Backup Firmware Rollback Attack Prevention Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing systems with primary and backup memory banks are vulnerable to rollback attacks, where the system is compromised by switching to an older firmware version in the backup bank, exploiting security holes.
Innovation Solution
An attack prevention module determines if the system is attempting to use backup firmware, checks if it's a previous version, and requires administrator authorization before allowing its use, configuring the system to utilize the backup firmware only if authorized.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system uses backup memory bank for auto-recovery, then system reliability is improved, but security vulnerability increases due to rollback attacks
Solution Approach 1:
The patent applies preliminary action by checking the firmware version in the backup memory bank before allowing the system to boot from it. The attack prevention module compares the backup firmware version with the primary firmware version in advance, and prevents booting if the backup version is older, thus preventing rollback attacks before they can occur.
Solution Approach 2:
The patent introduces an intermediary component - the attack prevention module - that mediates between the backup memory bank and the system boot process. This module acts as a security gatekeeper, verifying firmware versions and controlling whether the system can transition to using backup firmware, thereby resolving the conflict between reliability and security.
2Productivity
If the system allows automatic switching to backup firmware, then system availability is improved, but security control is weakened
Solution Approach 1:
The patent implements feedback by having the attack prevention module continuously monitor and compare firmware versions in the primary and backup memory banks. The module provides feedback control by automatically preventing system transitions when the backup firmware is detected to be an older version, thus maintaining security control while allowing automatic operation.
3Object-affected harmful factors
If the system implements firmware version checking, then security is improved, but system complexity increases
Solution Approach 1:
The patent applies universality by designing the attack prevention module to perform multiple functions: it monitors firmware versions, compares versions between primary and backup banks, prevents rollback attacks, and controls system boot operations. By consolidating these security functions into a single multi-functional module, the patent improves security while minimizing the increase in system complexity.
Data Source
AI summary
Preventing a rollback attack in a computing system that includes a primary memory bank and a backup memory bank, including during startup of the computing system: determining whether the computing system is attempting to use firmware in the backup memory bank; responsive to determining that the computing system is attempting to use firmware in the backup memory bank, determining whether the firmware in the backup memory bank is a previous version of firmware in the primary memory bank; responsive to determining that the firmware in the backup memory bank is a previous version of firmware in the primary memory bank, determining whether a system administrator has authorized the use of the firmware in the backup memory bank; and responsive to determining that the system administrator has authorized the use of the firmware in the backup memory bank, configuring the computing system to utilize the firmware in the backup memory bank.


