Dual Root of Trust Firmware Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems lack robust and automated mechanisms for detecting and recovering from firmware corruption, particularly in the firmware images stored in flash ROM, which can lead to security attacks and unintentional corruption during updates, and existing recovery utilities are cumbersome and insecure.

Innovation Solution

Implementing an independent second root of trust (ROT) within the computing system's BIOS or Baseboard Management Controller (BMC) to enable automated recovery of corrupted firmware images using hardware signals and physical presence switches, with bi-directional verification and recovery capabilities between two controllers to ensure integrity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If existing recovery utilities are used to recover corrupted firmware images, then firmware recovery is possible, but the process is cumbersome and insecure

Engineering Contradiction:
Improvefirmware recovery processVSAvoidrecovery utility complexity
Core Design Contradiction:
Ease of repairVSDevice complexity

Solution Approach 1:

The system performs automated self-diagnosis and self-recovery by having the second controller automatically detect firmware corruption through integrity verification and execute recovery operations without external intervention, eliminating the need for cumbersome manual recovery utilities

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a second controller as an intermediary component that mediates the recovery process by verifying firmware integrity and restoring corrupted firmware images, replacing complex external recovery utilities with an integrated internal mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firmware images are stored in flash ROM for persistent storage, then system boot capability is maintained, but the firmware becomes vulnerable to security attacks and corruption

Engineering Contradiction:
Improvesystem boot capabilityVSAvoidfirmware corruption risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary integrity verification of firmware images before execution by having the second controller verify the firmware's digital signature and hash values stored in flash ROM, detecting potential corruption or tampering before the firmware is executed

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The second controller acts as an intermediary security layer between the stored firmware images in flash ROM and the system execution, verifying integrity and enabling safe recovery without compromising boot capability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of repair

If manual recovery processes are used for firmware corruption, then recovery can be performed, but the process is time-consuming and labor-intensive

Engineering Contradiction:
Improvefirmware recovery capabilityVSAvoidrecovery time
Core Design Contradiction:
Ease of repairVSLoss of time

Solution Approach 1:

The system automatically detects firmware corruption through integrity verification and executes the complete recovery process without human intervention, eliminating time-consuming manual operations and reducing recovery time to automated system response time

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary detection of firmware corruption and automatically initiates recovery operations, eliminating the time loss associated with manual diagnosis and intervention by having the second controller continuously verify firmware integrity and self-correct issues

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10740468B2Multiple roots of trust to verify integrity
Publication Date: 2020.08.11 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10740468B2 patent drawing
  • US10740468B2 patent drawing
  • US10740468B2 patent drawing

AI summary

An example computing system in accordance with an aspect of the present disclosure includes a first controller and a second controller. The first controller is to verify integrity of a first root of trust (ROT), and generate an integrity signal indicating the results. The second controller is to verify integrity of a second ROT, write the firmware image to the first controller, and verify integrity of the written firmware image.