Terminal Chip Security Subsystem Boot Sequence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the number of key services increases, the trusted computing base of the Trusted Execution Environment (TEE) becomes larger, leading to a larger attack surface and compromising the security of the computing subsystem.

Innovation Solution

A terminal chip with a security subsystem that measures the computing subsystem by performing integrity verification on data during the boot and running processes, ensuring that the security subsystem boots before the computing subsystem and has access to all its resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the quantity of key services in the TEE increases, then the functionality and security coverage are improved, but the trusted computing base becomes larger and the attack surface increases

Engineering Contradiction:
Improvefunctionality coverageVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the computing subsystem into two independent parts: a security subsystem responsible for security verification and an application subsystem responsible for running services. This segmentation allows the security subsystem to remain small and trusted while the application subsystem can expand functionality, thereby resolving the contradiction between functionality coverage and attack surface.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the TEE performs integrity measurement on the computing subsystem, then security verification is improved, but the security subsystem must boot before the computing subsystem which complicates the system architecture

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security subsystem is designed to boot before the computing subsystem and perform integrity measurements on the application subsystem's boot process. This preliminary action ensures security verification is established before the main system operates, resolving the contradiction between security verification and system architecture complexity by making the boot sequence a fundamental design feature rather than a complex coordination problem.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4273722B1Terminal chip and measurement method therefor
Publication Date: 2025.05.21 HUAWEI TECH CO LTD
  • EP4273722B1 patent drawingFigure 1~2
  • EP4273722B1 patent drawingFigure 3
  • EP4273722B1 patent drawingFigure 4

AI summary

Embodiments of this application disclose a terminal chip and a measurement method thereof, and relate to the field of chips. By measuring a boot process of a computing subsystem, security of the boot process of the computing subsystem can be ensured. A specific solution is as follows: The terminal chip includes a computing subsystem and a security subsystem. The security subsystem is configured to measure the computing subsystem. A boot time of the security subsystem is earlier than a boot time of the computing subsystem. The security subsystem includes: an integrity verification unit. The integrity verification unit is configured to perform integrity measurement on data in a boot process of the computing subsystem.