IGV Controller OEM Component Validation in IHS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Non-supported components in information handling systems, such as dual in-line memory modules (DIMMs), can cause system instabilities and increase warranty costs due to lack of validation and potential manipulation, as existing identification methods are not secure and do not provide permanent protection against illegitimate components.
Innovation Solution
An information handling system with a securely generated unique identifier code validation method using a programmable device's identifier generation and validation (IGV) controller, which interfaces with BIOS/UEFI, performs decryption processes to verify the component's validity by comparing the generated component validation code with OEM proprietary codes, ensuring only OEM validated devices are enabled with advanced capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If easily identified or reverse engineered identification strings are used, then device identification is simplified, but security against third-party manipulation is compromised
Solution Approach 1:
The patent changes the parameter of identification string complexity by using permanently locked JEDEC standard contents in SPD EEPROM bytes 0-127 that cannot be read, written, or modified by third parties. This creates a secure identification mechanism that is both simple to implement and resistant to manipulation, resolving the contradiction between ease of operation and security.
Solution Approach 2:
The patent applies preliminary action by permanently locking the JEDEC standard contents during the manufacturing process before the device reaches the user. This preliminary locking prevents any future manipulation of the identification data, ensuring security while maintaining simplicity in subsequent operation.
2Reliability
If permanently locked JEDEC standard contents are used in SPD EEPROM, then security against third-party manipulation is improved, but the need to keep OEM area unlocked for programming creates complexity
Solution Approach 1:
The patent segments the SPD EEPROM into two distinct areas: bytes 0-127 containing permanently locked JEDEC standard contents that cannot be modified, and the OEM area (bytes 128-255 for DDR3, bytes 256-511 for DDR4) that remains unlocked for programming purposes. This segmentation allows simultaneous achievement of permanent protection and programming flexibility without complexity.
Solution Approach 2:
The patent applies local quality by providing different access characteristics to different parts of the SPD EEPROM. The JEDEC standard area has permanent read-only protection, while the OEM area maintains full read-write access for programming. This localized differentiation resolves the contradiction between security and programming capability.
3Ease of manufacture
If non-supported components are installed to reduce costs, then system cost is reduced, but system stability and operational margin are compromised
Solution Approach 1:
The patent implements feedback by using the IGV controller to read the permanently locked JEDEC standard contents from installed components and verify their authenticity against expected values. This feedback mechanism automatically detects non-supported components and can trigger appropriate responses, ensuring system stability while allowing cost-effective component selection.
Solution Approach 2:
The patent applies this principle by using inexpensive, permanently locked identification data in the SPD EEPROM to provide continuous verification of component authenticity. The low-cost locked contents enable ongoing security checks without requiring expensive complex verification systems, resolving the contradiction between cost and reliability.
Data Source
AI summary
A method validates whether a component/device installed within an information handling system (IHS) is an OEM (original equipment manufacturer) programmed device, by: reading identification (ID) data and an identifier code from the target device; generating a unique encrypted sequence using the ID data; providing a unique validation check code based on the ID data; generating a component validation code corresponding to the target device via a decryption process involving the unique encrypted sequence; and comparing the component validation code to the validation check code. The method further includes: in response to the component validation code matching the validation check code, identifying the target device as an OEM programmed device with a valid identifier code stored as the identifier code; and enabling certain processes reserved for only verified OEM programmed devices. The decryption process reverses an encryption process utilized when generating the unique OEM identifier code of the target device.


