Firmware Verification via Security Processor

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems rely heavily on proprietary verification processes and hardware-specific keys for ensuring firmware and recovery firmware integrity, which limits usability, customization, and user control while also being less secure against physical attacks.

Innovation Solution

A computing system that employs a security processor to verify system firmware and recovery firmware independently of an integrated circuit manufacturer's Mask ROM verification process, using firmware management parameters to define the verification process and relying on hash values for verification, thereby decoupling verification from hardware-specific keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-specific verification keys and write-protection features are used to ensure firmware integrity, then system security is improved, but usability and user control are limited

Engineering Contradiction:
Improvefirmware integrityVSAvoiduser control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a security processor as an intermediary component that manages verification keys and performs firmware verification independently of the main application processor. This mediator architecture allows the system to maintain security through hardware-specific keys while providing user control through software-based verification management, resolving the contradiction between security and usability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent divides the verification function into separate components: a security processor that handles cryptographic verification and a firmware management processor that handles verification logic. This segmentation allows hardware-specific security features to coexist with flexible software-based verification processes, enabling both security and user control.

Inventive Principle:
Principle #1Segmentation

2Reliability

If manufacturer's proprietary verification process with hardware-specific keys is used, then firmware authenticity is ensured, but adaptability and customization are limited

Engineering Contradiction:
Improvefirmware authenticityVSAvoidcustomization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic verification system where the verification process can be configured and modified through firmware management parameters. Instead of a fixed proprietary verification process, the system allows flexible configuration of verification behavior, enabling customization while maintaining authenticity through cryptographic verification.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security processor provides universal verification capabilities that can work with different firmware types and verification methods. The architecture supports multiple verification approaches (cryptographic verification, hash comparison) and can adapt to different customization needs while ensuring firmware authenticity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If write-protection features of system memory are relied upon to prevent firmware modification, then security is improved, but the system becomes vulnerable to physical attacks

Engineering Contradiction:
ImprovesecurityVSAvoidphysical attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces physical write-protection mechanisms with a computational verification system. Instead of relying on physical memory protection features that can be bypassed with physical access, the system uses cryptographic verification and hash comparison to ensure firmware integrity, making security independent of physical memory protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The security processor acts as an intermediary that performs verification before firmware execution, creating a layer of security that is independent of physical memory protection. This mediator approach ensures that even if physical write-protection is compromised, the verification process maintains security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If proprietary verification keys burned into hardware during manufacturing are used, then verification process is simplified, but user control and customization are unnecessarily limited

Engineering Contradiction:
Improveverification process complexityVSAvoiduser control
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent segments verification responsibilities: the security processor handles cryptographic operations with hardware keys, while the firmware management processor handles verification logic and user control. This segmentation simplifies the overall verification process while maintaining user control through software-based management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service verification where the security processor automatically performs cryptographic verification using hardware keys, while the firmware management processor provides user-controlled verification management. This reduces verification complexity while preserving user control through automated yet configurable verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4318285B1Secure verification of firmware
Publication Date: 2025.02.19 GOOGLE LLC
  • EP4318285B1 patent drawingFigure 1
  • EP4318285B1 patent drawingFigure 2A~2B
  • EP4318285B1 patent drawingFigure 3

AI summary

A computing system is described for securely verifying system firmware and recovery firmware to ensure system integrity without relying on a manufacture's proprietary verification process, hardware-specific keys, or inherent write-protection features of system memory. The computing system relies on a security processor that maintains firmware management parameters which define a process for verifying firmware and recovery firmware independent of an integrated circuit manufacturer's Mask ROM (read-only-memory) verification process. The security processor ensures that the firmware or recovery firmware is signed appropriately and consistent with previously executed versions, or if different, produces verification results (e.g., generated hash values) that are consistent with expected results embedded in the firmware, at compile time. In this way, the computing system improves usability, customization, and user control over the firmware and recovery firmware that is executed within the computing system.