IP Library Granted Patent US 11,520,891
Granted Patent B1
US 11,520,891 · App. 16/710,487 · Granted Dec 6, 2022

Secure boot of an integrated circuit

Inventors: Adi Karolitsky (Jerusalem, IL); Akram Baransi (Nazareth Illit, IL); Andrew Robert Sinton (Jerusalem, IL)
Assignee: Amazon Technologies, Inc.
G06F21/575G06F8/65G06F21/572H04L9/0891H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,520,891
App. No.
16/710,487
Granted
Dec 6, 2022
Kind
B1
Abstract

A computer chip, such as an System on chip (SOC), can receive firmware updates having two separate signatures; a first of the signatures is used to authenticate the firmware using a processor within the computer chip, and a second of the signatures is used by a controller, separate from the processor. A first key, used by the processor to authenticate the firmware, can be a boot key that is hardwired in the computer chip. A second key, used by the controller, can be a key that is provided to the controller at any time and is updatable. The controller can suspend the processor so that the controller can perform a first authentication of the firmware using the second signature and the second key. If the authentication is successful, the controller can release the processor, which then uses the first key and the first signature to perform a second authentication.

Claims (29)

1. A method of updating firmware of a computer chip, the method comprising:

during an initialization phase of the computer chip, halting an internal processor within the computer chip using an external controller coupled to the computer chip;

while the internal processor is halted, authenticating firmware stored in the computer chip using the external controller and using a first digital signature of the firmware with a first key;

unhalting the internal processor using the external controller after the authentication of the firmware is successful; and

authenticating the firmware using the internal processor and using a second digital signature of the firmware with a second key.

2. The method of claim 1 , further including receiving the firmware in the computer chip as an update and receiving, at the external controller, the first key used for authenticating the firmware.

3. The method of claim 1 , wherein the first digital signature and the second digital signature are received with the firmware image.

4. The method of claim 1 , wherein the second key is hardcoded into fuses in the computer chip.

5. The method of claim 1 , wherein the authenticating the firmware using the external controller includes comparing a portion of the firmware stored in the computer chip to a portion of the firmware stored by the external controller.

6. A method, comprising:

during an initialization of an Integrated Circuit (IC), pausing a processor within the IC using a controller;

authenticating firmware within the IC using a first authentication performed by the controller; and

if the first authentication of the firmware is successful, releasing the pause by the controller to resume initialization of the IC, and authenticating the firmware using a second authentication performed by the processor after the pause is released.

7. The method of claim 6 , wherein the firmware includes first and second signatures signed with first and second keys, respectively, wherein the first authentication includes verifying the first signature using a key stored in hardware fuses within the IC and verifying the second signature using an updatable key stored in the controller.

8. The method of claim 6 , wherein the second authentication is performed using a key stored within trusted storage of the IC.

9. The method of claim 6 , wherein the first authentication includes comparing a first portion of the firmware stored by the controller to a second portion of the firmware stored within the IC to determine whether the first and second portions match.

10. The method of claim 6 , wherein the pausing includes storing a pause command within a register of the processor using the controller, wherein the register controls a state of the processor.

11. The method of claim 6 , wherein the IC is within a server computer.

12. The method of claim 6 , further including receiving updated firmware at the IC and receiving an updated key at the controller, wherein the updated key is used to authenticate the updated firmware.

13. A system, comprising:

a System On Chip (SOC) including a processor and a memory for storing an updated version of a firmware; and

a controller coupled to the SOC;

wherein the controller is configured to pause the processor during initialization of the SOC to perform a first authentication of the updated version of the firmware stored within the SOC and to unpause the processor when the authentication is successful;

wherein the SOC is configured to perform a second authentication of the updated version of the firmware, using the processor, through the use of a key stored in trusted storage of the SOC.

14. The system of claim 13 , wherein the controller is configured to perform the first authentication by comparing a portion of the updated version of the firmware stored by the controller to a portion of the updated version of the firmware stored in the memory.

15. The system of claim 14 , wherein the portion of the updated version of the firmware includes a header and version number.

16. The system of claim 13 , wherein the updated version of the firmware includes two signatures, a first for the first authentication by the controller and a second for the second authentication by the processor.

17. The system of claim 13 , wherein the SOC is within a server computer.

18. The system of claim 13 , wherein the controller can update a register within the SOC to pause the processor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2020
From: KAROLITSKY, ADI; BARANSI, AKRAM; SINTON, ANDREW ROBERT
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 051475/0433 →
Cited By (5)
US 12,498,912 US 12,561,124 US 12,591,681 US 12,608,141 US 12,670,258