Terminal Chip Security Subsystem Boot Sequence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As the number of key services increases, the trusted computing base of the Trusted Execution Environment (TEE) becomes larger, leading to a larger attack surface and compromising the security of the computing subsystem.
Innovation Solution
A terminal chip with a security subsystem that measures the computing subsystem by performing integrity verification on data during the boot and running processes, ensuring that the security subsystem boots before the computing subsystem and has access to all its resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the quantity of key services in the TEE increases, then the functionality and security coverage are improved, but the trusted computing base becomes larger and the attack surface increases
Solution Approach 1:
The patent divides the computing subsystem into two independent parts: a security subsystem responsible for security verification and an application subsystem responsible for running services. This segmentation allows the security subsystem to remain small and trusted while the application subsystem can expand functionality, thereby resolving the contradiction between functionality coverage and attack surface.
2Reliability
If the TEE performs integrity measurement on the computing subsystem, then security verification is improved, but the security subsystem must boot before the computing subsystem which complicates the system architecture
Solution Approach 1:
The security subsystem is designed to boot before the computing subsystem and perform integrity measurements on the application subsystem's boot process. This preliminary action ensures security verification is established before the main system operates, resolving the contradiction between security verification and system architecture complexity by making the boot sequence a fundamental design feature rather than a complex coordination problem.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Embodiments of this application disclose a terminal chip and a measurement method thereof, and relate to the field of chips. By measuring a boot process of a computing subsystem, security of the boot process of the computing subsystem can be ensured. A specific solution is as follows: The terminal chip includes a computing subsystem and a security subsystem. The security subsystem is configured to measure the computing subsystem. A boot time of the security subsystem is earlier than a boot time of the computing subsystem. The security subsystem includes: an integrity verification unit. The integrity verification unit is configured to perform integrity measurement on data in a boot process of the computing subsystem.