Read-Only Memory Locking for ACPI Table Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computing systems lack protection for system memory prior to system boot up, making them vulnerable to attacks on sensitive data such as ACPI tables, which can lead to security vulnerabilities and OEM OS piracy.
Innovation Solution
Implementing a trusted control block and trusted BIOS to select a region of system memory for protection, configuring it as read-only using an address decoder circuit, and locking it to prevent modifications during pre-boot and boot operations, ensuring that sensitive data like ACPI tables are secured.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If system memory is left unprotected during pre-boot operations, then system complexity and boot time are reduced, but security vulnerabilities increase allowing malicious modifications to ACPI tables
Solution Approach 1:
The patent applies preliminary action by configuring the address decoder circuit to lock specific memory regions (such as ACPI table locations) in read-only mode before the system boot process begins. This pre-configuration occurs during system setup, ensuring that critical memory regions are protected from malicious modification before any pre-boot or boot-time code executes, thereby preventing security vulnerabilities without adding complex runtime protection mechanisms
2Reliability
If read-only locking is implemented during pre-boot, then protection against malicious modifications is achieved, but system complexity and boot time increase
Solution Approach 1:
The locking mechanism is configured in advance during system setup rather than being activated during the boot process. The address decoder circuit is pre-programmed with the memory addresses of critical data structures, and the read-only locking is already in place before the CPU begins executing boot code, thus providing protection without adding any time overhead to the boot sequence
Solution Approach 2:
The address decoder circuit performs the locking function automatically based on pre-configured address ranges, without requiring software intervention or additional processing during boot. The hardware automatically enforces the read-only protection on specified memory regions, eliminating the need for software-based protection mechanisms that would consume CPU cycles and extend boot time
3Reliability
If ACPI tables are protected from modification, then security against piracy and attacks is improved, but system adaptability and configuration flexibility are reduced
Solution Approach 1:
The patent applies local quality by selectively locking only specific memory regions that contain critical ACPI tables and other protected data structures, while leaving other memory regions unlocked and writable. The address decoder circuit is configured with specific address ranges for locking, allowing the system to maintain protection for security-critical components while preserving configuration flexibility for non-critical system components
Solution Approach 2:
The memory space is segmented into protected and unprotected regions. The address decoder circuit is configured to lock only specific segments containing ACPI tables and other critical data, while other segments remain accessible for normal system operations and configuration changes. This segmentation allows simultaneous protection of critical data and flexibility for system configuration
Data Source
AI summary
Generally, this disclosure provides methods and systems for secure data protection with improved read-only memory locking during system pre-boot including protection of Advanced Configuration and Power Interface (ACPI) tables. The methods may include selecting a region of system memory to be protected, the selection occurring in response to a system reset state and performed by a trusted control block (TCB) comprising a trusted basic input/output system (BIOS); programming an address decoder circuit to configure the selected region as read-write; moving data to be secured to the selected region; programming the address decoder circuit to configure the selected region as read-only; and locking the read-only configuration in the address decoder circuit.


