Dual Root of Trust Firmware Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing systems lack robust and automated mechanisms for detecting and recovering from firmware corruption, particularly in the firmware images stored in flash ROM, which can lead to security attacks and unintentional corruption during updates, and existing recovery utilities are cumbersome and insecure.
Innovation Solution
Implementing an independent second root of trust (ROT) within the computing system's BIOS or Baseboard Management Controller (BMC) to enable automated recovery of corrupted firmware images using hardware signals and physical presence switches, with bi-directional verification and recovery capabilities between two controllers to ensure integrity and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of repair
If existing recovery utilities are used to recover corrupted firmware images, then firmware recovery is possible, but the process is cumbersome and insecure
Solution Approach 1:
The system performs automated self-diagnosis and self-recovery by having the second controller automatically detect firmware corruption through integrity verification and execute recovery operations without external intervention, eliminating the need for cumbersome manual recovery utilities
Solution Approach 2:
The patent introduces a second controller as an intermediary component that mediates the recovery process by verifying firmware integrity and restoring corrupted firmware images, replacing complex external recovery utilities with an integrated internal mechanism
2Reliability
If firmware images are stored in flash ROM for persistent storage, then system boot capability is maintained, but the firmware becomes vulnerable to security attacks and corruption
Solution Approach 1:
The system performs preliminary integrity verification of firmware images before execution by having the second controller verify the firmware's digital signature and hash values stored in flash ROM, detecting potential corruption or tampering before the firmware is executed
Solution Approach 2:
The second controller acts as an intermediary security layer between the stored firmware images in flash ROM and the system execution, verifying integrity and enabling safe recovery without compromising boot capability
3Ease of repair
If manual recovery processes are used for firmware corruption, then recovery can be performed, but the process is time-consuming and labor-intensive
Solution Approach 1:
The system automatically detects firmware corruption through integrity verification and executes the complete recovery process without human intervention, eliminating time-consuming manual operations and reducing recovery time to automated system response time
Solution Approach 2:
The system performs preliminary detection of firmware corruption and automatically initiates recovery operations, eliminating the time loss associated with manual diagnosis and intervention by having the second controller continuously verify firmware integrity and self-correct issues
Data Source
AI summary
An example computing system in accordance with an aspect of the present disclosure includes a first controller and a second controller. The first controller is to verify integrity of a first root of trust (ROT), and generate an integrity signal indicating the results. The second controller is to verify integrity of a second ROT, write the firmware image to the first controller, and verify integrity of the written firmware image.


