Unified Pre-Boot Firmware Update System for Secure Hardware Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional firmware update mechanisms for hardware resources in computing platforms often operate in a post-boot environment, creating security threats by providing entry points for attackers to inject malicious firmware, as different vendors use proprietary and independent systems for updating firmware.

Innovation Solution

A firmware update system is implemented to collectively handle firmware updates in a pre-boot environment, defining update states for managed hardware resources to enable and apply updates securely before loading the operating system, and then disabling updates to prevent unauthorized changes in the runtime environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If firmware updates are handled in a post-boot environment by multiple independent vendors, then each vendor can use their own proprietary update mechanism, but this creates multiple entry points for attackers to inject malicious firmware

Engineering Contradiction:
Improvevendor independenceVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent consolidates multiple independent firmware update mechanisms into a single unified firmware update system that operates in the pre-boot environment. This single system manages firmware updates for all hardware resources, eliminating the need for multiple separate vendor-specific mechanisms and thereby removing the corresponding multiple entry points that attackers could exploit.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs firmware update operations in the pre-boot environment before the operating system loads, rather than allowing updates during post-boot operation. This preliminary action ensures that firmware is updated before any potential malicious software could execute, and it establishes update control before the system becomes vulnerable to post-boot attacks.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple third-party firmware update mechanisms are used, then different vendors can manage their hardware independently, but this exposes multiple entry points that may be exploited to take control of the computing platform

Engineering Contradiction:
Improvevendor controlVSAvoidplatform security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges the firmware update control function into a single unified system that operates independently of vendor-specific mechanisms. This single system provides centralized control over firmware updates for all hardware resources, eliminating the distributed third-party mechanisms that created multiple attack vectors and compromised platform security.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If firmware updates are enabled in the runtime environment, then updates can be applied during system operation, but this creates continuous exposure to security threats

Engineering Contradiction:
Improveupdate availabilityVSAvoidattack exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent performs all firmware update operations in the pre-boot environment before the operating system loads, rather than enabling updates during runtime operation. This preliminary action window allows updates to be applied securely before the system becomes operational, eliminating continuous exposure to security threats while still ensuring updates are available and applied timely.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8898654B2Secure firmware updates
Publication Date: 2014.11.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8898654B2 patent drawing
  • US8898654B2 patent drawing
  • US8898654B2 patent drawing

AI summary

A firmware update system is described that collectively handles secure firmware updates for hardware resources in a defined and consistent manner. The firmware update system may be configured to manage at least some firmware updates in a pre-boot environment (e.g., before an operating system is loaded). By doing so, the firmware update system exercises control over the updates and reduce entry points exposed to attackers. In one approach, update states are defined for hardware resources that are managed by the firmware update system. In a pre-boot environment, the update states for the managed hardware resources are set to enable firmware updates. The firmware update system may then detect and apply firmware updates available for the managed hardware resources. Update states may be set to disable before loading the operating so that firmware updates for managed resources are disabled outside of the secure pre-boot environment.