US2023020278A1PendingUtilityA1

Secure boot assist for devices, and related systems, methods and devices

Assignee: MICROCHIP TECH INCPriority: Nov 13, 2018Filed: Sep 26, 2022Published: Jan 19, 2023
Est. expiryNov 13, 2038(~12.3 yrs left)· nominal 20-yr term from priority
G06F 21/575G06F 2221/2149G06F 9/4401G06F 21/34G06F 21/572G06F 21/12
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems, methods, and devices of the disclosure relate, generally, to secure boot assist for devices. In one or more embodiments, a first device includes firmware that needs to be verified as secure as part of a secure boot process, and a second device assists the first device to secure the secure boot process. In some embodiments the second device verifies security of the firmware responsive to security data provided by the first device, or verifies security of a program provided by the first device, the program for verifying security of the firmware. In some embodiments the second device provides a program for verifying security of the firmware to the first device.

Claims

exact text as granted — not AI-modified
1 . A method, comprising:
 placing and holding a device in a restricted mode of operation, wherein independent initiation of execution of code at the device is disabled during the restricted mode of operation;   copying, to another device, code stored at a program memory of the device utilizing an interface enabled to control a central processing (CPU) of the device; and   verifying the copied code is secure.   
     
     
         2 . The method of  claim 1 , wherein the verifying the copied code is secure comprises:
 performing a hashing function on the copied code to obtain a first security data; and   verifying the copied code is secure responsive to the first security data.   
     
     
         3 . The method of  claim 2 , wherein the verifying the copied code is secure responsive to the first security data comprises:
 comparing the first security data to second security data stored at the other device; and   verifying the copied code responsive the comparing.   
     
     
         4 . The method of  claim 2 , wherein the verifying the copied code is secure responsive to the first security data comprises verifying the copied code by performing signature validation on the first security data. 
     
     
         5 . The method of  claim 2 , comprising:
 verifying the copied code is secure;   instructing the device to execute code corresponding to the copied code upon exiting the restricted mode of operation; and   releasing the device from the restricted mode of operation.   
     
     
         6 . The method of  claim 2 , comprising:
 determining the copied code is unsecure responsive to the first security data; and   holding the device in the restricted mode of operation until verifying that code installed at the device is secure.   
     
     
         7 . The method of  claim 1 , wherein the copying code stored at the program memory of the device comprises copying boot code stored at the program memory of the device. 
     
     
         8 . The method of  claim 1 , wherein the copying code stored at the program memory of the device comprises: copying a portion of operating code stored at the program memory of the device, wherein the device is to execute the copied portion of the operating code upon a boot-up of the device or upon a reset condition of the device. 
     
     
         9 . An apparatus, comprising:
 at least one processor; and   a memory having hardware-executable instructions stored thereon, wherein the instructions, upon execution by the at least one processor, enable the at least one processor to:
 place and hold a device in a restricted mode of operation, wherein independent initiation of execution of code at the device is disabled during the restricted mode of operation; 
 copy, to another device, code stored at a program memory of the device using an interface enabled to control a central processing (CPU) of the device; and 
 verify the copied code is secure. 
   
     
     
         10 . The apparatus of  claim 9 , wherein the instructions enable the at least one processor to verify the copied code is secure by:
 performing a hashing function on the copied code to obtain a first security data; and   verifying the copied code is secure responsive to the first security data.   
     
     
         11 . The apparatus of  claim 10 , wherein the instructions enable the at least one processor to verify the copied code is secure responsive to the first security data by:
 comparing the first security data to second security data stored at the other device; and   verifying the copied code responsive the comparing.   
     
     
         12 . The apparatus of  claim 10 , wherein the instructions enable the at least one processor to verify the copied code is secure responsive to the first security data by performing signature validation on the first security data. 
     
     
         13 . The apparatus of  claim 10 , wherein the instructions enable the at least one processor to:
 verify the copied code is secure;   instruct the device to execute code corresponding to the copied code upon exiting the restricted mode of operation; and   release the device from the restricted mode of operation.   
     
     
         14 . The apparatus of  claim 10 , wherein the instructions enable the at least one processor to:
 determine the copied code is unsecure responsive to the first security data; and   hold the device in the restricted mode of operation until verifying that code installed at the device is secure.   
     
     
         15 . The apparatus of  claim 9 , wherein the instructions enable the at least one processor to copy code stored at the program memory of the device by copying boot code stored at the program memory of the device. 
     
     
         16 . The apparatus of  claim 9 , wherein the instructions enable the at least one processor to copy code stored at the program memory of the device by copying a portion of operating code stored at the program memory of the device, wherein the device is to execute the copied portion of the operating code upon a boot-up of the device or upon a reset condition of the device.

Join the waitlist — get patent alerts

Track US2023020278A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.