Hardware Integrity Validation via Platform Configuration Values

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing systems lack effective methods to protect hardware devices from unauthorized software modifications and malicious changes during the supply chain process or at customer locations, where attackers can reset platform configuration registers to deceive verification processes.

Innovation Solution

The method involves obtaining platform configuration values for hardware devices, comparing them to stored values in a platform configuration table, and performing automated remedial actions when discrepancies are found, using a combination of local and global configuration tables secured by a cryptographic module and an integrity validation monitor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If platform configuration registers are used to record software state, then hardware device integrity can be monitored, but attackers can reset these registers to deceive verification processes

Engineering Contradiction:
Improveintegrity monitoring reliabilityVSAvoidmalicious reset attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by computing and storing platform configuration values (PCVs) in advance during a reference state before the device is deployed to the customer environment. These pre-computed PCVs serve as the ground truth for later comparison, enabling the system to detect any deviations caused by malicious modifications or resets of platform configuration registers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism by using cryptographic hashing functions to transform platform configuration register values into platform configuration values (PCVs). This intermediary transformation layer obscures the actual register states while maintaining verifiable integrity, making it difficult for attackers to manipulate the verification process even if they can access or reset the underlying registers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If automated remedial actions are implemented upon detecting configuration discrepancies, then device protection is enhanced, but system complexity increases

Engineering Contradiction:
Improvedevice protectionVSAvoidintegrity validation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by implementing automated remedial actions that are triggered automatically when platform configuration value mismatches are detected. The system autonomously compares current PCVs against stored reference PCVs, identifies discrepancies, and executes pre-defined remediation protocols without requiring manual intervention, thereby enhancing device protection while managing complexity through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback mechanisms by continuously monitoring platform configuration values and comparing them against reference values, then using the comparison results to trigger appropriate remedial actions. This closed-loop feedback system automatically adjusts device states based on integrity verification outcomes, improving protection while maintaining manageable complexity through rule-based automated responses.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11853417B2Hardware device integrity validation using platform configuration values
Publication Date: 2023.12.26 EMC IP HLDG CO LLC
  • US11853417B2 patent drawing
  • US11853417B2 patent drawing
  • US11853417B2 patent drawing

AI summary

Techniques are provided for hardware device integrity validation using platform configuration values. One method comprises obtaining platform configuration values associated with software of a hardware device; comparing the obtained platform configuration values for the hardware device to one or more platform configuration values stored in a platform configuration table; and performing one or more automated remedial actions (e.g., initiating a reboot of the hardware device) based on a result of the comparison. The platform configuration values for the hardware device may be obtained from a local platform configuration value table of the hardware device. The platform configuration values for the hardware device may be obtained by an integrity validation monitor associated with the hardware device, and the integrity validation monitor may send the obtained platform configuration values for the hardware device to an integrity validation server that securely stores the platform configuration table and performs the comparison.