Secure Boot Algorithm Switching for Post-Quantum Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic algorithms used in secure boot processes, such as RSA and ECC, are vulnerable to post-quantum attacks and may not meet the higher security requirements needed for communication devices, particularly in the post-quantum era, posing a risk to network device security.
Innovation Solution
A secure boot method that allows communication devices to switch to a first cryptographic algorithm capable of resisting post-quantum attacks by obtaining external secure boot code (ESBC) and performing integrity checks before verifying the signature of next-level software using the first cryptographic algorithm, which may be stored in a secure storage entity like a one-time programmable memory or security chip.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cryptographic algorithms (RSA, ECC) are used for secure boot, then the device can perform secure boot verification, but the security protection cannot meet higher security requirements or post-quantum security standards
Solution Approach 1:
The patent implements a dynamic cryptographic algorithm selection mechanism that allows the secure boot process to adaptively choose between traditional algorithms (RSA, ECC) and post-quantum resistant algorithms based on security requirements. The system can switch algorithms dynamically, enabling it to meet both current and future security standards without requiring hardware redesign.
Solution Approach 2:
The patent changes the cryptographic algorithm parameter from fixed to variable, allowing the system to select different algorithms based on security threats. By introducing algorithm selection capability, the system can adjust its cryptographic parameters to resist both classical and quantum computing attacks, thereby improving adaptability while maintaining reliability.
2Reliability
If a new cryptographic algorithm is introduced to resist post-quantum attacks, then post-quantum security is achieved, but the device complexity increases due to multiple algorithm support
Solution Approach 1:
The patent creates a universal secure boot framework that can handle multiple cryptographic algorithms through a unified interface. The verification module is designed to work with different algorithms (RSA, ECC, and post-quantum algorithms) without requiring separate verification paths, thereby reducing overall system complexity while maintaining multi-algorithm support.
Solution Approach 2:
The patent introduces an intermediary algorithm selection mechanism that mediates between the secure boot verification process and multiple cryptographic algorithms. This intermediary layer abstracts the complexity of multiple algorithms, allowing the core verification process to remain simple while supporting diverse cryptographic implementations.
3Adaptability or versatility
If external secure boot code is obtained and integrity check is performed, then the communication device can flexibly switch cryptographic algorithms, but the boot process time increases
Solution Approach 1:
The patent performs preliminary integrity checks on external secure boot code during the boot process before full verification. By conducting initial integrity validation early in the process, the system can quickly determine whether to proceed with full verification or accept the code, thereby reducing overall boot time while maintaining security.
Solution Approach 2:
The patent implements a conditional verification process where, after initial integrity checks pass, the system can skip certain verification steps if the cryptographic algorithm is already trusted or previously validated. This allows the boot process to rush through unnecessary verification steps, reducing time loss while maintaining adaptability.
Data Source
AI summary
A secure boot method. The method may be performed by a communication device. According to the method, the communication device can flexibly perform secure boot by using different cryptographic algorithms based on different security requirements, to ensure security of the communication device. The communication device may obtain external secure boot code (ESBC). The ESBC includes a code segment of a first cryptographic algorithm. After the ESBC is obtained, the communication device may perform an integrity check on the ESBC, and after the integrity check on the ESBC succeeds, verify a signature of next-level software based on the first cryptographic algorithm. When a cryptographic algorithm used by the communication device cannot meet a security requirement, the ESBC may be obtained, and the first cryptographic algorithm included in the ESBC is used to perform the secure boot, to meet the security requirement.


