Storage Controller Firmware Authentication With Dual Signature Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage devices face security vulnerabilities due to the inability to verify dual signatures of firmware images, leading to potential attacks and reduced versatility when manufacturing for multiple customers.
Innovation Solution
A storage controller that authenticates firmware images using a host public key and switches to dual signature verification after initial shipment, allowing the host to generate dual-signed firmware without vendor intervention, and stores public keys securely in OTP memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the storage device verifies only a single firmware vendor signature, then the device complexity is low and ease of manufacture is high, but the security is insufficient and versatility for multiple customers is reduced
Solution Approach 1:
The storage controller dynamically switches between single-signature verification mode (for firmware vendor) and dual-signature verification mode (for customer) based on the operational phase. This dynamic adaptation allows the system to maintain low complexity during manufacturing while enhancing security for customer operations, resolving the contradiction between simplicity and security.
Solution Approach 2:
The signature verification process is segmented into two distinct phases: initial firmware verification using only the vendor's public key, and subsequent firmware verification using both vendor and customer public keys. This segmentation allows the system to manage complexity by handling different verification requirements at different stages, while achieving high security in the customer phase.
2Reliability
If the storage device requires dual signature verification for all firmware, then the security is high, but the ease of manufacture and initial setup is reduced
Solution Approach 1:
The firmware vendor's public key is pre-loaded into the storage controller's secure memory during manufacturing. This preliminary action establishes a baseline security mechanism that simplifies initial setup and manufacturing, while the dual-signature capability is prepared but not activated until the customer phase, thus avoiding unnecessary complexity during manufacturing.
Solution Approach 2:
The verification system dynamically transitions from a simplified single-signature mode during manufacturing to a secure dual-signature mode during customer operation. This dynamic behavior allows the device to be easy to manufacture with basic security, then automatically enhances security when deployed to customers without requiring complex initial configuration.
3Adaptability or versatility
If the storage device uses fixed firmware verification, then the manufacturing process is simple, but the adaptability to different customers is reduced
Solution Approach 1:
The storage controller implements a dynamic verification configuration that adapts to the operational phase. In the customer phase, the system activates dual-signature verification by loading both the vendor's public key and the customer's public key into the verification process. This dynamic adaptation enables customer-specific firmware support while managing complexity through automated phase-based configuration.
Solution Approach 2:
The storage controller is designed with universal firmware verification capability that can handle both vendor-signed firmware (single signature) and customer-specific firmware (dual signature). This multi-functionality allows the same device to serve multiple customers with different security requirements without requiring different hardware designs, achieving versatility while managing complexity through software-based configuration.
Data Source
AI summary
A storage controller configured to control a nonvolatile memory includes a one-time programmable (OTP) memory configured to store a first public key, and a processor configured to, based on a first signature added to a firmware image including a host authentication public key being verified using the first public key, receive a storage command including at least one second public key and a first host authentication signature for the at least one second public key and store the at least one second public key in the OTP memory based on the first host authentication signature being verified using the host authentication public key.


