Shared Storage Boot Security for Wireless and Application Processors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multifunctional devices, such as smartphones, face challenges in reducing size and cost due to the need for separate non-volatile storage for each processor, which increases device size and cost, and requires complex booting and software update processes.

Innovation Solution

A multifunctional computing device shares a non-volatile storage device between a wireless communications processor and an application processor, using a high-speed communications link for data access, and employs a ROM boot loader to authenticate and execute boot code, eliminating the need for a dedicated storage device on the wireless processor, and enables secure software updates through encryption and key-based authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate non-volatile storage devices are provided for each processor, then each processor can independently store and execute code, but device size and cost increase

Engineering Contradiction:
Improveprocessor independenceVSAvoiddevice size
Core Design Contradiction:
ReliabilityVSVolume of moving object

Solution Approach 1:

The patent merges the storage resources by allowing the wireless communications processor to access the application processor's non-volatile storage device through a high-speed communication link, eliminating the need for separate storage devices while maintaining functional independence

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The application processor's storage device is made universal by enabling both the application processor and wireless communications processor to utilize it for code storage and execution, maximizing resource utilization and reducing overall device size

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate non-volatile storage devices are provided for each processor, then code security can be maintained, but manufacturing cost increases

Engineering Contradiction:
Improvecode securityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent combines storage resources while implementing security through authentication mechanisms, allowing shared storage access without compromising code security, thereby reducing manufacturing cost associated with multiple storage devices

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The application processor acts as an intermediary between the wireless communications processor and the shared storage device, managing access control and authentication to ensure secure code execution while enabling cost-effective shared storage

Inventive Principle:
Principle #24Intermediary (Mediator)

3Volume of moving object

If a shared storage device is used between processors, then device size and cost are reduced, but secure access control becomes more complex

Engineering Contradiction:
Improvedevice sizeVSAvoidaccess control mechanism
Core Design Contradiction:
Volume of moving objectVSDevice complexity

Solution Approach 1:

The application processor serves as a mediator that manages the complexity of access control, handling authentication and authorization for the wireless communications processor's access to shared storage, thereby simplifying the overall system architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service authentication where the wireless communications processor can autonomously authenticate and execute code from shared storage using established security protocols, reducing the need for complex external access control mechanisms

Inventive Principle:
Principle #25Self-service

4Volume of moving object

If boot code is fetched from shared storage, then separate storage on wireless processor is eliminated, but booting security requirements increase

Engineering Contradiction:
Improvedevice sizeVSAvoidbooting security
Core Design Contradiction:
Volume of moving objectVSReliability

Solution Approach 1:

The application processor acts as a trusted intermediary during the boot process, verifying the authenticity of boot code fetched from shared storage before allowing execution, thereby ensuring booting security while enabling shared storage usage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Authentication and verification of boot code are performed in advance before execution, ensuring security requirements are met before the wireless communications processor begins operation, allowing safe use of shared storage for boot code

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8589667B2Booting and configuring a subsystem securely from non-local storage
Publication Date: 2013.11.19 APPLE INC
  • US8589667B2 patent drawing
  • US8589667B2 patent drawing
  • US8589667B2 patent drawing

AI summary

According to one aspect, a multifunctional computing device having a wireless communications processor (e.g., cellular processor) and an application processor (e.g., general-purpose processor such as a CPU) share a storage device that is associated with or attached to the application processor. An example of such a multifunctional computing device may be a Smartphone device having a cellular phone and handheld computer functionalities. There is no specific storage device directly associated with or attached to the wireless communications processor (hereinafter simply referred to as a wireless processor). Instead, the wireless processor communicates with the application processor via a high speed communications link, such as a USB link, to access code and data stored in the storage device (e.g., flash memory device) associated with the application processor.