Privileged Firmware Mode Protection via Detection Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in efficiently protecting privileged firmware modes of computing devices from malicious access, as firmware updates are slow, difficult to distribute, and require device restarts, leaving devices vulnerable until updates are fully implemented.

Innovation Solution

A detection engine is implemented to intercept and analyze OS communications in the shared communication buffer, determining in real-time whether requests to access privileged firmware modes are anomalous or hazardous, and either denying or permitting these requests based on predefined policies that can be updated without requiring a device restart.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware updates are used to protect privileged firmware modes, then security protection is provided, but the update process is slow and devices remain vulnerable until updates are deployed

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability window
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the firmware protection mechanism into two parts: a static detection engine embedded in firmware that provides immediate protection, and a separate policy database that can be updated independently. This allows the detection engine to remain intact while security policies are updated remotely without requiring full firmware updates or device restarts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The detection engine is pre-configured with the ability to enforce security policies locally on the device. When policy updates are deployed remotely, the device can immediately apply new security rules without waiting for a firmware update cycle, effectively performing preliminary protection actions before vulnerabilities can be exploited.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If firmware updates are distributed to protect against attacks, then security patches are applied, but the distribution and deployment process is difficult and time-consuming

Engineering Contradiction:
Improvesecurity patchingVSAvoidfirmware update distribution
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the security policy component from the firmware update process. Instead of requiring full firmware updates to apply security patches, the policy database is separated and can be updated independently through lightweight remote deployments, significantly simplifying the distribution process.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transforms the static firmware update model into a dynamic policy update model. Security policies can be modified and deployed remotely in real-time based on emerging threats, allowing the security mechanism to adapt dynamically without the constraints of traditional firmware update cycles.

Inventive Principle:
Principle #15Dynamics

3Reliability

If firmware updates are implemented to address vulnerabilities, then protection is provided, but device restarts are required which users may delay

Engineering Contradiction:
Improvevulnerability protectionVSAvoiddevice restart requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The detection engine operates autonomously within the firmware, continuously monitoring and enforcing security policies without requiring user intervention. When policies are updated remotely, the system self-applies the new rules immediately, eliminating the need for users to manually restart devices to activate security updates.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If privileged firmware modes are accessed to support manufacturer-specific tasks, then full system control is available, but the system becomes vulnerable to malicious attacks

Engineering Contradiction:
Improvesystem control capabilityVSAvoidmalicious attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a detection engine as an intermediary layer between privileged firmware modes and system operations. This mediator monitors and controls access to privileged functions, allowing legitimate manufacturer-specific tasks to execute while blocking malicious attempts to exploit privileged mode vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12333004B2Privileged firmware mode protection
Publication Date: 2025.06.17 SAMSUNG ELECTRONICS CO LTD
  • US12333004B2 patent drawing
  • US12333004B2 patent drawing
  • US12333004B2 patent drawing

AI summary

In one embodiment, a method includes accessing a request from a lower privileged process executing on a computing device to access a privileged firmware mode of the computing device and accessing a set of access policies for detecting whether the request is an unauthorized access to the privileged firmware mode. The method further includes determining, based on at least part of a content of the request and on the set of access policies, whether the request to access a privileged firmware mode is authorized; and denying or permitting, based on the determination, access by the lower privileged process to the privileged firmware mode.