Secure Boot Sequencer Hardware Verification for IoT Downsizing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Semiconductor systems face challenges in secure booting due to excessive computational time and security requirements, especially in IoT devices, where malfunction can result in user harm, and downsizing is necessary to fit within these devices.

Innovation Solution

A secure boot device with a secure boot sequencer implemented by a finite state machine, which includes an external memory interface, internal memories for boot images and public key hashes, and a secure accelerator, allowing for secure boot operations without relying on a processor, thus reducing security threats and enabling downsizing by omitting a phase locked loop.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure booting is performed using processor-based verification, then security verification capability is improved, but processing time increases and device size increases

Engineering Contradiction:
Improvesecurity verification capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the processor-based verification system with a dedicated hardware verification device. This hardware device includes a verification unit that directly verifies boot images through cryptographic operations without requiring processor intervention, thereby eliminating the time loss associated with processor-based verification while maintaining security capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a dedicated verification device as an intermediary between the boot image storage and the processor. This verification device handles all security verification operations independently, acting as a mediator that prevents the processor from being burdened with verification tasks, thus reducing processing time while maintaining reliable security verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure booting is performed using processor-based verification, then security verification capability is improved, but device size increases

Engineering Contradiction:
Improvesecurity verification capabilityVSAvoiddevice size
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the system into distinct functional modules: a dedicated verification device for security operations, external memory for boot image storage, and a processor for execution. This segmentation allows the verification functionality to be isolated in a specialized hardware unit rather than requiring the processor to handle both verification and execution, thereby maintaining security capabilities while reducing overall device complexity and size.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the security verification functionality from the processor and places it in a separate dedicated verification device. This extraction removes the burden of verification operations from the processor, allowing the processor to be smaller and less complex while the verification device handles security tasks independently, thus improving security without increasing overall device size.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If processor is included for secure booting, then security verification is achieved, but downsizing is limited

Engineering Contradiction:
Improvesecurity verificationVSAvoiddownsizing capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the processor-based secure booting mechanism with a dedicated hardware verification device that performs all security verification operations. This substitution enables the system to be downsized because the verification device is more compact and efficient than a full processor, yet it maintains complete security verification capability through specialized cryptographic hardware operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If external memory interface and secure accelerator are added, then secure booting functionality is improved, but device complexity increases

Engineering Contradiction:
Improvesecure booting functionalityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the external memory interface and secure accelerator into an integrated verification device that handles both boot image retrieval and cryptographic verification in a single unified hardware unit. This merging reduces device complexity by eliminating the need for separate interface circuits and accelerator units, while still providing complete secure booting functionality through the combined operations of the integrated device.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11354416B2Secure boot sequencer and secure boot device
Publication Date: 2022.06.07 SAMSUNG ELECTRONICS CO LTD
  • US11354416B2 patent drawing
  • US11354416B2 patent drawing
  • US11354416B2 patent drawing

AI summary

A boot secure device that performs a secure booting operation of a semiconductor system includes an external memory interface that provides an interface with an external memory, a first internal memory that stores a boot image stored in the external memory, a second internal memory that stores a hash of a first public key, a secure accelerator that verifies the boot image using the hash of the first public key, and a secure boot sequencer that includes a plurality of states and a plurality of operation and that controls the external memory interface, the first internal memory, the second internal memory, and the secure accelerator using at least one of the plurality of operations when a state transition occurs between two of the plurality of states.