Privileged Firmware Mode Protection via Detection Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in efficiently protecting privileged firmware modes of computing devices from malicious access, as firmware updates are slow, difficult to distribute, and require device restarts, leaving devices vulnerable until updates are fully implemented.
Innovation Solution
A detection engine is implemented to intercept and analyze OS communications in the shared communication buffer, determining in real-time whether requests to access privileged firmware modes are anomalous or hazardous, and either denying or permitting these requests based on predefined policies that can be updated without requiring a device restart.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firmware updates are used to protect privileged firmware modes, then security protection is provided, but the update process is slow and devices remain vulnerable until updates are deployed
Solution Approach 1:
The patent segments the firmware protection mechanism into two parts: a static detection engine embedded in firmware that provides immediate protection, and a separate policy database that can be updated independently. This allows the detection engine to remain intact while security policies are updated remotely without requiring full firmware updates or device restarts.
Solution Approach 2:
The detection engine is pre-configured with the ability to enforce security policies locally on the device. When policy updates are deployed remotely, the device can immediately apply new security rules without waiting for a firmware update cycle, effectively performing preliminary protection actions before vulnerabilities can be exploited.
2Reliability
If firmware updates are distributed to protect against attacks, then security patches are applied, but the distribution and deployment process is difficult and time-consuming
Solution Approach 1:
The patent extracts the security policy component from the firmware update process. Instead of requiring full firmware updates to apply security patches, the policy database is separated and can be updated independently through lightweight remote deployments, significantly simplifying the distribution process.
Solution Approach 2:
The system transforms the static firmware update model into a dynamic policy update model. Security policies can be modified and deployed remotely in real-time based on emerging threats, allowing the security mechanism to adapt dynamically without the constraints of traditional firmware update cycles.
3Reliability
If firmware updates are implemented to address vulnerabilities, then protection is provided, but device restarts are required which users may delay
Solution Approach 1:
The detection engine operates autonomously within the firmware, continuously monitoring and enforcing security policies without requiring user intervention. When policies are updated remotely, the system self-applies the new rules immediately, eliminating the need for users to manually restart devices to activate security updates.
4Adaptability or versatility
If privileged firmware modes are accessed to support manufacturer-specific tasks, then full system control is available, but the system becomes vulnerable to malicious attacks
Solution Approach 1:
The patent introduces a detection engine as an intermediary layer between privileged firmware modes and system operations. This mediator monitors and controls access to privileged functions, allowing legitimate manufacturer-specific tasks to execute while blocking malicious attempts to exploit privileged mode vulnerabilities.
Data Source
AI summary
In one embodiment, a method includes accessing a request from a lower privileged process executing on a computing device to access a privileged firmware mode of the computing device and accessing a set of access policies for detecting whether the request is an unauthorized access to the privileged firmware mode. The method further includes determining, based on at least part of a content of the request and on the set of access policies, whether the request to access a privileged firmware mode is authorized; and denying or permitting, based on the determination, access by the lower privileged process to the privileged firmware mode.


