Processor Microcode Update Authentication via Extended Secure Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current processor architectures face limitations in microcode patching due to the non-modifiable read-only memory storing microcode, which restricts updates and the small size of patch memory, making it difficult to address critical functionality and security issues post-manufacturing.
Innovation Solution
The solution involves extending microcode patching by utilizing on-die and off-die secure memory elements, such as sections of cache and system memory, to provide additional storage for microcode patches, allowing for secure and flexible updates beyond the manufacturing constraints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If read-only memory is used to store microcode, then microcode stability and security are improved, but microcode updatability deteriorates
Solution Approach 1:
The microcode storage is segmented into read-only memory (for stable, security-critical microcode) and separate updateable storage regions (for modifiable microcode patches). This segmentation allows the system to maintain stability of core microcode while enabling updates to specific microcode segments through authentication-based patching mechanisms.
2Quantity of substance
If patch memory size is increased, then microcode patching capability is improved, but device complexity increases
Solution Approach 1:
The patch memory architecture is designed to serve multiple functions: storing authentication data, storing microcode patches, and managing update sequences. By making the memory system multi-functional, the patent avoids adding separate dedicated components for each function, thereby increasing patching capability without proportionally increasing device complexity.
3Reliability
If authentication mechanisms are added to microcode updates, then update security is improved, but update speed deteriorates
Solution Approach 1:
Authentication data and verification mechanisms are prepared and integrated into the memory architecture in advance, before actual microcode updates occur. The authentication structures are pre-configured, allowing verification to proceed efficiently without adding significant overhead to the update process itself.
Data Source
AI summary
An apparatus and method are described for authenticating extended service microcode updates. For example, one embodiment of a method comprises: storing extended service microcode update (MCU) in a memory of a processor; reading processor signature data, platform identification data, and processor extended service data from one or more registers of the processor; identifying MCU extended service period data based on processor signature data and platform identification data; determining whether to apply the extended service MCU on the processor based on a comparison between the MCU extended service period data and the processor extended service data.


