CPU Chipset Secure Channel Session for Swappable Platform Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of swappable CPUs in computing systems can lead to compatibility issues and boot failures due to mismatches in security parameters and firmware versions between the CPU and chipset, resulting in potential security exploits and functionality failures.

Innovation Solution

Implementing security engines on both the CPU and chipset to establish a secure channel session through synchronized security parameters and identity key management, ensuring compatibility and secure communication, while using image versioning and generation matching to enforce compatibility across multiple generations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If swappable CPUs are implemented to improve hardware flexibility and upgradability, then adaptability is improved, but compatibility problems and security parameter mismatches occur between CPU and chipset

Engineering Contradiction:
ImproveCPU swap abilityVSAvoidsystem compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing secure channel sessions and synchronizing security parameters between CPU and chipset before the CPU is physically swapped. Identity keys are pre-established and stored in non-volatile memory, and security version numbers are pre-verified to ensure compatibility. This preliminary setup prevents compatibility issues and security parameter mismatches when the CPU is later replaced, allowing flexible CPU swapping while maintaining system reliability and security.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If security engines are added to both CPU and chipset to establish secure channels, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity exploits preventionVSAvoidsecurity engine implementation
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies merging by integrating security engines directly into the existing CPU and chipset architectures rather than adding separate external security devices. The security engines are combined with the memory controllers and non-volatile memory systems, allowing secure channel establishment and parameter synchronization to be performed using existing hardware resources. This reduces overall system complexity while maintaining strong security protections against exploits.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If generation matching and SVN verification are enforced to ensure compatibility, then reliability is improved, but ease of operation decreases due to additional verification steps

Engineering Contradiction:
Improvefirmware compatibilityVSAvoidCPU installation process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the security engines to automatically perform generation matching and SVN verification without requiring manual intervention from users or system administrators. When a CPU is installed, the security engine autonomously retrieves the identity key from non-volatile memory, verifies the security version number against the chipset, and establishes the secure channel session automatically. This self-verification process maintains high firmware compatibility reliability while keeping the CPU installation process simple and user-friendly.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11741227B2Platform security mechanism
Publication Date: 2023.08.29 INTEL CORP
  • US11741227B2 patent drawing
  • US11741227B2 patent drawing
  • US11741227B2 patent drawing

AI summary

An apparatus comprising a computer platform, including a central processing unit (CPU) comprising a first security engine to perform security operations at the CPU and a chipset comprising a second security engine to perform security operations at the chipset, wherein the first security engine and the second security engine establish a secure channel session between the CPU and the chipset to secure data transmitted between the CPU and the chipset.