CA2767574C

Managing booting of secure devices with untrusted software

Abstract

Normally, at the time of manufacturing, security may be provided to a device being manufactured through the loading of an operating system that has been cryptographically signed. The present application discloses a "factory mode" for the device. The "factory mode" allows the device to execute untrusted operating system code, such as unsigned operating system code and operating system code that has been signed, but the certificate authority is not trusted. To support execution of untrusted operating system code in a secure manner, the device may be adapted to prevent data of predetermined type from being loaded on the device while the device is in the "factory mode". In contrast to the "factory mode", the secure mode of the device is referred to herein as a "product mode". There develops a need to manage, in a secure manner, transitions between the "product mode" and the "factory mode".

CA2767574C, drawing sheet 1
Sheet 1 of 4

Term

5.4 yearsleft in the term

Expires 13 February 2032.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

28 claims: 20 independent, 8 dependent

  1. 1
    CA 2767574 2017-03-16 39135-ca-pat - 13- 42783-3270 WHAT IS CLAIMED IS:1. Ona device having a collection of hardware resources designated as a security block, a method of executing an unsigned operating system, said method comprising: performing a transition from an unprovisioned state into a first operational mode, said first operational mode allowing execution of untrusted operating systems;storing an indication that said device is in said first operational mode;loading an operating system;subsequent to said loading, determining that said operating system has not been signed by a trusted entity;subsequent to said loading, determining, upon review of said indication, that said device is in the first operational mode;responsive to determining that said device is in said first operational mode, determining that a counter of allowed insecure boots exceeds zero;responsive to the determining that the counter exceeds zero: decrementing the counter of allowed insecure boots;disabling operating system access to said security block;and executing said operating system.
  2. 4
    The method of any one of claims 1-3 wherein said security block stores authentication keys. CA 2767574 2017-03-16 39135-CA-PAT -14- 42783-3270
  3. 5
    The method of any one of claims 1-4 further comprising erasing stored user data.
  4. 6
    The method of any one of claims 1 -5 wherein one of the untrusted operating systems comprises the unsigned operating system.
  5. 7
    The method of any one of claims 1-5 wherein one of the untrusted operating systems comprises an operating system signed with a digital signature that identifies a certificate authority that is not among a set of trusted certificate authorities.
  6. 8
    A secure device comprising:a security block;and a processor adapted to: perform a transition from an unprovisioned state into a first operational mode, said first operational mode allowing execution of untrusted operating systems;store an indication that said device is in said first operational mode;load an operating system;determine, subsequent to said loading, that said operating system has not been signed by a trusted entity;determine, subsequent to said loading and upon review of said indication, that said device is in said first operational mode;determine that a counter of allowed insecure boots exceeds zero;decrement the counter of allowed insecure boots;disable, responsive to determining that said device is in said first operational mode, operating system access to said security block;and execute said operating system. CA 2767574 2017-03-16 39135-ca-pat -15- 42783-3270
  7. 11
    The secure device of any one of claims 8-10 wherein said security block comprises secure persistent storage.
  8. 13
    The secure device of any one of claims 8-12 wherein said security block stores processor fuse settings.
  9. 14
    The secure device of any one of claims 8-13 wherein said security block stores a device-specific cryptographic key.
  10. 15
    The secure device of any one of claims 8-14 wherein said security block stores device provisioning data.
  11. 16
    The secure device of any one of claims 8-15 wherein said processor is adapted to erase stored user data.
  12. 17
    The secure device of any one of claims 8-16 wherein said security block stores an authentication key.
  13. 19
    A computer readable medium containing computer-executable instructions that, when performed by a processor in a secure device, wherein the secure device includes a security block, cause said processor to:CA 2767574 2017-03-16 39135-ca-pat -16- 42783-3270 perform a transition from an unprovisioned state into a first operational mode, said first operational mode allowing execution of untrusted operating systems;store an indication that said device is in said first operational mode;load an operating system;determine, subsequent to said loading, that said operating system has not been signed by a trusted entity;determine, subsequent to said loading and upon review of said indication, that said device is in said first operational mode;determine that a counter of allowed insecure boots exceeds zero;decrement the counter of allowed insecure boots;disable, responsive to determining that said device is in said first operational mode, operating system access to said security block;and execute said operating system.
  14. 22
    The computer readable medium of any one of claims 19-21 wherein said security block stores a relay protected memory block.
  15. 23
    The computer readable medium of any one of claims 19-22 wherein said security block stores device provisioning data.
  16. 24
    The computer readable medium of any one of claims 19-23 wherein said computer-executable instructions cause said processor to erase stored user data.
  17. 25
    The computer readable medium of any one of claims 19-24 wherein said security block stores an authentication key. CA 2767574 2017-03-16
  18. 26
    On a device having a collection of hardware resources designated as a security block, a method of executing an unsigned operating system, the method comprising:39135-CA-PAT -IT42783-3270 performing a transition from an unprovisioned state into a first operational mode, the first operational mode allowing execution of untrusted operating systems;storing an indication that the device is in the first operational mode;loading an operating system;subsequent to the loading, determining that the operating system has not been signed by a trusted entity;subsequent to the loading, determining, upon review of the indication, that the device is in a first operational mode;responsive to determining that the device is in the first operational mode, determining that a counter of allowed insecure boots has reached zero;responsive to the determining that the counter has reached zero: deactivating the first operational mode;and restarting the operating system.
  19. 27
    A secure device comprising:a security block;and a processor adapted to: perform a transition from an unprovisioned state into a first operational mode, the first operational mode allowing execution of untrusted operating systems;store an indication that the device is in the first operational mode;load an operating system;CA 2767574 2017-03-16 39135-CA-PAT -18- 42783-3270 determine, subsequent to the loading, that the operating system has not been signed by a trusted entity;determine, subsequent to the loading and upon review of the indication, that the device is in the first operational mode;determine that a counter of allowed insecure boots has reached zero;deactivate the first operational mode;and restart the operating system.
  20. 28
    A computer readable medium containing computer-executable instructions that, when performed by a processor in a secure device, wherein the secure device includes a security block, cause the processor to:perform a transition from an unprovisioned state into a first operational mode, the first operational mode allowing execution of untrusted operating systems;store an indication that the device is in the first operational mode;load an operating system;determine, subsequent to the loading, that the operating system has not been signed by a trusted entity;determine, subsequent to the loading and upon review of the indication, that the device is in the first operational mode;determine that a counter of allowed insecure boots has reached zero;deactivate the first operational mode;and restart the operating system.
Independent claims20