Management Controller Validates Security Co-Processor Endorsement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in ensuring the authenticity and security of computing devices, particularly in preventing the replacement of security co-processors with counterfeit ones, which can compromise the integrity of the system.

Innovation Solution

A management controller is implemented to request and receive device unique data from the security co-processor during manufacturing and validate it during usage, ensuring that only the authentic security co-processor is used for booting the computing device by analyzing the endorsement information and stored representation of device unique data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the security co-processor is replaced with a counterfeit one, then device authenticity is compromised, but system security is weakened

Engineering Contradiction:
Improvedevice authenticityVSAvoidsystem security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary validation of the security co-processor during the boot process by verifying endorsement information and device unique data before allowing the system to operate. This prevents counterfeit co-processors from compromising system security by rejecting them before they can cause harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management controller continuously monitors and validates the security co-processor by comparing current endorsement information against stored reference values. This feedback mechanism detects counterfeit co-processors and prevents system boot, maintaining security while ensuring authenticity.

Inventive Principle:
Principle #23Feedback

2Reliability

If endorsement information validation is performed during boot, then system security is enhanced, but boot time increases

Engineering Contradiction:
Improvesystem securityVSAvoidboot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Endorsement information and device unique data are validated during the boot process before the operating system loads. By performing this security check early in the boot sequence, the system ensures security without requiring additional time during normal operation, as the validation is integrated into the existing boot timeline.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11580225B2Determine whether to perform action on computing device based on analysis of endorsement information of a security co-processor
Publication Date: 2023.02.14 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11580225B2 patent drawing
  • US11580225B2 patent drawing
  • US11580225B2 patent drawing

AI summary

Examples disclosed herein relate to a computing device that includes a central processing unit, a management controller separate from the central processing unit, and a security co-processor. The management controller is powered using an auxiliary power rail that provides power to the management controller while the computing device is in an auxiliary power state. The security co-processor includes device unique data. The management controller receives the device unique data and stores a representation at a secure location. At a later time, the management controller receives endorsement information from an expected location of the security co-processor. The management controller determines whether to perform an action on the computing device based on an analysis of the endorsement information and the stored representation of the device unique data.