Hardware Management via Delayed Write Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware management systems face challenges in securely updating hardware devices without relying on management controllers or side-band communications, which can introduce security threats and impair system operation.

Innovation Solution

A method that involves generating security data during startup, storing delayed writes in a secure environment, and validating them during subsequent startups to ensure only valid updates are implemented in secure registers, allowing updates to be executed during more secure phases without out-of-band mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If management controllers or side-band communications are used to update hardware devices, then hardware updates can be performed, but security threats are introduced and system operation is impaired

Engineering Contradiction:
Improvesystem securityVSAvoidhardware update capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the hardware update capability from the traditional management controller/side-band communication architecture and integrates it directly into the core processing device. This eliminates the need for separate management controllers and side-band communication interfaces, thereby removing the security threats associated with these components while preserving the ability to update hardware devices securely through normal privileged execution paths

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The processing device is designed to perform both core computing functions and hardware management functions using the same execution resources. The processor can execute privileged instructions to perform read-after-write operations for hardware updates, combining multiple functions into a single unified architecture that eliminates the need for dedicated management hardware and reduces the attack surface

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security data is generated during startup and validation is performed during subsequent startups, then only valid updates are implemented, but update execution is delayed until the next startup

Engineering Contradiction:
Improveupdate validation securityVSAvoidupdate execution delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions during the current execution phase by preparing and validating update data before the next startup. The read-after-write operation is initiated during the current execution phase, and the update data is prepared and stored in memory for subsequent execution. This allows the validation process to begin early, reducing the actual delay experienced during the next startup while maintaining security requirements

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuity of the update process across execution phases and startups. The update validation and preparation actions continue from the current execution phase into the next startup, rather than completely restarting the process. This continuous approach minimizes the perceived delay by keeping the update pipeline active and progressing through different stages across system boundaries

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12079376B2System and method for hardware management through operation update
Publication Date: 2024.09.03 DELL PROD LP
  • US12079376B2 patent drawing
  • US12079376B2 patent drawing
  • US12079376B2 patent drawing

AI summary

Methods and systems for managing the operation of data processing systems are disclosed. A data processing system may include a computing device that may perform various operations using hardware devices. The operation of the hardware devices may be updated by storing data in secure locations of the hardware devices. To store data in the secure locations, a delayed write may be stored in an unsecure storage location of a hardware devices during an unsecure phase of operation of a data processing system. Once the data processing system enters a more secure phase of operation, the delayed write may be validated and used to update the data in the secure locations during the more secure phase of operation of the data processing system.