Processor Microcode Update Authentication via Extended Secure Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current processor architectures face limitations in microcode patching due to the non-modifiable read-only memory storing microcode, which restricts updates and the small size of patch memory, making it difficult to address critical functionality and security issues post-manufacturing.

Innovation Solution

The solution involves extending microcode patching by utilizing on-die and off-die secure memory elements, such as sections of cache and system memory, to provide additional storage for microcode patches, allowing for secure and flexible updates beyond the manufacturing constraints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If read-only memory is used to store microcode, then microcode stability and security are improved, but microcode updatability deteriorates

Engineering Contradiction:
Improvemicrocode stabilityVSAvoidmicrocode updatability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The microcode storage is segmented into read-only memory (for stable, security-critical microcode) and separate updateable storage regions (for modifiable microcode patches). This segmentation allows the system to maintain stability of core microcode while enabling updates to specific microcode segments through authentication-based patching mechanisms.

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If patch memory size is increased, then microcode patching capability is improved, but device complexity increases

Engineering Contradiction:
Improvepatch memory capacityVSAvoidmemory architecture complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patch memory architecture is designed to serve multiple functions: storing authentication data, storing microcode patches, and managing update sequences. By making the memory system multi-functional, the patent avoids adding separate dedicated components for each function, thereby increasing patching capability without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If authentication mechanisms are added to microcode updates, then update security is improved, but update speed deteriorates

Engineering Contradiction:
Improveupdate securityVSAvoidupdate speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Authentication data and verification mechanisms are prepared and integrated into the memory architecture in advance, before actual microcode updates occur. The authentication structures are pre-configured, allowing verification to proceed efficiently without adding significant overhead to the update process itself.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250005157A1System and method for authenticating extended service microcode updates
Publication Date: 2025.01.02 INTEL CORP
  • US20250005157A1 patent drawing
  • US20250005157A1 patent drawing
  • US20250005157A1 patent drawing

AI summary

An apparatus and method are described for authenticating extended service microcode updates. For example, one embodiment of a method comprises: storing extended service microcode update (MCU) in a memory of a processor; reading processor signature data, platform identification data, and processor extended service data from one or more registers of the processor; identifying MCU extended service period data based on processor signature data and platform identification data; determining whether to apply the extended service MCU on the processor based on a comparison between the MCU extended service period data and the processor extended service data.