IP Library Patent Application 17935446
Patent Application
App. No. 17/935,446

SECURE BOOT ASSIST FOR DEVICES, AND RELATED SYSTEMS, METHODS AND DEVICES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/935,446
Abstract

Systems, methods, and devices of the disclosure relate, generally, to secure boot assist for devices. In one or more embodiments, a first device includes firmware that needs to be verified as secure as part of a secure boot process, and a second device assists the first device to secure the secure boot process. In some embodiments the second device verifies security of the firmware responsive to security data provided by the first device, or verifies security of a program provided by the first device, the program for verifying security of the firmware. In some embodiments the second device provides a program for verifying security of the firmware to the first device.

Claims (42)

1 . A method, comprising:

placing and holding a device in a restricted mode of operation, wherein independent initiation of execution of code at the device is disabled during the restricted mode of operation;

copying, to another device, code stored at a program memory of the device utilizing an interface enabled to control a central processing (CPU) of the device; and

verifying the copied code is secure.

2 . The method of claim 1 , wherein the verifying the copied code is secure comprises:

performing a hashing function on the copied code to obtain a first security data; and

verifying the copied code is secure responsive to the first security data.

3 . The method of claim 2 , wherein the verifying the copied code is secure responsive to the first security data comprises:

comparing the first security data to second security data stored at the other device; and

verifying the copied code responsive the comparing.

4 . The method of claim 2 , wherein the verifying the copied code is secure responsive to the first security data comprises verifying the copied code by performing signature validation on the first security data.

5 . The method of claim 2 , comprising:

verifying the copied code is secure;

instructing the device to execute code corresponding to the copied code upon exiting the restricted mode of operation; and

releasing the device from the restricted mode of operation.

6 . The method of claim 2 , comprising:

determining the copied code is unsecure responsive to the first security data; and

holding the device in the restricted mode of operation until verifying that code installed at the device is secure.

7 . The method of claim 1 , wherein the copying code stored at the program memory of the device comprises copying boot code stored at the program memory of the device.

8 . The method of claim 1 , wherein the copying code stored at the program memory of the device comprises: copying a portion of operating code stored at the program memory of the device, wherein the device is to execute the copied portion of the operating code upon a boot-up of the device or upon a reset condition of the device.

9 . An apparatus, comprising:

at least one processor; and

a memory having hardware-executable instructions stored thereon, wherein the instructions, upon execution by the at least one processor, enable the at least one processor to:

place and hold a device in a restricted mode of operation, wherein independent initiation of execution of code at the device is disabled during the restricted mode of operation;

copy, to another device, code stored at a program memory of the device using an interface enabled to control a central processing (CPU) of the device; and

verify the copied code is secure.

10 . The apparatus of claim 9 , wherein the instructions enable the at least one processor to verify the copied code is secure by:

performing a hashing function on the copied code to obtain a first security data; and

verifying the copied code is secure responsive to the first security data.

11 . The apparatus of claim 10 , wherein the instructions enable the at least one processor to verify the copied code is secure responsive to the first security data by:

comparing the first security data to second security data stored at the other device; and

verifying the copied code responsive the comparing.

12 . The apparatus of claim 10 , wherein the instructions enable the at least one processor to verify the copied code is secure responsive to the first security data by performing signature validation on the first security data.

13 . The apparatus of claim 10 , wherein the instructions enable the at least one processor to:

verify the copied code is secure;

instruct the device to execute code corresponding to the copied code upon exiting the restricted mode of operation; and

release the device from the restricted mode of operation.

14 . The apparatus of claim 10 , wherein the instructions enable the at least one processor to:

determine the copied code is unsecure responsive to the first security data; and

hold the device in the restricted mode of operation until verifying that code installed at the device is secure.

15 . The apparatus of claim 9 , wherein the instructions enable the at least one processor to copy code stored at the program memory of the device by copying boot code stored at the program memory of the device.

16 . The apparatus of claim 9 , wherein the instructions enable the at least one processor to copy code stored at the program memory of the device by copying a portion of operating code stored at the program memory of the device, wherein the device is to execute the copied portion of the operating code upon a boot-up of the device or upon a reset condition of the device.