Trusted High-Speed Encryption Card Firmware Integrity Measurement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies fail to guarantee active measurements of a platform and a system, as well as static and dynamic loading measurements of firmware related to high-speed cryptographic operations during device startup, particularly in ensuring the integrity of cryptographic operations.
Innovation Solution
A measurement method and system utilizing a trusted high-speed encryption card, where the BIOS actively measures firmware integrity and prevents system startup or enters a non-secure mode if corruption is detected, ensuring the integrity of cryptographic operations by loading only uncorrupted firmware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional TPM or TPCM is used for integrity measurement, then a trusted root can be established, but active measurements of the platform and system cannot be guaranteed during device startup
Solution Approach 1:
The patent transitions from static measurement (TPM/TPCM) to dynamic measurement by enabling the BIOS to actively measure firmware integrity during the startup process. The measurement capability is made dynamic through the interaction between the trusted security chip and BIOS, allowing real-time integrity verification of cryptographic firmware as it is loaded and executed.
Solution Approach 2:
The BIOS is empowered to perform self-measurement of firmware integrity using the trusted security chip. The system serves itself by having the BIOS actively measure its own loaded firmware components, eliminating the need for external measurement mechanisms and enabling autonomous integrity verification during startup.
2Speed
If cryptographic firmware is dynamically loaded during startup, then high-speed cryptographic operations can be enabled, but simultaneous static and dynamic loading measurements cannot be performed
Solution Approach 1:
The patent implements preliminary measurement action by having the BIOS measure the integrity of cryptographic firmware immediately before loading and executing it. This preliminary verification ensures that only authenticated firmware is loaded into memory and executed, maintaining measurement precision while enabling dynamic loading of high-speed cryptographic operations.
Solution Approach 2:
The measurement process continues continuously during the firmware loading and execution phases. The trusted security chip and BIOS maintain an ongoing measurement chain that follows the firmware from storage through loading to execution, ensuring unbroken integrity verification throughout the entire dynamic loading process.
3Ease of operation
If the trusted root is located in BIOS (TPCM approach), then system control and I/O interface control can be achieved, but the measurement root is not protected by the TPM
Solution Approach 1:
The patent introduces a trusted security chip as an intermediary between the BIOS and the firmware being measured. This intermediary provides the measurement root protection function that was previously only available in TPM/TPCM, while allowing the BIOS to retain its system control and I/O interface control capabilities. The trusted security chip mediates the integrity verification process without interfering with BIOS control functions.
Data Source
AI summary
Measurement methods, devices and systems based on a trusted high-speed encryption card are disclosed. One of the methods includes: a BIOS actively measuring at least one firmware in a device if an integrity measurement result made by a trusted security chip for the BIOS indicates that the integrity thereof is not corrupted; loading one or more firmware if the integrity of the one or more firmware in the device actively measured by the BIOS is not corrupted; and forbidding a system of the device from being started or controlling the system to enter into a non-secure mode if the integrity of one or more firmware in the device actively measured by the BIOS is corrupted.


