before full verification. By conducting initial integrity validation early in the process, the system can quickly determine whether to proceed with full verification or accept the code, thereby reducing overall boot time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a conditional verification process where, after initial integrity checks pass, the system can skip certain verification steps if the cryptographic algorithm is already trusted or previously validated. This allows the boot process to rush through unnecessary verification steps, reducing time loss while maintaining adaptability.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS12585781B2Secure boot method and apparatus
Publication Date: 2026.03.24 HUAWEI TECH CO LTD
  • US12585781B2 patent drawing
  • US12585781B2 patent drawing
  • US12585781B2 patent drawing

AI summary

A secure boot method. The method may be performed by a communication device. According to the method, the communication device can flexibly perform secure boot by using different cryptographic algorithms based on different security requirements, to ensure security of the communication device. The communication device may obtain external secure boot code (ESBC). The ESBC includes a code segment of a first cryptographic algorithm. After the ESBC is obtained, the communication device may perform an integrity check on the ESBC, and after the integrity check on the ESBC succeeds, verify a signature of next-level software based on the first cryptographic algorithm. When a cryptographic algorithm used by the communication device cannot meet a security requirement, the ESBC may be obtained, and the first cryptographic algorithm included in the ESBC is used to perform the secure boot, to meet the security requirement.