Firmware Downgrade Security Policy Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information handling systems lack the ability to control firmware downgrades effectively, leading to potential security vulnerabilities and operational issues when older firmware versions are necessary for compatibility or security mitigation.
Innovation Solution
An information handling system with a basic input/output system configured to update a system-wide firmware downgrade security policy before booting, allowing or disallowing firmware downgrades based on a processor-checking attribute, and storing or discarding firmware images accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If firmware downgrades are allowed without control, then system compatibility and security mitigation are improved, but system security is worsened due to potential installation of vulnerable older versions
Solution Approach 1:
The patent changes the parameter of firmware version control by introducing a configurable security policy attribute that can be set to allow or disallow downgrades. This parameter change enables flexible control over firmware version transitions, allowing administrators to permit downgrades when compatibility or security mitigation is needed while preventing them when security risks are concerned.
Solution Approach 2:
The patent implements feedback through the security policy attribute that provides system-wide control over firmware downgrade operations. The attribute feedback mechanism allows the system to respond to administrative decisions by either permitting or blocking downgrade attempts, creating a closed-loop control system that balances security and compatibility requirements.
2Reliability
If firmware downgrades are disallowed by default, then system security is improved, but system compatibility and security mitigation capabilities are worsened
Solution Approach 1:
The patent applies dynamics by making the firmware downgrade policy configurable rather than static. The security policy attribute can be dynamically changed by administrators to switch between allowing and disallowing downgrades, enabling the system to adapt its security posture based on specific operational requirements, compatibility needs, or threat landscapes.
Solution Approach 2:
The patent implements preliminary action by establishing the security policy attribute before firmware downgrade operations are attempted. This pre-configured attribute provides advance guidance to the firmware management system, allowing it to make informed decisions about whether to permit downgrade operations based on pre-established security and compatibility requirements.
3Manufacturing precision
If firmware images are stored in scratchpad for verification, then downgrade control accuracy is improved, but system resource usage is worsened
Solution Approach 1:
The patent extracts the firmware image temporarily into a scratchpad area for verification purposes during the downgrade control process. This extraction allows the system to examine the firmware image attributes and compare them against the security policy without permanently storing or executing the potentially problematic firmware, enabling precise control while limiting resource exposure.
Data Source
AI summary
An information handling system includes a basic input/output system configured to update an attribute of a system-wide firmware downgrade security policy prior to booting to an operating system of the information handling system. The attribute of the system-wide firmware downgrade security policy is used to determine whether to allow or to disallow downgrade of a firmware to a version. A processor may perform the downgrade of the firmware, wherein the downgrade of the firmware includes the processor further configured to check the attribute of the system-wide firmware downgrade security policy and to store a firmware image in a scratchpad. If the attribute of the system-wide firmware downgrade security policy allows the downgrade of the firmware to the version, then the processor may continue with the downgrade of the firmware otherwise discard the firmware image in the scratchpad.


