Neutral CPU Secure Boot Policy via OTP Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems face challenges in maintaining security while allowing flexibility in hardware component reuse, as physical binding of hardware components restricts the re-use of CPUs between systems and limits flexibility in establishing trusted relationships.

Innovation Solution

Implementing a secure boot policy that allows neutral CPUs to be installed without fusing, with the policy stored in one-time-programmable storage, enabling verification and optional fusion, thereby establishing a trusted relationship and maintaining security without permanent binding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical binding of hardware components is implemented to create trusted relationships, then security is improved, but hardware component reusability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidhardware component reusability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the trust establishment process into two independent parts: (1) a secure boot policy stored in OTP memory that provides cryptographic verification, and (2) an optional fusing mechanism that can be selectively applied. This segmentation allows the system to achieve security through the secure boot policy while preserving CPU reusability by making fusing optional rather than mandatory.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure boot policy is configured in advance during system assembly, establishing cryptographic trust relationships before the CPU is installed or fused. This preliminary configuration of authentication keys and policies in OTP memory enables security verification to occur prior to any physical binding, allowing CPUs to remain unfused and reusable while maintaining security through pre-established cryptographic credentials.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If CPUs are fused to create trusted relationships, then security against malicious attacks is improved, but flexibility in CPU installation and reuse deteriorates

Engineering Contradiction:
Improvesecurity against malicious attacksVSAvoidCPU installation flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces dynamic configurability to the previously static fusing process. The secure boot policy in OTP memory contains configurable parameters that determine whether fusing is required, optional, or disabled. This dynamic approach allows the same hardware platform to adapt its security model based on deployment requirements, enabling CPUs to be installed and reused flexibly while maintaining security through cryptographic verification of the secure boot policy itself.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the security model from physical parameter binding (fused CPU identifiers) to cryptographic parameter verification (secure boot policy authentication). By storing authentication keys and policy parameters in OTP memory rather than fusing them into the CPU, the system maintains security through parameter verification while allowing the CPU hardware to remain unfused and reusable across different systems.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If neutral CPUs are allowed without fusing, then hardware reusability is improved, but establishing trusted relationships becomes more difficult

Engineering Contradiction:
ImproveCPU reusabilityVSAvoidtrusted relationship establishment
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a secure boot policy stored in OTP memory as an intermediary that mediates trust between the CPU and the system. Instead of requiring direct physical binding between CPU and motherboard, the OTP-stored policy acts as a cryptographic intermediary that verifies and establishes trusted relationships. This intermediary mechanism simplifies CPU reusability while maintaining security, as the same CPU can be authenticated through the secure boot policy without requiring system-specific fusing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11615190B2Secure boot policy for platform security using neutral processors in an information handling system
Publication Date: 2023.03.28 DELL PROD LP
  • US11615190B2 patent drawing
  • US11615190B2 patent drawing
  • US11615190B2 patent drawing

AI summary

A secure boot policy may be stored in the information handling system and used to create a trusted relationship with a CPU, including a neutral CPU that has not been fused with an OEM key. The secure boot policy may be a data blob including platform-specific identification information (e.g., one or more of flash memory unique ID, motherboard ePPID), a boot policy (e.g., specifying to enable or disable neutral CPU fusing), and a signature. The secure boot policy may be stored in a one-time-programmable (OTP) storage of the information handling system, such as an OTP region in the serial peripheral interface (SPI) flash memory part storing the basic input/output system (BIOS). The BIOS may verify the secure boot policy using a public key and check if the boot policy is bound to current BIOS flash part and/or system configuration, and then apply the boot policy if the verification is passed.