Firmware Verification via Security Processor
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing systems rely heavily on proprietary verification processes and hardware-specific keys for ensuring firmware and recovery firmware integrity, which limits usability, customization, and user control while also being less secure against physical attacks.
Innovation Solution
A computing system that employs a security processor to verify system firmware and recovery firmware independently of an integrated circuit manufacturer's Mask ROM verification process, using firmware management parameters to define the verification process and relying on hash values for verification, thereby decoupling verification from hardware-specific keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-specific verification keys and write-protection features are used to ensure firmware integrity, then system security is improved, but usability and user control are limited
Solution Approach 1:
The patent introduces a security processor as an intermediary component that manages verification keys and performs firmware verification independently of the main application processor. This mediator architecture allows the system to maintain security through hardware-specific keys while providing user control through software-based verification management, resolving the contradiction between security and usability.
Solution Approach 2:
The patent divides the verification function into separate components: a security processor that handles cryptographic verification and a firmware management processor that handles verification logic. This segmentation allows hardware-specific security features to coexist with flexible software-based verification processes, enabling both security and user control.
2Reliability
If manufacturer's proprietary verification process with hardware-specific keys is used, then firmware authenticity is ensured, but adaptability and customization are limited
Solution Approach 1:
The patent implements a dynamic verification system where the verification process can be configured and modified through firmware management parameters. Instead of a fixed proprietary verification process, the system allows flexible configuration of verification behavior, enabling customization while maintaining authenticity through cryptographic verification.
Solution Approach 2:
The security processor provides universal verification capabilities that can work with different firmware types and verification methods. The architecture supports multiple verification approaches (cryptographic verification, hash comparison) and can adapt to different customization needs while ensuring firmware authenticity.
3Reliability
If write-protection features of system memory are relied upon to prevent firmware modification, then security is improved, but the system becomes vulnerable to physical attacks
Solution Approach 1:
The patent replaces physical write-protection mechanisms with a computational verification system. Instead of relying on physical memory protection features that can be bypassed with physical access, the system uses cryptographic verification and hash comparison to ensure firmware integrity, making security independent of physical memory protection.
Solution Approach 2:
The security processor acts as an intermediary that performs verification before firmware execution, creating a layer of security that is independent of physical memory protection. This mediator approach ensures that even if physical write-protection is compromised, the verification process maintains security.
4Device complexity
If proprietary verification keys burned into hardware during manufacturing are used, then verification process is simplified, but user control and customization are unnecessarily limited
Solution Approach 1:
The patent segments verification responsibilities: the security processor handles cryptographic operations with hardware keys, while the firmware management processor handles verification logic and user control. This segmentation simplifies the overall verification process while maintaining user control through software-based management.
Solution Approach 2:
The system implements self-service verification where the security processor automatically performs cryptographic verification using hardware keys, while the firmware management processor provides user-controlled verification management. This reduces verification complexity while preserving user control through automated yet configurable verification.
Data Source
Figure 1
Figure 2A~2B
Figure 3
AI summary
A computing system is described for securely verifying system firmware and recovery firmware to ensure system integrity without relying on a manufacture's proprietary verification process, hardware-specific keys, or inherent write-protection features of system memory. The computing system relies on a security processor that maintains firmware management parameters which define a process for verifying firmware and recovery firmware independent of an integrated circuit manufacturer's Mask ROM (read-only-memory) verification process. The security processor ensures that the firmware or recovery firmware is signed appropriately and consistent with previously executed versions, or if different, produces verification results (e.g., generated hash values) that are consistent with expected results embedded in the firmware, at compile time. In this way, the computing system improves usability, customization, and user control over the firmware and recovery firmware that is executed within the computing system.