Secure Boot System on Chip Using Encrypted Initialization Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing image forming apparatuses face security challenges as unauthorized access to consumable units' memory can lead to hacking of the boot process, compromising the security and integrity of the device.
Innovation Solution
A system on chip is introduced that performs secure boot using encrypted data stored in non-volatile memory, with a CPU decrypting initialization data and controlling access through circuits to ensure only authorized access during the boot process, utilizing a memory controller to manage encryption keys and prevent unauthorized writing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If memory is embedded in consumable unit to track usage, then usage tracking capability is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent extracts the security-critical boot process data from the consumable unit memory and stores it in the main body apparatus memory. The consumable unit only contains usage information, while the encrypted boot data resides separately in the main apparatus, preventing unauthorized access to critical security data while maintaining usage tracking functionality.
Solution Approach 2:
The patent introduces an encryption key as an intermediary between the stored boot data and the consumable unit. The boot data is encrypted with a key that is not stored in the consumable unit, creating a security barrier that allows usage tracking while preventing unauthorized access to the boot process.
2Reliability
If security technology is applied to consumable unit, then security of consumable unit is improved, but vulnerability to hacking via main memory boot process deteriorates
Solution Approach 1:
The patent performs preliminary encryption of the boot process data before storing it in the main body apparatus memory. This preliminary security measure ensures that even if the consumable unit security is compromised, the boot data remains protected through pre-applied encryption, preventing hacking via the boot process.
Solution Approach 2:
The patent segments the security system into two parts: the consumable unit contains usage tracking data, while the main body apparatus contains the encrypted boot process data. This segmentation isolates the critical security data from the consumable unit, preventing hacking vulnerability while maintaining consumable unit security.
3Reliability
If encrypted data is stored in non-volatile memory, then security of boot process is improved, but complexity of decryption and authentication deteriorates
Solution Approach 1:
The patent implements self-service decryption where the system automatically retrieves the encryption key from secure storage and performs decryption and authentication of the boot data without requiring external intervention. This automates the complex security processes, maintaining high security while reducing operational complexity.
Solution Approach 2:
The patent uses an encryption key as an intermediary that simplifies the decryption process. The key acts as a mediator between the encrypted boot data and the processing system, enabling automatic decryption and authentication without complex manual procedures, thus maintaining security while managing complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system on chip is provided. The system on chip includes a first memory to store a plurality of encryption keys, a second memory, a third memory to store an encryption key setting value, and a CPU to decrypt encrypted data which is stored in an external non-volatile memory using an encryption key corresponding to the encryption key setting value from among the plurality of encryption keys, to store the decrypted data in the second memory, and to perform a boot using data stored in the second memory. Accordingly, security of a boot operation can be improved.