Read-Only Memory Locking for ACPI Table Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems lack protection for system memory prior to system boot up, making them vulnerable to attacks on sensitive data such as ACPI tables, which can lead to security vulnerabilities and OEM OS piracy.

Innovation Solution

Implementing a trusted control block and trusted BIOS to select a region of system memory for protection, configuring it as read-only using an address decoder circuit, and locking it to prevent modifications during pre-boot and boot operations, ensuring that sensitive data like ACPI tables are secured.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If system memory is left unprotected during pre-boot operations, then system complexity and boot time are reduced, but security vulnerabilities increase allowing malicious modifications to ACPI tables

Engineering Contradiction:
ImprovesecurityVSAvoidmemory protection mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by configuring the address decoder circuit to lock specific memory regions (such as ACPI table locations) in read-only mode before the system boot process begins. This pre-configuration occurs during system setup, ensuring that critical memory regions are protected from malicious modification before any pre-boot or boot-time code executes, thereby preventing security vulnerabilities without adding complex runtime protection mechanisms

Inventive Principle:
Principle #10Preliminary action

2Reliability

If read-only locking is implemented during pre-boot, then protection against malicious modifications is achieved, but system complexity and boot time increase

Engineering Contradiction:
Improvedata protectionVSAvoidboot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The locking mechanism is configured in advance during system setup rather than being activated during the boot process. The address decoder circuit is pre-programmed with the memory addresses of critical data structures, and the read-only locking is already in place before the CPU begins executing boot code, thus providing protection without adding any time overhead to the boot sequence

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The address decoder circuit performs the locking function automatically based on pre-configured address ranges, without requiring software intervention or additional processing during boot. The hardware automatically enforces the read-only protection on specified memory regions, eliminating the need for software-based protection mechanisms that would consume CPU cycles and extend boot time

Inventive Principle:
Principle #25Self-service

3Reliability

If ACPI tables are protected from modification, then security against piracy and attacks is improved, but system adaptability and configuration flexibility are reduced

Engineering Contradiction:
ImproveACPI protectionVSAvoidconfiguration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by selectively locking only specific memory regions that contain critical ACPI tables and other protected data structures, while leaving other memory regions unlocked and writable. The address decoder circuit is configured with specific address ranges for locking, allowing the system to maintain protection for security-critical components while preserving configuration flexibility for non-critical system components

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The memory space is segmented into protected and unprotected regions. The address decoder circuit is configured to lock only specific segments containing ACPI tables and other critical data, while other segments remain accessible for normal system operations and configuration changes. This segmentation allows simultaneous protection of critical data and flexibility for system configuration

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9075751B2Secure data protection with improved read-only memory locking during system pre-boot
Publication Date: 2015.07.07 TAHOE RES LTD
  • US9075751B2 patent drawing
  • US9075751B2 patent drawing
  • US9075751B2 patent drawing

AI summary

Generally, this disclosure provides methods and systems for secure data protection with improved read-only memory locking during system pre-boot including protection of Advanced Configuration and Power Interface (ACPI) tables. The methods may include selecting a region of system memory to be protected, the selection occurring in response to a system reset state and performed by a trusted control block (TCB) comprising a trusted basic input/output system (BIOS); programming an address decoder circuit to configure the selected region as read-write; moving data to be secured to the selected region; programming the address decoder circuit to configure the selected region as read-only; and locking the read-only configuration in the address decoder circuit.