Two-Step Secure Boot Mechanism for Semiconductor Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for provisioning operating systems (OS) in semiconductor devices are vulnerable to security attacks during the manufacturing process, particularly in the OEM/ODM stage, where attackers can insert malware or spyware, compromising the security of network processors and IoT devices, and posing risks to copyrighted content distribution.

Innovation Solution

A 2-step secure boot mechanism is implemented, where the first boot instructions provide minimal functionality to enable the semiconductor device, and the second boot instructions, encrypted with a different key, complete the device's functionality and secure communication capabilities, allowing secure provisioning without exposing the vendor to critical keys, thereby preventing attacks during OS installation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the chip manufacturer programs the network processor with dedicated key material during manufacturing, then the device can be securely identified and authenticated, but the security is compromised when the OS is provisioned downstream by OEM/ODM where attackers can insert malware or spyware

Engineering Contradiction:
ImprovesecurityVSAvoidOS provisioning flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the boot process into two distinct phases: a first boot phase that provides minimal functionality for secure key establishment, and a second boot phase that enables full device functionality. This segmentation allows the chip vendor to maintain security control during the critical provisioning stage while still enabling OEM/ODM flexibility for OS installation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by establishing secure cryptographic keys and authentication mechanisms during the first boot phase before any OS provisioning occurs. This preliminary security setup ensures that subsequent OS installation by OEM/ODM cannot introduce malware, as the device will only execute authenticated software.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If the same encryption key is used for both boot phases, then the implementation is simpler, but the vendor is exposed to critical keys during OEM/ODM provisioning stages

Engineering Contradiction:
Improvekey managementVSAvoidvendor security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent extracts the vendor's critical encryption key from the provisioning process entirely. The first boot phase uses a vendor-specific key that is never exposed to OEM/ODM systems. This extraction of the sensitive key from the provisioning workflow eliminates the security vulnerability while maintaining implementation simplicity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary cryptographic mechanism where the vendor's key signs the first boot image, and a separate second key is used for the second boot phase. This intermediary signature verification system allows secure key management without requiring the vendor to expose their critical keys during provisioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If minimal functionality is provided in the first boot phase, then security is improved by limiting attack surface, but the device cannot perform secure communication until the second boot phase

Engineering Contradiction:
ImprovesecurityVSAvoidtime to functional operation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a dynamic boot process that transitions from a restricted first boot phase to a fully functional second boot phase. The device adapts its functionality based on the boot phase, initially providing only essential security functions and then expanding to full communication capabilities once authentication is verified. This dynamic approach minimizes the attack surface during critical phases while enabling timely functional operation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11550877B2Root of trust
Publication Date: 2023.01.10 MAXLINEAR INC
  • US11550877B2 patent drawing
  • US11550877B2 patent drawing
  • US11550877B2 patent drawing

AI summary

First transistor logic is arranged by a first logic provider in circuit form and provides a minimum of functionality of the semiconductor device employed to bring up the semiconductor device, wherein the minimum of functionality is encrypted using a first encryption key. Second transistor logic is arranged by a second logic provider, different than the first logic provider, in circuit form to include security keys capable to perform cryptographic capabilities using a second encryption key. The second transistor logic further includes functionality that completes the semiconductor device as a chip device and is ready to process secure communication signals.