Fixed Function Hardware Runtime Integrity Measurement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for ensuring the run-time integrity of hypervisors in virtualized environments, such as cloud computing, are inefficient and vulnerable to malware attacks, as they either impact system performance or are susceptible to the same security threats they aim to protect against, and lack visibility into the integrity of system software with full access privileges.

Innovation Solution

A dedicated fixed function hardware component within the processor is used to perform runtime integrity measurements, which includes hardware structures like a platform controller hub, securely interfacing with a trusted module to compare initial and run-time hash values of system software, and reporting integrity failures out-of-band to prevent interference with system operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software based methods are used to monitor run-time integrity of system software, then integrity verification is achieved, but system performance is negatively impacted due to stealing clock cycles from CPU

Engineering Contradiction:
Improveintegrity verificationVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces software-based integrity monitoring with a hardware-based solution. A dedicated fixed function hardware component is introduced that operates independently of the CPU, performing integrity measurements through hardware mechanisms rather than software routines. This substitution eliminates the performance penalty of stealing CPU clock cycles while maintaining integrity verification capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a trusted module as an intermediary between the hardware and the integrity verification process. This trusted module securely stores initial hash values and provides them to the fixed function hardware component, enabling integrity verification without direct CPU involvement. The intermediary architecture allows the system to verify integrity while the CPU remains fully available for productive work.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software based methods are used to monitor run-time integrity, then integrity monitoring is achieved, but the methods are subject to the same malware attacks as the system software they protect

Engineering Contradiction:
Improveintegrity monitoringVSAvoidmalware attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based integrity monitoring with hardware-based verification. The fixed function hardware component performs integrity measurements independently of the software stack, creating a security boundary that malware cannot compromise. Since the hardware operates at a lower level than the software it monitors, malicious software cannot infect or manipulate the verification process itself.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent segments the system into distinct layers: the trusted hardware layer that performs verification and the software layer that is being verified. This segmentation isolates the security-critical verification function from the potentially compromised software environment. The fixed function hardware component exists as a separate, protected entity that cannot be accessed or manipulated by malware running in the guest operating system or even the hypervisor.

Inventive Principle:
Principle #1Segmentation

3Reliability

If periodic rebooting of servers is performed to verify hypervisor integrity, then security verification is achieved, but service availability is negatively impacted

Engineering Contradiction:
Improvehypervisor integrity verificationVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements continuous periodic integrity verification through the fixed function hardware component, which automatically performs measurements at regular intervals without requiring system reboots. This continuous monitoring approach replaces the periodic reboot strategy, maintaining security verification while ensuring uninterrupted service availability. The hardware component operates autonomously in the background, verifying integrity without disrupting guest operating systems or hosted services.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent enables continuous integrity verification without interrupting normal system operations. The fixed function hardware component performs measurements continuously or periodically while the system remains fully operational, eliminating the need to stop services for verification. This continuous action maintains both security and productivity simultaneously, as the verification process runs concurrently with normal computing workloads.

Inventive Principle:
Principle #20Continuity of useful action

4Productivity

If dedicated fixed function hardware is used for runtime integrity measurements, then verification speed is improved and CPU clock cycles are preserved, but device complexity increases

Engineering Contradiction:
Improveverification speed and CPU availabilityVSAvoidhardware structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the integrity verification function from the main CPU and implements it as a dedicated fixed function hardware component. This extraction allows the verification function to operate independently with its own execution resources, improving verification speed without burdening the CPU. The component is self-contained with dedicated logic for performing hash comparisons, eliminating the need for complex software coordination while maintaining relatively simple hardware architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10146571B2Apparatus for hardware accelerated runtime integrity measurement
Publication Date: 2018.12.04 INTEL CORP
  • US10146571B2 patent drawing
  • US10146571B2 patent drawing
  • US10146571B2 patent drawing

AI summary

Techniques are described for providing processor-based dedicated fixed function hardware to perform runtime integrity measurements for detecting attacks on system supervisory software, such as a hypervisor or native Operating System (OS). The dedicated fixed function hardware is provided with memory addresses of the system supervisory software for monitoring. After obtaining the memory addresses and other information required to facilitate integrity monitoring, the dedicated fixed function hardware activates a lock-out to prevent reception of any additional information, such as information from a corrupted version of the system supervisory software. The dedicated fixed function hardware then automatically performs periodic integrity measurements of the system supervisory software. Upon detection of an integrity failure, the dedicated fixed function hardware uses out-of-band signaling to report that an integrity failure has occurred.The dedicated fixed function hardware provides for runtime integrity verification of a platform in a secure manner without impacting the performance of the platform.