Software Image Authentication Using Embedded Keychain Images

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current system security techniques are inefficient and costly, as they cause overhead in manufacturing, operations, and maintenance, and fail to effectively protect against advanced attacks that modify software or extract information from systems.

Innovation Solution

A system that includes a system memory storing software images with associated keychain images containing soft keys, where processing circuitry authenticates software images by obtaining and verifying soft keys based on included key information, reducing the reliance on hard keys and minimizing exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional system security techniques are used to protect the system, then system security is improved, but manufacturing overhead, operational overhead, and costs increase

Engineering Contradiction:
Improvesystem securityVSAvoidmanufacturing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security validation process from traditional complex security systems and implements it through a simplified keychain image verification mechanism. The keychain image contains cryptographic keys that enable authentication without requiring complex external security infrastructure, thereby reducing manufacturing and operational overhead while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses cryptographic copying where the keychain image is embedded within the software image itself. This self-contained copy of authentication credentials eliminates the need for separate security hardware or external verification systems, reducing system complexity and costs while preserving security functionality.

Inventive Principle:
Principle #26Copying

2Reliability

If traditional system security techniques are used to protect the system, then system security is improved, but operational overhead and costs increase

Engineering Contradiction:
Improvesystem securityVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs security validation in advance by embedding the keychain image within the software image during the software build process. This preliminary authentication preparation eliminates the need for complex runtime security checks and external verification operations, reducing operational overhead and time loss during system execution.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If software images are authenticated using traditional methods, then security against unauthorized modifications is improved, but system overhead increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication credentials (keychain image) directly into the software image structure. This combination eliminates the need for separate security modules, external key management systems, or additional hardware components, thereby reducing system overhead while maintaining robust authentication security against unauthorized modifications.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11829464B2Apparatus and method for authentication of software
Publication Date: 2023.11.28 SAMSUNG ELECTRONICS CO LTD
  • US11829464B2 patent drawing
  • US11829464B2 patent drawing
  • US11829464B2 patent drawing

AI summary

A system includes processing circuitry and a system memory configured to store at least one software image. The at least one software image includes at least one program image and a keychain image associated with the at least one software image, the keychain image including at least one soft key. The processing circuitry is configured to obtain a desired soft key associated with the at least one software image from the keychain image based on key information included in the at least one software image, and authenticate the at least one software image based on the obtained soft key.