Firmware Controller Virtual ROM Link Secure Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure boot authentication methods do not extend to the firmware of hardware components stored in separate ROMs, leaving a potential security vulnerability as they cannot detect malware intrusion or firmware compromise in these components.
Innovation Solution
A firmware controller with secure boot authentication capabilities is connected to both the ROM and hardware components, exposing virtual ROM links that allow the controller to perform secure boot authentication of the firmware before permitting access, even for components with insufficient processing capability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware components store firmware in separate ROMs without centralized authentication, then device complexity is reduced and ease of manufacture is improved, but security reliability deteriorates due to inability to detect malware intrusion
Solution Approach 1:
The patent introduces a firmware controller as an intermediary component between the ROM and hardware components. This controller exposes virtual ROM links and performs centralized secure boot authentication, mediating access to firmware while maintaining security. The intermediary handles authentication requests from multiple hardware components without requiring them to have direct ROM access or built-in authentication capabilities.
Solution Approach 2:
The firmware controller serves multiple hardware components simultaneously through a single centralized authentication mechanism. It provides universal firmware authentication services to various components (USB controllers, network cards, storage devices) without requiring each component to have its own dedicated authentication system, thus improving reliability while controlling complexity.
2Reliability
If hardware components perform their own secure boot authentication, then firmware security is improved, but device complexity increases and processing requirements are elevated
Solution Approach 1:
The firmware controller acts as an intermediary that performs authentication on behalf of hardware components. Instead of each component performing its own authentication (which would increase complexity and processing requirements), the controller centralizes this function and provides authentication services to all components through virtual ROM links.
Solution Approach 2:
The firmware controller creates virtual copies of ROM links for each hardware component, allowing them to access firmware through authenticated virtual interfaces. This copying mechanism enables centralized authentication while maintaining the appearance of direct ROM access for each component, thus improving security without increasing component complexity.
3Reliability
If multiple separate ROMs are used for different hardware components, then ease of manufacture is improved and device complexity is reduced, but security reliability deteriorates due to lack of centralized control
Solution Approach 1:
The patent merges multiple separate ROM authentication functions into a single firmware controller that manages all hardware component firmware authentication. This consolidation provides centralized security control while maintaining a relatively simple manufacturing process, as the controller can be integrated into the existing system architecture without requiring complete redesign of individual component ROMs.
Data Source
AI summary
A read-only memory (ROM) stores firmware code for a hardware component. A firmware controller is directly physically connected to the hardware component and to the ROM. The firmware controller exposes a virtual ROM link to the hardware component. The hardware component accesses the firmware code over the virtual ROM link exposed by the firmware controller.


