SoC Secure Boot Update Using OTP-Verified Signature Algorithms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing system-on-chips (SoCs) face security vulnerabilities due to software design errors and program defects, leading to insecure data authentication, necessitating a method to safely and permanently change security measures while maintaining secure booting performance.
Innovation Solution
A system-on-chip design incorporating a nonvolatile memory, volatile memory, and one-time programmable (OTP) memory, along with a processor, allows for loading and verifying different signature verification algorithms by programming a hash value in the OTP memory, enabling secure booting with updated security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the signature verification algorithm is permanently changed after SoC release, then security vulnerability is addressed, but verification of changed security measures becomes difficult
Solution Approach 1:
The patent applies preliminary action by verifying the safety of changed security measures before they are permanently deployed. The system performs verification of the new signature verification algorithm's safety before changing the algorithm, ensuring that the change is safe to implement. This preliminary verification step addresses the difficulty of detecting and measuring security measure changes by establishing a verification mechanism in advance.
2Reliability
If the signature verification algorithm is changed after SoC release, then security is improved, but the complexity of the system increases
Solution Approach 1:
The patent applies segmentation by dividing the signature verification process into separate components: a first signature verification algorithm stored in non-volatile memory and a second signature verification algorithm that can be loaded from external storage. This segmentation allows the system to maintain the original algorithm for backward compatibility while incorporating a new algorithm for improved security, thereby managing system complexity through modular architecture.
Solution Approach 2:
The patent applies dynamics by making the signature verification algorithm changeable and adaptable. The system can dynamically switch between different signature verification algorithms based on security requirements, allowing the algorithm to be updated after SoC release without requiring hardware changes. This dynamic capability enables security improvements while managing complexity through software-based flexibility.
3Adaptability or versatility
If multiple signature verification algorithms are supported, then adaptability is improved, but device complexity increases
Solution Approach 1:
The patent applies universality by designing a system that can perform multiple signature verification functions using different algorithms. The SoC is configured to support both a first signature verification algorithm (embedded in non-volatile memory) and a second signature verification algorithm (loadable from external storage), enabling the system to adapt to different security requirements while using a unified verification framework that manages complexity.
Data Source
AI summary
A system-on-chip includes a nonvolatile memory configured to load a first image received from external storage and a first signature verification algorithm; at least one processor configured to control the nonvolatile memory such that first verifications are performed on the first image; a volatile memory; and a one-time programmable (OTP) memory configured to program a programmed hash value of a second signature verification algorithm different from the first signature verification algorithm. The at least one processor further is configured to: load a second image received from the external storage to the volatile memory, the second image being different from the first image; perform a second verification on the second image based on the programmed hash value; based on the second verification succeeding, execute the second signature verification algorithm corresponding to the version information; and perform the first verifications by applying the second signature verification algorithm to the first image.


