Stored-Program Module Secure Boot via Loadable Trust Anchor

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing embedded systems lack a cost-effective and simple method to establish a secure boot mechanism without dedicated hardware support, relying on expensive hardware-integrated trust anchors for integrity protection.

Innovation Solution

A memory-programmable module with a loadable test device that acts as a trust anchor, using a cryptographic function and validation parameter to verify data integrity, allowing only authorized data streams to activate components, thereby ensuring secure boot without additional hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware-integrated trust anchor (e.g., boot ROM) is used to ensure secure boot, then integrity protection is achieved, but system cost increases significantly

Engineering Contradiction:
Improveintegrity protectionVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a software-based copy of the trust anchor functionality that resides in the load bitstream rather than requiring dedicated hardware. The verification unit is implemented as programmable logic that replicates the cryptographic verification functions traditionally performed by hardware trust anchors, thereby achieving the same security goals without the associated hardware costs

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/hardware-based trust anchor (boot ROM) with a software/firmware-based verification unit implemented in programmable logic. This substitution allows the same security function to be achieved through configurable logic that can be loaded and verified, eliminating the need for expensive dedicated security hardware

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a hardware-integrated trust anchor is implemented, then secure boot is enabled, but device complexity increases

Engineering Contradiction:
Improvesecure bootVSAvoidhardware components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the trust anchor functionality with the existing load bitstream and programmable logic resources. The verification unit is integrated into the same fabric that executes the load bitstream, combining configuration and verification functions into a unified software-based system rather than adding separate hardware security modules

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The verification unit implemented in programmable logic serves multiple functions: it verifies the load bitstream integrity, acts as a trust anchor for subsequent boot operations, and can potentially verify other loaded code segments. This multi-functional approach eliminates the need for dedicated single-purpose security hardware

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dedicated secure boot support hardware is added, then integrity protection is improved, but ease of manufacture deteriorates due to additional hardware requirements

Engineering Contradiction:
Improveintegrity protectionVSAvoidadditional hardware components
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The load bitstream itself serves as the trust anchor by containing the verification unit that checks its own integrity. This self-verification mechanism eliminates the need for external or pre-provisioned security hardware, as the system uses its own configuration data to establish the chain of trust

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3347848B1Stored-program module and method for the secured transfer of data to a stored-program module
Publication Date: 2020.08.26 SIEMENS MOBILITY GMBH
  • EP3347848B1 patent drawingFigure 1
  • EP3347848B1 patent drawingFigure 2~3

AI summary

The invention relates to a stored-program module having a loadable trust anchor, comprising a checking device (13) and at least one further component (11), wherein the checking device (13) can be generated on the module (10) by means of a loading bit stream (9) and the at least one component (11) is automatically deactivated after the loading. The checking device (13) is designed to read in at least one data bit stream (16) for execution on the at least one component (11) of the module (10) from an external data source (20), to check the data bit stream (16), and, in the case of a positive checking result, to output a control signal (17), which activates the component (11) with the data of the data bit stream (16). The method for the secured transfer of data from an external data source to at least one component (11) of a stored-program module comprises generating (41) a checking device (13) on the module (10) by means of a loading bit stream (9) and deactivating the at least one component (11), reading (42) at least one data bit stream (16) for execution on the at least one component (11) of the module (10) into the checking device (13) from an external data source (20), checking (43) the data bit stream (16) in the checking device, and outputting (44) a control signal (17) in the case of a positive checking result in order to activate the component (11) with the data of the data bit stream (16).