Dynamic Hardware BOM Verification for Computing Device Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for ensuring the integrity of computing devices throughout the supply chain are inadequate, as they either focus on software components or require static data that can be tampered with, lacking robust verification of hardware components.

Innovation Solution

A method involving a trusted application that measures hardware component identifiers and generates a dynamic bill of materials within a secure environment, comparing it to a predefined static bill to verify the integrity of hardware components before booting the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static bill of materials is used for verification, then verification simplicity is improved, but security against tampering deteriorates

Engineering Contradiction:
Improveverification simplicityVSAvoidsecurity against tampering
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transitions from static bill of materials to dynamic bill of materials that are automatically generated and updated. The dynamic BOMs are created by executing a trusted application that reads component identifiers directly from hardware, ensuring they reflect the actual current state of the device and cannot be tampered with statically.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a trusted application as an intermediary between the hardware components and the verification process. This trusted application executes in a secure environment, reads component identifiers, generates the dynamic BOM, and performs verification, thereby mediating between the physical hardware and the verification system while ensuring integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If trusted application in secure environment is used, then hardware verification reliability is improved, but system complexity deteriorates

Engineering Contradiction:
Improvehardware verification reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted application performs multiple functions: it reads identifiers from hardware components, generates the dynamic bill of materials, verifies component integrity, and controls the boot process. By consolidating these functions into a single trusted application executing in a secure environment, the system achieves high verification reliability without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The trusted application executes before the operating system boots, performing verification of hardware components in advance. This preliminary action ensures that the boot process only proceeds if hardware integrity is confirmed, preventing malicious hardware from executing system software while maintaining a relatively simple overall system architecture.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4600852A1Method of verifying integrity of a computing device, and computing device
Publication Date: 2025.08.13 SIEMENS AG
  • EP4600852A1 patent drawingFigure 1~3
  • EP4600852A1 patent drawingFigure 4~5
  • EP4600852A1 patent drawingFigure 6~7

AI summary

The invention relates to a method of verifying integrity of a computing device (1) comprising a number of hardware device components (1), the method comprising the steps of: a) measuring (S1) a number of identifiers (30) of each of the hardware device components (10); and b) generating (S2) a dynamic bill of materials (3) from the number of measured identifiers (30), wherein steps a) and b) are performed by executing an application (21) comprised in a trusted code base (121) of the computing device (1). The dynamic bill of materials generated by the application that is part of the trusted code base allows to verify the integrity of the hardware device components of the computing device in a trusted manner.