Hardware Manifest Integrity Tracking via Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

It is challenging to determine whether a computing system or information handling device has been modified or is in its original state without close inspection, as existing methods lack effective tracking and protection mechanisms for hardware changes.

Innovation Solution

An apparatus and method for storing a hardware manifest, including a processor and memory that manages and protects the manifest by using unique signatures, encryption, and a read-only format, which tracks and logs modifications to hardware components, ensuring the manifest is secure and up-to-date.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If hardware components are replaced or repaired, then device functionality is maintained or improved, but device integrity and authenticity are compromised

Engineering Contradiction:
Improvedevice functionalityVSAvoiddevice integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system creates a hardware manifest recording the original hardware configuration before any modifications occur. This preliminary record serves as a baseline for future comparisons, allowing the system to detect when hardware components have been replaced or altered, thus maintaining device integrity awareness while permitting functional modifications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors hardware configuration changes by comparing current hardware states against the stored manifest. When modifications are detected, the system can trigger alerts, deny access, or log the changes, providing feedback mechanisms that maintain device integrity while allowing controlled functionality improvements.

Inventive Principle:
Principle #23Feedback

2Reliability

If hardware modifications are tracked, then device integrity is maintained, but system complexity increases

Engineering Contradiction:
Improvedevice integrityVSAvoidtracking system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a digital copy (manifest) of the hardware configuration that can be stored and compared without requiring complex real-time monitoring hardware. This copy-based approach simplifies the tracking mechanism while maintaining integrity verification capabilities through periodic or event-triggered comparisons.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The hardware manifest serves multiple functions: it records original configuration, enables change detection, provides audit trails, and can trigger security responses. This multi-functionality reduces the need for separate systems for each purpose, thereby managing complexity while maintaining comprehensive integrity tracking.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If hardware manifest is protected from modification, then security is enhanced, but accessibility for legitimate updates is reduced

Engineering Contradiction:
Improvemanifest securityVSAvoidmanifest accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different protection levels to different portions of the hardware manifest or different access paths. Critical integrity data may be stored in read-only memory or protected by cryptographic signatures, while other portions may allow controlled updates through authenticated processes, enabling both security and legitimate maintenance.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces an intermediary authentication mechanism that mediates between the protected manifest and modification requests. This intermediary verifies the legitimacy of update operations, allowing controlled accessibility for authorized maintenance while maintaining security against unauthorized modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10963269B2Apparatus, method, and program product for storing a hardware manifest
Publication Date: 2021.03.30 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US10963269B2 patent drawing
  • US10963269B2 patent drawing
  • US10963269B2 patent drawing

AI summary

Apparatus, methods, and program products are disclosed for storing a hardware manifest. One apparatus includes a processor and a memory that stores code executable by the processor. The code is executable by the processor to store a hardware manifest for an information handling device. The code is further executable by the processor to manage modification of the hardware manifest. Methods and computer program products that perform the functions of the apparatus are also disclosed.