Hardware-Protected Firmware Measurement for Secure Boot Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing platform security mechanisms in computing systems are vulnerable to attacks on firmware, which undermines the establishment of a reliable chain of trust, as they require firmware interaction during system boot and are susceptible to malware exploitation.

Innovation Solution

A hardware-based approach that calculates and stores component measurements in registers without involving device firmware, allowing secure authentication and attestation by comparing new measurements to reference values, ensuring the integrity and authenticity of system components without relying on firmware interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware interaction is used during system boot for security mechanisms, then platform security can be implemented, but the system becomes vulnerable to firmware-based attacks and malware exploitation

Engineering Contradiction:
Improveplatform securityVSAvoidfirmware-based attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the measurement and validation functions from the firmware layer and places them in hardware registers that operate independently of firmware. The measurement register stores component measurements and the validation register contains expected values, allowing security verification to occur at the hardware level without firmware involvement, thus eliminating the attack surface while maintaining security functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces hardware registers as an intermediary between the system components and the security validation process. These registers act as a mediator that stores and compares measurements without requiring firmware interaction, creating a trusted path that bypasses the vulnerable firmware layer while still enabling comprehensive security checks

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firmware-based security mechanisms are implemented, then system authentication can be performed, but the authentication process becomes susceptible to malware spoofing

Engineering Contradiction:
Improvesystem authenticationVSAvoidauthentication integrity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the authentication verification process from the firmware domain and implements it in hardware registers that are inaccessible to firmware modification. By storing measurements of critical components (CPU, chipset, storage controller, boot device) in hardware registers and comparing them against expected values, the system achieves authentication that cannot be spoofed by malware since the comparison logic resides in immutable hardware

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If hardware-based measurement storage is implemented without firmware interaction, then security against firmware attacks is improved, but the device complexity increases

Engineering Contradiction:
Improvefirmware attack vulnerabilityVSAvoidhardware register structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the security validation functionality into distinct hardware registers: a measurement register for storing actual component measurements and a validation register for storing expected values. This segmentation allows the security function to be implemented as discrete, manageable hardware components rather than a complex monolithic structure, reducing implementation complexity while maintaining security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware registers are designed to automatically perform the measurement storage and validation comparison functions without requiring firmware assistance. The system processor can directly write measurements to the measurement register and read both registers to perform validation, making the security mechanism self-sufficient and eliminating the need for complex firmware-hardware interaction protocols

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260037634A1Hardware-protected system measurements
Publication Date: 2026.02.05 MICRON TECHNOLOGY INC
  • US20260037634A1 patent drawing
  • US20260037634A1 patent drawing
  • US20260037634A1 patent drawing

AI summary

Devices and techniques that provide hardware-protected system measurements are described herein. A system comprises a memory device accessible by a first device and a host device, wherein the first device is configured for use with the host device; processing circuitry coupled to the memory device; and programmable read-only memory coupled to the memory device, the programmable read-only memory comprising instructions to: initialize the first device; validate firmware that is to execute on the first device; obtain a measurement of the firmware; store the measurement in the memory device; and initiate execution of the firmware.