EP2487618A2

Managing booting of secure devices with untrusted software

Abstract

Normally, at the time of manufacturing, security may be provided to a device being manufactured through the loading of an operating system that has been cryptographically signed. The present application discloses a "factory mode" for the device. The "factory mode" allows the device to execute untrusted operating system code, such as unsigned operating system code and operating system code that has been signed, but the certificate authority is not trusted. To support execution of untrusted operating system code in a secure manner, the device may be adapted to prevent data of predetermined type from being loaded on the device while the device is in the "factory mode". In contrast to the "factory mode", the secure mode of the device is referred to herein as a "product mode". There develops a need to manage, in a secure manner, transitions between the "product mode" and the "factory mode".

EP2487618A2, drawing sheet 1
Sheet 1 of 5

Term

4.4 yearsto projected expiry

Projected expiry 15 February 2031, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 7 independent, 8 dependent

  1. 1
    On a device (100) having a collection of hardware resources designated as a security block, a method of executing an unsigned operating system, said method comprising:loading (302) an operating system;determining (310) that said operating system has not been signed by a trusted entity;determining (304) that said device is in a first operational mode, said first operational mode allowing execution of unsigned operating systems;responsive to determining that said device is in said first operational mode, disabling (316) operating system access to said security block;and executing (318) said operating system.
  2. 4
    A secure device (100) comprising:a security block (116, 120);and a processor (128) adapted to: load an operating system;determine that said operating system has not been signed by a trusted entity;determine that said device is in a first operational mode, said first operational mode allowing execution of unsigned operating systems;disable operating system access to said security block;and execute said unsigned operating system.
  3. 9
    The secure device of any one of claims 4 to 8 wherein said security block stores:a device-specific cryptographic key;processor fuse settings;device provisioning data;or an authentication key.
  4. 10
    The secure device of any one of claims 4 to 9 wherein said processor is adapted to erase stored user data.
  5. 11
    The secure device of any one of claims 4 to 10 further comprising a write-protected read only memory storing a boot loader and wherein the processor is further adapted to:load said boot loader;and under instructions from said boot loader, load said operating system.
  6. 12
    A computer readable medium containing computer-executable instructions that, when performed by a processor in a secure device, wherein the secure device includes a security block, cause said processor to:load an operating system;determine that said operating system has not been signed by a trusted entity;determine that said device is in a first operational mode, said first operational mode allowing execution of unsigned operating systems;disable operating system access to said security block;and execute said unsigned operating system.
  7. 15
    The computer readable medium of any one of claims 12 to 14 wherein said computer-executable instructions cause said processor to erase stored user data.