Storage Device Content Authentication via Hash Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The security of set-top box (STB) systems-on-a-chip (SoC) is compromised when storage device content is altered or replaced, as the host processor may execute compromised instructions without verification, leading to potential breaches in security.
Innovation Solution
Implementing a method and system that uses a security processor to partition storage device content into regions, generate and compare hashed regional content, and verify authenticity using hashing functions and public key encryption to ensure the integrity of storage device content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the host processor executes storage device content without verification, then the system operates with high speed and simplicity, but the security and reliability of the system is compromised
Solution Approach 1:
The patent applies preliminary action by computing hash values of storage device content in advance and storing them in a verification table within the host processor. During operation, the host processor simply compares incoming content hashes against the pre-stored verification hashes, eliminating the need for complex real-time verification algorithms while ensuring security.
Solution Approach 2:
The patent introduces a hash function as an intermediary mechanism that transforms storage device content into fixed-size hash values. This intermediary layer enables efficient verification by allowing the host processor to compare compact hash representations rather than analyzing the entire content, thus maintaining security without sacrificing performance.
2Reliability
If the storage device content is partitioned and hashed for verification, then the authenticity and integrity of content is verified, but the processing time and computational resources increase
Solution Approach 1:
The patent segments storage device content into distinct regions, each with its own hash verification. This segmentation allows the system to verify only specific critical regions rather than the entire storage content, reducing overall verification time while maintaining integrity checks where most needed.
Solution Approach 2:
The patent changes the parameter of content representation by transforming variable-size storage content into fixed-size hash values. This parameter transformation enables rapid comparison operations and reduces the computational burden of verification, as hash comparison is significantly faster than full content analysis.
Data Source
AI summary
Systems and methods that storage device content authentication are provided. A system that verfies storage device content received from a storage device may comprise, for exmple, a security processor coupled to the storage device. The security processor may be adapted to receive a partitioned storage device region from the storage device. The partitioned storage device region may comprise, for example, regional content and first hashed regional content. The security processor may generate, for example, second hashed regional content by performing a hashing function on the regional content received by the security processor. The security processor may compare, for example, the first hashed regional content to the second hashed regional content. The security processor may varify the regional content received by the security processor if the first hashed regional content is the same as the second hashed regional content.


