Hardware Root of Trust SMI Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a security gap between the execution of boot code and the operating system in computing systems, making it difficult for the hardware root of trust (HRoT) to ensure computing system security during the boot process and runtime.

Innovation Solution

A computer-implemented method that receives custom boot codes from a security device to install a security module, configures a periodic System Management Interrupt (SMI), and validates configuration registers using a hardware root of trust device, ensuring secure execution and validation of the boot process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional boot process is used, then the system can boot and operate, but there is a security gap between boot code execution and OS runtime that prevents HRoT from ensuring system security

Engineering Contradiction:
Improvesystem securityVSAvoidboot process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by installing a security module during the boot process that proactively configures periodic SMI handlers and validation mechanisms before the OS runs. This pre-configuration enables continuous security validation during runtime, closing the security gap without requiring complex runtime interventions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security module that acts as a mediator between the HRoT and the boot process. This module captures SMI handlers, configures periodic validation, and communicates with HRoT to validate configuration registers, thereby enabling HRoT to provide security introspection during the boot process and runtime without directly interfering with normal operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If HRoT validates configuration registers continuously, then system security is maintained, but processing overhead and validation time increase

Engineering Contradiction:
Improveconfiguration register validationVSAvoidvalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies periodic action by configuring the security module to handle periodic System Management Interrupts (SMIs) rather than continuously validating configuration registers. The periodic SMI handlers validate configuration registers at scheduled intervals, maintaining security while reducing processing overhead and validation time compared to continuous validation.

Inventive Principle:
Principle #19Periodic action

3Adaptability or versatility

If custom boot codes are received and executed, then security module installation is enabled, but the boot process requires additional steps

Engineering Contradiction:
Improvesecurity module installationVSAvoidboot process steps
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies merging by combining the security module installation process with the existing boot process. The custom boot codes received from HRoT are integrated into the boot sequence, and the security module installation is merged with the initialization of system components. This integration allows security functionality to be established without requiring completely separate boot steps.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11379588B2System validation by hardware root of trust (HRoT) device and system management mode (SMM)
Publication Date: 2022.07.05 NIGHTWING GROUP LLC
  • US11379588B2 patent drawing
  • US11379588B2 patent drawing
  • US11379588B2 patent drawing

AI summary

Techniques are disclosed for assessment and verification of processor configuration and settings using System Management Mode (SMM) in conjunction with a hardware root of trust (HRoT). A method may include receiving custom boot codes from a security device, the custom boot codes configured to install a security module to process a periodic System Management Interrupt (SMI), configure the periodic SMI for initiation, and configure at least one configuration register for validation in response to execution of the security module. The method may also include responsive to initiation of the configured periodic SMI, validating, using the security device, the at least one configuration register.