BIOS Integrity Checking via Dedicated Security Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems face challenges in ensuring the integrity and security of the Basic Input/Output System (BIOS) during reset periods, as existing methods rely on the CPU for BIOS measurement and hashing, which can be slow and vulnerable to tampering.

Innovation Solution

A security module with direct access to non-volatile memory via a dedicated interface processes and hashes the BIOS, enabling autonomous BIOS processing and integrity checking, even during reset periods, thereby enhancing security and speed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the CPU performs BIOS hashing after reset period, then system integrity can be checked, but processing speed is slow and system vulnerable to tampering during reset

Engineering Contradiction:
ImproveBIOS integrity checkingVSAvoidBIOS processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent divides the BIOS processing function between the CPU and a dedicated security module. The security module independently reads and hashes the BIOS during reset period, while the CPU handles other boot tasks. This segmentation allows parallel processing and eliminates the bottleneck of CPU being occupied with other initialization tasks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security module as an intermediary component between the BIOS and the CPU. This security module is specifically designed to perform integrity checking operations, acting as a dedicated mediator that can operate independently during reset period without blocking CPU operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If CPU reads and processes BIOS after reset, then system can boot normally, but security against tampering is reduced during reset period

Engineering Contradiction:
ImproveSystem boot operationVSAvoidSecurity against BIOS tampering
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs BIOS integrity checking during the reset period before the CPU fully initializes the system. The security module reads and hashes the BIOS in advance, storing the hash value for later verification. This preliminary action ensures that even if the BIOS is tampered with after reset, the system can detect it during boot.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security module operates autonomously during reset period to perform integrity checking without requiring CPU intervention. It self-manages the process of reading BIOS, computing hash, and storing results, providing security services independently of the main boot process.

Inventive Principle:
Principle #25Self-service

3Productivity

If security module has direct interface with non-volatile memory, then BIOS processing speed increases and autonomy improves, but device complexity increases

Engineering Contradiction:
ImproveBIOS processing throughputVSAvoidSecurity module interface structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent combines the security module's memory interface directly with the non-volatile memory containing the BIOS. By merging these interfaces, the security module gains direct access to the BIOS data without requiring CPU mediation, thereby increasing processing throughput and enabling autonomous operation during reset period.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8886955B2Systems and methods for BIOS processing
Publication Date: 2014.11.11 NUVOTON
  • US8886955B2 patent drawing
  • US8886955B2 patent drawing
  • US8886955B2 patent drawing

AI summary

Methods and systems for Basic Input/Output System BIOS processing such as hashing are disclosed. In one embodiment, there is a direct interface between a security module and a non-volatile memory storing the BIOS in a computing system so that the security module may directly access the BIOS without using the central processing unit CPU as an intermediary. In one embodiment, the security module is powered by standby power and therefore can begin BIOS processing even if the computing system has not yet been turned on.