Trusted High-Speed Encryption Card Firmware Integrity Measurement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies fail to guarantee active measurements of a platform and a system, as well as static and dynamic loading measurements of firmware related to high-speed cryptographic operations during device startup, particularly in ensuring the integrity of cryptographic operations.

Innovation Solution

A measurement method and system utilizing a trusted high-speed encryption card, where the BIOS actively measures firmware integrity and prevents system startup or enters a non-secure mode if corruption is detected, ensuring the integrity of cryptographic operations by loading only uncorrupted firmware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional TPM or TPCM is used for integrity measurement, then a trusted root can be established, but active measurements of the platform and system cannot be guaranteed during device startup

Engineering Contradiction:
Improveintegrity measurement reliabilityVSAvoidmeasurement execution capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent transitions from static measurement (TPM/TPCM) to dynamic measurement by enabling the BIOS to actively measure firmware integrity during the startup process. The measurement capability is made dynamic through the interaction between the trusted security chip and BIOS, allowing real-time integrity verification of cryptographic firmware as it is loaded and executed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The BIOS is empowered to perform self-measurement of firmware integrity using the trusted security chip. The system serves itself by having the BIOS actively measure its own loaded firmware components, eliminating the need for external measurement mechanisms and enabling autonomous integrity verification during startup.

Inventive Principle:
Principle #25Self-service

2Speed

If cryptographic firmware is dynamically loaded during startup, then high-speed cryptographic operations can be enabled, but simultaneous static and dynamic loading measurements cannot be performed

Engineering Contradiction:
Improvecryptographic operation speedVSAvoidfirmware integrity measurement accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent implements preliminary measurement action by having the BIOS measure the integrity of cryptographic firmware immediately before loading and executing it. This preliminary verification ensures that only authenticated firmware is loaded into memory and executed, maintaining measurement precision while enabling dynamic loading of high-speed cryptographic operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The measurement process continues continuously during the firmware loading and execution phases. The trusted security chip and BIOS maintain an ongoing measurement chain that follows the firmware from storage through loading to execution, ensuring unbroken integrity verification throughout the entire dynamic loading process.

Inventive Principle:
Principle #20Continuity of useful action

3Ease of operation

If the trusted root is located in BIOS (TPCM approach), then system control and I/O interface control can be achieved, but the measurement root is not protected by the TPM

Engineering Contradiction:
Improvesystem control capabilityVSAvoidmeasurement root protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted security chip as an intermediary between the BIOS and the firmware being measured. This intermediary provides the measurement root protection function that was previously only available in TPM/TPCM, while allowing the BIOS to retain its system control and I/O interface control capabilities. The trusted security chip mediates the integrity verification process without interfering with BIOS control functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11379586B2Measurement methods, devices and systems based on trusted high-speed encryption card
Publication Date: 2022.07.05 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US11379586B2 patent drawing
  • US11379586B2 patent drawing
  • US11379586B2 patent drawing

AI summary

Measurement methods, devices and systems based on a trusted high-speed encryption card are disclosed. One of the methods includes: a BIOS actively measuring at least one firmware in a device if an integrity measurement result made by a trusted security chip for the BIOS indicates that the integrity thereof is not corrupted; loading one or more firmware if the integrity of the one or more firmware in the device actively measured by the BIOS is not corrupted; and forbidding a system of the device from being started or controlling the system to enter into a non-secure mode if the integrity of one or more firmware in the device actively measured by the BIOS is corrupted.