Hardware Attestation via Boot Firmware Platform Certificate
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The industry lacks an effective approach for ensuring the security of hardware components and firmware in information handling systems against tampering during transit and after delivery, as existing security measures primarily focus on software security.
Innovation Solution
Incorporating a basic input/output system with boot firmware that executes a hardware attestation verification application, which reads a platform certificate, performs hardware attestation by comparing recorded information with stored information, and generates a log to verify the integrity of information handling system components before the operating system is executed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware attestation verification is implemented in the basic input/output system, then hardware security and integrity verification are improved, but device complexity increases
Solution Approach 1:
The patent implements hardware attestation verification in the basic input/output system before the operating system loads, performing security checks during the boot process. This preliminary action ensures hardware integrity is verified before any user-space software executes, preventing tampered systems from operating while maintaining a relatively simple overall architecture.
2Measurement precision
If hardware attestation is performed by comparing platform certificate information with stored information, then measurement precision of hardware integrity verification is improved, but loss of time during system boot increases
Solution Approach 1:
The patent extracts only the essential hardware identification information from the platform certificate into a compact stored representation during manufacturing. During boot, only this extracted information is compared against current hardware identifiers, rather than verifying the entire platform certificate. This extraction approach maintains high verification accuracy while significantly reducing the time and computational resources needed during the boot process.
Data Source
AI summary
A method may include, during execution of a basic input/output system comprising boot firmware configured to be the first code executed by the processor when the information handling system is booted and/or powered on and execute prior to execution of an operating system of the information handling system, executing a hardware attestation verification application configured to: (i) read a platform certificate comprising information associated with one or more information handling resources of the information handling system recorded during creation of the platform certificate; (ii) perform hardware attestation of the information handling system by comparing information associated with the one or more information handling resources and the information stored within the platform certificate; and (iii) generate a log indicative of the results of the hardware attestation.

