Secure Boot Sequencer Hardware Verification for IoT Downsizing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Semiconductor systems face challenges in secure booting due to excessive computational time and security requirements, especially in IoT devices, where malfunction can result in user harm, and downsizing is necessary to fit within these devices.
Innovation Solution
A secure boot device with a secure boot sequencer implemented by a finite state machine, which includes an external memory interface, internal memories for boot images and public key hashes, and a secure accelerator, allowing for secure boot operations without relying on a processor, thus reducing security threats and enabling downsizing by omitting a phase locked loop.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure booting is performed using processor-based verification, then security verification capability is improved, but processing time increases and device size increases
Solution Approach 1:
The patent replaces the processor-based verification system with a dedicated hardware verification device. This hardware device includes a verification unit that directly verifies boot images through cryptographic operations without requiring processor intervention, thereby eliminating the time loss associated with processor-based verification while maintaining security capabilities.
Solution Approach 2:
The patent introduces a dedicated verification device as an intermediary between the boot image storage and the processor. This verification device handles all security verification operations independently, acting as a mediator that prevents the processor from being burdened with verification tasks, thus reducing processing time while maintaining reliable security verification.
2Reliability
If secure booting is performed using processor-based verification, then security verification capability is improved, but device size increases
Solution Approach 1:
The patent segments the system into distinct functional modules: a dedicated verification device for security operations, external memory for boot image storage, and a processor for execution. This segmentation allows the verification functionality to be isolated in a specialized hardware unit rather than requiring the processor to handle both verification and execution, thereby maintaining security capabilities while reducing overall device complexity and size.
Solution Approach 2:
The patent extracts the security verification functionality from the processor and places it in a separate dedicated verification device. This extraction removes the burden of verification operations from the processor, allowing the processor to be smaller and less complex while the verification device handles security tasks independently, thus improving security without increasing overall device size.
3Reliability
If processor is included for secure booting, then security verification is achieved, but downsizing is limited
Solution Approach 1:
The patent replaces the processor-based secure booting mechanism with a dedicated hardware verification device that performs all security verification operations. This substitution enables the system to be downsized because the verification device is more compact and efficient than a full processor, yet it maintains complete security verification capability through specialized cryptographic hardware operations.
4Reliability
If external memory interface and secure accelerator are added, then secure booting functionality is improved, but device complexity increases
Solution Approach 1:
The patent merges the external memory interface and secure accelerator into an integrated verification device that handles both boot image retrieval and cryptographic verification in a single unified hardware unit. This merging reduces device complexity by eliminating the need for separate interface circuits and accelerator units, while still providing complete secure booting functionality through the combined operations of the integrated device.
Data Source
AI summary
A boot secure device that performs a secure booting operation of a semiconductor system includes an external memory interface that provides an interface with an external memory, a first internal memory that stores a boot image stored in the external memory, a second internal memory that stores a hash of a first public key, a secure accelerator that verifies the boot image using the hash of the first public key, and a secure boot sequencer that includes a plurality of states and a plurality of operation and that controls the external memory interface, the first internal memory, the second internal memory, and the secure accelerator using at least one of the plurality of operations when a state transition occurs between two of the plurality of states.


