Platform Data Resiliency Mechanism for Boot Critical Firmware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current system-on-chip (SoC) platforms face security vulnerabilities due to firmware attacks, leading to privacy data leaks and system downtime, with existing firmware resiliency solutions focusing on secondary copies but not addressing data integrity and increasing costs.

Innovation Solution

Implementing a data resiliency mechanism that collects and stores encrypted boot critical data from various platform components in non-volatile storage, using a platform data resiliency component (PDRC) to provide data resiliency logic, including secondary firmware storage for backup and recovery, isolated from primary firmware to prevent unauthorized changes and attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secondary firmware storage is implemented for backup and recovery, then data resiliency and security are improved, but device complexity and storage requirements increase

Engineering Contradiction:
Improvedata resiliencyVSAvoidstorage structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the storage system into distinct primary and secondary firmware storage regions, each with specific functions. The primary storage holds the main firmware while secondary storage maintains backup copies and resiliency data, allowing independent management and recovery operations without affecting the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a firmware resiliency component as an intermediary layer between the hardware storage and the firmware operations. This component manages the complexity of backup, recovery, and resiliency operations, shielding the rest of the system from the underlying storage complexity while enabling robust data protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firmware resiliency solutions focus on secondary copies, then data recovery capability is improved, but costs increase due to additional storage and management overhead

Engineering Contradiction:
Improverecovery capabilityVSAvoidstorage resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the firmware storage with the existing storage pool, allowing secondary firmware copies to share storage resources with other system data. This consolidation eliminates the need for dedicated separate storage infrastructure, reducing overall storage requirements while maintaining recovery capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements selective copying of firmware data to secondary storage, creating backup copies only when necessary for resiliency purposes. The system intelligently determines which firmware images require backup and maintains appropriate copy retention policies, avoiding unnecessary duplication of all system data.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If encrypted boot critical data is collected and stored in non-volatile storage, then security against unauthorized changes is improved, but data management complexity increases

Engineering Contradiction:
Improveunauthorized changesVSAvoiddata management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the firmware resiliency component automatically performs encryption, backup, and integrity verification of boot critical data without requiring external intervention. The system autonomously manages the encrypted storage operations, reducing the burden on system administrators while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the state of firmware data from plaintext to encrypted form, fundamentally altering its parameters to protect against unauthorized access. The encryption transformation is applied systematically to boot critical data, changing its cryptographic properties while maintaining its functional integrity for authorized operations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11429496B2Platform data resiliency mechanism
Publication Date: 2022.08.30 INTEL CORP
  • US11429496B2 patent drawing
  • US11429496B2 patent drawing
  • US11429496B2 patent drawing

AI summary

An apparatus to facilitate data resiliency in a computer system platform is disclosed. The apparatus comprises a non-volatile memory to store data resiliency logic and one or more processors to execute the data resiliency logic to collect boot critical data from a plurality of platform components and store the data within the non-volatile memory.