Stored-Program Module Secure Boot via Loadable Trust Anchor
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing embedded systems lack a cost-effective and simple method to establish a secure boot mechanism without dedicated hardware support, relying on expensive hardware-integrated trust anchors for integrity protection.
Innovation Solution
A memory-programmable module with a loadable test device that acts as a trust anchor, using a cryptographic function and validation parameter to verify data integrity, allowing only authorized data streams to activate components, thereby ensuring secure boot without additional hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hardware-integrated trust anchor (e.g., boot ROM) is used to ensure secure boot, then integrity protection is achieved, but system cost increases significantly
Solution Approach 1:
The patent creates a software-based copy of the trust anchor functionality that resides in the load bitstream rather than requiring dedicated hardware. The verification unit is implemented as programmable logic that replicates the cryptographic verification functions traditionally performed by hardware trust anchors, thereby achieving the same security goals without the associated hardware costs
Solution Approach 2:
The patent replaces the mechanical/hardware-based trust anchor (boot ROM) with a software/firmware-based verification unit implemented in programmable logic. This substitution allows the same security function to be achieved through configurable logic that can be loaded and verified, eliminating the need for expensive dedicated security hardware
2Reliability
If a hardware-integrated trust anchor is implemented, then secure boot is enabled, but device complexity increases
Solution Approach 1:
The patent merges the trust anchor functionality with the existing load bitstream and programmable logic resources. The verification unit is integrated into the same fabric that executes the load bitstream, combining configuration and verification functions into a unified software-based system rather than adding separate hardware security modules
Solution Approach 2:
The verification unit implemented in programmable logic serves multiple functions: it verifies the load bitstream integrity, acts as a trust anchor for subsequent boot operations, and can potentially verify other loaded code segments. This multi-functional approach eliminates the need for dedicated single-purpose security hardware
3Reliability
If dedicated secure boot support hardware is added, then integrity protection is improved, but ease of manufacture deteriorates due to additional hardware requirements
Solution Approach 1:
The load bitstream itself serves as the trust anchor by containing the verification unit that checks its own integrity. This self-verification mechanism eliminates the need for external or pre-provisioned security hardware, as the system uses its own configuration data to establish the chain of trust
Data Source
Figure 1
Figure 2~3
AI summary
The invention relates to a stored-program module having a loadable trust anchor, comprising a checking device (13) and at least one further component (11), wherein the checking device (13) can be generated on the module (10) by means of a loading bit stream (9) and the at least one component (11) is automatically deactivated after the loading. The checking device (13) is designed to read in at least one data bit stream (16) for execution on the at least one component (11) of the module (10) from an external data source (20), to check the data bit stream (16), and, in the case of a positive checking result, to output a control signal (17), which activates the component (11) with the data of the data bit stream (16). The method for the secured transfer of data from an external data source to at least one component (11) of a stored-program module comprises generating (41) a checking device (13) on the module (10) by means of a loading bit stream (9) and deactivating the at least one component (11), reading (42) at least one data bit stream (16) for execution on the at least one component (11) of the module (10) into the checking device (13) from an external data source (20), checking (43) the data bit stream (16) in the checking device, and outputting (44) a control signal (17) in the case of a positive checking result in order to activate the component (11) with the data of the data bit stream (16).