Hardware Attestation via Boot Firmware Platform Certificate

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The industry lacks an effective approach for ensuring the security of hardware components and firmware in information handling systems against tampering during transit and after delivery, as existing security measures primarily focus on software security.

Innovation Solution

Incorporating a basic input/output system with boot firmware that executes a hardware attestation verification application, which reads a platform certificate, performs hardware attestation by comparing recorded information with stored information, and generates a log to verify the integrity of information handling system components before the operating system is executed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware attestation verification is implemented in the basic input/output system, then hardware security and integrity verification are improved, but device complexity increases

Engineering Contradiction:
Improvehardware securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements hardware attestation verification in the basic input/output system before the operating system loads, performing security checks during the boot process. This preliminary action ensures hardware integrity is verified before any user-space software executes, preventing tampered systems from operating while maintaining a relatively simple overall architecture.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If hardware attestation is performed by comparing platform certificate information with stored information, then measurement precision of hardware integrity verification is improved, but loss of time during system boot increases

Engineering Contradiction:
Improvehardware integrity verification accuracyVSAvoidboot time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts only the essential hardware identification information from the platform certificate into a compact stored representation during manufacturing. During boot, only this extracted information is compared against current hardware identifiers, rather than verifying the entire platform certificate. This extraction approach maintains high verification accuracy while significantly reducing the time and computational resources needed during the boot process.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11481497B2Systems and methods for hardware attestation in an information handling system
Publication Date: 2022.10.25 DELL PROD LP
  • US11481497B2 patent drawing
  • US11481497B2 patent drawing

AI summary

A method may include, during execution of a basic input/output system comprising boot firmware configured to be the first code executed by the processor when the information handling system is booted and/or powered on and execute prior to execution of an operating system of the information handling system, executing a hardware attestation verification application configured to: (i) read a platform certificate comprising information associated with one or more information handling resources of the information handling system recorded during creation of the platform certificate; (ii) perform hardware attestation of the information handling system by comparing information associated with the one or more information handling resources and the information stored within the platform certificate; and (iii) generate a log indicative of the results of the hardware attestation.