Multi-chip Firmware Storage for Unauthorized Modification Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unauthorized modifications of device firmware, such as BIOS, pose a significant threat due to their privileged position in device architecture, potentially leading to denial of service or persistent malware presence.
Innovation Solution
The method involves obtaining a firmware image, encrypting it, splitting the encrypted image into multiple portions, and storing these portions on multiple recovery chips. A threshold number of portions from different chips are required to reconstruct the original firmware image.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If firmware image is stored on a single chip, then ease of operation is improved, but security against unauthorized modification deteriorates
Solution Approach 1:
The firmware image is divided into multiple portions and stored on separate recovery chips. A threshold number of these portions are required to reconstruct the original firmware, making unauthorized modification significantly more difficult while maintaining operational functionality through distributed storage.
Solution Approach 2:
The patent implements a layered protection structure where the firmware image is first encrypted, then split into portions that are stored on multiple chips. This nested approach combines encryption with physical distribution, creating multiple barriers against unauthorized access while preserving the ability to restore firmware when needed.
2Object-affected harmful factors
If firmware image is split and stored on multiple chips, then security against unauthorized modification is improved, but device complexity increases
Solution Approach 1:
By segmenting the firmware image into portions stored on separate chips, the system achieves enhanced security without requiring complex protection mechanisms on each individual chip. The simplicity of each storage unit is maintained while the overall system gains robustness through distribution.
Solution Approach 2:
The patent changes the storage parameter from centralized to distributed across multiple chips. This parameter change simplifies the security model by relying on the mathematical properties of threshold reconstruction rather than implementing complex access control mechanisms, thereby reducing overall system complexity while improving security.
3Object-affected harmful factors
If threshold number of portions from multiple chips is required for reconstruction, then security is improved, but ease of repair deteriorates
Solution Approach 1:
The system performs preliminary actions by pre-distributing firmware portions across multiple chips and establishing the threshold reconstruction mechanism in advance. This allows for automated recovery processes where the system can autonomously reconstruct firmware from available portions without requiring complex manual intervention, thus maintaining ease of repair while ensuring security.
Solution Approach 2:
The firmware recovery system is designed to be self-service capable, where the threshold reconstruction mechanism automatically recovers firmware from the distributed portions on recovery chips without requiring external assistance. This self-healing capability simplifies the repair process while maintaining strong security through the distributed storage architecture.
Data Source
AI summary
Techniques are provided for firmware protection using multi-chip storage of firmware images. One method comprises obtaining a firmware image; encrypting the firmware image; splitting the encrypted firmware image into a plurality of encrypted firmware image portions; and storing the plurality of encrypted firmware image portions on a plurality of recovery chips, wherein a threshold number of the encrypted firmware image portions from at least two different recovery chips are needed to reconstruct the firmware image. The threshold number of the encrypted firmware image portions can be obtained from the at least two different recovery chips and a validation can be applied to the obtained encrypted firmware image portions. The threshold number of encrypted firmware image portions may be obtained in response to a chip that stores the firmware image being inactive.


