Secure Boot ROM Verification for Device Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for computing devices fail to provide robust protection against attacks while allowing for software updates and flexibility, as they are often vulnerable to new threats and limit device capabilities.

Innovation Solution

A method and apparatus for secure booting and recovery of computing devices using a certified code image digitally signed with a public key certification process, verified through a secure ROM, allowing for trusted software execution and updates while maintaining device security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strict security measures are implemented to seal the device from installing additional software, then security protection is improved, but device flexibility and update capability are severely limited

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system is segmented into multiple trust levels: a secure boot loader in ROM that provides base security, and a certificate-based verification system that allows controlled software installation. This segmentation enables both strict security for critical components and flexibility for user applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security credentials (private key and certificate) are pre-loaded into the secure ROM during manufacturing. This preliminary action establishes a trusted foundation that enables both security protection and flexible software updates without requiring physical device sealing.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If operating system security features are used to guard against attacks, then some security protection is provided, but the system remains vulnerable to new attacks and bypasses during booting

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The secure boot loader and certificate verification system execute before the main operating system is loaded, establishing security credentials in advance. This preliminary security layer prevents attacks during the vulnerable booting phase and before OS security features are initialized.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A certificate-based verification system acts as an intermediary between the boot loader and the operating system. This intermediary validates software credentials before execution, providing security protection that operates independently of and complements OS security features.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If complete sealing of the device is implemented to prevent malicious software installation, then security is improved, but software updates become costly and difficult

Engineering Contradiction:
Improvesecurity protectionVSAvoidsoftware update capability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The device is pre-configured with secure credentials and a certificate verification system during manufacturing. This preliminary setup enables both security protection and easy software updates through digital signature validation, eliminating the need for physical sealing or costly re-manufacturing for updates.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If traditional security measures are used, then some protection is provided, but they fail to protect against new threats and daily attacks

Engineering Contradiction:
Improvesecurity protectionVSAvoidability to counter new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system dynamically validates software credentials at runtime rather than relying on static security measures. The certificate-based verification can adapt to new threats by rejecting any software that lacks valid credentials, providing protection against both known and emerging attacks.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10142104B2Securely recovering a computing device
Publication Date: 2018.11.27 APPLE INC
  • US10142104B2 patent drawing
  • US10142104B2 patent drawing
  • US10142104B2 patent drawing

AI summary

A method and an apparatus for establishing an operating environment by certifying a code image received from a host over a communication link are described. The code image may be digitally signed through a central authority server. Certification of the code image may be determined by a fingerprint embedded within a secure storage area such as a ROM (read only memory) of the portable device based on a public key certification process. A certified code image may be assigned a hash signature to be stored in a storage of the portable device. An operating environment of the portable device may be established after executing the certified code.