Multi-chip Firmware Storage for Unauthorized Modification Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized modifications of device firmware, such as BIOS, pose a significant threat due to their privileged position in device architecture, potentially leading to denial of service or persistent malware presence.

Innovation Solution

The method involves obtaining a firmware image, encrypting it, splitting the encrypted image into multiple portions, and storing these portions on multiple recovery chips. A threshold number of portions from different chips are required to reconstruct the original firmware image.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If firmware image is stored on a single chip, then ease of operation is improved, but security against unauthorized modification deteriorates

Engineering Contradiction:
Improvefirmware operationVSAvoidunauthorized modification
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The firmware image is divided into multiple portions and stored on separate recovery chips. A threshold number of these portions are required to reconstruct the original firmware, making unauthorized modification significantly more difficult while maintaining operational functionality through distributed storage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a layered protection structure where the firmware image is first encrypted, then split into portions that are stored on multiple chips. This nested approach combines encryption with physical distribution, creating multiple barriers against unauthorized access while preserving the ability to restore firmware when needed.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Object-affected harmful factors

If firmware image is split and stored on multiple chips, then security against unauthorized modification is improved, but device complexity increases

Engineering Contradiction:
Improveunauthorized modificationVSAvoidfirmware storage structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

By segmenting the firmware image into portions stored on separate chips, the system achieves enhanced security without requiring complex protection mechanisms on each individual chip. The simplicity of each storage unit is maintained while the overall system gains robustness through distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the storage parameter from centralized to distributed across multiple chips. This parameter change simplifies the security model by relying on the mathematical properties of threshold reconstruction rather than implementing complex access control mechanisms, thereby reducing overall system complexity while improving security.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If threshold number of portions from multiple chips is required for reconstruction, then security is improved, but ease of repair deteriorates

Engineering Contradiction:
Improvemalware presenceVSAvoidfirmware recovery
Core Design Contradiction:
Object-affected harmful factorsVSEase of repair

Solution Approach 1:

The system performs preliminary actions by pre-distributing firmware portions across multiple chips and establishing the threshold reconstruction mechanism in advance. This allows for automated recovery processes where the system can autonomously reconstruct firmware from available portions without requiring complex manual intervention, thus maintaining ease of repair while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The firmware recovery system is designed to be self-service capable, where the threshold reconstruction mechanism automatically recovers firmware from the distributed portions on recovery chips without requiring external assistance. This self-healing capability simplifies the repair process while maintaining strong security through the distributed storage architecture.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12265623B2Firmware protection using multi-chip storage of firmware image
Publication Date: 2025.04.01 EMC IP HLDG CO LLC
  • US12265623B2 patent drawing
  • US12265623B2 patent drawing
  • US12265623B2 patent drawing

AI summary

Techniques are provided for firmware protection using multi-chip storage of firmware images. One method comprises obtaining a firmware image; encrypting the firmware image; splitting the encrypted firmware image into a plurality of encrypted firmware image portions; and storing the plurality of encrypted firmware image portions on a plurality of recovery chips, wherein a threshold number of the encrypted firmware image portions from at least two different recovery chips are needed to reconstruct the firmware image. The threshold number of the encrypted firmware image portions can be obtained from the at least two different recovery chips and a validation can be applied to the obtained encrypted firmware image portions. The threshold number of encrypted firmware image portions may be obtained in response to a chip that stores the firmware image being inactive.