Backup Firmware Rollback Attack Prevention Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing systems with primary and backup memory banks are vulnerable to rollback attacks, where the system is compromised by switching to an older firmware version in the backup bank, exploiting security holes.

Innovation Solution

An attack prevention module determines if the system is attempting to use backup firmware, checks if it's a previous version, and requires administrator authorization before allowing its use, configuring the system to utilize the backup firmware only if authorized.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system uses backup memory bank for auto-recovery, then system reliability is improved, but security vulnerability increases due to rollback attacks

Engineering Contradiction:
Improvesystem reliabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by checking the firmware version in the backup memory bank before allowing the system to boot from it. The attack prevention module compares the backup firmware version with the primary firmware version in advance, and prevents booting if the backup version is older, thus preventing rollback attacks before they can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary component - the attack prevention module - that mediates between the backup memory bank and the system boot process. This module acts as a security gatekeeper, verifying firmware versions and controlling whether the system can transition to using backup firmware, thereby resolving the conflict between reliability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the system allows automatic switching to backup firmware, then system availability is improved, but security control is weakened

Engineering Contradiction:
Improvesystem availabilityVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements feedback by having the attack prevention module continuously monitor and compare firmware versions in the primary and backup memory banks. The module provides feedback control by automatically preventing system transitions when the backup firmware is detected to be an older version, thus maintaining security control while allowing automatic operation.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If the system implements firmware version checking, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the attack prevention module to perform multiple functions: it monitors firmware versions, compares versions between primary and backup banks, prevents rollback attacks, and controls system boot operations. By consolidating these security functions into a single multi-functional module, the patent improves security while minimizing the increase in system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9448888B2Preventing a rollback attack in a computing system that includes a primary memory bank and a backup memory bank
Publication Date: 2016.09.20 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US9448888B2 patent drawing
  • US9448888B2 patent drawing
  • US9448888B2 patent drawing

AI summary

Preventing a rollback attack in a computing system that includes a primary memory bank and a backup memory bank, including during startup of the computing system: determining whether the computing system is attempting to use firmware in the backup memory bank; responsive to determining that the computing system is attempting to use firmware in the backup memory bank, determining whether the firmware in the backup memory bank is a previous version of firmware in the primary memory bank; responsive to determining that the firmware in the backup memory bank is a previous version of firmware in the primary memory bank, determining whether a system administrator has authorized the use of the firmware in the backup memory bank; and responsive to determining that the system administrator has authorized the use of the firmware in the backup memory bank, configuring the computing system to utilize the firmware in the backup memory bank.