Firmware authentication
View Patent ↗An example computing device comprises a memory to store control instructions, and a processor to: perform a first authentication of the control instructions using a first key; and in response to receipt of a command to enable a second authentication of the control instructions, add a second key to a one-time programmable portion of the memory, wherein the command is signed using the first key, the second key to perform a second authentication of the control instructions with the first key to perform the first authentication of the control instructions.
1 . A computing device, comprising:
a memory comprising:
a read-only memory (ROM) bootloader portion to store control instructions and a first key; and
a one-time programmable portion; and
a processor to:
perform a first authentication of the control instructions using the first key;
in response to receipt of a command to enable a second authentication of the control instructions, add a second key to the one-time programmable portion of the memory, wherein the command is signed using the first key; and
use the second key to perform a second authentication of the control instructions.
2 . The computing device of claim 1 , wherein the processor is to receive the control instructions from an external memory.
3 . The computing device of claim 1 , wherein the processor is to:
when an update flag of the one-time programmable portion of the memory is set to a first value, perform the first authentication of the control instructions using the first key;
in response to verifying the second authentication using the first key, set the update flag to a second value;
enable receipt of the command to enable the second authentication of the control instructions in response to the update flag set to the second value; and
add the second key to the one-time programmable portion of the memory.
4 . The computing device of claim 3 , wherein the processor is to:
when the update flag of the one-time programmable portion of the memory is set to the first value, block write access to the memory; and
in response to verifying the second authentication, allow write access to the memory to allow the second key to be added to the one-time programmable portion of the memory.
5 . The computing device of claim 1 , wherein the second key is a one-time signing key selected from a plurality of possible one-time signing keys of a hash-based signature scheme.
6 . The computing device of claim 1 , wherein the second key is associated with a quantum-safe cryptographic protocol.
7 . The computing device of claim 6 , wherein the quantum-safe cryptographic protocol comprises a Leighton-Micali Signature (LMS) scheme or an extended Merkle Signature Scheme (XMSS).
8 . A computing device, comprising:
a memory comprising:
a read-only memory (ROM) bootloader portion to store control instructions and a first key; and
a one-time programmable portion; and
a processor to:
perform a first authentication of the control instructions using the first key;
after performing the first authentication of the control instructions, execute the control instructions to enable the computing device to obtain a second key; wherein
store the second key in the one-time programmable portion of the memory; and
perform a second authentication of the control instructions using the second key.
9 . The computing device of claim 8 , wherein the processor is to:
execute the control instructions to enable the computing device to obtain a second authentication code;
store the second authentication code in the memory; and
use the second authentication code to perform the second authentication.
10 . The computing device of claim 9 , wherein:
the second authentication code comprises a header, the header comprising:
the second key;
a first checking key; and
a second checking key; and
prior to enabling the computing device to obtain the second key, the processor is to verify the second authentication code by:
verifying a first key checking signature of the second authentication code using the first checking key; and
verifying a second key checking signature of the second authentication code using the second checking key.
11 . The computing device of claim 10 , wherein;
the first checking key is to verify the second authentication code using a first verification protocol of the first key; and
the second checking key is to verify the second authentication code using a second verification protocol of the second key.
12 . The computing device of claim 11 , wherein the processor is to:
sign the second authentication code using a first signature generated using the first checking key; and
sign the second authentication code using a second signature generated using the second checking key; and
use the first signature and the second signature to verify validity of the second authentication code prior to enabling the computing device to obtain the second key.
13 . The computing device of claim 8 , wherein the second key is associated with a quantum-safe cryptographic protocol.
14 . The computing device of claim 8 , wherein the second key is associated with a Leighton-Micali Signature (LMS) scheme or an extended Merkle Signature Scheme (XMSS).
15 . A non-transitory computer-readable medium comprising instructions that, when executed by a processor of a computing device, cause the computing device to:
perform a first authentication of control instructions received from an external memory using a first key stored in a read-only memory (ROM) bootloader portion of a memory of the computing device and using a first cryptographic protocol;
receive, from a trusted source, a second key;
store the second key in a one-time programmable portion of the memory; and
perform a second authentication of the control instructions using the second key and using a second cryptographic protocol.
16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the processor, cause the computing device to:
allow write access to the memory, to allow the second key to be stored in the one-time programmable portion of the memory, in response to receipt of an authentication indicator indicating that the trusted source has verified the second cryptographic protocol.
17 . The non-transitory computer-readable medium of claim 16 , wherein the instructions, when executed by the processor, cause the computing device to:
disable write access to the memory after storing the second key in the one-time programmable portion of the memory.
18 . The non-transitory computer-readable medium of claim 15 , wherein the second key is a quantum-safe public cryptography key.
19 . The non-transitory computer-readable medium of claim 18 , wherein the second cryptographic protocol comprises a quantum-safe cryptographic protocol.
20 . The non-transitory computer-readable medium of claim 18 , wherein the second cryptographic protocol comprises a Leighton-Micali Signature (LMS) scheme or an extended Merkle Signature Scheme (XMSS).