Secure OS Distribution via Public Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multiprocessing environments, there is a need for secure distribution and execution of multiple operating systems to prevent unauthorized access and modification, particularly when hardware manufacturers and software developers are competitors, and multiple OS platforms coexist.

Innovation Solution

A method and apparatus that utilize a secret key stored in a secure ROM, where a trusted third party creates public keys paired with the secret key to encrypt operating systems and an authentication program, which are then stored in secure storage media, allowing only authorized entities to decrypt and execute the OS, ensuring secure boot and authentication processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If operating systems are distributed to hardware manufacturers for loading into multiprocessing systems, then the systems can execute multiple OS platforms, but the proprietary information of operating systems may be exposed to unauthorized access or modification

Engineering Contradiction:
Improvemulti-OS platform executionVSAvoidOS security and proprietary information protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a trusted third party as an intermediary that encrypts operating systems with public keys before distribution to hardware manufacturers. This mediator ensures that OS proprietary information remains protected while still allowing the hardware manufacturer to load and execute multiple OS platforms. The trusted third party establishes a secure chain of custody through cryptographic mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The operating systems are encrypted with public keys in advance before being distributed to hardware manufacturers. This preliminary encryption action ensures that the OS code is protected from unauthorized access or modification during the manufacturing and loading process. The decryption can only occur under controlled conditions using corresponding private keys.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If operating systems are encrypted with public keys by a trusted third party, then security against unauthorized access is improved, but the complexity of the distribution and authentication process increases

Engineering Contradiction:
ImproveOS protection from unauthorized accessVSAvoiddistribution and authentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs universal cryptographic mechanisms (public-key encryption and authentication programs) that can handle multiple operating systems through a unified security framework. Instead of creating separate security systems for each OS, the same encryption and authentication infrastructure serves all OS platforms, reducing overall system complexity while maintaining robust security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication program is designed to automatically verify the integrity and authenticity of encrypted operating systems without requiring manual intervention. The system self-authenticates by executing the authentication program that validates cryptographic signatures, reducing operational complexity while ensuring security.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple operating systems are stored and executed in a multiprocessing system, then system versatility is enhanced, but the risk of unauthorized modification during manufacturing and use increases

Engineering Contradiction:
Improvenumber of OS platformsVSAvoidunauthorized access and modification
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The trusted third party acts as a mediator that establishes a secure chain of custody for each operating system through cryptographic encryption. This intermediary ensures that even as multiple OS platforms are added to the multiprocessing system, each one maintains its security through individual encryption with public keys, preventing unauthorized modification while preserving system versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates secure cryptographic copies of operating systems that can be distributed and executed across multiple processors. Each OS is encrypted to create a protected copy that can be safely stored and executed without risk of unauthorized modification. This allows multiple OS platforms to coexist in the multiprocessing system, each with its own security envelope.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7958371B2Methods and apparatus for secure operating system distribution in a multiprocessor system
Publication Date: 2011.06.07 SONY INTERACTIVE ENTERTAINMENT LLC
  • US7958371B2 patent drawing
  • US7958371B2 patent drawing
  • US7958371B2 patent drawing

AI summary

Methods and apparatus provide for: decrypting a first of a plurality of operating systems (OSs) within a first processor of a multiprocessing system using a private key thereof, the plurality of OSs having been encrypted by a trusted third party, other than a manufacturer of the multiprocessing system, using respective public keys, each paired with the private key; executing an authentication program using the first processor to verify that the first OS is valid; and executing the first OS on the first processor.