Platform Properties Assessment Module for Trustworthy SMM Configuration Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer system configuration checkers cannot observe details restricted to System Management Mode (SMM) and can be subverted by their environment, leading to insecure configurations that may go undetected until discovered by security validation or malware writers.

Innovation Solution

The implementation of a Platform Properties Assessment Module (PPAM) that inspects the trusted portion of the SMI handler and generates a report on configuration and code integrity, using Trusted Execution Technology (TXT) to provide a hardware-rooted dynamic trust chain, allowing for trustworthy attestation of SMM and non-SMM components without relying on virtualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If conventional configuration checkers are used, then device complexity is reduced, but measurement precision of SMM configuration details deteriorates

Engineering Contradiction:
Improveconfiguration checker complexityVSAvoidSMM configuration observation accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent introduces an SMM driver as an intermediary component that runs within SMM to collect and report configuration details to the configuration checker. This mediator enables the checker to obtain precise SMM configuration information without requiring the checker itself to operate in SMM, thus maintaining low complexity while achieving high measurement precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If conventional configuration checkers are used, then ease of operation is maintained, but reliability of configuration assessment deteriorates

Engineering Contradiction:
Improveconfiguration checking operationVSAvoidconfiguration assessment trustworthiness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The SMM driver acts as a trusted intermediary that collects configuration data directly from SMM components, ensuring the data originates from a reliable source. The driver signs the configuration report with a key stored in secure hardware, providing cryptographic proof of authenticity and integrity, thus enhancing reliability while keeping the operation simple for the end user.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by having the SMM driver collect and sign configuration data before the configuration checker processes it. This advance preparation ensures that when the checker receives the data, its authenticity is already established, improving reliability without complicating the checker's operation.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If SMM configuration details are made observable, then measurement precision improves, but object-generated harmful factors increase

Engineering Contradiction:
ImproveSMM configuration observation accuracyVSAvoidsecurity vulnerabilities from exposed interfaces
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The SMM driver serves as a controlled intermediary that selectively exposes only the necessary configuration details to the configuration checker. By filtering and controlling what information is made observable, the system achieves measurement precision for critical parameters while minimizing the exposure of potentially harmful interfaces and details.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies different levels of observability to different parts of the SMM configuration. Critical configuration parameters are made observable with high precision, while other parts remain hidden or are exposed with reduced detail. This localized approach to information exposure balances measurement precision needs with security concerns.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10769269B2Method and apparatus to gather platform configuration profile in a trustworthy manner
Publication Date: 2020.09.08 INTEL CORP
  • US10769269B2 patent drawing
  • US10769269B2 patent drawing
  • US10769269B2 patent drawing

AI summary

Various embodiments are generally directed to an apparatus, method and other techniques for gathering configuration information of a computer system during a system management mode of the computer system and exposing the gathered configuration information to securely attest to the configuration of the system.