Unsecured SoC Secure Boot via Locked Off-Chip NVM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional System-on-Chip (SoC) devices lack secure boot functionalities, making it difficult to verify the integrity and authenticity of firmware and software components upon startup, which is essential for preventing malicious software loading and compliance with regulatory requirements.

Innovation Solution

An unsecured SoC is equipped with a locked off-chip memory component for storing cryptographic data and an unlocked off-chip memory component for storing software components, where the SoC verifies the trustworthiness of software using cryptographic data and boots only verified components, leveraging a public key and second stage Boot Loader program as a Root-of-Trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If conventional unsecured SoC devices are used, then manufacturing cost is reduced and ease of manufacture is improved, but secure boot functionality is lost and reliability deteriorates

Engineering Contradiction:
Improveease of manufactureVSAvoidsecure boot functionality
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system segments security-critical cryptographic data from the main SoC by storing it in a separate locked off-chip memory component. This segmentation allows the SoC to remain unsecured and cost-effective while the external locked memory provides the necessary secure boot functionality, resolving the contradiction between ease of manufacture and reliability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If locked off-chip memory components are added to provide secure boot, then secure boot functionality is improved, but device complexity increases

Engineering Contradiction:
Improvesecure boot functionalityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The locked off-chip memory component acts as an intermediary that provides secure storage for cryptographic data without requiring the SoC itself to be secured. This intermediary approach enables secure boot functionality while keeping the main SoC simple and unsecured, thus improving reliability without significantly increasing overall device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10657260B2Electronic devices and methods supporting unsecured system-on-chip secure boot functionalities
Publication Date: 2020.05.19 DISH NETWORK TECHNOLOGIES INDIA PTE LTD
  • US10657260B2 patent drawing
  • US10657260B2 patent drawing
  • US10657260B2 patent drawing

AI summary

Electronic device and methods supporting secure boot functionalities performed utilizing an unsecured System-on-Chip (SoC) are provided. In various embodiments, the electronic device contains an unsecured SoC, a locked off-chip Non-Volatile Memory (NVM) component, and an unlocked off-chip NVM component. An on-chip or first stage boot loader program is stored in a first on-chip memory area; and, when execute, causes an on-chip processor to loads an image of a cryptographic key, such as a public key, into a second on-chip memory area. The cryptographic key is stored in the locked off-chip NVM component, possibly in conjunction with a second stage boot loader program. The on-chip processor then utilizes the cryptographic key, alone or in combination with other data, as a root-of-trust to verify the authenticity of one or more software components, such as an operating system, stored in the unlocked off-chip NVM component prior to booting the software component(s).