Virtual OTP Authentication for Secure RAMBOOT Bootup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in verifying and authenticating a RAMBOOT on a virtual one-time programmable (OTP) device before enabling the OTP hardware module for RAMBOOT boot up, leading to potential errors and dead chips during the programming process.
Innovation Solution
The proposed solution involves methods, computer program products, and systems for verifying and authenticating a RAMBOOT boot up by the key or key hash stored on a virtual OTP prior to enabling the OTP hardware module. This includes determining whether the key or key hash is enabled, initiating authentication if not, and enabling the OTP device by burning an enable bit once authentication is successful.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If OTP programming is performed during chip manufacturing or afterwards, then security applications can be implemented with unique identifiers, but programming errors can cause dead chips
Solution Approach 1:
The patent implements a preliminary verification step before final OTP programming. A virtual OTP is used to store the key or key hash temporarily, and the system verifies whether the key is enabled and whether RAMBOOT bootup is authenticated before committing the programming to the actual OTP hardware module. This preliminary action prevents dead chips by ensuring programming only occurs when authentication succeeds.
Solution Approach 2:
The patent introduces a virtual OTP as an intermediary between the programming process and the actual OTP hardware module. The virtual OTP serves as a testing ground where keys are stored and verified before being transferred to the permanent OTP. This intermediary layer allows verification of the programming process without risking the actual chip functionality.
2Reliability
If verification and authentication of RAMBOOT on virtual OTP is implemented, then dead chips are reduced, but additional verification steps increase manufacturing complexity
Solution Approach 1:
The patent creates a virtual copy of the OTP (virtual OTP) that mirrors the structure and functionality of the actual OTP hardware module. This copy is used for verification purposes, allowing the system to test key storage and authentication logic without affecting the real OTP. The virtual OTP contains the same key or key hash structure, enabling safe verification before permanent programming.
3Reliability
If key or key hash is stored on virtual OTP for authentication, then secure RAMBOOT bootup is enabled, but additional storage and processing requirements increase device size
Solution Approach 1:
The patent extracts the verification and authentication functionality from the main OTP hardware module and implements it separately in the virtual OTP. This separation allows the authentication logic to be tested and verified independently before being transferred to the compact OTP structure. The virtual OTP handles the bulky verification processes, while the actual OTP remains compact and efficient.
Data Source
AI summary
Responsive to OTP device not being enabled for an SoC, the RAMBOOT bootup authenticated by the key or key hash of an OTP is precluded and a determination is made whether the RAMBOOT bootup has been authenticated by the key or key hash on the virtual OTP. Responsive to not being authenticated, authentication of the RAMBOOT bootup is initiated. Responsive to being authenticated, enablement of the OTP device is initiated by burning an enable bit. Content of the virtual OTP is verified. The verified content can then be transferred from the virtual OTP to the OTP hardware module. Finally, authenticated RAMBOOT bootup is enabled from the OTP hardware module using the verified content prior to enablement of the OTP hardware module. ROMBOOT is read-only.


