Platform Data Resiliency Mechanism for Boot Critical Firmware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current system-on-chip (SoC) platforms face security vulnerabilities due to firmware attacks, leading to privacy data leaks and system downtime, with existing firmware resiliency solutions focusing on secondary copies but not addressing data integrity and increasing costs.
Innovation Solution
Implementing a data resiliency mechanism that collects and stores encrypted boot critical data from various platform components in non-volatile storage, using a platform data resiliency component (PDRC) to provide data resiliency logic, including secondary firmware storage for backup and recovery, isolated from primary firmware to prevent unauthorized changes and attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secondary firmware storage is implemented for backup and recovery, then data resiliency and security are improved, but device complexity and storage requirements increase
Solution Approach 1:
The patent segments the storage system into distinct primary and secondary firmware storage regions, each with specific functions. The primary storage holds the main firmware while secondary storage maintains backup copies and resiliency data, allowing independent management and recovery operations without affecting the entire system.
Solution Approach 2:
The patent introduces a firmware resiliency component as an intermediary layer between the hardware storage and the firmware operations. This component manages the complexity of backup, recovery, and resiliency operations, shielding the rest of the system from the underlying storage complexity while enabling robust data protection.
2Reliability
If firmware resiliency solutions focus on secondary copies, then data recovery capability is improved, but costs increase due to additional storage and management overhead
Solution Approach 1:
The patent merges the firmware storage with the existing storage pool, allowing secondary firmware copies to share storage resources with other system data. This consolidation eliminates the need for dedicated separate storage infrastructure, reducing overall storage requirements while maintaining recovery capability.
Solution Approach 2:
The patent implements selective copying of firmware data to secondary storage, creating backup copies only when necessary for resiliency purposes. The system intelligently determines which firmware images require backup and maintains appropriate copy retention policies, avoiding unnecessary duplication of all system data.
3Object-affected harmful factors
If encrypted boot critical data is collected and stored in non-volatile storage, then security against unauthorized changes is improved, but data management complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where the firmware resiliency component automatically performs encryption, backup, and integrity verification of boot critical data without requiring external intervention. The system autonomously manages the encrypted storage operations, reducing the burden on system administrators while maintaining high security standards.
Solution Approach 2:
The patent changes the state of firmware data from plaintext to encrypted form, fundamentally altering its parameters to protect against unauthorized access. The encryption transformation is applied systematically to boot critical data, changing its cryptographic properties while maintaining its functional integrity for authorized operations.
Data Source
AI summary
An apparatus to facilitate data resiliency in a computer system platform is disclosed. The apparatus comprises a non-volatile memory to store data resiliency logic and one or more processors to execute the data resiliency logic to collect boot critical data from a plurality of platform components and store the data within the non-volatile memory.


