Power Sequencer for Information Handling System Firmware Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information handling systems face issues during runtime resets due to incorrect voltage sequencing and unexpected behavior, such as entering a built-in self-test mode or taking internal unrecoverable errors, when an external Hardware Root of Trust (HWRoT) device holds the processor in reset for firmware authentication.
Innovation Solution
A power sequencer device is used to differentiate between runtime reset types like operating system restart and cold reset, ensuring proper voltage sequencing, and a HWRoT device is configured to authenticate information handling system firmware after receiving notifications from the power sequencer, while also determining if the power sequencer device has been compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the HWRoT device holds the processor in reset for firmware authentication during runtime resets, then firmware security is improved, but voltage sequencing becomes incorrect causing system errors
Solution Approach 1:
A power sequencer device is introduced as an intermediary between the HWRoT device and the processor. The power sequencer receives the hold processor in reset signal from the HWRoT device and generates the appropriate voltage sequencing signals to the processor, thereby mediating the conflict between firmware authentication requirements and voltage sequencing requirements
Solution Approach 2:
The system is segmented into distinct functional components: the HWRoT device responsible for security authentication, the power sequencer responsible for voltage sequencing control, and the processor responsible for system operations. This segmentation allows each component to perform its function independently without interfering with others
2Measurement precision
If the HWRoT device differentiates between runtime reset types, then authentication accuracy is improved, but device complexity increases
Solution Approach 1:
The power sequencer device preliminarily identifies the type of reset condition (runtime reset vs. cold reset) before initiating the firmware authentication process. By detecting reset type indicators in advance, the system can prepare the appropriate authentication sequence without adding complex real-time decision logic to the HWRoT device
Data Source
AI summary
In one or more embodiments, one or more systems, one or more methods, and/or one or more processes may determine that a platform reset signal from a processor of an information handling system has been asserted; may determine that a power conservation state from the processor was not asserted within an amount of time; may determine that an operating system restart occurred; may notify a hardware root of trust device to authenticate information handling system firmware; may assert a resume reset signal to the processor; may authenticate the information handling system firmware; may de-assert a power OK signal to the processor; may remove power from the processor; may determine that the resume reset signal to the processor is de-asserted and that the processor is out of the power conservation state; and may provide power to the processor.


