Secure OS Distribution via Public Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multiprocessing environments, there is a need for secure distribution and execution of multiple operating systems to prevent unauthorized access and modification, particularly when hardware manufacturers and software developers are competitors, and multiple OS platforms coexist.
Innovation Solution
A method and apparatus that utilize a secret key stored in a secure ROM, where a trusted third party creates public keys paired with the secret key to encrypt operating systems and an authentication program, which are then stored in secure storage media, allowing only authorized entities to decrypt and execute the OS, ensuring secure boot and authentication processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If operating systems are distributed to hardware manufacturers for loading into multiprocessing systems, then the systems can execute multiple OS platforms, but the proprietary information of operating systems may be exposed to unauthorized access or modification
Solution Approach 1:
The patent introduces a trusted third party as an intermediary that encrypts operating systems with public keys before distribution to hardware manufacturers. This mediator ensures that OS proprietary information remains protected while still allowing the hardware manufacturer to load and execute multiple OS platforms. The trusted third party establishes a secure chain of custody through cryptographic mechanisms.
Solution Approach 2:
The operating systems are encrypted with public keys in advance before being distributed to hardware manufacturers. This preliminary encryption action ensures that the OS code is protected from unauthorized access or modification during the manufacturing and loading process. The decryption can only occur under controlled conditions using corresponding private keys.
2Reliability
If operating systems are encrypted with public keys by a trusted third party, then security against unauthorized access is improved, but the complexity of the distribution and authentication process increases
Solution Approach 1:
The patent employs universal cryptographic mechanisms (public-key encryption and authentication programs) that can handle multiple operating systems through a unified security framework. Instead of creating separate security systems for each OS, the same encryption and authentication infrastructure serves all OS platforms, reducing overall system complexity while maintaining robust security.
Solution Approach 2:
The authentication program is designed to automatically verify the integrity and authenticity of encrypted operating systems without requiring manual intervention. The system self-authenticates by executing the authentication program that validates cryptographic signatures, reducing operational complexity while ensuring security.
3Adaptability or versatility
If multiple operating systems are stored and executed in a multiprocessing system, then system versatility is enhanced, but the risk of unauthorized modification during manufacturing and use increases
Solution Approach 1:
The trusted third party acts as a mediator that establishes a secure chain of custody for each operating system through cryptographic encryption. This intermediary ensures that even as multiple OS platforms are added to the multiprocessing system, each one maintains its security through individual encryption with public keys, preventing unauthorized modification while preserving system versatility.
Solution Approach 2:
The patent creates secure cryptographic copies of operating systems that can be distributed and executed across multiple processors. Each OS is encrypted to create a protected copy that can be safely stored and executed without risk of unauthorized modification. This allows multiple OS platforms to coexist in the multiprocessing system, each with its own security envelope.
Data Source
AI summary
Methods and apparatus provide for: decrypting a first of a plurality of operating systems (OSs) within a first processor of a multiprocessing system using a private key thereof, the plurality of OSs having been encrypted by a trusted third party, other than a manufacturer of the multiprocessing system, using respective public keys, each paired with the private key; executing an authentication program using the first processor to verify that the first OS is valid; and executing the first OS on the first processor.


