CPU-Chipset Secure Channel for Swappable Platform Boot Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Swappable CPUs in computing systems can lead to compatibility issues and boot failures due to mismatched chipset configurations, as well as vulnerabilities from unauthorized firmware rollbacks and lack of secure communication protocols.

Innovation Solution

Implementing security engines on both the CPU and chipset for secure channel establishment, using symmetric identity keys and generation matching to ensure compatibility, and integrating boot security mechanisms to verify the authenticity of firmware and boot policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If swappable CPUs are implemented to improve hardware flexibility and upgradability, then adaptability is improved, but compatibility problems and security vulnerabilities arise due to mismatched security parameters between CPU and chipset

Engineering Contradiction:
ImproveCPU swapabilityVSAvoidsystem compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by synchronizing security parameters and establishing secure channel sessions between CPU and chipset before the CPU is physically swapped. Security version numbers (SVNs) and generation identifiers are pre-configured and verified during the handoff process, ensuring compatibility is established in advance rather than reacting to mismatches after insertion. This prevents boot failures and security vulnerabilities by preparing the security context beforehand.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the chipset and CPU continuously exchange and verify security parameters during the swap process. The chipset monitors CPU insertion, retrieves security information, and validates compatibility through authenticated communication channels. This closed-loop feedback ensures that any mismatch in security versions or generation identifiers is detected and handled appropriately, maintaining system reliability while enabling CPU swapability.

Inventive Principle:
Principle #23Feedback

2Reliability

If security engines are added to both CPU and chipset to establish secure channels, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity engine integration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security functions by integrating security engines directly into the existing CPU and chipset architectures rather than adding separate external security modules. The security engines are combined with the memory controllers and I/O interfaces, sharing physical and logical resources. This consolidation provides robust security capabilities while minimizing the increase in overall device complexity through resource sharing and integrated design.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security engines are designed with multi-functionality to handle various security operations including secure channel establishment, authentication, encryption, and generation matching. By creating universal security components that can perform multiple security tasks rather than separate specialized modules for each function, the patent reduces the total number of components needed while maintaining comprehensive security coverage across different CPU generations and swap scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4020295B1Platform security mechanism
Publication Date: 2026.04.29 INTEL CORP
  • EP4020295B1 patent drawingFigure 1
  • EP4020295B1 patent drawingFigure 2
  • EP4020295B1 patent drawingFigure 3A

AI summary

An apparatus comprising a computer platform, including a central processing unit (CPU) comprising a first security engine to perform security operations at the CPU and a chipset comprising a second security engine to perform security operations at the chipset, wherein the first security engine and the second security engine establish a secure channel session between the CPU and the chipset to secure data transmitted between the CPU and the chipset.