Secure Boot System on Chip Using Encrypted Initialization Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing image forming apparatuses face security challenges as unauthorized access to consumable units' memory can lead to hacking of the boot process, compromising the security and integrity of the device.

Innovation Solution

A system on chip is introduced that performs secure boot using encrypted data stored in non-volatile memory, with a CPU decrypting initialization data and controlling access through circuits to ensure only authorized access during the boot process, utilizing a memory controller to manage encryption keys and prevent unauthorized writing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If memory is embedded in consumable unit to track usage, then usage tracking capability is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveusage tracking capabilityVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the security-critical boot process data from the consumable unit memory and stores it in the main body apparatus memory. The consumable unit only contains usage information, while the encrypted boot data resides separately in the main apparatus, preventing unauthorized access to critical security data while maintaining usage tracking functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an encryption key as an intermediary between the stored boot data and the consumable unit. The boot data is encrypted with a key that is not stored in the consumable unit, creating a security barrier that allows usage tracking while preventing unauthorized access to the boot process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security technology is applied to consumable unit, then security of consumable unit is improved, but vulnerability to hacking via main memory boot process deteriorates

Engineering Contradiction:
Improvesecurity of consumable unitVSAvoidhacking vulnerability via boot process
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary encryption of the boot process data before storing it in the main body apparatus memory. This preliminary security measure ensures that even if the consumable unit security is compromised, the boot data remains protected through pre-applied encryption, preventing hacking via the boot process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the security system into two parts: the consumable unit contains usage tracking data, while the main body apparatus contains the encrypted boot process data. This segmentation isolates the critical security data from the consumable unit, preventing hacking vulnerability while maintaining consumable unit security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If encrypted data is stored in non-volatile memory, then security of boot process is improved, but complexity of decryption and authentication deteriorates

Engineering Contradiction:
Improvesecurity of boot processVSAvoidcomplexity of decryption and authentication
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service decryption where the system automatically retrieves the encryption key from secure storage and performs decryption and authentication of the boot data without requiring external intervention. This automates the complex security processes, maintaining high security while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses an encryption key as an intermediary that simplifies the decryption process. The key acts as a mediator between the encrypted boot data and the processing system, enabling automatic decryption and authentication without complex manual procedures, thus maintaining security while managing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2741228B1System on chip to perform a secure boot, an image forming apparatus using the same, and method thereof
Publication Date: 2020.03.18 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • EP2741228B1 patent drawingFigure 1
  • EP2741228B1 patent drawingFigure 2
  • EP2741228B1 patent drawingFigure 3

AI summary

A system on chip is provided. The system on chip includes a first memory to store a plurality of encryption keys, a second memory, a third memory to store an encryption key setting value, and a CPU to decrypt encrypted data which is stored in an external non-volatile memory using an encryption key corresponding to the encryption key setting value from among the plurality of encryption keys, to store the decrypted data in the second memory, and to perform a boot using data stored in the second memory. Accordingly, security of a boot operation can be improved.